Authentication methods and related hardware based on quantum encryption technology

By establishing a secure key transmission channel in the security system through quantum encryption technology, the problem of data encryption algorithms being easily cracked in existing technologies is solved, achieving absolutely secure communication during the identity verification process and protecting user privacy.

CN117118609BActive Publication Date: 2026-01-06CHINA TELECOM CORP LTD TECHNOLOGY INNOVATION CENTER +1
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202311069414.5
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2023-08-23
Publication Date
2026-01-06
Estimated Expiration
2043-08-23

AI Technical Summary

Technical Problem

Existing security systems rely on mathematical principles in data encryption algorithms during user authentication, which are at risk of being cracked. This is especially true as computing power increases, posing a serious challenge to data security. Furthermore, the need to collect user privacy information makes it difficult to properly protect user privacy within the legal and compliant framework.

Method used

The authentication method employs quantum encryption technology. It establishes secure keys between servers through quantum key distribution (QKD) technology and uses quantum random number encryption to communicate between the authentication terminal and the server, ensuring absolute security of information transmission.

Benefits of technology

It achieves key transmission that is theoretically impossible to eavesdrop on, improves the security of encrypted communication between servers and between authentication terminals and servers, effectively addresses the security challenges brought about by increased computing power, and protects the security of user privacy information.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN117118609B_ABST
    Figure CN117118609B_ABST
Patent Text Reader

Abstract

Embodiments of the present application provide an identity verification method based on quantum encryption technology and related hardware, wherein an identity verification terminal sends identity verification request information of a target user collected in a quantum random number encryption mode to a first server. The first server encrypts at least part of the identity verification request information by using a first quantum key and sends the encrypted information to a second server. The second server decrypts the information by using the first quantum key to obtain at least part of the identity verification request information, generates identity verification response information according to a matching result in a database, encrypts the identity verification response information by using a second quantum key, and sends the encrypted information to the first server. The first server decrypts the information by using the second quantum key to obtain the identity verification response information, generates verification result information of the target user according to the identity verification response information, and sends the verification result information to the identity verification terminal in a quantum random number encryption mode. The identity verification terminal performs corresponding operations according to the verification result information.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This invention relates to the field of security technology, and more particularly to an authentication method and related hardware based on quantum encryption technology. Background Technology

[0002] This section is intended to provide background or context for the embodiments of this application as set forth in the claims. The description herein is not intended to be a prior art simply because it is included in this section.

[0003] With the advancement of technologies such as the Internet of Things (IoT), big data, and artificial intelligence (AI), security systems are rapidly developing towards intelligence. By leveraging IoT, big data, and AI technologies, security systems can collect, process, and analyze diverse types of security data to achieve intelligent management of security areas.

[0004] However, when security systems perform user authentication, even with authorization from users in accordance with relevant laws and regulations, they inevitably still need to collect personal privacy information (including user names, identification information, biometric identification information, etc.). To ensure that user privacy information is handled securely and legally, and to prevent its leakage, data security measures are necessary to protect it. Currently, the security of some common data security measures (such as data encryption algorithms) is based on the complexity of mathematical principles, and theoretically, they can be cracked. With the development of computer technology, the computing power of future computing devices may increase significantly, posing a serious challenge to the security of these data security measures. Summary of the Invention

[0005] This invention provides an authentication method and related hardware based on quantum encryption technology to improve the security of user privacy data transmission during the authentication process.

[0006] In a first aspect, embodiments of the present invention provide an authentication system, comprising:

[0007] An authentication terminal is connected to a first server and is used to send the collected authentication request information of the target user to the first server in a quantum random number encryption method; receive the verification result information returned by the first server in a quantum random number encryption method, and perform corresponding operations based on the verification result information;

[0008] The first server is also connected to the second server, and is configured to, upon receiving an authentication request message from a target user sent by an authentication terminal using quantum random number encryption, encrypt at least a portion of the authentication request message using a first quantum key obtained through quantum key distribution (QKD) technology to obtain a first ciphertext, and send the first ciphertext to the second server; receive the second ciphertext sent by the second server; decrypt the second ciphertext using the second quantum key obtained through QKD technology to obtain the authentication response message; generate authentication result information for the target user based on the authentication response information, and send the authentication result information to the authentication terminal using quantum random number encryption.

[0009] The second server is configured to receive a first ciphertext sent by the first server; decrypt the first ciphertext using a first quantum key obtained through QKD technology to obtain at least a portion of the authentication request information; match authentication data corresponding to the at least a portion of the authentication request information from a database, and generate authentication response information based on the matching result; encrypt the authentication response information using a second quantum key obtained through QKD technology to obtain a second ciphertext, and send the second ciphertext to the first server.

[0010] Furthermore, the authentication terminal sends the collected authentication request information of the target user to the first server using quantum random number encryption, specifically including: encrypting the authentication request information using a first symmetric key to obtain a third ciphertext; wherein the first symmetric key is determined by the authentication terminal based on a first quantum random number; encrypting the first symmetric key using a first PQC encryption / decryption algorithm with a first asymmetric public key to obtain a fourth ciphertext; and sending the third ciphertext and the fourth ciphertext to the first server.

[0011] The first server receives an authentication request message sent by the authentication terminal using quantum random number encryption. Specifically, this includes: receiving the third ciphertext and the fourth ciphertext sent by the authentication terminal; using the first PQC encryption and decryption algorithm with the first asymmetric private key to decrypt the fourth ciphertext to obtain the first symmetric key; and using the first symmetric key to decrypt the third ciphertext to obtain the authentication request message.

[0012] Furthermore, the first server sends the verification result information to the authentication terminal using quantum random number encryption, specifically including: sending a second symmetric key acquisition request to the authentication terminal; receiving the fifth ciphertext sent by the authentication terminal; decrypting the fifth ciphertext using the first asymmetric private key with the first PQC encryption / decryption algorithm to obtain the second symmetric key; encrypting the verification result information with the second symmetric key to obtain the sixth ciphertext, and sending the sixth ciphertext to the authentication terminal.

[0013] The authentication terminal receives the authentication result information returned by the first server using quantum random number encryption, specifically including: receiving a request to obtain the second symmetric key sent by the first server; encrypting the second symmetric key using the first PQC encryption / decryption algorithm with the first asymmetric public key to obtain the fifth ciphertext, and sending the fifth ciphertext to the first server; wherein the second symmetric key is determined by the authentication terminal based on the second quantum random number; receiving the sixth ciphertext sent by the first server; and decrypting the sixth ciphertext using the second symmetric key to obtain the authentication result information.

[0014] Optionally, the authentication response information includes the target user's historical location information and the time information corresponding to the historical location information;

[0015] The first server generates verification result information for the target user based on the authentication response information, specifically including:

[0016] Based on the target user's historical location information and the corresponding time information, filter out the target historical location information that is within the target location range and whose corresponding time information belongs to the target time period from all target historical location information;

[0017] Based on the time information corresponding to the filtered target historical location information, determine the total duration of time the target user is within the target location range during the target time period;

[0018] The identity of the target user is verified based on the total duration to obtain verification result information.

[0019] Optionally, the authentication system further includes:

[0020] A first quantum key distribution management device is connected to the first server and a second quantum key distribution management device, respectively, and is used to obtain the first quantum key and the second quantum key through QKD technology and provide them to the first server.

[0021] The second quantum key distribution management device is also connected to the second server and is used to obtain the first quantum key and the second quantum key through QKD technology and provide them to the second server.

[0022] Secondly, based on the same inventive concept, embodiments of the present invention also provide an authentication method based on quantum encryption technology, applied to a first server, comprising:

[0023] After receiving the authentication request information of the target user sent by the authentication terminal in the form of quantum random number encryption, the authentication request information is encrypted with at least a portion of the first quantum key obtained by quantum key distribution (QKD) technology to obtain the first ciphertext, and the first ciphertext is sent to the second server.

[0024] The second ciphertext sent by the second server is received; wherein the second ciphertext is generated by the second server after matching the at least part of the authentication request information.

[0025] The second ciphertext is decrypted using the second quantum key obtained through QKD technology to obtain the authentication response information;

[0026] The authentication result information for the target user is generated based on the authentication response information, and the authentication result information is sent to the authentication terminal using quantum random number encryption.

[0027] Furthermore, the receipt of the authentication request information sent by the authentication terminal using quantum random number encryption specifically includes:

[0028] The system receives a third ciphertext and a fourth ciphertext sent by the authentication terminal; wherein the third ciphertext is ciphertext obtained by the authentication terminal encrypting the authentication request information, and the fourth ciphertext is ciphertext obtained by the authentication terminal encrypting the key used to encrypt the third ciphertext.

[0029] The fourth ciphertext is decrypted using the first post-quantum cryptography PQC encryption and decryption algorithm with the first asymmetric private key to obtain the first symmetric key; wherein, the first symmetric key is determined by the authentication terminal based on the first quantum random number;

[0030] The third ciphertext is decrypted using the first symmetric key to obtain the authentication request information.

[0031] Furthermore, the step of sending the verification result information to the authentication terminal using quantum random number encryption specifically includes:

[0032] Send a second symmetric key acquisition request to the authentication terminal;

[0033] The system receives a fifth ciphertext sent by the authentication terminal; wherein the fifth ciphertext is ciphertext obtained by the authentication terminal encrypting a second symmetric key, and the second symmetric key is determined by the authentication terminal based on a second quantum random number.

[0034] The first PQC encryption and decryption algorithm is used to decrypt the fifth ciphertext using the first asymmetric private key to obtain the second symmetric key;

[0035] The verification result information is encrypted using the second symmetric key to obtain the sixth ciphertext, and the sixth ciphertext is sent to the authentication terminal.

[0036] Optionally, the authentication response information includes the target user's historical location information and the time information corresponding to the historical location information;

[0037] The step of generating verification result information for the target user based on the authentication response information specifically includes:

[0038] Based on the target user's historical location information and the corresponding time information, filter out the target historical location information that is within the target location range and whose corresponding time information belongs to the target time period from all target historical location information;

[0039] Based on the time information corresponding to the filtered target historical location information, determine the total duration of time the target user is within the target location range during the target time period;

[0040] The identity of the target user is verified based on the total duration to obtain verification result information.

[0041] Thirdly, based on the same inventive concept, an authentication method based on quantum encryption technology is applied to a second server, including:

[0042] Receive the first ciphertext sent by the first server;

[0043] The first ciphertext is decrypted using the first quantum key obtained through QKD technology to obtain the authentication request information of the target user; wherein the authentication request information is at least part of the information collected and encrypted by the authentication terminal from the target user and sent to the first server;

[0044] Match the authentication data corresponding to the authentication request information from the database, and generate authentication response information based on the matching result;

[0045] The authentication response information is encrypted using a second quantum key obtained through QKD technology to obtain a second ciphertext, which is then sent to the first server so that the first server can generate authentication result information for the target user based on the authentication response information and send it to the authentication terminal.

