Method for managing and controlling inter-vpn gateway key, quantum vpn controller and system
By monitoring the key update cycle within the gateway communication group through the quantum VPN controller, generating a security parameter index (SPI), and sending encrypted information, the problems of easy cracking of IPSec VPN gateway negotiation session keys and high computational communication costs are solved, thus realizing secure encrypted forwarding of data between gateways.
Patent Information
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- CHINA TELECOM QUANTUM TECH CO LTD
- Filing Date
- 2023-08-10
- Publication Date
- 2026-08-04
AI Technical Summary
Existing IPSec VPN gateway negotiation session keys may be cracked by higher-performance quantum computers, and the key negotiation process between gateways is computationally and communicationally expensive, making it impossible to perform unified key distribution and SPI security parameter management.
The quantum VPN controller monitors the key update cycle within the gateway communication group, sends a session key acquisition request to the quantum key management system, generates a security parameter index (SPI), and sends encrypted information to the gateway communication group to activate the session key and perform encrypted data forwarding between gateways.
The quantum VPN controller enables unified key distribution and SPI security parameter management among IPSec VPN gateways, preventing quantum computer threats and reducing the computational and communication costs between gateways.
Smart Images

Figure CN117201231B_ABST
Abstract
Description
Technical Field
[0001] This invention relates to the fields of VPN technology and quantum key service technology, specifically to a method for key management between VPN gateways, a quantum VPN controller, and a system. Background Technology
[0002] Tunneling technology, also known as VPN (Virtual Private Network) technology, can establish a secure and stable private network on the insecure Internet.
[0003] IPSec VPN, short for Internet Protocol Security, is a security standard framework defined by the IETF (Internet Engineering Task Force). It provides a secure, encrypted communication channel between two private networks over the public internet, ensuring connection security through this encrypted channel—providing confidential data packet services between two public gateways. It is an international network encryption communication standard with a wide range of applications. The cryptographic industry standard GM / T0022-2014, "IPSec VPN Technical Specification," details the key negotiation process for the IKE phase of the Chinese national cryptographic IPSec protocol. Compared to the IKE process of the international IPSec protocol, there are significant changes, primarily including the replacement of international standard cryptographic algorithms with Chinese cryptographic algorithms and the mandatory use of a Chinese cryptographic dual-digital certificate system.
[0004] IPSec, a Chinese national cryptographic standard, uses public-key algorithms for authentication and key negotiation, offering high security. However, it still has the following issues:
[0005] 1) With the advent of higher-performance quantum computers, the negotiation session key of IPSec VPN gateways may be cracked more quickly, making communication links no longer secure.
[0006] 2) Negotiating session keys, encryption algorithms, and authentication algorithms between IPSec VPN gateways requires maintaining network channel connections and opening corresponding network communication ports, incurring certain computational and communication costs. Information exchange and communication between gateways are scheduled and managed by the VPN controller, enabling IPSec VPN gateway registration management, key request proxy, session key configuration, security parameter SPI, and configuration and distribution control of encryption and authentication algorithms.
[0007] In related technologies, Chinese invention patent application CN116055091A describes a method where a management platform generates IPSec VPN security policies for IPSec VPN gateway device nodes based on real-time traffic information and requests session keys from a quantum key distribution network. The device node acts as the execution point for reporting traffic information and performing IPSec VPN tunnel encapsulation, decapsulation, and encryption / decryption processing on the data stream. This method separates key distribution from the generation of the security parameter SPI. The key distribution logic involves the IPSec VPN gateway requesting the key from the quantum key distribution network, and the management platform then distributing the keys. The SPI security parameter index is generated by each of the communicating IPSec VPN gateways and then exchanged through the management platform. In this approach, the management platform cannot perform unified key distribution and SPI security parameter management. Summary of the Invention
[0008] The technical problem to be solved by this invention is how to achieve secure distribution of session keys and secure index (SPI) information, and protect the confidentiality of session keys.
[0009] The present invention solves the above-mentioned technical problems through the following technical means:
[0010] In a first aspect, the present invention proposes a VPN gateway key management method, applied to a quantum VPN controller, the method comprising:
[0011] Monitor the key update cycle within the gateway communication group, and send a session key acquisition request to the quantum key management system when the key update cycle reaches a set value;
[0012] Receive the session key ciphertext information issued by the quantum key management system, and generate the security parameter index (SPI) used by the gateway communication group within the current key update cycle based on the session key ciphertext information;
[0013] The encrypted information containing the security parameter index SPI is sent to the gateway communication group to activate the session keys of each gateway and perform encrypted data forwarding between gateways.
[0014] Furthermore, before sending a session key acquisition request to the quantum key management system when the key update cycle within the monitoring gateway communication group reaches a set value, the method further includes:
[0015] Receive registration requests sent by each gateway, wherein the registration request carries the gateway ID and the security medium ID;
[0016] Each of the gateways integrates a security medium, which stores a master key pre-filled by the quantum key management system.
[0017] Furthermore, before sending a session key acquisition request to the quantum key management system when the key update cycle within the monitoring gateway communication group reaches a set value, the method further includes:
[0018] Each successfully registered gateway is divided into a gateway communication group.
