A key distribution method based on quantum secure network terminal pairing

CN117527231BActive Publication Date: 2026-09-25MATRICTIME DIGITAL TECH CO LTD
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202311756641.5
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2023-12-19
Publication Date
2026-09-25
Estimated Expiration
2043-12-19

AI Technical Summary

Technical Problem

量子密钥分发(QKD)的系统通常依赖于专用的光学设备,来产生和检测量子比特(或称作光子),这些设备包括高精度的光源、光学调制器、单光子探测器和相关的电子组件,其技术的精细程度决定了成本相对较高

Benefits of technology

[0039]本申请的有益效果如下:在本申请的方案中,用户端的请求和响应消息均通过安全中继节点组中的设备去转发,具体包括:在同一局域网内通过用户端归属的不用接入基站去进行请求和响应消息的中继,在不同局域网间,通过边界基站这一专用设备进行配对或响应消息的传输,边界基站与接入基站相连,由接入基站负责用户端的身份合法性认证,只有通过接入基站认证的用户端,才能够通过接入基站和边界基站构成的安全中继节点组,进行消息的转发,以此确保其消息传输过程中的安全性;同时实现了在局域网范围内,以及包含有多个局域网的广域网范围内量子密钥的分发;此外用于分发的量子密钥基于密钥中心根据量子随机数发生器产生的真随机数,与传统QKD密钥的生成和分发相比其系统结构更加简单,设备使用成本更低。

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN117527231B_ABST
    Figure CN117527231B_ABST
Patent Text Reader

Abstract

The application discloses a key distribution method based on quantum security network terminal pairing, comprising: a user terminal forwards a request and a response message through a first security relay node group, the first security relay node group at least comprising a first access base station to which a first user terminal belongs and a second access base station to which a second user terminal belongs, wherein the first access base station and the second access base station are different access base stations; when determining a pairing key center for distributing a key, the pairing key center that can be paired and distributed with the first access base station is selected by the second access base station according to a configuration strategy; through the method, the distribution of quantum keys in a local area network range and a wide area network range containing multiple local area networks is realized; in addition, the quantum key for distribution is based on a true random number generated by a quantum random number generator, and compared with the generation and distribution of a conventional QKD key, the system structure is simpler and the equipment use cost is lower.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This application relates to the field of information security technology, and in particular to a key distribution method based on quantum-secure network terminal pairing. Background Technology

[0002] Quantum-secure networking technology is a communication network security technology based on the principles of quantum mechanics, designed to protect communication content from eavesdropping and tampering. Its core concept is to utilize the entanglement of qubits and the measurement of quantum states to achieve an unbreakable communication method. Quantum-secure networking technology provides a high degree of confidentiality and security for communication through methods such as quantum key distribution and quantum authentication. In this technology, both communicating parties can use securely distributed quantum keys to encrypt and decrypt information, thereby achieving secure communication.

[0003] However, existing quantum secure networks still rely on existing QKD systems for quantum key distribution. Quantum key distribution (QKD) systems typically depend on specialized optical equipment to generate and detect qubits (or photons). These devices include high-precision light sources, optical modulators, single-photon detectors, and related electronic components; the sophistication of the technology results in relatively high costs. Furthermore, quantum channels usually require a stable and low-noise environment to maintain the integrity of the quantum states, further increasing the complexity and economic cost of implementing QKD systems.

[0004] Furthermore, the transmission characteristics of QKD currently limit its application in the real world because it is based on a point-to-point communication protocol, meaning information can only be securely transmitted between two defined locations. In QKD systems, establishing a quantum channel requires a direct physical connection, such as fiber optic cables or free-space transmission paths, which limits its scalability.

[0005] Therefore, reducing the complexity of distributing quantum keys in quantum-safe networks and achieving quantum key distribution on a larger scale have become urgent technical problems to be solved. Summary of the Invention

[0006] To address the aforementioned technical problems, this application discloses a key distribution method based on terminal pairing in a quantum-safe network, comprising the following steps:

[0007] The first user terminal sends a pairing request to the second user terminal through the first secure relay node group, and carries pairing key size information in the pairing request; the first secure relay node group includes at least the first access base station to which the first user terminal belongs, and the second access base station to which the second user terminal belongs, wherein the first access base station and the second access base station are different access base stations.

[0008] If the second user terminal determines to accept the pairing request, it sends a pairing key distribution request to the second access base station, and carries the pairing key size information, the first user terminal network access ID and the second user terminal network access ID in the pairing key distribution request;

[0009] The second access base station negotiates and selects a pairing key center that can be paired with the first access base station for distribution according to the configuration policy, forwards the pairing key distribution request to this pairing key center, and carries the first user terminal network access ID and the second user terminal network access ID.

[0010] The pairing key center generates a corresponding pairing key file based on the key size information in the pairing key distribution request, generates corresponding pairing key acquisition information for the first user terminal and the second user terminal respectively, and then generates a pairing key generation message to be returned to the second access base station.