[0046] Fourthly, based on the same inventive concept, embodiments of the present invention provide an authentication method based on quantum encryption technology, applied to an authentication terminal, comprising:

[0047] The collected identity verification request information of the target user is sent to the first server in a quantum random number encryption method; so that the first server sends the first ciphertext to the second server, wherein the first ciphertext is obtained by the first server encrypting at least part of the identity verification request information based on the first quantum key obtained through QKD technology;

[0048] The system receives verification result information returned by the first server using quantum random number encryption, wherein the verification result information is generated by the first server based on the authentication response information, and the authentication response information is obtained by the first server decrypting the second ciphertext sent by the second server based on the second quantum key obtained through QKD technology.

[0049] Perform the corresponding operation based on the verification result information.

[0050] Furthermore, the step of sending the collected target user's authentication request information to the first server using quantum random number encryption includes:

[0051] The authentication request information is encrypted using a first symmetric key to obtain a third ciphertext; wherein the first symmetric key is determined by the authentication terminal based on a first quantum random number.

[0052] The first symmetric key is encrypted using the first PQC encryption and decryption algorithm with the first asymmetric public key to obtain the fourth ciphertext;

[0053] The third ciphertext and the fourth ciphertext are sent to the first server.

[0054] Furthermore, receiving the verification result information returned by the first server using quantum random number encryption specifically includes:

[0055] Receive the second symmetric key acquisition request sent by the first server;

[0056] The second symmetric key is encrypted using the first PQC encryption and decryption algorithm with the first asymmetric public key to obtain the fifth ciphertext, and the fifth ciphertext is sent to the first server; wherein the second symmetric key is determined by the authentication terminal based on the second quantum random number;

[0057] Receive the sixth ciphertext sent by the first server; wherein the sixth ciphertext is the ciphertext obtained by the first server encrypting the verification result;

[0058] The sixth ciphertext is decrypted using the second symmetric key to obtain the verification result information.

[0059] Fifthly, based on the same inventive concept, embodiments of the present invention also provide a first server, comprising:

[0060] The first encryption / decryption module is used to receive the identity verification request information of the target user sent by the identity verification terminal in a quantum random number encryption method;

[0061] The second encryption / decryption module is used to encrypt at least a portion of the authentication request information using a first quantum key obtained through quantum key distribution (QKD) technology to obtain a first ciphertext, and then send the first ciphertext to the second server.

[0062] The third encryption / decryption module is used to receive the second ciphertext sent by the second server; wherein the second ciphertext is generated by the second server after matching the at least part of the authentication request information; and the second ciphertext is decrypted using the second quantum key obtained through QKD technology to obtain the authentication response information.

[0063] The fourth encryption / decryption module is used to generate verification result information for the target user based on the authentication response information, and send the verification result information to the authentication terminal using quantum random number encryption.

[0064] Sixthly, based on the same inventive concept, embodiments of the present invention also provide a second server, comprising:

[0065] The first encryption / decryption module is used to receive a first ciphertext sent by a first server; and to decrypt the first ciphertext using a first quantum key obtained through QKD technology to obtain the authentication request information of the target user; wherein the authentication request information is at least a portion of the information collected and encrypted by the authentication terminal from the target user and sent to the first server.

[0066] The matching module is used to match the authentication data corresponding to the authentication request information from the database, and generate authentication response information based on the matching results;

[0067] The second encryption / decryption module is used to encrypt the authentication response information using a second quantum key obtained through QKD technology to obtain a second ciphertext, and send the second ciphertext to the first server so that the first server can generate authentication result information for the target user based on the authentication response information and send it to the authentication terminal.

[0068] Seventhly, based on the same inventive concept, embodiments of the present invention also provide an authentication terminal, comprising:

[0069] The first encryption / decryption module is used to send the collected identity verification request information of the target user to the first server in a quantum random number encryption method; so that the first server sends the first ciphertext to the second server, wherein the first ciphertext is obtained by the first server encrypting at least part of the identity verification request information based on the first quantum key obtained through QKD technology;

[0070] The second encryption / decryption module is used to receive the verification result information returned by the first server using quantum random number encryption, wherein the verification result information is generated by the first server based on the authentication response information, and the authentication response information is obtained by the first server decrypting the second ciphertext sent by the second server based on the second quantum key obtained through QKD technology.

[0071] The execution module is used to perform corresponding operations based on the verification result information.

[0072] Eighthly, based on the same inventive concept, embodiments of the present invention also provide an electronic device, including: a processor and a memory for storing processor-executable instructions;

[0073] The processor is configured to execute the instructions to implement the authentication method based on quantum encryption technology as described in the second aspect, or the authentication method based on quantum encryption technology as described in the third aspect, or the authentication method based on quantum encryption technology as described in the fourth aspect.

[0074] Ninthly, based on the same inventive concept, embodiments of the present invention also provide a computer-readable storage medium storing a computer program that is used to implement the authentication method based on quantum encryption technology as described in the second aspect, or to implement the authentication method based on quantum encryption technology as described in the third aspect, or to implement the authentication method based on quantum encryption technology as described in the fourth aspect.

[0075] The beneficial effects of this invention are as follows:

[0076] The authentication method and related hardware based on quantum encryption technology provided in this invention employ quantum encryption communication between servers located at considerable physical distances to encrypt and transmit identity information involving user privacy. Theoretically, quantum encryption communication technology can ensure the absolute security of the keys used for communication between servers during transmission, preventing eavesdropping. Simultaneously, quantum random number encryption is used for communication between the authentication terminal and the server, leveraging the unpredictable nature of quantum random numbers to ensure the key used in communication between the authentication terminal and the server is difficult to crack. This effectively improves the security of encrypted communication between servers and between the authentication terminal and the server, effectively addressing the security challenges brought about by increased computing power. Attached Figure Description

[0077] Figure 1 This is one of the structural schematic diagrams of the identity verification system provided in the embodiments of the present invention;

[0078] Figure 2 This is a second schematic diagram of the structure of the identity verification system provided in an embodiment of the present invention;

[0079] Figure 3 This is a schematic diagram of the workflow of the identity verification system provided in an embodiment of the present invention;

[0080] Figure 4 This is one of the schematic diagrams illustrating a partial workflow of the identity verification system provided in an embodiment of the present invention;

[0081] Figure 5 This is the second schematic diagram of a partial workflow of the identity verification system provided in this embodiment of the invention;

[0082] Figure 6 This is the third schematic diagram of a partial workflow of the identity verification system provided in this embodiment of the invention;

[0083] Figure 7 This is the fourth schematic diagram of a partial workflow of the identity verification system provided in this embodiment of the invention.

[0084] Figure 8 Fifth schematic diagram of a partial workflow of the identity verification system provided in this embodiment of the invention;

[0085] Figure 9 This is the sixth schematic diagram of a partial workflow of the identity verification system provided in this embodiment of the invention;

[0086] Figure 10 A flowchart illustrating an authentication method based on quantum encryption technology applied to an authentication terminal, as provided in an embodiment of the present invention;

[0087] Figure 11A flowchart illustrating an authentication method based on quantum encryption technology applied to a first server, as provided in an embodiment of the present invention;

[0088] Figure 12 A partial flowchart illustrating an authentication method based on quantum encryption technology applied to a first server, as provided in an embodiment of the present invention.

[0089] Figure 13 A flowchart illustrating an authentication method based on quantum encryption technology applied to a second server, as provided in an embodiment of the present invention;

[0090] Figure 14 This is a schematic diagram of the structure of the authentication terminal provided in an embodiment of the present invention;

[0091] Figure 15 This is a schematic diagram of the structure of the first server provided in an embodiment of the present invention;

[0092] Figure 16 This is a schematic diagram of the structure of the second server provided in an embodiment of the present invention;

[0093] Figure 17 This is a partial connection diagram of an authentication system provided in an embodiment of the present invention;

[0094] Figure 18 This is a schematic diagram of the structure of an electronic device provided in an embodiment of the present invention. Detailed Implementation

[0095] To make the above-mentioned objects, features, and advantages of the present invention more apparent and understandable, the present invention will be further described below in conjunction with the accompanying drawings and embodiments. However, the exemplary embodiments can be implemented in many forms and should not be construed as limited to the embodiments set forth herein; rather, these embodiments are provided to make the present invention more comprehensive and complete, and to fully convey the concept of the exemplary embodiments to those skilled in the art. The same reference numerals in the figures denote the same or similar structures, and therefore repeated descriptions of them will be omitted. Terms describing position and direction in the present invention are illustrative based on the accompanying drawings, but changes can be made as needed, and all such changes are included within the scope of protection of the present invention. The accompanying drawings of the present invention are for illustrative purposes only and do not represent actual proportions.

[0096] It should be noted that specific details are set forth in the following description to provide a full understanding of the invention. However, the invention can be practiced in many ways other than those described herein, and those skilled in the art can make similar extensions without departing from the spirit of the invention. Therefore, the invention is not limited to the specific embodiments disclosed below. The following description is a preferred embodiment for carrying out the present application; however, the description is for the purpose of illustrating the general principles of the application and is not intended to limit the scope of the application. The scope of protection of this application shall be determined by the appended claims.

[0097] The authentication method and related hardware based on quantum encryption technology provided in the embodiments of the present invention will be described in detail below with reference to the accompanying drawings. It should be stated that the acquisition, storage, use, and processing of data in the technical solutions of this application embodiments all comply with the relevant provisions of national laws and regulations.

[0098] In a first aspect, embodiments of the present invention provide an authentication system S, such as... Figure 1 and Figure 2 As shown, the system includes a first server E1, a second server E2, and an authentication terminal E3. The authentication terminal E3 is connected to the first server E1. The first server E1 is also connected to the second server E2. In practice, the connections between the first server E1 and the second server E2, and between the first server E1 and the authentication terminal E3, can be wired and / or wireless. These connections can include wired networks, wireless local area networks (WLANs), Bluetooth, cellular networks, NB-IoT, Zigbee, LoRa, etc., and are not limited here.

[0099] In the specific implementation process, such as Figure 1 and Figure 2 As shown, the authentication system may include at least one authentication terminal E3. The authentication terminal E3 can be a device of the same or different types and models; for example, the authentication terminal E3 may specifically be one or more of the following: a smart door lock, access control device, fixed / mobile / handheld authentication machine, etc. The first server E1 can be configured to be geographically close to the authentication terminal E3, used for managing and controlling the authentication terminal E3. The second server E2 can be configured as a server shared by multiple authentication systems S, connected to the first server E1 of each authentication system S, providing corresponding authentication functions for each authentication system S. Accordingly, the physical distance between the first server E1 and the second server E2 is relatively far.

[0100] The following section uses the data interaction process of authentication system S to illustrate the functions of authentication system S. For example... Figure 3 As shown, the authentication system S performs the following steps:

[0101] S1010, the authentication terminal collects the authentication request information of the target user.

[0102] Before performing step S1010, it is necessary to obtain the target user's authorization in accordance with the relevant laws and regulations. Only after obtaining the target user's authorization can the target user's identity verification request information be collected.