[0019] Send security policy information and security key information to each gateway in each of the aforementioned gateway communication groups;
[0020] The security policy information includes the interconnection relationship between gateways within each gateway communication group, the bridging rules for each gateway's uplink and downlink ports, and the gateway's encrypted data stream policy.
[0021] The security key information includes the symmetric encryption algorithm, cryptographic hash algorithm, and key update cycle used by each of the gateway communication groups.
[0022] Furthermore, the step of sending security policy information and security key information to each gateway within each of the gateway communication groups includes:
[0023] Perform a digest operation on the security policy information and the security key information to obtain a first digest value;
[0024] The first digest value, the security policy information, and the security key information are sent to each gateway in the gateway communication group.
[0025] Furthermore, after sending security policy information and security key information to each gateway within each of the gateway communication groups, the method further includes:
[0026] When performing digest operations on security policy information and security key information at each gateway and failing to verify data consistency, the system receives data transmission failure information returned by the gateway.
[0027] When the digest operation of security policy information and security key information is performed on each gateway and the data consistency is successfully verified, the data delivery success message returned by the gateway is received.
[0028] Furthermore, the session key acquisition request carries information including the number of session keys, the session key length, and the ID list information of the security media integrated by each gateway in the gateway communication group.
[0029] Further, the step of receiving the session key ciphertext information issued by the quantum key management system and generating the security parameter index (SPI) used by the gateway communication group within the current key update cycle dimension based on the session key ciphertext information includes:
[0030] The system receives session key ciphertext information from the quantum key management system. The format of the session key ciphertext information corresponding to different gateways is: [{session key ciphertext, security medium ID, master key serial number ID}]. Each gateway integrates a security medium, which stores the master key pre-filled by the quantum key management system.
[0031] The corresponding gateway ID is queried based on the security medium ID. Based on the correspondence between the gateway ID, the security medium ID, the master key serial number ID, and the session key ciphertext, the security parameter index (SPI) is generated.
[0032] Furthermore, the step of sending encrypted information containing the security parameter index SPI to the gateway communication group to activate and enable the session keys of each gateway for encrypted data forwarding between gateways includes:
[0033] When all gateways in the gateway communication group are online, a second digest value is generated by performing a digest operation based on the corresponding security medium ID, the master key sequence number ID, the session key ciphertext, and the security parameter index SPI.
[0034] The corresponding ciphertext information is sent to each gateway in the gateway communication group to activate the session key of each gateway and perform encrypted data forwarding between gateways. The ciphertext information includes the second digest value, the security medium ID, the master key serial number ID, the session key ciphertext, and the security parameter index SPI.
[0035] Furthermore, after sending the encrypted information containing the security parameter index SPI to the gateway communication group, the method further includes:
[0036] Receive response status information returned by each gateway in the gateway communication group, synchronously send session key distribution failure or success status information to the peer gateway of each gateway, and activate the session key of each gateway.
[0037] Receive session key activation status information returned by peer gateways from each gateway, and synchronously issue session key activation activation commands so that each gateway can encrypt data streams and forward them according to the configured security policy information.
[0038] Secondly, this invention proposes a quantum VPN controller, comprising:
[0039] The session key acquisition request sending unit is used to monitor the key update cycle within the gateway communication group and send a session key acquisition request to the quantum key management system when the key update cycle reaches a set value.
[0040] The security parameter index generation unit is used to receive the session key ciphertext information issued by the quantum key management system, and generate the security parameter index (SPI) used by the gateway communication group within the current key update cycle based on the session key ciphertext information.
[0041] The activation unit is used to send encrypted information containing the security parameter index SPI to the gateway communication group to activate and enable the session keys of each gateway for encrypted data forwarding between gateways.
[0042] Thirdly, this invention proposes a VPN gateway key management system, the system comprising: a quantum VPN controller, gateways, and a quantum key management system, each gateway integrating a security medium, each gateway being connected to the quantum VPN controller, and the quantum key management system being connected to each security medium, the quantum VPN controller comprising:
[0043] The session key acquisition request sending unit is used to monitor the key update cycle within the gateway communication group composed of each of the gateways, and send a session key acquisition request to the quantum key management system when the key update cycle reaches a set value.
[0044] The security parameter index generation unit is used to receive the session key ciphertext information issued by the quantum key management system, and generate the security parameter index (SPI) used by the gateway communication group within the current key update cycle based on the session key ciphertext information.
[0045] The activation unit is used to send encrypted information containing the security parameter index SPI to the gateway communication group to activate and enable the session keys of each gateway for encrypted data forwarding between gateways.
[0046] The advantages of this invention are:
[0047] (1) This invention sets the quantum VPN controller to monitor the key update cycle within the gateway communication group. When an update is required, it sends a session key acquisition request to the quantum key management system and obtains the session key ciphertext information. Then, based on the session key ciphertext information, it generates the security parameter index (SPI) used by the gateway communication group for this key update. It then sends the ciphertext information containing the security parameter index (SPI) to the gateway communication group, activates the session keys of each gateway, and performs encrypted data forwarding between gateways. The quantum VPN controller software service realizes the negotiation and control of encrypted session keys between VPN gateways. The session keys between IPSec VPN gateways are encrypted and controlled by the quantum VPN controller. This realizes unified key distribution and SPI security parameter management by the quantum VPN controller, prevents security threats brought by future quantum computers, and is applied to the establishment of VPN encrypted tunnels.