[0011] The second access base station sends a key distribution response message to the second user terminal, and the second user terminal sends a pairing response message to the first user terminal through the first security relay node group, thereby enabling the first user terminal and the second user terminal to download the pairing key file from the pairing key center respectively.

[0012] In the above scheme, the pairing key generation message includes: pairing key ID, the key center ID of the pairing key center itself, the first user terminal network access ID, and the second user terminal network access ID;

[0013] The pairing key acquisition information includes: a distribution key for encrypting the pairing key file, and a pairing key index corresponding to the pairing key file; the pairing key center further identifies the pairing key acquisition information corresponding to the first user terminal and the second user terminal respectively through the pairing key ID and the user terminal network access ID.

[0014] In the above scheme, the specific steps involved in the second access base station sending a key distribution response message to the second user terminal and the second user terminal sending a pairing response message to the first user terminal through the first secure relay node group are as follows:

[0015] The second access base station generates a pairing key distribution response message carrying the key center IP based on the received pairing key generation message, obtains the second terminal link corresponding to the second user terminal according to the network access ID of the second user terminal, and sends the pairing key distribution response message to the second user terminal through the second terminal link.

[0016] The second user terminal generates a pairing response message based on the pairing key distribution response message and sends it to the first user terminal. The pairing response message is then forwarded to the first user terminal by the first security relay node group. The content of the pairing response message includes: key center ID, pairing key ID, and key center IP.

[0017] In the above scheme, the downloading of the pairing key file by the first user terminal and the second user terminal specifically includes the following steps:

[0018] Based on the received pairing response message, the first user terminal obtains the pairing key acquisition information from the pairing key center through the second secure relay node group; based on the received pairing key distribution response message, the second user terminal obtains the pairing key acquisition information from the pairing key center through the third secure relay node group.

[0019] The first and second user terminals obtain information based on their respective pairing keys, download the encrypted pairing key file from the pairing key center, decrypt it according to the corresponding distribution key, and then each performs integrity verification on the plaintext of the decrypted pairing key file, retaining the pairing key file that has been successfully verified by both parties.

[0020] In the above scheme, the method for forwarding the pairing request from the first user terminal as the sender to the second user terminal as the receiver, and the method for forwarding the key pairing response message from the second user terminal as the sender to the first user terminal as the receiver through the first secure relay node group, includes the following steps:

[0021] The sending end sends a pairing request to its home access base station, carrying the receiving end's network access ID;

[0022] When the access base station to which the sending end belongs determines that the receiving end does not belong to this local area network based on the receiving end's network access ID, it further obtains the link of the access base station to which the receiving end belongs based on the receiving end's network access ID, and forwards the request or response message to the access base station to which the receiving end belongs based on the obtained link.

[0023] The access base station to which the receiving end belongs matches the corresponding receiving end link based on the terminal identifier in the receiving end's network access ID, and forwards the request or response message to the receiving end based on this receiving end link.

[0024] In the above scheme, the method for forwarding the pairing request from the first user terminal as the sender to the second user terminal as the receiver, and the method for forwarding the key pairing response message from the second user terminal as the sender to the first user terminal as the receiver through the first secure relay node group, includes the following steps:

[0025] The sending end sends a pairing request to its home access base station, carrying the receiving end's network access ID;

[0026] When the access base station to which the sending end belongs determines that the receiving end does not belong to this local area network based on the receiving end's network access ID, it further selects a boundary base station within this local area network based on the receiving end's network access ID and forwards the request or response message to that boundary base station.

[0027] The boundary base station within this local area network selects the next-hop boundary base station based on the receiver's network access ID and forwards the request or response message to that next-hop boundary base station;

[0028] If the next-hop border base station determines that the receiver belongs to its own local area network (LAN) based on the receiver's network access ID, it determines the access base station within the LAN to which the receiver belongs based on the receiver's network access identifier and forwards the request or response message to that access base station. The access base station then matches the corresponding receiver link based on the terminal identifier in the receiver's network access ID and forwards the request or response message to the receiver based on this receiver link. If the next-hop border base station determines that the receiver does not belong to its own LAN based on the receiver's network access ID, it continues to select the next next-hop border base station based on the receiver's network access ID and forwards the request or response message to that next next-hop border base station until a border base station within the LAN to which the receiver belongs is selected, and the request or response message is forwarded to the border base station within the LAN to which the receiver belongs.

[0029] In the above scheme, the method for the first user terminal and the second user terminal to obtain pairing key acquisition information from the pairing key center includes the following steps:

[0030] The user terminal generates a pairing key acquisition information download request and sends the pairing key acquisition information download request to the access base station to which the user terminal belongs. The pairing key acquisition information download request includes: key center ID and pairing key ID.

[0031] The access base station to which the user belongs matches the corresponding pairing key center link based on the key center ID, and forwards the download request for the pairing key acquisition information carrying the user's network access ID to the corresponding pairing key center according to this pairing key center link.

[0032] The pairing key center matches the corresponding pairing key to obtain information based on the pairing key ID and the user terminal network access ID, and returns the pairing key acquisition information to the access base station to which the user terminal belongs based on the user terminal network access ID.