[0103] In the specific implementation process, the identity verification request information may include, but is not limited to, at least one of the following: the target user's name, the target user's identification number (e.g., ID card number, passport number, employee number, etc.), the target user's identification data information (e.g., data information stored in the chip of ID card, medical insurance card, bank card, etc.), the target user's biometric identification information (e.g., two-dimensional or three-dimensional face image, voice, fingerprint, palm print, iris information, etc.), password, and SMS verification code.

[0104] S1020, the authentication terminal sends the authentication request information to the first server using quantum random number encryption.

[0105] S1030, The first server decrypts the authentication request information received in the encrypted manner to obtain the authentication request information.

[0106] S1040, the first server, and the second server use quantum key distribution (QKD) technology to obtain the first quantum key.

[0107] QKD (Quantum Key Digitization) is a secure communication technology based on quantum mechanics principles, used to establish a secure key between communicating parties. The principle of QKD is as follows: The sender randomly generates a series of photons, each of which can be in multiple states (e.g., vertical and horizontal polarization). The sender then transmits the generated photons to the receiver via a quantum channel (e.g., optical fiber). Upon receiving the photons transmitted through the quantum channel, the receiver selects a random measurement basis for each photon and performs a quantum measurement. The sender and receiver then share their respective measurement basis but do not disclose the measurement results. By comparing the measurement basis of the sender and receiver, they can identify identical observations produced when observing the quantum using the same measurement basis. The two parties then determine the bit value of the quantum key based on these identical observations. During photon transmission, according to the Heisenberg uncertainty principle of quantum mechanics, the measurement of a quantum will interfere with its quantum state and cannot be copied. Therefore, if an eavesdropper attempts to steal the quantum, it will inevitably cause errors in the measurement results of both the sender and receiver, thus allowing them to discover that the quantum has been eavesdropped on. In this process, to ensure the security of the quantum key used each time, the photons generated by the sender need to be randomly generated, and the measurement basis used by the sender and receiver needs to be randomly selected. This ensures that the quantum key used each time is different, making it impossible to crack the ciphertext encrypted with the quantum key by analyzing the characteristics of the ciphertext and reversing the key.

[0108] S1050, The first server uses the first quantum key to encrypt at least part of the authentication request information to obtain the first ciphertext.

[0109] In practice, the authentication request instruction that matches the authentication request information can also be encrypted into the first ciphertext.

[0110] S1060, The first server sends the first ciphertext to the second server.

[0111] S1070, the second server uses the first quantum key to decrypt the first ciphertext and obtains at least part of the authentication request information.

[0112] S1080, The second server matches the authentication data corresponding to the at least part of the authentication request information from the database, and generates authentication response information based on the matching result.

[0113] In the specific implementation process, if the first ciphertext also includes an authentication request instruction, then step S1080 can be triggered by the decrypted authentication request instruction.

[0114] In practical implementation, when a match is successful, the authentication response information can be the authentication data corresponding to the authentication request information. For example, the authentication request information collected by the authentication terminal includes the target user's ID number and the face image to be verified. The first server encrypts the ID number into a first ciphertext and sends it to the second server. With the authorization of the corresponding user, the second server's database stores face images of different users. Therefore, the second server can send the target face image corresponding to the ID number in the database as the authentication response information to the first server. Alternatively, when a match is successful, the authentication response information can also be a successful match message generated by the second server. For example, the authentication request information collected by the authentication terminal includes the target user's ID number and the SMS verification code to be verified. The first server encrypts the ID number and the SMS verification code to be verified into a first ciphertext and sends it to the second server. With the authorization of the corresponding user, the second server's database stores SMS verification codes corresponding to different users. Therefore, when the second server determines that the target SMS verification code stored in the database matches the SMS verification code to be verified, it generates a successful match message as the authentication response information and sends it to the first server. When a match fails, the authentication response information can be a failed match message generated by the second server.

[0115] S1090, the first server, and the second server use QKD technology to obtain the second quantum key.

[0116] The second quantum key is a different key from the first quantum key. The process of obtaining the second quantum key is the same as that of obtaining the first quantum key, and will not be repeated here.

[0117] S1100, the second server uses the second quantum key to encrypt the authentication response information to obtain the second ciphertext.

[0118] S1110, The second server sends the second ciphertext to the first server.

[0119] S1120, The first server uses the second quantum key to decrypt the second ciphertext and obtain the authentication response information.

[0120] S1130. The first server generates verification result information for the target user based on the authentication response information.

[0121] Specifically, the verification result information includes two types of information: the target user's authentication is successful and the target user's authentication is unsuccessful.

[0122] In practice, if the authentication response information is a match success / failure message generated by the second server, the first server can directly generate authentication result information indicating whether the target user's authentication has passed / failed. If the authentication response information is authentication data corresponding to the authentication request information, the first server needs to generate authentication result information based on whether the authentication request information and the returned authentication data meet the authentication pass requirements. The authentication pass requirements can be set as the authentication request information being the same as or similar to authentication data of the same content type, or as the authentication data meeting preset rules, etc. For example, the authentication request information collected by the authentication terminal includes the target user's ID number and the face image to be verified. The first server encrypts the ID number into a first ciphertext and sends it to the second server. With the authorization of the corresponding user, the second server's database stores face images of different users. Therefore, the second server can send the target face image corresponding to the ID number in the database as authentication response information to the first server. The first server generates verification result information based on whether the similarity between the face image to be verified and the target face image is greater than a preset similarity threshold. If the similarity is greater than the preset similarity threshold, a verification result information indicating that the target user's identity verification has passed is generated. If the similarity is less than or equal to the preset similarity threshold, a verification result information indicating that the target user's identity verification has failed is generated.

[0123] S1140, The first server sends the verification result information to the authentication terminal using quantum random number encryption.

[0124] S1150, The authentication terminal decrypts the encrypted authentication result information.

[0125] S1160. The authentication terminal performs the corresponding operation based on the authentication result information.

[0126] In practice, the authentication terminal performs different corresponding operations based on the verification result. If the user's authentication is successful, it performs an operation indicating approval; if the user's authentication fails, it performs an operation indicating disapproval. Different types of authentication terminals may perform different operations based on the verification result. For example, for smart locks and access control terminals, when the verification result indicates successful authentication, the corresponding operation is to open the lock or turnstile to allow the user to pass; when the verification result indicates failed authentication, the corresponding operation is to close the lock or turnstile to prevent the user from passing. For mobile / handheld / fixed authentication machines, when the verification result indicates successful authentication, the corresponding operation is to notify the user that the user's authentication has succeeded; however, when the verification result indicates failed authentication, the corresponding operation is to notify the user that the user's authentication has failed. Furthermore, if the authentication machine is connected to an alarm light or bell, it can also trigger the alarm light or bell to indicate that the user's authentication has failed.

[0127] Thus, this invention provides an authentication system that uses quantum encryption communication between physically distant servers to encrypt and transmit user privacy-related identity information. By using quantum encryption communication technology and generating a new quantum key for each communication, theoretically, the keys used for communication between servers can be absolutely secure and cannot be eavesdropped on during transmission. Simultaneously, quantum random number encryption is used for communication between the authentication terminal and the server. Leveraging the truly random and unpredictable nature of quantum random numbers, the key used in communication between the authentication terminal and the server is extremely difficult to crack. This effectively improves the security of encrypted communication between servers and between authentication terminals and servers, effectively addressing the security challenges brought about by increased computing power.

[0128] Furthermore, in the communication process of the authentication system described above, steps S1020-S1030 and steps S1140-S1150 involve using quantum random number encryption to encrypt and transmit information, which can include the following encrypted communication approaches:

[0129] (1) One of the devices in the authentication terminal or the first server is equipped with a quantum random number generator (QRNG), which generates quantum random numbers by calling the integrated QRNG and generates a symmetric key based on the quantum random numbers.

[0130] In the authentication terminal and the first server, when the first device, which generates the symmetric key, needs to send information M1 to another device, namely the second device (if the first device is the authentication terminal, then the second device is the first server, and information M1 is the authentication request information; if the first device is the first server, then the second device is the authentication terminal, and information M1 is the authentication result information), the first device generates a symmetric key K1 using quantum random numbers, encrypts information M1 using the symmetric key K1 to obtain ciphertext SM1, and then encrypts the symmetric key K1 using the asymmetric public key PK1 of the Post-quantum cryptography (PQC) encryption / decryption algorithm F1 to obtain the key ciphertext KM1. The first device then sends the ciphertext SM1 and the key ciphertext KM1 to the second device. Upon receiving the ciphertext SM1 and the key ciphertext KM1, the second device decrypts the key ciphertext KM1 using the same asymmetric private key SK1 of the PQC encryption / decryption algorithm F1 to obtain the symmetric key K1. Finally, the second device uses the symmetric key K1 to decrypt the ciphertext SM1 to obtain information M1.

[0131] When the second device needs to send information M2 to the first device (if the first device is the first server, information M2 is an authentication request; if the first device is the authentication terminal, information M2 is the authentication result), the second device sends a request to the first device to obtain the symmetric key. The first device generates a symmetric key K2 using quantum random numbers, and encrypts the symmetric key K2 using the PQC encryption / decryption algorithm F1 and the asymmetric public key PK1 to obtain the ciphertext KM2, which is then sent to the second device. Upon receiving the ciphertext KM2, the second device decrypts the ciphertext KM2 using the same PQC encryption / decryption algorithm F1 and the asymmetric private key SK1, obtaining the symmetric key K2. Then, the second device uses the symmetric key K2 to encrypt information M2, obtaining the ciphertext SM2, which is sent to the first device. The first device uses the symmetric key K2 to decrypt the ciphertext SM2, obtaining the information M2.

[0132] The symmetric key K1 used by the first device to send information to the second device is different from the symmetric key K2 used by the second device to send information to the first device.

[0133] The following is a specific embodiment to illustrate the above solution.

[0134] Example 1:

[0135] like Figure 4 As shown, step S1020 specifically includes the following steps:

[0136] S1021A: The authentication terminal uses the first symmetric key to encrypt the authentication request information to obtain the third ciphertext.

[0137] The first symmetric key is determined by the authentication terminal based on the first quantum random number.

[0138] In the specific implementation process, the authentication terminal integrates QRNG, and the authentication terminal generates the first quantum random number by calling the integrated QRNG.

[0139] S1022A: The authentication terminal uses the first PQC encryption and decryption algorithm to encrypt the first symmetric key with the first asymmetric public key to obtain the fourth ciphertext.

[0140] S1023A, the authentication terminal sends the third and fourth ciphertexts to the first server.

[0141] In practical implementation, the authentication terminal can encrypt multiple authentication request messages using the same first symmetric key (for example, the authentication terminal generates a first symmetric key each time a new session is generated, and the third ciphertext sent to the first server through this session is encrypted using the same first symmetric key, so the fourth ciphertext only needs to be sent to the first server once when the first symmetric key is updated); or it can encrypt each authentication request message using a first symmetric key, that is, each time an authentication request message needs to be sent to the first server, a new first symmetric key is generated to encrypt the authentication request message, so the fourth ciphertext also needs to be sent to the first server each time the third ciphertext is sent.