[0048] (2) Each encryption gateway integrates a security medium, which stores the master key pre-filled by the quantum key management system. The pre-filled key in the security medium is combined with quantum key distribution technology to protect the confidentiality of the session key issued by the quantum VPN controller.
[0049] Additional aspects and advantages of the invention will be set forth in part in the description which follows, and in part will be obvious from the description, or may be learned by practice of the invention. Attached Figure Description
[0050] Figure 1 This is a flowchart illustrating a VPN gateway key management method according to an embodiment of the present invention;
[0051] Figure 2 This is a schematic diagram of the structure of a quantum VPN controller proposed in an embodiment of the present invention;
[0052] Figure 3 This is a schematic diagram of the complete structure of a quantum VPN controller proposed in an embodiment of the present invention;
[0053] Figure 4 This is a schematic diagram of the structure of a VPN gateway key management system proposed in an embodiment of the present invention. Detailed Implementation
[0054] To make the objectives, technical solutions, and advantages of the embodiments of the present invention clearer, the technical solutions of the embodiments of the present invention will be clearly and completely described below in conjunction with the embodiments of the present invention. Obviously, the described embodiments are only some embodiments of the present invention, not all embodiments. Based on the embodiments of the present invention, all other embodiments obtained by those skilled in the art without creative effort are within the scope of protection of the present invention.
[0055] like Figure 1 As shown, the first embodiment of the present invention proposes a VPN gateway key management method, applied to a quantum VPN controller, the method comprising the following steps:
[0056] S10. Monitor the key update cycle within the gateway communication group, and when the key update cycle reaches the set value, send a session key acquisition request to the quantum key management system.
[0057] It should be noted that the gateway communication group includes multiple VPN encryption gateways. As a device that provides IPSec VPN functionality and information encryption, the VPN encryption gateway provides security guarantees such as confidentiality, integrity protection, and data source authentication for data transmission within the user's internal network. Through IPSec VPN products, various network interconnection needs such as remote access between the corporate headquarters and various branches, partners, and mobile office personnel can be met. At the same time, it provides security protection measures such as privacy and integrity for the data transmitted in these remote networks.
[0058] S20. Receive the session key ciphertext information issued by the quantum key management system, and generate the security parameter index (SPI) used by the gateway communication group within the current key update cycle based on the session key ciphertext information.
[0059] It should be noted that the quantum key management system is used to provide national cryptographic algorithm capabilities based on quantum keys, provide unified cryptographic access standards for business systems / user terminals, and realize multi-level cryptographic security application capabilities.
[0060] S30. Send encrypted information containing the security parameter index SPI to the gateway communication group to activate the session keys of each gateway and perform encrypted data forwarding between gateways.
[0061] This embodiment sets the quantum VPN controller to monitor the key update cycle within the gateway communication group. When an update is needed, it sends a session key acquisition request to the quantum key management system and obtains the ciphertext information of the session key. Then, based on the ciphertext information of the session key, it generates a Security Parameter Index (SPI) for the gateway communication group to use in this key update. It then sends the ciphertext information containing the SPI to the gateway communication group, activates the session keys of each gateway, and performs encrypted data forwarding between gateways. The quantum VPN controller software service enables the negotiation and control of encrypted session keys between VPN gateways. The session keys between IPSec VPN gateways are encrypted and controlled by the quantum VPN controller to prevent security threats posed by future quantum computers.
[0062] In one embodiment, before step S10: monitoring the key update cycle within the gateway communication group and sending a session key acquisition request to the quantum key management system when the key update cycle reaches a set value, the method further includes the following steps:
[0063] Receive registration requests sent by each gateway, wherein the registration request carries the gateway ID and the security medium ID;
[0064] Each of the gateways integrates a security medium, which stores a master key pre-filled by the quantum key management system.
[0065] It should be noted that the secure medium includes, but is not limited to, a SIM card or a secure TF card. The secure medium complies with the certificate issued by the State Commercial Cryptography Administration, has security protection capabilities, and is initially written with ID information. It can interface with the quantum key management system to realize the key filling function within the secure medium.
[0066] Furthermore, the quantum key management system pre-charges the quantum master key into the secure medium through the charging software. At the same time, the key management system maintains the correspondence between the ID of the charged secure medium and the charged master key.
[0067] The VPN encryption gateway starts up and sends a registration request to the Quantum VPN controller, transmitting information such as gateway ID and security medium ID. The Quantum VPN controller is used to maintain the relationship between each gateway ID and medium ID, as well as the online status of each gateway.
[0068] In one embodiment, before step S10: monitoring the key update cycle within the gateway communication group and sending a session key acquisition request to the quantum key management system when the key update cycle reaches a set value, the method further includes the following steps:
[0069] Each successfully registered gateway is divided into a gateway communication group.
[0070] Send security policy information and security key information to each gateway in each of the aforementioned gateway communication groups;
[0071] The security policy information includes the interconnection relationship between gateways within each gateway communication group, the bridging rules for each gateway's uplink and downlink ports, and the gateway's encrypted data stream policy.
[0072] The security key information includes the symmetric encryption algorithm, cryptographic hash algorithm, and key update cycle used by each of the gateway communication groups.