[0033] The access base station to which the user belongs matches the corresponding user connection based on the user's network access ID, and forwards the pairing key acquisition information to the user based on the user connection.

[0034] In the above scheme, the method for the first user terminal and the second user terminal to obtain pairing key acquisition information from the pairing key center includes the following steps:

[0035] The user terminal generates a pairing key acquisition information download request and sends the pairing key acquisition information download request to the access base station to which the user terminal belongs. The pairing key acquisition information download request includes: key center ID and pairing key ID.

[0036] The access base station to which the user belongs selects a boundary base station within its local area network based on the key center ID, and forwards the pairing key acquisition information download request to the selected boundary base station within its local area network. The pairing key acquisition information download request includes: key center ID, pairing key ID, and user's network access ID.

[0037] Within this local area network, the boundary base station selects the next-hop boundary base station based on the key center ID and forwards the paired key acquisition information download request to that next-hop boundary base station.

[0038] If the next-hop border base station determines that the paired key center belongs to its own local area network based on the key center ID, it will match the corresponding paired key center link based on the key center ID and forward the paired key acquisition information download request to the corresponding paired key center according to this paired key center link; if the next-hop border base station determines that the paired key center does not belong to its own local area network based on the key center ID, it will continue to select the next next-hop border base station according to the key center ID until the paired key acquisition information download request is forwarded to the border base station in the local area network to which the paired key center belongs.

[0039] The beneficial effects of this application are as follows: In the scheme of this application, both request and response messages from the user terminal are forwarded through devices in the secure relay node group. Specifically, this includes: relaying request and response messages within the same local area network (LAN) through the access base station to which the user terminal belongs; and between different LANs, pairing or transmission of response messages is carried out through a dedicated device called the boundary base station. The boundary base station is connected to the access base station, which is responsible for authenticating the user terminal's identity. Only user terminals authenticated by the access base station can forward messages through the secure relay node group composed of the access base station and the boundary base station, thereby ensuring the security of message transmission. Simultaneously, it realizes the distribution of quantum keys within the LAN and within a wide area network containing multiple LANs. Furthermore, the quantum keys used for distribution are based on truly random numbers generated by the key center using a quantum random number generator. Compared with the generation and distribution of traditional QKD keys, its system structure is simpler and the equipment usage cost is lower. Attached Figure Description

[0040] To more clearly illustrate the technical solutions in the embodiments of this application, the accompanying drawings used in the description of the embodiments will be briefly introduced below. Obviously, the accompanying drawings described below are only some embodiments of this application. For those skilled in the art, other drawings can be obtained based on these drawings without creative effort.

[0041] Figure 1This is a schematic diagram of the key distribution method based on quantum-safe network terminal pairing in this embodiment;

[0042] Figure 2 This is a schematic diagram of a method for forwarding request or response messages through a first secure relay node group in this embodiment;

[0043] Figure 3 This is a schematic diagram of another method for forwarding request or response messages through a first secure relay node group in this embodiment;

[0044] Figure 4 This is a flowchart of a method for a user terminal to obtain pairing key information from a pairing key center in this embodiment;

[0045] Figure 5 This is a flowchart of another method for a user terminal to obtain pairing key information from a pairing key center in this embodiment. Detailed Implementation

[0046] To make the objectives, technical solutions, and advantages of this application clearer, the application will be further described in detail below with reference to the accompanying drawings. Obviously, the described embodiments are only some embodiments of this application, and not all embodiments. Based on the embodiments in this application, all other embodiments obtained by those skilled in the art without creative effort are within the scope of protection of this application.

[0047] Example: A key distribution method based on quantum-safe network terminal pairing is applied to the distribution of paired keys in a quantum-safe local area network (LAN) comprising multiple quantum-safe terminals, multiple access base stations, boundary base stations, and a key center, and a wide area network (WAN) comprising multiple quantum-safe LANs. In the quantum-safe LAN, each access base station has one or more quantum-safe terminals connected to it. The access base stations are interconnected, and each access base station is connected to at least one boundary base station. The access base stations and boundary base stations are connected to the key center. The quantum-safe LANs are connected through the boundary base stations, and data is transmitted between the quantum-safe LANs through the boundary base stations. Each quantum-secure terminal connected to the access base station is assigned a unique network access ID. The key center distributes paired keys, i.e., quantum keys, to the quantum-secure terminals using truly random numbers generated by a quantum random number generator. The quantum-secure terminals use quantum keys to encrypt and decrypt data, and the access base station and the boundary base station adopt a server architecture. Paired key distribution means distributing symmetric keys to the two quantum-secure terminals requesting point-to-point communication, so that the two quantum-secure terminals can share the same quantum key and perform quantum encryption and decryption processing on their respective transmitted and received data. For ease of description, the two quantum-secure terminals requesting the distribution of symmetric keys are referred to as the first user terminal and the second user terminal, respectively.