[0142] Accordingly, such as Figure 4 As shown, step S1030 specifically includes the following steps:

[0143] S1031A, The first server receives the third and fourth ciphertexts sent by the authentication terminal.

[0144] S1032A, The first server uses the first PQC encryption and decryption algorithm and the first asymmetric private key to decrypt the fourth ciphertext and obtain the first symmetric key.

[0145] S1033A, The first server uses the first symmetric key to decrypt the third ciphertext to obtain the authentication request information.

[0146] Furthermore, such as Figure 5 As shown, step S1140 specifically includes the following steps:

[0147] S1141A, The first server sends a second symmetric key acquisition request to the authentication terminal.

[0148] S1142A, The authentication terminal uses the first PQC encryption algorithm to encrypt the second symmetric key with the first asymmetric public key to obtain the fifth ciphertext.

[0149] The second symmetric key is determined by the authentication terminal based on the second quantum random number. The specific implementation method for generating the second quantum random number can be the same as the corresponding implementation method for the first quantum random number mentioned above, and the determination of the second symmetric key can be the same as the corresponding implementation method for the first symmetric key mentioned above, which will not be repeated here.

[0150] S1143A, the authentication terminal sends the fifth ciphertext to the first server.

[0151] S1144A, The first server uses the first PQC encryption and decryption algorithm and the first asymmetric private key to decrypt the fifth ciphertext and obtain the second symmetric key.

[0152] S1145A, The first server uses the second symmetric key to encrypt the verification result information, resulting in the sixth ciphertext.

[0153] S1146A, The first server sends the sixth ciphertext to the authentication terminal.

[0154] In the specific implementation process, the first server can refer to the contents of the third and fourth ciphertexts generated by the authentication terminal mentioned above, select another second symmetric key to encrypt one or more authentication result information, and then send the obtained sixth ciphertext to the authentication terminal. The specific implementation method will not be described in detail here.

[0155] Accordingly, step S1150 specifically includes the following steps:

[0156] S1151A: The authentication terminal uses the second symmetric key to decrypt the sixth ciphertext and obtain the authentication result information.

[0157] (2) The authentication terminal is equipped with a QRNG. It generates quantum random numbers by calling the integrated QRNG and generates symmetric keys based on the quantum random numbers.

[0158] When the authentication terminal needs to send an authentication request to the first server, it generates a symmetric key K3 using quantum random numbers. The terminal then encrypts the authentication request using K3 to obtain ciphertext SM3. Next, it encrypts K3 using the asymmetric public key PK2 of the PQC encryption / decryption algorithm F2 to obtain ciphertext KM3. Both ciphertext SM3 and KM3 are sent to the first server. Upon receiving SM3 and KM3, the first server decrypts KM3 using the same asymmetric private key SK2 of the PQC encryption / decryption algorithm F2 to obtain the symmetric key K3. Finally, the first server uses K3 to decrypt SM3 to obtain the authentication request.

[0159] When the first server needs to send verification result information to the authentication terminal, it uses the symmetric key K3, which is used to encrypt the authentication request information corresponding to the verification result information, to encrypt the verification result information to obtain ciphertext SM4, and then sends ciphertext SM4 to the authentication terminal. Upon receiving ciphertext SM4, the authentication terminal decrypts it using the symmetric key K3, which was used to encrypt the authentication request information corresponding to the verification result information, to obtain the verification result information.

[0160] The following is a specific embodiment to illustrate the above solution.

[0161] Example 2:

[0162] The specific implementation process of steps S1020 and S1030 is the same as that in Example 1, which can be found in [reference 1]. Figure 4 The illustrated process.

[0163] Furthermore, such as Figure 6 As shown, step S1140 specifically includes the following steps:

[0164] S1141B, The first server uses the first symmetric key to encrypt the verification result information, obtaining the seventh ciphertext.

[0165] S1142B, The first server sends the seventh ciphertext to the authentication terminal.

[0166] In the specific implementation process, the first server can refer to the content of the third and fourth ciphertexts generated by the authentication terminal in Embodiment 1 above, select another first symmetric key to encrypt one or more authentication result information, and then send the obtained seventh ciphertext to the authentication terminal. The specific implementation method is not described here.

[0167] Accordingly, such as Figure 6As shown, step S1150 specifically includes the following steps:

[0168] S1151B, the authentication terminal receives the seventh ciphertext sent by the first server.

[0169] S1152B: The authentication terminal uses the first symmetric key to decrypt the seventh ciphertext and obtain the authentication result information.

[0170] (3) The first server integrates QRNG, which generates quantum random numbers by calling the integrated QRNG, and generates symmetric keys based on the quantum random numbers.

[0171] When the authentication terminal needs to send an authentication request to the first server, it sends a request to obtain a symmetric key. The first server generates a symmetric key K4 using quantum random numbers, and encrypts it with an asymmetric public key PK3 using the PQC encryption algorithm F3 to obtain ciphertext KM4, which is then sent to the authentication terminal. Upon receiving ciphertext KM4, the authentication terminal decrypts it using the same PQC encryption algorithm F3 and its asymmetric private key SK3, obtaining the symmetric key K4. Then, the authentication terminal uses symmetric key K4 to encrypt the authentication request information, obtaining ciphertext SM5, which it sends to the first server. The first server uses symmetric key K4 to decrypt ciphertext SM5, obtaining the authentication request information.

[0172] When the first server needs to send verification result information to the authentication terminal, it uses the symmetric key K4, which is used to encrypt the authentication request information corresponding to the verification result information, to encrypt the verification result information into ciphertext SM6, and then sends ciphertext SM6 to the authentication terminal. Upon receiving ciphertext SM6, the authentication terminal decrypts it using the symmetric key K4, which was used to encrypt the authentication request information corresponding to the verification result information, to obtain the verification result information.

[0173] The following is a specific embodiment to illustrate the above solution.

[0174] Example 3:

[0175] like Figure 7 As shown, step S1020 specifically includes the following steps:

[0176] S1021C: The authentication terminal sends a request to the first server to obtain the third symmetric key.

[0177] S1022C, The first server uses the first PQC encryption algorithm to encrypt the third symmetric key with the first asymmetric public key to obtain the eighth ciphertext.

[0178] The third symmetric key is determined by the first server based on the third quantum random number. The specific implementation method for generating the third quantum random number is similar to the corresponding implementation methods for the first and second quantum random numbers in Embodiment 1 above. The determination of the third symmetric key can be the same as the corresponding implementation methods for the first and second symmetric keys in Embodiment 1 above, and will not be repeated here.

[0179] S1023C, The first server sends the eighth ciphertext to the authentication terminal.

[0180] S1024C: The authentication terminal uses the first PQC encryption and decryption algorithm and the first asymmetric private key to decrypt the eighth ciphertext and obtain the third symmetric key.

[0181] S1025C: The authentication terminal uses the third symmetric key to encrypt the authentication request information, resulting in the ninth ciphertext.

[0182] S1026C, the authentication terminal sends the ninth ciphertext to the first server.

[0183] In the specific implementation process, the first server can refer to the content of the third ciphertext generated by the authentication terminal as described in Embodiment 1 above, select another third symmetric key to encrypt one or more authentication request information, and then send the obtained ninth ciphertext to the first server. The specific implementation method will not be described in detail here.

[0184] Accordingly, such as Figure 7 As shown, step S1030 specifically includes the following steps:

[0185] S1031C, The first server receives the ninth ciphertext sent by the authentication terminal.

[0186] S1032C: The first server uses the third symmetric key to decrypt the ninth ciphertext and obtain the authentication request information.

[0187] Furthermore, such as Figure 8 As shown, step S1140 specifically includes the following steps:

[0188] S1141C, The first server uses the third symmetric key to encrypt the verification result information, obtaining the tenth ciphertext.

[0189] S1142C, The first server sends the tenth ciphertext to the authentication terminal.

[0190] In the specific implementation process, the first server can refer to the content of the third and fourth ciphertexts generated by the authentication terminal in Embodiment 1 above, select another third symmetric key to encrypt one or more authentication result information, and then send the obtained tenth ciphertext to the authentication terminal. The specific implementation method is not described here.

[0191] Accordingly, such as Figure 8 As shown, step S1150 specifically includes the following steps:

[0192] S1151C: The authentication terminal receives the tenth ciphertext sent by the first server.

[0193] S1152C: The authentication terminal uses the third symmetric key to decrypt the tenth ciphertext and obtain the authentication result information.

[0194] (4) Both the authentication terminal and the first server are integrated with QRNG. The integrated QRNG is called to generate quantum random numbers and generate symmetric keys based on the quantum random numbers.

[0195] In the authentication terminal and the first server, when one device (the first device) needs to send information M3 to another device (the second device) (if the first device is the authentication terminal, then the second device is the first server, and information M3 is an authentication request; if the first device is the first server, then the second device is the authentication terminal, and information M3 is the authentication result), the first device generates a symmetric key K5 using quantum random numbers, encrypts information M3 using symmetric key K5 to obtain ciphertext SM7, and then encrypts symmetric key K5 using the asymmetric public key PK4 of PQC encryption / decryption algorithm F4 to obtain key ciphertext KM5. The first device then sends information ciphertext SM7 and key ciphertext KM5 to the second device. Upon receiving information ciphertext SM7 and key ciphertext KM5, the second device decrypts key ciphertext KM5 using the same asymmetric private key SK4 of PQC encryption / decryption algorithm F4 to obtain the symmetric key K5. Then, the second device uses symmetric key K5 to decrypt information ciphertext SM7 to obtain the first information M3.

[0196] In the process of the authentication terminal sending authentication request information to the first server, the symmetric key K5 generated is different from that generated when the first server sends authentication result information to the authentication terminal. The PQC encryption and decryption algorithm F4 used can be the same or different. If the PQC encryption and decryption algorithm F4 is the same, the asymmetric key pair (i.e., the asymmetric public key PK4 and the corresponding asymmetric private key SK4) used in the two processes—the authentication terminal sending authentication request information to the first server and the first server sending authentication result information to the authentication terminal—is different.

[0197] The following is a specific embodiment to illustrate the above solution.

[0198] Example 4:

[0199] The specific implementation process of steps S1020 and S1030 is the same as that in Example 1, which can be found in [reference 1]. Figure 4 The illustrated process.

[0200] Furthermore, such as Figure 9 As shown, step S1140 specifically includes the following steps:

[0201] S1141D: The first server uses the fourth symmetric key to encrypt the verification result information, obtaining the eleventh ciphertext.

[0202] The fourth symmetric key is determined by the first server based on the fourth quantum random number.

[0203] In the specific implementation process, the first server generates the fourth quantum random number by calling its integrated QRNG. The specific implementation methods for generating the fourth quantum random number and determining the fourth symmetric key can be referred to the corresponding content of the first server in Embodiment 3 above, and will not be repeated here.

[0204] S1142D: The first server uses the second PQC encryption and decryption algorithm to encrypt the second symmetric key with the second asymmetric public key to obtain the twelfth ciphertext.