[0073] Specifically, the quantum VPN controller maintains the online status of each encryption gateway, and the interface provides a visual operation to divide the gateway communication groups and configure the security policy information and security key information of the gateway communication groups.
[0074] Furthermore, the security policy information includes the interconnection relationship between gateways within the gateway communication group (one-to-one, one-to-many, full interconnection), the bridging rules for each gateway's uplink and downlink ports, and the gateway's encrypted data stream policy (source IP, destination IP, source port, destination port, protocol).
[0075] It should be noted that the security policy information of each gateway in the same gateway communication group is different, and a visual configuration operation is required.
[0076] Furthermore, the security key information configuration includes the symmetric encryption algorithm (such as CBC-SM4, ECB-SM4), cryptographic hash algorithm (such as SM3), and key update cycle (≥5 minutes / time) for the gateway communication group.
[0077] It should be noted that the same symmetric encryption algorithm and cryptographic hash algorithm are used in the same encrypted gateway communication group.
[0078] In one embodiment, the step of sending security policy information and security key information to each gateway within each of the gateway communication groups specifically includes the following steps:
[0079] Perform a digest operation on the security policy information and the security key information to obtain a first digest value;
[0080] The first digest value, the security policy information, and the security key information are sent to each gateway in the gateway communication group.
[0081] In this embodiment, the quantum VPN controller performs HMAC-SM3 operations on the security policy rules and security key information of the divided gateway communication groups, and sends the HMAC-SM3 digest value, security policy information, and security key information to each gateway in the communication group.
[0082] In one embodiment, after sending security policy information and security key information to each gateway within each of the gateway communication groups, the method further includes the following steps:
[0083] When performing digest operations on security policy information and security key information at each gateway and failing to verify data consistency, the system receives data transmission failure information returned by the gateway.
[0084] When the digest operation of security policy information and security key information is performed on each gateway and the data consistency is successfully verified, the data delivery success message returned by the gateway is received.
[0085] It should be noted that each VPN encryption gateway within the gateway communication group receives information, synchronously performs digest calculations on security policy information and security key information, and verifies data consistency. If the verification fails, a data transmission failure response is sent to the quantum VPN controller. If the verification succeeds, the security policy information and security key information are stored locally and written to the security policy database and security association database, with the status set to disabled. Simultaneously, a data transmission success response is sent to the quantum VPN controller.
[0086] It should be noted that the networking relationships among the gateways within the gateway communication group can be one-to-one, one-to-many, or fully interconnected, and multiple sets of security policy information are maintained by each gateway within the communication group.
[0087] In one embodiment, in step S10, the quantum VPN controller monitors the key update cycle and the online status of the gateways within the gateway communication group. When the key update cycle reaches 90%, the quantum VPN controller uses the security medium IDs integrated by each gateway in the communication group to initiate a session key session request to the quantum key management system, transmitting the number of session keys, the session key length (an integer multiple of 16 bytes), and a list of ID sets of the security mediums integrated by each gateway in the communication group.
[0088] That is, the session key acquisition request carries information including the number of session keys, the length of the session keys, and the ID list information of the security media integrated by the gateway in the gateway communication group.
[0089] In one embodiment, step S20: receiving the session key ciphertext information issued by the quantum key management system, and generating the security parameter index (SPI) used by the gateway communication group within the current key update cycle based on the session key ciphertext information, specifically includes the following steps:
[0090] S21. Receive the session key ciphertext information issued by the quantum key management system. The format of the session key ciphertext information corresponding to different gateways is: [{session key ciphertext, security medium ID, master key serial number ID}], wherein each gateway integrates a security medium, and the security medium stores the master key pre-filled by the quantum key management system.
[0091] Specifically, the quantum key management system receives the session key acquisition request, and based on the session key acquisition request, the number of session keys, the session key length, the security medium ID integrated by each gateway, and other information, queries the information of the master key stored in each security medium ID, obtains a pre-filled master key in each security medium, and encrypts and issues a session key using the SM4 symmetric algorithm.
[0092] It should be noted that while the plaintext of the session key distributed by the quantum key management system to each gateway in the gateway communication group is the same, the ciphertext information of the session key is different for each gateway. The specific ciphertext format is: [{session key ciphertext, security medium ID, master key serial number ID}, {session key ciphertext, security medium ID, master key serial number ID}..].
[0093] S22. Query the corresponding gateway ID based on the security medium ID, and generate the security parameter index SPI based on the correspondence between the gateway ID, the security medium ID, the master key serial number ID and the session key ciphertext.
[0094] In one embodiment, step S30: sending encrypted information containing the security parameter index SPI to the gateway communication group to activate and enable the session keys of each gateway for encrypted data forwarding between gateways, specifically includes the following steps:
[0095] S31. When all gateways in the gateway communication group are online, perform a digest operation based on the corresponding security medium ID, master key serial number ID, session key ciphertext and security parameter index SPI to generate a second digest value.
[0096] S32. Send corresponding ciphertext information to each gateway in the gateway communication group to activate the session key of each gateway and perform encrypted forwarding of data between gateways. The ciphertext information includes the second digest value, the security medium ID, the master key serial number ID, the session key ciphertext, and the security parameter index SPI.