[0048] The method specifically includes the following steps:

[0049] S101: The first user terminal sends a pairing request to the second user terminal through the first secure relay node group, and carries pairing key size information in the pairing request; the first secure relay node group includes at least the first access base station to which the first user terminal belongs, and the second access base station to which the second user terminal belongs, wherein the first access base station and the second access base station are different access base stations.

[0050] For example, when the first user terminal and the second user terminal are in the same local area network, the first security relay node group includes the first access base station and the second access base station, and the first user terminal forwards the pairing request to the second user terminal through the first access base station and the second access base station;

[0051] When the first user terminal and the second user terminal are in different local area networks, the first user terminal forwards the pairing request to the second user terminal through the first access base station, the boundary base station in the local area network where the first user terminal is located, the boundary base station in the local area network where the second user terminal is located, and the second access base station.

[0052] The pairing request should also include the network access ID of the second user terminal, so that the first access base station can determine the corresponding receiving terminal, i.e., the second user terminal; the first user terminal is connected under the first access base station, and the first access base station assigns its corresponding unique network access ID, i.e., the first network access ID, to the first user terminal; similarly, the network access ID of the second access base station is assigned by the second access base station.

[0053] The first access base station and the second access base station are further used to authenticate the legitimacy of the identity of the first user terminal and the second user terminal based on their unique device identifiers, and to assign a network access ID after successful authentication.

[0054] In this step, the access base station authenticates the user's identity to ensure its security. Only authenticated user terminals can forward pairing requests through the first secure relay node group, which isolates spoofing requests from illegitimate devices and improves the security of message transmission.

[0055] S102: If the second user terminal determines to accept the pairing request, it sends a pairing key distribution request to the second access base station, and carries the pairing key size information, the first user terminal network access ID and the second user terminal network access ID in the pairing key distribution request;

[0056] The second user terminal can determine whether to accept the request based on preset conditions, such as whether the current storage capacity meets the storage requirements of the new pairing key, or manually confirm whether to accept it.

[0057] S103: The second access base station negotiates and selects a pairing key center that can be paired with the first access base station for distribution according to the configuration policy, forwards the pairing key distribution request to this pairing key center, and carries the first user terminal network access ID and the second user terminal network access ID.

[0058] In one possible implementation, the specific negotiation strategy includes: the second access base station and the first access base station listing a set of key centers to which both have established connections; calculating the number of hops to each key center in the set based on the routing table; and selecting the key center with the smallest sum of hops between the two parties as the key center for generating the pairing key. If there is a key center with the smallest sum of hops and there are multiple corresponding key centers, the second access base station further determines the corresponding key center in a random manner, or selects the key center with the closest routing to it as the key center for generating the pairing key, thereby saving response time.

[0059] S104: The pairing key center generates a corresponding pairing key file based on the key size information in the pairing key distribution request, and generates corresponding pairing key acquisition information for the first user terminal and the second user terminal respectively. The pairing key acquisition information for the first user terminal and the second user terminal is identified by the pairing key ID and the user terminal network access ID respectively. The pairing key acquisition information includes: a distribution key for encrypting the pairing key file, and a pairing key index corresponding to the pairing key file.

[0060] A pairing key generation message is then generated for return to the second access base station. The pairing key generation message includes: pairing key ID, the key center ID of the pairing key center itself, the first user terminal network access ID, and the second user terminal network access ID.

[0061] The pairing key center generates a true random number file of the corresponding length using a random number generator based on the key size information, and uses this file as the pairing key file;

[0062] The pairing key index is used to identify the file location information corresponding to the pairing key file generated by the pairing key center. When the user requests to download the pairing key from the pairing key center, it provides the pairing key index to the pairing key center to download the corresponding pairing key file.

[0063] To ensure security, when the pairing key center sends the pairing key file to the user, it further encrypts the sent pairing key file using the distribution key it generates. When the user receives the encrypted pairing key file, it decrypts it according to the distribution key to obtain the plaintext of the pairing key file.

[0064] The pairing key center is identified by the key center ID, which further includes fields for identifying its network location and fields for device ID information. For example, the key center ID includes a country code, a carrier code, a region identifier, a local area network identifier, and a device identifier. The device identifier is used to identify the manufacturer, model, and production serial number of the key center. Each identifier in the key center ID is unique, so the specific device corresponding to it, i.e., the key center, can be determined through the key center ID.

[0065] S105: The second access base station generates a pairing key distribution response message carrying the key center IP based on the received pairing key generation message, obtains the second terminal link corresponding to the second user terminal according to the network access ID of the second user terminal, and sends the pairing key distribution response message to the second user terminal through the second terminal link.