[0205] In specific implementation, the second PQC encryption / decryption algorithm may be the same as or different from the first PQC encryption / decryption algorithm. This embodiment of the invention does not impose further limitations here. The specific implementation of the second PQC encryption / decryption algorithm can be referred to the corresponding content of the first PQC encryption / decryption algorithm in Embodiment 1 above, and will not be repeated here.

[0206] S1143D, the first server sends the eleventh and twelfth ciphertexts to the authentication terminal.

[0207] In the specific implementation process, the first server can refer to the content of the third and fourth ciphertexts generated by the authentication terminal in Embodiment 1 above, select another fourth symmetric key to encrypt one or more authentication result information, and then send the obtained eleventh and twelfth ciphertexts to the authentication terminal. The specific implementation methods are not described here.

[0208] Accordingly, such as Figure 9 As shown, step S1150 specifically includes the following steps:

[0209] S1151D, the authentication terminal receives the eleventh and twelfth ciphertexts sent by the first server.

[0210] S1152D: The authentication terminal uses the second PQC encryption and decryption algorithm and the second asymmetric private key to decrypt the twelfth ciphertext and obtain the fourth symmetric key.

[0211] S1153D: The authentication terminal uses the fourth symmetric key to decrypt the eleventh ciphertext and obtain the authentication result information.

[0212] In the specific implementation process, for the process of generating symmetric keys using quantum random numbers, the generated quantum random numbers can be directly used as the symmetric key, or the quantum random numbers can be pre-processed and transformed (e.g., selecting specific bits of the quantum random numbers to combine into a symmetric key, or swapping some bits of the quantum random numbers to use as a symmetric key, etc.) before being used as the symmetric key. This invention does not impose many limitations on this. The PQC algorithm can use algorithms such as McEliece, the Number Theory Research Unit (NTRU), and lattice-based cryptography. This invention does not impose many limitations on this. QRNGs can be classified as either the first type, i.e., quantum random number generators that utilize the random properties of quantum mechanics in microscopic physics to obtain truly random quantum random numbers by observing microscopic physical phenomena (including the quantum states of light quanta or the spin states of atoms); or the second type, i.e., quantum random number generators that utilize the reflection of microscopic physics in macroscopic physics to obtain truly random quantum random numbers by observing macroscopic physical phenomena (including the decay of radioactive materials, temperature noise of heat sources, radio noise, etc.).

[0213] Since current known technologies, including those still under research in quantum computing, cannot effectively crack the PQC encryption and decryption algorithm, this method effectively enhances the communication security between the authentication terminal and the primary server, ensuring that user privacy information is not leaked during communication. This effectively addresses the security challenges brought about by increased computing power. Furthermore, encrypting transmitted information through this process is less costly and less difficult to implement than using quantum key encryption, making it easier for widespread adoption.

[0214] Building upon this, to further enhance the communication security between the authentication terminal and the first server, ciphertexts containing different information can be transmitted through different channels. Specifically, the ciphertext obtained by encrypting the authentication request information and the authentication result information, and the ciphertext obtained by encrypting the symmetric key used to encrypt the authentication request information and the authentication result information, are transmitted using separate ciphertext channels and key ciphertext channels. This prevents eavesdroppers from simultaneously obtaining both the ciphertext containing the original text and the ciphertext of the key used to encrypt the original text during communication. The channels mentioned include physical channels or logical channels.

[0215] As an optional implementation, the first server and the second server can integrate modules for implementing QKD technology, so as to obtain the first quantum key and the second quantum key by calling the corresponding QKD module.

[0216] As another alternative implementation, in order to reduce the manufacturing costs of the first server and the second server, such as Figure 2 As shown, the authentication system also includes:

[0217] The first quantum key distribution management device E4 is connected to the first server E1 and the second quantum key distribution management device E5, respectively, and is used to obtain the first quantum key and the second quantum key through QKD technology and provide them to the first server.

[0218] The second quantum key distribution management device E5 is also connected to the second server E2, and is used to obtain the first quantum key and the second quantum key through QKD technology and provide them to the second server.

[0219] In the specific implementation process, the first quantum key distribution management device E4 and the second quantum key distribution management device E5 are connected through a quantum channel (such as quantum fiber).

[0220] In practice, quantum key distribution management equipment can be set up in a location that is very close to the physical location of the corresponding server (e.g., in the same computer room).

[0221] Furthermore, if the physical distance between the quantum key distribution management device and the corresponding server is large, posing a high risk of eavesdropping during communication, the quantum key distribution management device can, after obtaining the quantum key, encrypt it using a fifth symmetric key to obtain a thirteenth ciphertext. This fifth symmetric key is determined by the quantum key distribution management device generating a fifth quantum random number. The fifth symmetric key is then encrypted using a third asymmetric public key with a third PQC encryption / decryption algorithm to obtain a fourteenth ciphertext. Both the thirteenth and fourteenth ciphertexts are then sent to the corresponding server. Correspondingly, the server, upon receiving the thirteenth and fourteenth ciphertexts, decrypts the fourteenth ciphertext using a fifth asymmetric private key with a third PQC encryption / decryption algorithm to obtain a third symmetric key. This third symmetric key is then used to decrypt the thirteenth ciphertext to obtain the quantum key.

[0222] Alternatively, after acquiring the quantum key, the quantum key distribution and management device can send a request to the corresponding server for the sixth symmetric key. Upon receiving the request, the server generates a sixth quantum random number, then generates a sixth symmetric key based on this random number. The sixth symmetric key is then encrypted using the fourth PQC encryption / decryption algorithm with the fourth asymmetric public key to obtain the fifteenth ciphertext, which is then sent to the quantum key distribution and management device. The device then decrypts the fifteenth ciphertext using the fourth PQC encryption / decryption algorithm with the fourth asymmetric private key to obtain the sixth symmetric key. This sixth symmetric key is used to encrypt the quantum key to obtain the sixteenth ciphertext, which is then sent to the corresponding server. Upon receiving the sixteenth ciphertext, the server decrypts it using the sixth symmetric key to obtain the quantum key.

[0223] The quantum key distribution management device includes a first quantum key distribution management device and a second quantum key distribution management device. The first quantum key distribution management device corresponds to a first server, and the second quantum key distribution management device corresponds to a second server. The quantum key includes either the first quantum key or the second quantum key.

[0224] The specific details in this section are similar to those described above, and you can refer to the corresponding content for implementation. They will not be repeated here.

[0225] For semi-open areas (such as Central Business Districts (CBDs) and industrial parks), the identities of people within these areas are complex. Specifically, they may include internal personnel with unconditional access, visitors with conditional access, and external personnel not permitted entry. Current identity verification systems require pre-setting permissions for each user requesting entry into the controlled area, a cumbersome process. Therefore, this invention proposes a scheme for user identity verification based on historical location information.

[0226] Optionally, the authentication data and the authentication response information include the target user's historical location information and the time information corresponding to the historical location information.

[0227] Step S1130 specifically includes:

[0228] Based on the target user's historical location information and the corresponding time information, target historical location information that is within the target location range and whose corresponding time information belongs to the target time period is selected from all target historical location information; verification result information is generated based on the target historical location information.

[0229] For example, consider a semi-open area that allows unconditional entry to internal staff and also allows entry to visitors previously invited by internal staff during working hours. The entire semi-open area can be defined as the target location range, and working hours as the target time period. When a visitor first enters the semi-open area during working hours upon invitation from internal staff, and subsequently requests entry on another working day, the access control system, acting as an authentication terminal, can collect and encrypt the user's facial image, sending it to a first server. The first server then encrypts and forwards it to a second server. The second server, based on the user's facial information, returns encrypted historical location information and corresponding time information to the first server. The first server filters out the target user's target historical location information and generates an encrypted authentication result, sending it to the access control system, which then allows entry. This eliminates the need for manual registration or finding internal staff for entry.

[0230] In the specific implementation process, the target location range and target time period can be set as the access rules according to the actual needs of regional management. When the target historical location information is filtered out, a verification result information indicating that the target user's identity verification has passed can be generated and sent to the identity verification terminal. Alternatively, the target location range and target time period can be set as the access prohibition rules. When the target historical location information is filtered out, a verification result information indicating that the target user's identity verification has failed can be generated and sent to the identity verification terminal.

[0231] Further, step S1130 specifically includes:

[0232] Based on the target user's historical location information and the corresponding time information, target historical location information that is within the target location range and whose corresponding time information belongs to the target time period is selected from all target historical location information; based on the time information corresponding to the selected target historical location information, the total duration for which the target user is within the target location range during the target time period is determined; based on the total duration, the identity of the target user is verified to obtain verification result information.

[0233] For example, consider a semi-open area where internal staff working there are allowed unconditional entry, and where visitors previously invited by internal staff to enter during working hours are also permitted entry. The entire semi-open area can be defined as the target location range, and working hours as the target time period. When a target user is an internal staff member who previously visited the semi-open area at the invitation of other internal staff during working hours, upon requesting entry, the access control system, acting as an authentication terminal, can collect and encrypt the user's facial image information and send it to a first server. The first server then encrypts and forwards it to a second server. The second server, based on the user's facial information, encrypts and returns the corresponding historical location information and time information to the first server. The first server filters out the target user's target historical location information and calculates the total time the user spends within the target location range during the target time period. If the total time exceeds a preset threshold, an authentication result is generated and encrypted, sent to the access control system, which then allows the user entry. Therefore, target users no longer need to register or find other internal personnel for manual entry. When a target user is a visitor, they enter the semi-open area during working hours upon invitation from internal personnel and stay for a short period. Later, when the target user requests entry into the semi-open area during working hours on another day, the access control system, acting as an authentication terminal, can collect the target user's facial image information, encrypt it, and send it to the first server. The first server then encrypts and forwards it to the second server. The second server, based on the target user's facial information, encrypts and returns the corresponding historical location information and time information to the first server. The first server filters out the target user's target historical location information and calculates the total time the target user spends within the target location range during the target time period. If the total time exceeds a preset time threshold, an authentication failure message is generated and encrypted, and sent to the access control system, which then prohibits the target user from entering.

[0234] In the specific implementation process, based on the actual needs of regional management, target location ranges and target time periods can be set as access rules. When target historical location information is filtered out and the total duration is greater than a preset duration threshold, a verification result message indicating successful target user authentication is generated and sent to the authentication terminal. When target historical location information is not filtered out, or when target historical location information is filtered out but the total duration is less than or equal to the preset duration threshold, a verification result message indicating failed target user authentication is generated and sent to the authentication terminal. Alternatively, target location ranges and target time periods can be set as access prohibition rules. When target historical location information is filtered out and the total duration is greater than a preset duration threshold, a verification result message indicating failed target user authentication is generated and sent to the authentication terminal. When target historical location information is not filtered out, or when target historical location information is filtered out but the total duration is less than or equal to the preset duration threshold, a verification result message indicating successful target user authentication is generated and sent to the authentication terminal.