[0097] It should be noted that the quantum VPN controller monitors the online operating status of each gateway in the communication group. If each gateway in the communication group is online, the quantum VPN controller performs HMAC-SM3 operation on {Security Medium ID + Medium Key Serial Number ID + Session Key Ciphertext + Security Parameter Index SPI} and sends the corresponding HMAC-SM3 digest value, Security Medium ID, Medium Key Serial Number ID, Session Key Ciphertext, and Security Parameter Index SPI information to each gateway in the communication group.
[0098] It should be noted that if there is an offline state within the communication group, the key ciphertext information will not be distributed, and a gateway offline alarm will be generated simultaneously and pushed to the corresponding operation and maintenance administrator for on-site gateway operation and maintenance.
[0099] In one embodiment, after sending the encrypted information containing the security parameter index SPI to the gateway communication group in step S10, the method further includes the following steps:
[0100] Receive response status information returned by each gateway in the gateway communication group, synchronously send session key distribution failure or success status information to the peer gateway of each gateway, and activate the session key of each gateway.
[0101] Receive session key activation status information returned by peer gateways from each gateway, and synchronously issue session key activation activation commands so that each gateway can encrypt data streams and forward them according to the configured security policy information.
[0102] It should be noted that each gateway in the gateway communication group receives the HMAC-SM3 digest value, session key ciphertext, security medium ID, medium key sequence number ID, and security parameter index SPI issued by the quantum VPN controller, and performs data consistency verification as follows:
[0103] (1) If the security medium ID and medium key sequence number ID are consistent with the security medium ID and sequence number ID integrated into its own gateway, and the calculated HMAC-SM3 digest value is also consistent, then the pre-charged master key corresponding to the medium key sequence number ID is used to decrypt the session key ciphertext, and the session key and SPI are set to the security association database. At the same time, the quantum VPN controller responds with a received status information.
[0104] (2) If the security medium ID, medium key serial number ID are inconsistent with the security medium information integrated with its own gateway, or the calculated HMAC-SM3 digest value is inconsistent, then the response information to the VPN controller is inconsistent.
[0105] Furthermore, when the quantum VPN controller receives a received status information from the gateway, it receives the response status information from each gateway in the communication group, performs logical judgment and synchronization of each response status information, and synchronously sends the failure or success status information of session key distribution to the peer gateway of each gateway to activate the gateway session key.
[0106] Furthermore, the VPN gateway receives session key response statuses from each peer gateway: if the status is "failure," then it will not enable its own session key and will respond to the Quantum VPN controller with information indicating that it has obtained peer status information and that its own session key is not enabled. If the status is "success," then it will enable its own session key and respond to the Quantum VPN controller with information indicating that it has obtained peer status information and that its own session key is enabled.
[0107] When the session key response status returned by the peer gateway is successful, the quantum VPN controller receives the response information of the session key activation status of the peer gateway corresponding to each gateway in the communication group, and synchronously issues a session key activation and activation command; so that the VPN gateway receives the session key activation and activation command, enables the VPN gateway's session key, and encrypts and forwards data packets according to the set security policy.
[0108] like Figure 2 As shown, the second embodiment of the present invention proposes a quantum VPN controller, specifically including:
[0109] The session key acquisition request sending unit 11 is used to monitor the key update cycle in the gateway communication group and send a session key acquisition request to the quantum key management system when the key update cycle reaches a set value.
[0110] The security parameter index generation unit 12 is used to receive the session key ciphertext information issued by the quantum key management system, and generate the security parameter index (SPI) used by the gateway communication group within the current key update cycle based on the session key ciphertext information.
[0111] Activation unit 13 is used to send encrypted information containing the security parameter index SPI to the gateway communication group to activate the session keys of each gateway and perform encrypted forwarding of data between gateways.
[0112] This embodiment sets the quantum VPN controller to monitor the key update cycle within the gateway communication group. When an update is needed, it sends a session key acquisition request to the quantum key management system and obtains the session key ciphertext information. Then, based on the session key ciphertext information, it generates a Security Parameter Index (SPI) for the current key update of the gateway communication group. It then sends the ciphertext information containing the Security Parameter Index (SPI) to the gateway communication group, activates the session keys of each gateway, and performs encrypted data forwarding between gateways. The quantum VPN controller software service enables the negotiation and control of encrypted session keys between VPN gateways. The session keys between IPSec VPN gateways are encrypted and controlled by the quantum VPN controller to prevent security threats posed by future quantum computers and are applied to the establishment of encrypted VPN tunnels.
[0113] In one embodiment, the quantum VPN controller is used to provide VPN encryption gateway registration management, key application proxy, session key, encryption algorithm and authentication algorithm configuration and distribution control functions. Specifically, it includes a registration management module, a key proxy module, a media management module, a security policy module, a gateway management module and a network management module, wherein the session key acquisition request sending unit 11, the security parameter index generation unit 12 and the laser unit 13 constitute the key proxy module.
[0114] In one embodiment, the registration management module is used to receive registration requests sent by each gateway, the registration request carrying a gateway ID and a security medium ID;
[0115] Each of the gateways integrates a security medium, which stores a master key pre-filled by the quantum key management system.