[0066] In this step, the second access base station provides the second user terminal with the connection information of the pairing key center, namely the key center IP and key center ID, so that the second user terminal can connect to the pairing key center according to the key center IP and key center ID;

[0067] S106: The second user terminal generates a pairing response message based on the pairing key distribution response message and sends it to the first user terminal, and forwards the pairing response message to the first user terminal through the first security relay node group; the content of the pairing response message includes: key center ID, pairing key ID and key center IP;

[0068] That is, the second user terminal returns the pairing key center connection information to the first user terminal;

[0069] S107: Based on the received pairing response message, the first user terminal obtains the pairing key acquisition information from the pairing key center through the second security relay node group;

[0070] The second user terminal obtains the pairing key acquisition information from the pairing key center through the third security relay node group based on the received pairing key distribution response message.

[0071] That is, the first user terminal and the second user terminal each request the distribution key assigned to them by the pairing key center for decrypting the ciphertext of the pairing key file, as well as the pairing key index of the downloaded and generated pairing key file.

[0072] In one possible implementation, the first user terminal and the second user terminal respectively send a request containing a pairing key ID and a network access ID to their respective access base stations. The access base station forwards the request to the pairing key center. The pairing key center matches the distribution key and pairing key index corresponding to each user terminal based on the pairing key ID and the network access ID, and then sends the distribution key and pairing key index to the access base station to which the user terminal belongs. The access base station then forwards the distribution key and pairing key index to the corresponding user terminal.

[0073] The first and second user terminals obtain information according to their respective pairing keys, download the ciphertext of the pairing key file from the pairing key center and decrypt it according to the corresponding distribution key, and then each performs integrity verification on the plaintext of the decrypted pairing key file, and retains the pairing key file that has been successfully verified by both parties.

[0074] In one possible implementation, when the pairing key center sends the pairing key file to the user terminal, it divides the pairing key file into multiple independent files of equal length. Each independent file carries its corresponding sequence number identifier in its file header. For example, the first byte of each independent file is designated as its sequence number identifier, so that the user terminal can assemble a complete pairing key file according to the sequence number identifier. The sequence number identifier is then encrypted using an encryption key and stored in the file header in ciphertext. The encryption key is selected by the user terminal from its stored quantum key when the user terminal requests it from the pairing key center.

[0075] The pairing key center calculates the hash value corresponding to the pairing key file, then generates a true random number of the length corresponding to the independent file as the distribution key, uses the distribution key to encrypt each independent file, and returns the encrypted independent files and hash values ​​to the corresponding user terminal.

[0076] After receiving each individual file, the user terminal decrypts each individual file and its selected encryption key using the distribution key and the sequence number identifier within each file. Based on the order information provided by the sequence number identifier, the downloaded individual files are combined into a complete pairing key file, and its hash value is calculated for integrity verification. During this process, the pairing key file is divided into multiple parts. Only after correctly decrypting each individual file and its sequence number identifier can the complete pairing key file be obtained. The two encryption keys used in this process are provided by the pairing key center and the user terminal, respectively. This makes it difficult to decrypt the pairing key file to obtain the complete pairing key file even if the download is intercepted, resulting in higher overall security.

[0077] In one possible implementation, the first user terminal can send an encrypted pairing request, which can be encrypted using quantum encryption or a combination of classical and quantum encryption. Taking quantum encryption alone as an example, the first user terminal uses a pre-stored quantum key to encrypt the pairing request; for instance, it can encrypt the request's data payload to generate an encrypted pairing request. Then, the first user terminal sends the encrypted pairing request along with index information associated with the quantum key to its connected access base station. Upon receiving this index information and the encrypted pairing request, the access base station uses the network identifier of the first user terminal contained in the pairing request to determine the key repository matching the first user terminal. Next, it extracts the corresponding key from the key repository based on the index information and uses this key to decrypt the encrypted pairing request, thereby obtaining the original pairing request.

[0078] On the other hand, if the first user terminal uses classical encryption, it will encrypt the pairing request using an encryption algorithm and key pre-agreed with the second user terminal, obtaining the encrypted request, and then send the encrypted request to the second user terminal through the access base station. Upon receiving this request, the second user terminal will decrypt it using the same algorithm and key, thus completing the pairing process. This method combines the unbreakability of quantum encryption with the convenience of classical encryption, providing a secure pairing mechanism for both communicating parties.

[0079] The first user terminal, acting as the sender, sends a pairing request to the second user terminal, acting as the receiver, and the second user terminal, acting as the sender, sends a key pairing response message to the first user terminal, acting as the receiver. Both of these are forwarded through the first secure relay node group. The specific method includes the following steps:

[0080] The first user terminal's network access ID and the second user terminal's network access ID are used to identify the network location of the user terminal and the specific terminal it corresponds to. For example, the information contained in the first and second user terminal network access IDs includes: country code (CC), operator code (NC), regional identifier (LCI), local area network identifier (SCI), access base station identifier (BID), and terminal identifier (SID). Among these, the country code identifies the country to which the user terminal belongs, the operator code identifies the operator to which the user terminal belongs, and the regional identifier... The network access ID is used to identify the region to which the user terminal belongs. A region contains multiple local area networks (LANs). The LAN identifier is used to identify the LAN to which the user terminal belongs, and the terminal identifier is used to identify the user terminal. For example, the terminal identifier includes the generator manufacturer code, device model number, and generator serial number. Each identifier in the network access ID is unique. The network location of the user terminal can be determined by the country code, operator code, region identifier, and LAN identifier. The specific terminal in that network location, i.e., the corresponding user terminal, can be determined by the country code, operator code, region identifier, LAN identifier, access base station identifier, and terminal identifier.