[0235] Based on the above-described inventive concept, in a second aspect, embodiments of the present invention also provide an authentication method based on quantum encryption technology, applied to an authentication terminal, such as... Figure 10 As shown, it includes:

[0236] S210. The collected identity verification request information of the target user is sent to the first server in a quantum random number encryption method; so that the first server sends the first ciphertext to the second server, wherein the first ciphertext is obtained by the first server encrypting at least part of the identity verification request information based on the first quantum key obtained through QKD technology;

[0237] S220. Receive the verification result information returned by the first server using quantum random number encryption, wherein the verification result information is generated by the first server based on the authentication response information, and the authentication response information is obtained by the first server decrypting the second ciphertext sent by the second server based on the second quantum key obtained through QKD technology.

[0238] S230. Perform the corresponding operation based on the verification result information.

[0239] Further, step S210, sending the collected target user's authentication request information to the first server using quantum random number encryption, includes:

[0240] The authentication request information is encrypted using a first symmetric key to obtain a third ciphertext; wherein the first symmetric key is determined by the authentication terminal based on a first quantum random number.

[0241] The first symmetric key is encrypted using the first PQC encryption and decryption algorithm with the first asymmetric public key to obtain the fourth ciphertext;

[0242] The third ciphertext and the fourth ciphertext are sent to the first server.

[0243] Furthermore, step S220, receiving the verification result information returned by the first server using quantum random number encryption, specifically includes:

[0244] Receive the second symmetric key acquisition request sent by the first server;

[0245] The second symmetric key is encrypted using the first PQC encryption and decryption algorithm with the first asymmetric public key to obtain the fifth ciphertext, and the fifth ciphertext is sent to the first server; wherein the second symmetric key is determined by the authentication terminal based on the second quantum random number;

[0246] Receive the sixth ciphertext sent by the first server; wherein the sixth ciphertext is the ciphertext obtained by the first server encrypting the verification result;

[0247] The sixth ciphertext is decrypted using the second symmetric key to obtain the verification result information.

[0248] Thirdly, based on the same inventive concept, embodiments of the present invention also provide an authentication method based on quantum encryption technology, applied to a first server, such as... Figure 11 The above includes:

[0249] S310. After receiving the authentication request information of the target user sent by the authentication terminal in the form of quantum random number encryption, at least part of the authentication request information is encrypted using the first quantum key obtained by quantum key distribution (QKD) technology to obtain the first ciphertext.

[0250] S320. Send the first ciphertext to the second server;

[0251] S330. Receive the second ciphertext sent by the second server; wherein the second ciphertext is generated by the second server after matching the at least part of the authentication request information;

[0252] S340. The second ciphertext is decrypted using the second quantum key obtained through QKD technology to obtain the authentication response information;

[0253] S350. Generate verification result information for the target user based on the authentication response information;

[0254] S360. The verification result information is sent to the identity verification terminal using quantum random number encryption.

[0255] Furthermore, the receipt of the authentication request information sent by the authentication terminal using quantum random number encryption specifically includes:

[0256] The system receives a third ciphertext and a fourth ciphertext sent by the authentication terminal; wherein the third ciphertext is ciphertext obtained by the authentication terminal encrypting the authentication request information, and the fourth ciphertext is ciphertext obtained by the authentication terminal encrypting the key used to encrypt the third ciphertext.

[0257] The fourth ciphertext is decrypted using the first post-quantum cryptography PQC encryption and decryption algorithm with the first asymmetric private key to obtain the first symmetric key; wherein, the first symmetric key is determined by the authentication terminal based on the first quantum random number;

[0258] The third ciphertext is decrypted using the first symmetric key to obtain the authentication request information.

[0259] Further, step S360, sending the verification result information to the authentication terminal using quantum random number encryption, specifically includes:

[0260] Send a second symmetric key acquisition request to the authentication terminal;

[0261] The system receives a fifth ciphertext sent by the authentication terminal; wherein the fifth ciphertext is ciphertext obtained by the authentication terminal encrypting a second symmetric key, and the second symmetric key is determined by the authentication terminal based on a second quantum random number.

[0262] The first PQC encryption and decryption algorithm is used to decrypt the fifth ciphertext using the first asymmetric private key to obtain the second symmetric key;

[0263] The verification result information is encrypted using the second symmetric key to obtain the sixth ciphertext, and the sixth ciphertext is sent to the authentication terminal.

[0264] Optionally, the authentication response information includes the target user's historical location information and the time information corresponding to the historical location information;

[0265] like Figure 12 As shown, step S350, generating verification result information for the target user based on the authentication response information, specifically includes:

[0266] S351. Based on the target user's historical location information and the time information corresponding to the historical location information, filter out the target historical location information that is within the target location range and whose corresponding time information belongs to the target time period from all target historical location information;

[0267] S352. Based on the time information corresponding to the filtered target historical location information, determine the total duration of time the target user is within the target location range during the target time period;

[0268] S353. Verify the identity of the target user based on the total duration to obtain verification result information.

[0269] Fourthly, based on the same inventive concept, embodiments of the present invention also provide an authentication method based on quantum encryption technology, applied to a second server, such as... Figure 13 As shown, it includes:

[0270] S410, Receive the first ciphertext sent by the first server;

[0271] S420. The first ciphertext is decrypted using the first quantum key obtained through QKD technology to obtain the authentication request information of the target user; wherein the authentication request information is at least part of the information collected and encrypted by the authentication terminal from the target user and sent to the first server.

[0272] S430. Match the authentication data corresponding to the authentication request information from the database, and generate authentication response information based on the matching result;

[0273] S440. The authentication response information is encrypted using the second quantum key obtained through QKD technology to obtain the second ciphertext;

[0274] S450. The second ciphertext is sent to the first server, so that the first server generates verification result information for the target user based on the authentication response information and sends it to the authentication terminal.

[0275] Since the authentication methods based on quantum encryption technology described in the second to fourth aspects are basically the same as the working principles of the authentication terminal, the first server, and the second server in the authentication system described in the first aspect, the authentication methods based on quantum encryption technology described in the second to fourth aspects can be implemented with reference to the corresponding content in the first aspect, and will not be repeated here.

[0276] Fifthly, based on the same inventive concept, embodiments of the present invention also provide an authentication terminal, such as... Figure 14 As shown, it includes:

[0277] The first encryption / decryption module M101 is used to send the collected authentication request information of the target user to the first server in a quantum random number encryption method; so that the first server sends the first ciphertext to the second server, wherein the first ciphertext is obtained by the first server encrypting at least part of the authentication request information based on the first quantum key obtained through QKD technology;

[0278] The second encryption / decryption module M102 is used to receive the verification result information returned by the first server in a quantum random number encryption method, wherein the verification result information is generated by the first server based on the authentication response information, and the authentication response information is obtained by the first server decrypting the second ciphertext sent by the second server based on the second quantum key obtained through QKD technology.

[0279] The execution module M103 is used to perform corresponding operations based on the verification result information.

[0280] Optionally, sending the collected target user's authentication request information to the first server using quantum random number encryption includes:

[0281] The authentication request information is encrypted using a first symmetric key to obtain a third ciphertext; wherein the first symmetric key is determined by the authentication terminal based on a first quantum random number.

[0282] The first symmetric key is encrypted using the first PQC encryption and decryption algorithm with the first asymmetric public key to obtain the fourth ciphertext;

[0283] The third ciphertext and the fourth ciphertext are sent to the first server.

[0284] Optionally, receiving the verification result information returned by the first server using quantum random number encryption specifically includes:

[0285] Receive the second symmetric key acquisition request sent by the first server;

[0286] The second symmetric key is encrypted using the first PQC encryption and decryption algorithm with the first asymmetric public key to obtain the fifth ciphertext, and the fifth ciphertext is sent to the first server; wherein the second symmetric key is determined by the authentication terminal based on the second quantum random number;

[0287] Receive the sixth ciphertext sent by the first server; wherein the sixth ciphertext is the ciphertext obtained by the first server encrypting the verification result;

[0288] The sixth ciphertext is decrypted using the second symmetric key to obtain the verification result information.

[0289] Optionally, the authentication terminal further includes (not shown in the figure): a QRNG module for generating a first quantum random number and a second quantum random number.

[0290] Sixthly, based on the same inventive concept, embodiments of the present invention also provide a server as the first server described above, such as... Figure 15 As shown, it includes:

[0291] The first encryption / decryption module M201 is used to receive the authentication request information of the target user sent by the authentication terminal in the form of quantum random number encryption.

[0292] The second encryption / decryption module M202 is used to encrypt at least a portion of the authentication request information using a first quantum key obtained through quantum key distribution (QKD) technology to obtain a first ciphertext, and then send the first ciphertext to the second server.

[0293] The third encryption / decryption module M203 is used to receive the second ciphertext sent by the second server; wherein the second ciphertext is generated by the second server after matching the at least part of the authentication request information; and the second ciphertext is decrypted using the second quantum key obtained through QKD technology to obtain the authentication response information.

[0294] The fourth encryption / decryption module M204 is used to generate verification result information for the target user based on the authentication response information, and send the verification result information to the authentication terminal in a quantum random number encryption method.

[0295] Optionally, the first encryption / decryption module M201 is specifically used for:

[0296] The system receives a third ciphertext and a fourth ciphertext sent by the authentication terminal; wherein the third ciphertext is ciphertext obtained by the authentication terminal encrypting the authentication request information, and the fourth ciphertext is ciphertext obtained by the authentication terminal encrypting the key used to encrypt the third ciphertext.

[0297] The fourth ciphertext is decrypted using the first post-quantum cryptography PQC encryption and decryption algorithm with the first asymmetric private key to obtain the first symmetric key; wherein, the first symmetric key is determined by the authentication terminal based on the first quantum random number;

[0298] The third ciphertext is decrypted using the first symmetric key to obtain the authentication request information.

[0299] Optionally, sending the verification result information to the authentication terminal using quantum random number encryption specifically includes:

[0300] Send a second symmetric key acquisition request to the authentication terminal;

[0301] The system receives a fifth ciphertext sent by the authentication terminal; wherein the fifth ciphertext is ciphertext obtained by the authentication terminal encrypting a second symmetric key, and the second symmetric key is determined by the authentication terminal based on a second quantum random number.

[0302] The first PQC encryption and decryption algorithm is used to decrypt the fifth ciphertext using the first asymmetric private key to obtain the second symmetric key;

[0303] The verification result information is encrypted using the second symmetric key to obtain the sixth ciphertext, and the sixth ciphertext is sent to the authentication terminal.

[0304] Optionally, the authentication response information includes the target user's historical location information and the time information corresponding to the historical location information;

[0305] The step of generating verification result information for the target user based on the authentication response information specifically includes:

[0306] Based on the target user's historical location information and the corresponding time information, filter out the target historical location information that is within the target location range and whose corresponding time information belongs to the target time period from all target historical location information;

[0307] Based on the time information corresponding to the filtered target historical location information, determine the total duration of time the target user is within the target location range during the target time period;

[0308] The identity of the target user is verified based on the total duration to obtain verification result information.