[0116] In one embodiment, the network management module is specifically used to divide each successfully registered gateway into a communication group for each gateway.
[0117] In one embodiment, the security policy module is used to send security policy information and security key information to each gateway in each gateway communication group;
[0118] The security policy information includes the interconnection relationship between gateways within each gateway communication group, the bridging rules for each gateway's uplink and downlink ports, and the gateway's encrypted data stream policy.
[0119] The security key information includes the symmetric encryption algorithm, cryptographic hash algorithm, and key update cycle used by each of the gateway communication groups.
[0120] In one embodiment, the security policy module includes:
[0121] An encryption unit is used to perform a digest operation on the security policy information and the security key information to obtain a first digest value;
[0122] The policy distribution unit is used to distribute the first digest value, the security policy information, and the security key information to each gateway in the gateway communication group.
[0123] In one embodiment, the gateway management module is used to receive data transmission failure information returned by the gateway when the digest operation of security policy information and security key information fails to verify data consistency at each gateway.
[0124] When the digest calculations of security policy information and security key information are performed at each gateway, and the data consistency is successfully verified, a data delivery success message is received from the gateway.
[0125] In one embodiment, the session key acquisition request sent by the session key acquisition request sending unit 11 carries information including the number of session keys, the length of the session keys, and the ID list information of the security media integrated by the gateway in the gateway communication group.
[0126] In one embodiment, the security parameter index generation unit 12 specifically includes:
[0127] The session key ciphertext information receiving subunit is used to receive session key ciphertext information issued by the quantum key management system. The format of the session key ciphertext information corresponding to different gateways is: [{session key ciphertext, security medium ID, master key serial number ID}], wherein each gateway integrates a security medium, and the security medium stores the master key pre-filled by the quantum key management system.
[0128] The security parameter index generation subunit is used to query the corresponding gateway ID based on the security medium ID, and generate the security parameter index SPI based on the correspondence between the gateway ID, the security medium ID, the master key serial number ID and the session key ciphertext.
[0129] In one embodiment, the activation unit 13 specifically includes:
[0130] The encryption subunit is used to perform a digest operation based on the corresponding security medium ID, the master key sequence number ID, the session key ciphertext, and the security parameter index SPI to generate a second digest value when all gateways in the gateway communication group are in an online running state.
[0131] The activation subunit is used to send corresponding ciphertext information to each gateway in the gateway communication group to activate the session key of each gateway and perform encrypted data forwarding between gateways. The ciphertext information includes the second digest value, the security medium ID, the master key serial number ID, the session key ciphertext, and the security parameter index SPI.
[0132] In one embodiment, the activation subunit is specifically used for:
[0133] Receive response status information returned by each gateway in the gateway communication group, synchronously send session key distribution failure or success status information to the peer gateway of each gateway, and activate the session key of each gateway.
[0134] Receive session key activation status information returned by peer gateways from each gateway, and synchronously issue session key activation activation commands so that each gateway can encrypt data streams and forward them according to the configured security policy information.
[0135] It should be noted that other embodiments or implementation methods of the quantum VPN controller described in this invention can refer to the above-described method embodiments, and will not be repeated here.
[0136] like Figure 4 As shown, the third embodiment of the present invention proposes a VPN gateway key management system, the system comprising: a quantum VPN controller, gateways, and a quantum key management system, each gateway integrating a security medium, each gateway being connected to the quantum VPN controller, and the quantum key management system being connected to each security medium, the quantum VPN controller comprising:
[0137] The session key acquisition request sending unit is used to monitor the key update cycle within the gateway communication group composed of each of the gateways, and send a session key acquisition request to the quantum key management system when the key update cycle reaches a set value.
[0138] The security parameter index generation unit is used to receive the session key ciphertext information issued by the quantum key management system, and generate the security parameter index (SPI) used by the gateway communication group within the current key update cycle based on the session key ciphertext information.
[0139] The activation unit is used to send encrypted information containing the security parameter index SPI to the gateway communication group to activate and enable the session keys of each gateway for encrypted data forwarding between gateways.
[0140] The overall workflow of the VPN gateway key management system proposed in this embodiment is as follows:
[0141] (1) The quantum key management system pre-charges the quantum master key into the secure medium through the charging software.
[0142] (2) The VPN encryption gateway integrates a secure medium. When the gateway starts up, it sends a registration request to the quantum VPN controller, transmitting information such as the gateway ID and the medium ID.
[0143] (3) The quantum VPN controller maintains the online status of each gateway, and the interface provides a visual operation to divide the gateway communication groups and configure the security policy information and security key information of the communication groups.
[0144] (4) The quantum VPN controller performs HMAC-SM3 operations on the security policy rules and security key information of the divided gateway communication groups, and sends the HMAC-SM3 digest value, security policy, and security key information to each gateway in the communication group.
[0145] (5) Each VPN gateway in the communication group receives information, synchronously performs digest calculations of security policies and security key information, and verifies data consistency;
[0146] 1) If the verification fails, the quantum VPN controller will respond that the data delivery has failed.
[0147] 2) If the verification is successful, the security policy and security key information are stored locally and written to the security policy database and security association database, and the status is set to disabled. At the same time, a response is sent to the quantum VPN controller indicating that the data has been successfully delivered.