[0081] Scenario 1: The sender and receiver are on the same local area network (LAN). This is determined by the country code, carrier code, region identifier, and LAN identifier in the network access ID. This scenario includes the following steps:

[0082] S201: The sending end sends a pairing request to its home access base station and carries the receiving end's network access ID;

[0083] S202: When the access base station to which the sending end belongs determines that the receiving end does not belong to this local area network based on the receiving end's network access ID, it further obtains the link of the access base station to which the receiving end belongs based on the receiving end's network access ID, and forwards the request or response message to the access base station to which the receiving end belongs based on the obtained link.

[0084] S203: The access base station to which the receiving end belongs matches the corresponding receiving end link based on the terminal identifier in the receiving end's network access ID, and forwards the request or response message to the receiving end based on this receiving end link.

[0085] In one possible implementation, the access base station establishes a mapping relationship between the network access ID and IP address for each user terminal. The access base station matches the corresponding user terminal IP address based on the network access ID, obtains its IP information, and then sends the request or response message to the corresponding user terminal, i.e., the receiving terminal.

[0086] Scenario 2: The sender and receiver are in different local area networks (LANs). This is determined by the country code, operator code, region identifier, and LAN identifier in the network access ID. Each LAN contains a boundary base station used for data transmission between LANs.

[0087] S301: The sending end sends a pairing request to its home access base station and carries the receiving end's network access ID;

[0088] S302: When the access base station to which the sending end belongs determines that the receiving end does not belong to this local area network based on the receiving end's network access ID, it further selects a boundary base station within this local area network based on the receiving end's network access ID and forwards the request or response message to that boundary base station.

[0089] S303: The boundary base station within this local area network selects the next-hop boundary base station based on the receiver's network access ID and forwards the request or response message to that next-hop boundary base station;

[0090] S304: If the next-hop boundary base station determines that the receiver belongs to its own local area network based on the receiver's network access ID, it determines the access base station in the local area network to which the receiver belongs based on the receiver's network access identifier, and forwards the request or response message to the access base station. The access base station then matches the corresponding receiver link based on the terminal identifier in the receiver's network access ID, and forwards the request or response message to the receiver based on this receiver link.

[0091] If the next-hop border base station determines that the receiver does not belong to its own local area network based on the receiver's network access ID, it will continue to select the next next-hop border base station based on the receiver's network access ID and forward the request or response message to the next next-hop border base station until a border base station within the local area network to which the receiver belongs is selected, and the request or response message is forwarded to the border base station within the local area network to which the receiver belongs.

[0092] Between different local area networks, pairing or response message transmission is carried out through a dedicated device called a border base station. The border base station is connected to the access base station, which is responsible for authenticating the identity of the user terminal. Only user terminals authenticated by the access base station can forward messages through the secure relay node group composed of the access base station and the border base station, thereby ensuring the security of message transmission.

[0093] The methods by which the first user terminal and the second user terminal obtain pairing key information from the pairing key center include the following:

[0094] Scenario 1: When the access base station to which the user terminal belongs and the pairing key center belong to the same local area network, the method for downloading the pairing key acquisition information includes the following steps:

[0095] S401: The user terminal generates a pairing key acquisition information download request and sends the pairing key acquisition information download request to the access base station to which the user terminal belongs. The pairing key acquisition information download request includes: key center ID and pairing key ID.

[0096] S402: The access base station to which the user terminal belongs matches the corresponding pairing key center link based on the key center ID, and forwards the download request for the pairing key acquisition information carrying the user terminal's network access ID to the corresponding pairing key center according to this pairing key center link.

[0097] Within a local area network (LAN), each access base station establishes a mapping relationship between its own paired key center ID and its IP address. When forwarding messages, the key center ID is matched to its corresponding IP address, and then the message is forwarded based on that IP address.

[0098] S403: The pairing key center matches the corresponding pairing key to obtain information based on the pairing key ID and the user terminal network access ID, and returns the pairing key acquisition information to the access base station to which the user terminal belongs based on the user terminal network access ID.

[0099] S404: The access base station to which the user terminal belongs matches the corresponding user terminal link based on the user terminal's network access ID, and forwards the pairing key acquisition information to the user terminal based on the user terminal link.

[0100] Scenario 2: The user's access base station and the pairing key center are on different local area networks. The method for downloading the pairing key acquisition information includes the following steps:

[0101] S501: The user terminal generates a pairing key acquisition information download request and sends the pairing key acquisition information download request to the access base station to which the user terminal belongs. The pairing key acquisition information download request includes: key center ID and pairing key ID.

[0102] S502: The access base station to which the user terminal belongs selects a boundary base station within its local area network based on the key center ID, and forwards the pairing key acquisition information download request to the selected boundary base station within its local area network. The pairing key acquisition information download request includes: key center ID, pairing key ID, and user terminal network access ID.