[0309] Seventhly, based on the same inventive concept, embodiments of the present invention also provide a second server, such as... Figure 16 As shown, it includes:

[0310] The first encryption / decryption module M301 is used to receive the first ciphertext sent by the first server; and to decrypt the first ciphertext using the first quantum key obtained through QKD technology to obtain the authentication request information of the target user; wherein the authentication request information is at least part of the information collected and encrypted by the authentication terminal from the target user and sent to the first server.

[0311] The matching module M302 is used to match the authentication data corresponding to the authentication request information from the database, and generate authentication response information based on the matching result;

[0312] The second encryption / decryption module M303 is used to encrypt the authentication response information using a second quantum key obtained through QKD technology to obtain a second ciphertext, and send the second ciphertext to the first server so that the first server can generate authentication result information for the target user based on the authentication response information and send it to the authentication terminal.

[0313] In the several embodiments provided in this application, it should be understood that the device embodiments described above are merely illustrative. For example, the division of modules is only a logical functional division, and in actual implementation, there may be other division methods. For example, multiple modules or components may be combined or integrated into another system, or some features may be ignored or not executed. Furthermore, the coupling or direct coupling or communication connection shown or discussed may be indirect coupling or communication connection through some interfaces, devices, or modules, and may be electrical, mechanical, or other forms. The modules described as separate components may or may not be physically separate. The components shown as modules may or may not be physical modules, that is, they may be located in one place or distributed across multiple network modules. Some or all of the modules can be selected to achieve the purpose of this embodiment according to actual needs. In addition, the functional modules in the various embodiments of this application may be integrated into one processing module, or each module may exist physically separately, or two or more modules may be integrated into one module. The integrated modules described above can be implemented in hardware or as software functional modules. If the integrated module is implemented as a software functional module and sold or used as an independent product, it can be stored in a computer-readable storage medium.

[0314] For example, such as Figure 17As shown, for the authentication terminal E3, depending on the channel through which the transmitted original data (including authentication request information and verification result information) and the key used to encrypt the original data (including the first symmetric key and the second symmetric key) are transmitted, the functions corresponding to the first encryption / decryption module M101 and the second encryption / decryption module M102 can be implemented by the information encryption / decryption module M110 and the key encryption / decryption module M120. The information encryption / decryption module M110 requests the first symmetric key from the key encryption / decryption module M120, encrypts the collected target user's authentication request information into a third ciphertext using the first symmetric key, and sends it to the first server; and receives the sixth ciphertext sent by the first server, requests the second symmetric key from the key encryption / decryption module M120, and decrypts the sixth ciphertext using the second symmetric key to obtain the verification result information. The key encryption / decryption module M120 is used to call QRNG to generate a first quantum random number, generate a first symmetric key based on the first quantum random number, provide it to the information encryption / decryption module M110, encrypt the first symmetric key using a first PQC encryption / decryption algorithm with a first asymmetric public key to obtain a fourth ciphertext, and send the fourth ciphertext to the first server; it also receives a second symmetric key acquisition request from the first server, calls QRNG to generate a second quantum random number, generates a second symmetric key based on the second quantum random number, encrypts the second symmetric key using a first PQC encryption / decryption algorithm with a first asymmetric public key to obtain a fifth ciphertext, and sends the fifth ciphertext to the first server; and provides the second symmetric key to the information encryption / decryption module M110. Similarly, for the first server, the functions corresponding to the first encryption / decryption modules M201 to the fourth encryption / decryption module M204 can be implemented by the information encryption / decryption module M210 and the key encryption / decryption module M220. The information encryption / decryption module M210 is used to receive a third ciphertext sent by the authentication terminal, request a first symmetric key from the key encryption / decryption module M220, decrypt the third ciphertext using the first symmetric key to obtain the authentication request information, encrypt at least a portion of the authentication request information using a first quantum key obtained through QKD technology to obtain a first ciphertext, and send the first ciphertext to a second server; and to receive a second ciphertext sent by the second server, decrypt the second ciphertext using the second quantum key obtained through QKD technology to obtain the authentication response information, generate authentication result information for the target user based on the authentication response information, request a second symmetric key from the key encryption / decryption module M220, encrypt the authentication result information using the second symmetric key to obtain a sixth ciphertext, and send the sixth ciphertext to the authentication terminal.The key encryption / decryption module M220 receives the fourth ciphertext sent by the authentication terminal, decrypts the fourth ciphertext using the first PQC encryption / decryption algorithm and the first asymmetric private key to obtain the first symmetric key, and provides it to the information encryption / decryption module M210; it also sends a second symmetric key acquisition request to the authentication terminal, receives the fifth ciphertext sent by the authentication terminal, decrypts the fifth ciphertext using the first PQC encryption / decryption algorithm and the first asymmetric private key to obtain the second symmetric key, and provides the second symmetric key to the information encryption / decryption module M210. Therefore, by connecting the information encryption / decryption module M110 of the authentication terminal and the information encryption / decryption module M210 of the first server via a physical or logical channel, and by connecting the key encryption / decryption module M120 of the authentication terminal and the key encryption / decryption module M220 of the first server via a physical or logical channel, dual-channel encrypted transmission of the plaintext and the key is achieved.

[0315] Since the specific methods of execution of the various modules described in aspects five through seven have been described in detail in the corresponding contents of aspects one through four, they will not be repeated here.

[0316] Eighthly, based on the same inventive concept, embodiments of the present invention also provide an electronic device, such as... Figure 18 As shown, it includes: a processor 110 and a memory 120 for storing executable instructions of the processor 110; wherein the processor 110 is configured to execute the instructions to implement the authentication method based on quantum encryption technology as described in any one of the second to fourth aspects.

[0317] In specific implementations, the device may vary significantly due to differences in configuration or performance. It may include one or more processors 110, memory 120, and computer-readable storage media 130. The memory 120 and / or computer-readable storage media 130 may contain one or more application programs 131 or data 132. The memory 120 and / or computer-readable storage media 130 may also contain one or more operating systems 133, such as Windows, Mac OS, Linux, iOS, Android, Unix, FreeBSD, etc. The memory 120 and computer-readable storage media 130 may be temporary or persistent storage. The application program 131 may include one or more of the aforementioned modules (…). Figure 18 (Not shown in the image), each module may include a series of instruction operations. Furthermore, the processor 110 may be configured to communicate with the computer-readable storage medium 130 and execute a series of instruction operations in the computer-readable storage medium 130 on the device. The device may also include one or more power supplies (…). Figure 18(not shown in the image); one or more network interfaces 140, including wired network interface 141 and / or wireless network interface 142; one or more input / output interfaces 143.

[0318] Ninthly, based on the same inventive concept, embodiments of the present invention also provide a computer-readable storage medium storing a computer program that is used to implement the authentication method based on quantum encryption technology as described in at least one of the second to fourth aspects.

[0319] In a tenth aspect, based on the same inventive concept, embodiments of this application also provide a computer program product, which includes a computer program stored in a computer-readable storage medium, at least one processor can read the computer program from the computer-readable storage medium, and when the at least one processor executes the computer program, it can implement the authentication method based on quantum encryption technology as described in at least one of the second to fourth aspects.

[0320] The authentication method and related hardware based on quantum encryption technology provided in this invention encrypt and transmit user privacy-related identity information via quantum encryption communication between servers located at considerable physical distances. Theoretically, quantum encryption communication technology ensures the absolute security of the keys used for communication between servers during transmission, preventing eavesdropping. Simultaneously, quantum random number encryption is used for communication between the authentication terminal and the server, leveraging the unpredictable nature of quantum random numbers to guarantee that the keys used in communication between the authentication terminal and the server are difficult to crack. This effectively enhances the security of encrypted communication between servers and between the authentication terminal and the server, effectively addressing the security challenges brought about by increased computing power.

[0321] Those skilled in the art will understand that embodiments of this application can be provided as methods, systems, or computer program products. Therefore, this application can take the form of a completely hardware embodiment, a completely software embodiment, or an embodiment combining software and hardware aspects. Furthermore, this application can take the form of a computer program product embodied on one or more computer-usable storage media (including but not limited to disk storage, CD-ROM, optical storage, etc.) containing computer-usable program code.

[0322] This application is described with reference to flowchart illustrations and / or block diagrams of methods, apparatus (systems), and computer program products according to this application. It should be understood that each block of the flowchart illustrations and / or block diagrams, and combinations of blocks in the flowchart illustrations and / or block diagrams, can be implemented by computer program instructions. These computer program instructions can be provided to a processor of a general-purpose computer, special-purpose computer, embedded processor, or other programmable data processing apparatus to produce a machine, such that the instructions, which execute via the processor of the computer or other programmable data processing apparatus, generate instructions for implementing the flowchart illustrations. Figure 1 One or more processes and / or boxes Figure 1 A device that provides the functions specified in one or more boxes.

[0323] These computer program instructions may also be stored in a computer-readable storage medium that can direct a computer or other programmable data processing device to function in a particular manner, such that the instructions stored in the computer-readable storage medium produce an article of manufacture including instruction means, which are implemented in a process Figure 1 One or more processes and / or boxes Figure 1 The function specified in one or more boxes.

[0324] These computer program instructions may also be loaded onto a computer or other programmable data processing equipment to cause a series of operational steps to be performed on the computer or other programmable equipment to produce a computer-implemented process, thereby providing instructions that execute on the computer or other programmable equipment for implementing the process. Figure 1 One or more processes and / or boxes Figure 1 The steps of the function specified in one or more boxes.

[0325] Obviously, those skilled in the art can make various modifications and variations to this application without departing from the spirit and scope of this application. Therefore, if such modifications and variations fall within the scope of the claims of this application and their equivalents, this application also intends to include such modifications and variations.

Claims

1. An identity verification system, characterized by, The method comprises the following steps: An identity authentication terminal is connected to a first server, and is configured to send identity authentication request information of a target user collected by the identity authentication terminal to the first server in a quantum random number encryption manner; The identity authentication terminal receives verification result information returned by the first server in a quantum random number encryption manner, and performs corresponding operations according to the verification result information; The first server is further connected to a second server, and is configured to, after receiving the identity authentication request information of the target user sent by the identity authentication terminal in a quantum random number encryption manner, encrypt at least part of the identity authentication request information by using a first quantum key obtained through quantum key distribution (QKD) technology to obtain first ciphertext, and send the first ciphertext to the second server; receive second ciphertext sent by the second server; decrypt the second ciphertext by using a second quantum key obtained through QKD technology to obtain identity authentication response information; The first server generates verification result information of the target user according to the identity authentication response information, and sends the verification result information to the identity authentication terminal in a quantum random number encryption manner; The second server is configured to receive the first ciphertext sent by the first server; decrypt the first ciphertext by using a first quantum key obtained through QKD technology to obtain at least part of the identity authentication request information; match identity authentication data corresponding to at least part of the identity authentication request information from a database, and generate identity authentication response information according to a matching result; encrypt the identity authentication response information by using a second quantum key obtained through QKD technology to obtain second ciphertext, and send the second ciphertext to the first server.