[0148] (6) The quantum VPN controller monitors the key update cycle and the online status of the gateways in the gateway communication group. When the key update cycle reaches 90%, the quantum VPN controller uses the medium ID integrated by each gateway in the communication group to initiate the acquisition of session keys to the quantum key management system and transmits the number of session keys, the length of the session keys (in multiples of 16 bytes), and the list of security medium ID sets integrated by each gateway in the communication group.
[0149] (7) The quantum key management system receives the number of session keys requested, the length of the session keys, and the security medium IDs integrated by each gateway. It queries the information of the master key stored in each security medium ID, obtains a pre-filled master key in each security medium, and encrypts and distributes the session key using the SM4 symmetric algorithm.
[0150] (8) The quantum VPN controller receives the session key ciphertext information of each gateway in the gateway communication group, queries the corresponding gateway according to the security medium ID, maintains the relationship between the gateway ID, medium ID, medium key serial number ID, and session key ciphertext, and generates the security parameter index SPI used by the gateway communication group within the current key update cycle dimension.
[0151] (9) The quantum VPN controller monitors the online operation status of each gateway in the communication group. If each gateway in the communication group is online, the quantum VPN controller performs HMAC-SM3 operation on {Security Medium ID + Medium Key Serial Number ID + Session Key Ciphertext + Security Parameter Index SPI} and sends the corresponding HMAC-SM3 digest value, Security Medium ID, Medium Key Serial Number ID, Session Key Ciphertext, and Security Parameter Index SPI information to each gateway in the communication group.
[0152] (10) Each gateway in the gateway communication group receives the HMAC-SM3 digest value, session key ciphertext, security medium ID, medium key serial number ID, and security parameter index SPI sent by the gateway, and performs data consistency verification.
[0153] 1) If the security medium ID and medium key sequence number ID are consistent with the security medium ID and sequence number ID integrated with its own gateway, and the calculated HMAC-SM3 digest value is also consistent, then the pre-charged master key corresponding to the medium key sequence number ID is used to decrypt the session key ciphertext, and the session key and SPI are set to the security association database. At the same time, the quantum VPN controller responds with the received status information and continues to step (11);
[0154] 2) If the security medium ID, medium key serial number ID are inconsistent with the security medium information integrated into its own gateway, or if the calculated HMAC-SM3 digest value is inconsistent, then the response information to the VPN controller will be inconsistent.
[0155] (11) The quantum VPN controller receives the response status information of each gateway in the communication group, performs logical judgment and synchronization operation on each response status information, and synchronously sends the failure or success status information of the session key to the peer gateway of each gateway, and activates the gateway session key.
[0156] (12) The VPN gateway receives the session key response status from each peer gateway.
[0157] 1) If the status is failure, then the local session key will not be enabled, and the Quantum VPN controller will respond with a message indicating that the peer's status information has been obtained;
[0158] 2) If the status is successful, then enable the local session key and respond to the quantum VPN controller that the peer status information has been obtained, and continue to step (13).
[0159] (13) The quantum VPN controller receives the response information of the session key activation status of the peer gateway corresponding to each gateway in the communication group, and synchronously issues the session key activation command.
[0160] (14) The VPN gateway receives the session key activation command, enables the session key of the VPN gateway, and encrypts the data stream according to the set security policy to forward the encrypted data packets.
[0161] This embodiment uses the pre-stored information in the security medium integrated into the VPN gateway as an authentication factor. Combined with the national cryptographic algorithm and quantum key, and integrated with the quantum VPN controller, it can uniformly realize the secure distribution and management of quantum key and SPI security parameters, and apply it to the establishment of VPN encrypted tunnels, which has high security.
[0162] Session keys between IPSec VPN gateways are encrypted and distributed through the VPN controller to prevent security threats from future quantum computers. Furthermore, the use of quantum-safe cryptography for encrypted transmission makes it theoretically completely secure and trustworthy.
[0163] It should be noted that other embodiments or implementation methods of the VPN gateway key management system described in this invention can refer to the above-described method embodiments, and will not be repeated here.
[0164] In the description of this specification, references to terms such as "one embodiment," "some embodiments," "example," "specific example," or "some examples," etc., indicate that a specific feature, structure, material, or characteristic described in connection with that embodiment or example is included in at least one embodiment or example of the invention. In this specification, the illustrative expressions of the above terms do not necessarily refer to the same embodiment or example. Furthermore, the specific features, structures, materials, or characteristics described may be combined in any suitable manner in one or more embodiments or examples.
[0165] Furthermore, the terms "first" and "second" are used for descriptive purposes only and should not be construed as indicating or implying relative importance or implicitly specifying the number of technical features indicated. Thus, a feature defined as "first" or "second" may explicitly or implicitly include at least one of that feature. In the description of this invention, "a plurality of" means at least two, such as two, three, etc., unless otherwise explicitly specified.
[0166] Although embodiments of the present invention have been shown and described above, it is understood that the above embodiments are exemplary and should not be construed as limiting the present invention. Those skilled in the art can make changes, modifications, substitutions and variations to the above embodiments within the scope of the present invention.