[0103] S503: The boundary base station within this local area network selects the next-hop boundary base station based on the key center ID and forwards the paired key acquisition information download request to the next-hop boundary base station;

[0104] S504: If the next-hop boundary base station determines that the paired key center belongs to its own local area network based on the key center ID, it will match the corresponding paired key center link based on the key center ID and forward the paired key acquisition information download request to the corresponding paired key center based on this paired key center link.

[0105] Within the local area network, both the access base station and the boundary base station establish a mapping relationship between the key center ID and the IP address of their respective paired key centers within the local area network. When forwarding, the key center ID is matched to the corresponding IP address, and then the message is forwarded based on that IP address.

[0106] The pairing key center matches the pairing key ID and user terminal network access ID in the pairing key acquisition information download request with the corresponding pairing key acquisition information, and returns the pairing key acquisition information to the user terminal; the specific pairing key acquisition information can be returned according to the original transmission path of the pairing key acquisition information download request;

[0107] If the next-hop boundary base station determines that the paired key center does not belong to its own local area network based on the key center ID, it will continue to select the next next-hop boundary base station based on the key center ID until the paired key acquisition information download request is forwarded to the boundary base station in the local area network to which the paired key center belongs.

[0108] In the above process, the device in the secure relay node group used to forward the pairing key acquisition information download request and the pairing key acquisition information is determined based on the key center ID. Devices that do not belong to the secure relay node group are difficult to interact with the user terminal, and the security of pairing key distribution is higher.

[0109] Obviously, those skilled in the art can make various modifications and variations to this application without departing from the spirit and scope of this application. Therefore, if such modifications and variations fall within the scope of the claims of this application and their equivalents, this application also intends to include such modifications and variations.

Claims

1. A key distribution method based on terminal pairing in a quantum-safe network, characterized in that: Includes the following steps: The first user terminal sends a pairing request to the second user terminal through the first secure relay node group, and carries pairing key size information in the pairing request; the first secure relay node group includes at least the first access base station to which the first user terminal belongs, and the second access base station to which the second user terminal belongs, wherein the first access base station and the second access base station are different access base stations. If the second user terminal determines to accept the pairing request, it sends a pairing key distribution request to the second access base station, and carries the pairing key size information, the first user terminal network access ID and the second user terminal network access ID in the pairing key distribution request; The second access base station negotiates and selects a pairing key center that can be paired with the first access base station for distribution according to the configuration policy, forwards the pairing key distribution request to this pairing key center, and carries the first user terminal network access ID and the second user terminal network access ID. The pairing key center generates a corresponding pairing key file based on the key size information in the pairing key distribution request, generates corresponding pairing key acquisition information for the first user terminal and the second user terminal respectively, and then generates a pairing key generation message to be returned to the second access base station. The second access base station sends a key distribution response message to the second user terminal, and the second user terminal sends a pairing response message to the first user terminal through the first security relay node group, thereby enabling the first user terminal and the second user terminal to download the pairing key file from the pairing key center respectively.

2. The key distribution method based on quantum-safe network terminal pairing according to claim 1, characterized in that, The pairing key generation message includes: pairing key ID, the key center ID of the pairing key center itself, the first user terminal network access ID, and the second user terminal network access ID; The pairing key acquisition information includes: a distribution key for encrypting the pairing key file, and a pairing key index corresponding to the pairing key file; the pairing key center further identifies the pairing key acquisition information corresponding to the first user terminal and the second user terminal respectively through the pairing key ID and the user terminal network access ID.

3. The key distribution method based on quantum-safe network terminal pairing according to claim 2, characterized in that, The specific steps involved in the second access base station sending a key distribution response message to the second user terminal and the second user terminal sending a pairing response message to the first user terminal through the first secure relay node group are as follows: The second access base station generates a pairing key distribution response message carrying the key center IP based on the received pairing key generation message, obtains the second terminal link corresponding to the second user terminal according to the network access ID of the second user terminal, and sends the pairing key distribution response message to the second user terminal through the second terminal link. The second user terminal generates a pairing response message based on the pairing key distribution response message and sends it to the first user terminal. The pairing response message is then forwarded to the first user terminal by the first security relay node group. The content of the pairing response message includes: key center ID, pairing key ID, and key center IP.

4. A key distribution method based on quantum-safe network terminal pairing according to claim 3, characterized in that, The specific steps involved in downloading the pairing key file by the first and second user terminals are as follows: Based on the received pairing response message, the first user terminal obtains the pairing key acquisition information from the pairing key center through the second secure relay node group; based on the received pairing key distribution response message, the second user terminal obtains the pairing key acquisition information from the pairing key center through the third secure relay node group. The first and second user terminals obtain information based on their respective pairing keys, download the encrypted pairing key file from the pairing key center, decrypt it according to the corresponding distribution key, and then each performs integrity verification on the plaintext of the decrypted pairing key file, retaining the pairing key file that has been successfully verified by both parties.