2. The identity verification system of claim 1, wherein, The identity authentication terminal sends the identity authentication request information of the target user collected by the identity authentication terminal to the first server in a quantum random number encryption manner, specifically including: encrypting the identity authentication request information by using a first symmetric key to obtain third ciphertext; wherein the first symmetric key is determined by the identity authentication terminal according to a first quantum random number; encrypting the first symmetric key by using a first post-quantum cryptography (PQC) encryption and decryption algorithm and using a first asymmetric public key to obtain fourth ciphertext; and sending the third ciphertext and the fourth ciphertext to the first server; The first server receives the identity authentication request information sent by the identity authentication terminal in a quantum random number encryption manner, specifically including: receiving the third ciphertext and the fourth ciphertext sent by the identity authentication terminal; decrypting the fourth ciphertext by using the first PQC encryption and decryption algorithm and using a first asymmetric private key to obtain the first symmetric key; and decrypting the third ciphertext by using the first symmetric key to obtain the identity authentication request information.

3. The identity verification system of claim 1, wherein, The first server sends the verification result information to the identity verification terminal in a quantum random number encryption mode, specifically including: sending a second symmetric key acquisition request to the identity verification terminal; receiving a fifth ciphertext sent by the identity verification terminal; using a first PQC encryption and decryption algorithm to decrypt the fifth ciphertext using a first asymmetric private key to obtain a second symmetric key; encrypting the verification result information using the second symmetric key to obtain a sixth ciphertext, and sending the sixth ciphertext to the identity verification terminal; The identity verification terminal receives the verification result information returned by the first server in a quantum random number encryption mode, specifically including: receiving the second symmetric key acquisition request sent by the first server; encrypting the second symmetric key using the first PQC encryption and decryption algorithm using the first asymmetric public key to obtain the fifth ciphertext, and sending the fifth ciphertext to the first server; wherein the second symmetric key is determined by the identity verification terminal according to a second quantum random number; receiving the sixth ciphertext sent by the first server; decrypting the sixth ciphertext using the second symmetric key to obtain the verification result information.

4. The identity verification system of claim 1, wherein, The identity verification response information includes historical location information of the target user and time information corresponding to the historical location information; The first server generates verification result information for the target user according to the identity verification response information, specifically including: Filtering target historical location information located within a target location range and corresponding time information belonging to a target time period from all target historical location information according to the historical location information of the target user and the time information corresponding to the historical location information; Determining the total duration of the target user being located within the target location range during the target time period according to the time information corresponding to the filtered target historical location information; Verifying the identity of the target user according to the total duration to obtain verification result information.

5. The identity verification system of claim 1, wherein, The identity verification system further includes: A first quantum key distribution management device connected with the first server and a second quantum key distribution management device, respectively, for obtaining the first quantum key and the second quantum key through QKD technology and providing them to the first server; A second quantum key distribution management device also connected with the second server, for obtaining the first quantum key and the second quantum key through QKD technology and providing them to the second server.

6. An identity verification method based on quantum encryption technology, characterized by, The first server applied to the identity verification system of any one of claims 1-5, comprising: After receiving the identity verification request information of the target user sent by the identity verification terminal in a quantum random number encryption mode, encrypting at least part of the identity verification request information using the first quantum key obtained through QKD technology to obtain a first ciphertext, and sending the first ciphertext to the second server; Receiving a second ciphertext sent by the second server; wherein the second ciphertext is generated by the second server after matching at least part of the identity verification request information; The second ciphertext is decrypted using a second quantum key obtained through a QKD technology to obtain identity verification response information; The identity verification result information of the target user is generated according to the identity verification response information, and the identity verification result information is sent to the identity verification terminal in a quantum random number encryption mode.

7. The method of claim 6, wherein, The identity verification request information sent by the identity verification terminal in a quantum random number encryption mode is received, and specifically includes: The third ciphertext and the fourth ciphertext sent by the identity verification terminal are received; the third ciphertext is a ciphertext obtained by the identity verification terminal encrypting the identity verification request information, and the fourth ciphertext is a ciphertext obtained by the identity verification terminal encrypting a key used to encrypt the third ciphertext; The fourth ciphertext is decrypted using a first asymmetric private key of a first post-quantum cryptography (PQC) encryption and decryption algorithm to obtain a first symmetric key; the first symmetric key is determined by the identity verification terminal according to a first quantum random number; The third ciphertext is decrypted using the first symmetric key to obtain the identity verification request information.

8. The method of claim 7, wherein, The identity verification result information is sent to the identity verification terminal in a quantum random number encryption mode, and specifically includes: A second symmetric key acquisition request is sent to the identity verification terminal; The fifth ciphertext sent by the identity verification terminal is received; the fifth ciphertext is a ciphertext obtained by the identity verification terminal encrypting a second symmetric key, and the second symmetric key is determined by the identity verification terminal according to a second quantum random number; The fifth ciphertext is decrypted using the first asymmetric private key of the first PQC encryption and decryption algorithm to obtain the second symmetric key; The identity verification result information is encrypted using the second symmetric key to obtain sixth ciphertext, and the sixth ciphertext is sent to the identity verification terminal.

9. The method of claim 6, wherein, The identity verification response information includes historical location information of the target user and time information corresponding to the historical location information; The identity verification result information of the target user is generated according to the identity verification response information, and specifically includes: The target historical location information located within the target location range and corresponding to the target time period is filtered out from all target historical location information according to the historical location information of the target user and the time information corresponding to the historical location information; The total duration of the target user located within the target location range in the target time period is determined according to the time information corresponding to the filtered target historical location information; The identity of the target user is verified according to the total duration to obtain the verification result information.

10. An identity verification method based on quantum encryption technology, characterized by, The second server applied to the identity verification system of any one of claims 1-5 includes: The first ciphertext sent by the first server is received; The identity verification request information of the target user is obtained by decrypting the first ciphertext using a first quantum key obtained through a QKD technology; the identity verification request information is at least part of the information collected by the identity verification terminal and encrypted and sent to the first server. Matching authentication data corresponding to the authentication request information from the database, and generating authentication response information according to the matching result; The second ciphertext is sent to the first server, so that the first server generates authentication result information of the target user according to the authentication response information and sends it to the authentication terminal.

11. An identity verification method based on quantum encryption technology, characterized by, The authentication terminal applied to the authentication system of any one of claims 1-5, comprising: The authentication request information of the target user collected is sent to the first server in a quantum random number encryption manner; so that the first server sends the first ciphertext to the second server, the first ciphertext being obtained by the first server encrypting at least part of the authentication request information based on the first quantum key obtained through QKD technology; Receiving the authentication result information returned by the first server in a quantum random number encryption manner, wherein the authentication result information is information generated by the first server according to the authentication response information, and the authentication response information is obtained by the first server decrypting the second ciphertext sent by the second server based on the second quantum key obtained through QKD technology; According to the authentication result information, corresponding operation is performed.

12. The method of claim 11, wherein, The authentication request information of the target user collected is sent to the first server in a quantum random number encryption manner, comprising: The authentication request information is encrypted using a first symmetric key to obtain a third ciphertext; wherein the first symmetric key is determined by the authentication terminal according to a first quantum random number; The first symmetric key is encrypted using a first PQC encryption and decryption algorithm using a first asymmetric public key to obtain a fourth ciphertext; The third ciphertext and the fourth ciphertext are sent to the first server.

13. The method of claim 12, wherein, The authentication result information returned by the first server in a quantum random number encryption manner is received, specifically comprising: Receiving a second symmetric key acquisition request sent by the first server; The second symmetric key is encrypted using the first PQC encryption and decryption algorithm using a first asymmetric public key to obtain a fifth ciphertext, and the fifth ciphertext is sent to the first server; wherein the second symmetric key is determined by the authentication terminal according to a second quantum random number; Receiving the sixth ciphertext sent by the first server; wherein the sixth ciphertext is the ciphertext obtained by the first server encrypting the authentication result information; The sixth ciphertext is decrypted using the second symmetric key to obtain the authentication result information.

14. A first server, applied to the identity authentication system of any one of claims 1-5, characterized in that, Comprising: The first encryption and decryption module is used for receiving the authentication request information of the target user sent by the authentication terminal in a quantum random number encryption manner; The second encryption and decryption module is used for encrypting at least part of the authentication request information using the first quantum key obtained through QKD technology to obtain the first ciphertext, and sending the first ciphertext to the second server; a third encryption and decryption module, configured to receive second ciphertext sent by the second server, wherein the second ciphertext is generated by the second server after matching at least part of the identity verification request information; and decrypt the second ciphertext by using a second quantum key obtained through QKD technology to obtain identity verification response information; a fourth encryption and decryption module, configured to generate verification result information of the target user according to the identity verification response information, and send the verification result information to the identity verification terminal in a quantum random number encryption manner.

15. A second server, applied to the identity authentication system of any one of claims 1-5, characterized in that, comprising: a first encryption and decryption module, configured to receive first ciphertext sent by a first server, and decrypt the first ciphertext by using a first quantum key obtained through QKD technology to obtain identity verification request information of a target user, wherein the identity verification request information is at least part of information collected by an identity verification terminal from the target user and sent to the first server in an encrypted manner; a matching module, configured to match identity verification data corresponding to the identity verification request information from a database, and generate identity verification response information according to a matching result; a second encryption and decryption module, configured to encrypt the identity verification response information by using a second quantum key obtained through QKD technology to obtain second ciphertext, and send the second ciphertext to the first server, so that the first server generates verification result information of the target user according to the identity verification response information and sends the verification result information to the identity verification terminal.

16. An identity verification terminal applied in the identity verification system according to any one of claims 1-5, characterized in that, comprising: a first encryption and decryption module, configured to send identity verification request information of a target user collected in a quantum random number encryption manner to a first server; so that the first server sends first ciphertext to a second server, wherein the first ciphertext is obtained by the first server by encrypting at least part of the identity verification request information based on a first quantum key obtained through QKD technology; a second encryption and decryption module, configured to receive verification result information returned by the first server in a quantum random number encryption manner, wherein the verification result information is information generated by the first server according to identity verification response information, and the identity verification response information is obtained by the first server by decrypting second ciphertext sent by the second server based on a second quantum key obtained through QKD technology; an execution module, configured to perform a corresponding operation according to the verification result information.

17. An electronic device, comprising: comprising: a processor and a memory for storing instructions executable by the processor; wherein the processor is configured to execute the instructions to implement the identity verification method based on quantum encryption technology according to any one of claims 6-9, or implement the identity verification method based on quantum encryption technology according to claim 10, or implement the identity verification method based on quantum encryption technology according to any one of claims 11-13.

18. A computer-readable storage medium, characterized in that, The computer readable storage medium stores a computer program used to implement the identity authentication method based on quantum encryption technology according to any one of claims 6-9, or the identity authentication method based on quantum encryption technology according to claim 10, or the identity authentication method based on quantum encryption technology according to any one of claims 11-13.

Citation Information

Patent Citations

  • Identity authentication method and apparatus

    CN108347404A

  • Method, apparatus and system for identity authentication

    CN109104393A