Claims
1. A method for key management between VPN gateways, characterized in that, Applied to a quantum VPN controller, the method includes: Monitor the key update cycle within the gateway communication group, and send a session key acquisition request to the quantum key management system when the key update cycle reaches a set value; The process involves receiving session key ciphertext information from the quantum key management system and generating a Security Parameter Index (SPI) for the gateway communication group within the current key update cycle based on the session key ciphertext information. This includes receiving the session key ciphertext information from the quantum key management system, wherein the format of the session key ciphertext information corresponding to different gateways is: [{session key ciphertext, security medium ID, master key serial number ID}]. Each gateway integrates a security medium storing a master key pre-filled by the quantum key management system. The process also involves querying the corresponding gateway ID based on the security medium ID, and generating the Security Parameter Index (SPI) based on the correspondence between the gateway ID, the security medium ID, the master key serial number ID, and the session key ciphertext. The system sends encrypted information containing the security parameter index SPI to the gateway communication group to activate the session keys of each gateway and perform encrypted data forwarding between gateways. This includes performing a digest operation based on the corresponding security medium ID, master key serial number ID, session key ciphertext, and security parameter index SPI to generate a second digest value when all gateways in the gateway communication group are online; and sending corresponding encrypted information to each gateway in the gateway communication group to activate the session keys of each gateway and perform encrypted data forwarding between gateways. The encrypted information includes the second digest value, the security medium ID, the master key serial number ID, the session key ciphertext, and the security parameter index SPI.
2. The VPN gateway key management method as described in claim 1, characterized in that, Before sending a session key acquisition request to the quantum key management system when the key update cycle within the monitoring gateway communication group reaches a set value, the method further includes: Receive registration requests sent by each gateway, wherein the registration request carries the gateway ID and the security medium ID; Each of the gateways integrates a security medium, which stores a master key pre-filled by the quantum key management system.
3. The VPN gateway key management method as described in claim 1, characterized in that, Before sending a session key acquisition request to the quantum key management system when the key update cycle within the monitoring gateway communication group reaches a set value, the method further includes: Each successfully registered gateway is divided into a gateway communication group. Send security policy information and security key information to each gateway in each of the aforementioned gateway communication groups; The security policy information includes the interconnection relationship between gateways within each gateway communication group, the bridging rules for each gateway's uplink and downlink ports, and the gateway's encrypted data stream policy. The security key information includes the symmetric encryption algorithm, cryptographic hash algorithm, and key update cycle used by each of the gateway communication groups.
4. The VPN gateway key management method as described in claim 3, characterized in that, The step of sending security policy information and security key information to each gateway in each of the gateway communication groups includes: Perform a digest operation on the security policy information and the security key information to obtain a first digest value; The first digest value, the security policy information, and the security key information are sent to each gateway in the gateway communication group.
5. The VPN gateway key management method as described in claim 4, characterized in that, After sending security policy information and security key information to each gateway in each of the aforementioned gateway communication groups, the method further includes: When performing digest operations on security policy information and security key information at each gateway and failing to verify data consistency, the system receives data transmission failure information returned by the gateway. When the digest operation of security policy information and security key information is performed on each gateway and the data consistency is successfully verified, the data delivery success message returned by the gateway is received.
6. The VPN gateway key management method as described in claim 1, characterized in that, The session key acquisition request carries information including the number of session keys, the session key length, and a list of security media IDs integrated by each gateway in the gateway communication group.
7. The VPN gateway key management method as described in claim 1, characterized in that, After sending the encrypted information containing the security parameter index SPI to the gateway communication group, the method further includes: Receive response status information returned by each gateway in the gateway communication group, synchronously send session key distribution failure or success status information to the peer gateway of each gateway, and activate the session key of each gateway. Receive session key activation status information returned by peer gateways from each gateway, and synchronously issue session key activation activation commands so that each gateway can encrypt data streams and forward them according to the configured security policy information.
8. A quantum VPN controller, characterized in that, For implementing the VPN gateway key management method as described in any one of claims 1-7, comprising: The session key acquisition request sending unit is used to monitor the key update cycle within the gateway communication group and send a session key acquisition request to the quantum key management system when the key update cycle reaches a set value. The security parameter index generation unit is used to receive the session key ciphertext information issued by the quantum key management system, and generate the security parameter index (SPI) used by the gateway communication group within the current key update cycle based on the session key ciphertext information. The activation unit is used to send encrypted information containing the security parameter index SPI to the gateway communication group to activate and enable the session keys of each gateway for encrypted data forwarding between gateways.
9. A VPN gateway key management system, characterized in that, The system includes: a quantum VPN controller, gateways, and a quantum key management system. Each gateway integrates a security medium, and each gateway is connected to the quantum VPN controller. The quantum key management system is connected to each security medium. The quantum VPN controller is used to execute the VPN gateway inter-key management method as described in any one of claims 1-7, including: The session key acquisition request sending unit is used to monitor the key update cycle within the gateway communication group composed of each of the gateways, and send a session key acquisition request to the quantum key management system when the key update cycle reaches a set value. The security parameter index generation unit is used to receive the session key ciphertext information issued by the quantum key management system, and generate the security parameter index (SPI) used by the gateway communication group within the current key update cycle based on the session key ciphertext information. The activation unit is used to send encrypted information containing the security parameter index SPI to the gateway communication group to activate and enable the session keys of each gateway for encrypted data forwarding between gateways.