5. A key distribution method based on quantum-safe network terminal pairing according to claim 1, characterized in that: When the first user terminal, acting as the sender, sends a pairing request to the second user terminal, acting as the receiver, and the second user terminal, acting as the sender, sends a key pairing response message to the first user terminal, acting as the receiver, both of which are forwarded through the first secure relay node group, the method includes the following steps: The sending end sends a pairing request to its home access base station, carrying the receiving end's network access ID; When the access base station to which the sending end belongs determines that the receiving end does not belong to this local area network based on the receiving end's network access ID, it further obtains the link of the access base station to which the receiving end belongs based on the receiving end's network access ID, and forwards the request or response message to the access base station to which the receiving end belongs based on the obtained link. The access base station to which the receiving end belongs matches the corresponding receiving end link based on the terminal identifier in the receiving end's network access ID, and forwards the request or response message to the receiving end based on this receiving end link.

6. A key distribution method based on quantum-safe network terminal pairing according to claim 1, characterized in that: When the first user terminal, acting as the sender, sends a pairing request to the second user terminal, acting as the receiver, and the second user terminal, acting as the sender, sends a key pairing response message to the first user terminal, acting as the receiver, both of which are forwarded through the first secure relay node group, the method includes the following steps: The sending end sends a pairing request to its home access base station, carrying the receiving end's network access ID; When the access base station to which the sending end belongs determines that the receiving end does not belong to this local area network based on the receiving end's network access ID, it further selects a boundary base station within this local area network based on the receiving end's network access ID and forwards the request or response message to that boundary base station. The boundary base station within this local area network selects the next-hop boundary base station based on the receiver's network access ID and forwards the request or response message to that next-hop boundary base station; If the next-hop boundary base station determines that the receiver belongs to its own local area network based on the receiver's network access ID, it determines the access base station in the local area network to which the receiver belongs based on the receiver's network access identifier, and forwards the request or response message to the access base station. The access base station then matches the corresponding receiver link based on the terminal identifier in the receiver's network access ID, and forwards the request or response message to the receiver based on this receiver link. If the next-hop border base station determines that the receiver does not belong to its own local area network based on the receiver's network access ID, it will continue to select the next next-hop border base station based on the receiver's network access ID and forward the request or response message to the next next-hop border base station until a border base station within the local area network to which the receiver belongs is selected, and the request or response message is forwarded to the border base station within the local area network to which the receiver belongs.

7. A key distribution method based on quantum-safe network terminal pairing according to claim 4, characterized in that: The method for the first and second user terminals to obtain pairing key information from the pairing key center includes the following steps: The user terminal generates a pairing key acquisition information download request and sends the pairing key acquisition information download request to the access base station to which the user terminal belongs. The pairing key acquisition information download request includes: key center ID and pairing key ID. The access base station to which the user belongs matches the corresponding pairing key center link based on the key center ID, and forwards the download request for the pairing key acquisition information carrying the user's network access ID to the corresponding pairing key center according to this pairing key center link. The pairing key center matches the corresponding pairing key to obtain information based on the pairing key ID and the user terminal network access ID, and returns the pairing key acquisition information to the access base station to which the user terminal belongs based on the user terminal network access ID. The access base station to which the user belongs matches the corresponding user connection based on the user's network access ID, and forwards the pairing key acquisition information to the user based on the user connection.

8. A key distribution method based on quantum-safe network terminal pairing according to claim 4, characterized in that: The method for the first and second user terminals to obtain pairing key information from the pairing key center includes the following steps: The user terminal generates a pairing key acquisition information download request and sends the pairing key acquisition information download request to the access base station to which the user terminal belongs. The pairing key acquisition information download request includes: key center ID and pairing key ID. The access base station to which the user belongs selects a boundary base station within its local area network based on the key center ID, and forwards the pairing key acquisition information download request to the selected boundary base station within its local area network. The pairing key acquisition information download request includes: key center ID, pairing key ID, and user's network access ID. Within this local area network, the boundary base station selects the next-hop boundary base station based on the key center ID and forwards the paired key acquisition information download request to that next-hop boundary base station. If the next-hop border base station determines that the paired key center belongs to its own local area network based on the key center ID, it will match the corresponding paired key center link based on the key center ID and forward the paired key acquisition information download request to the corresponding paired key center according to this paired key center link; if the next-hop border base station determines that the paired key center does not belong to its own local area network based on the key center ID, it will continue to select the next next-hop border base station according to the key center ID until the paired key acquisition information download request is forwarded to the border base station in the local area network to which the paired key center belongs.

9. A key distribution method based on quantum-safe network terminal pairing according to claim 1, characterized in that: The first user terminal is the user terminal that has been authenticated by the first access base station, and the second user terminal is the user terminal that has been authenticated by the second access base station.

Citation Information

Patent Citations

  • Mobile communication terminal quantum communication method and system based on base station

    CN111917537A

  • Quantum security key distribution method and system

    CN115442040A