Method for encrypted communication based on integration of quantum key distribution and communication
By integrating quantum key distribution and communication in a quantum key distribution system and employing end-to-end encrypted transmission, the high fiber optic resource requirements and key transmission security challenges of existing technologies are solved, thereby improving both security and resource efficiency, and making it suitable for complex topologies.
Patent Information
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- CAS QUANTUM NETWORK CO LTD
- Filing Date
- 2022-08-22
- Publication Date
- 2026-04-28
AI Technical Summary
Existing quantum key distribution systems, when deployed independently in large-scale networking scenarios, suffer from high fiber optic resource requirements, difficulty in ensuring key transmission security, and an inability to detect the routing addresses of encryption devices, leading to a rapid increase in network burden and limiting system scalability.
By integrating quantum key distribution and communication in receiving, relaying, and transmitting devices, session keys and service data are transmitted using end-to-end encrypted transmission. Components such as QKD boards, QKX boards, random number boards, encryption/decryption boards, and optical interface boards are used to achieve key encryption and decryption. The relaying device generates the XOR value of the encryption key through XOR operation, reducing the exposure time of the plaintext key.
It effectively ensures the security of session keys and service data, reduces the demand for fiber optic resources, simplifies network complexity, is suitable for complex topologies, and reduces the network burden of key relay.
Smart Images

Figure CN117675176B_ABST
Abstract
Description
Technical Field
[0001] This invention relates to the field of quantum secure communication, and more specifically to an encrypted communication method based on an integrated design of quantum key distribution and communication. Background Technology
[0002] Quantum key distribution (QKD) utilizes quantum systems to prepare, transmit, receive, and purify information to obtain a secure symmetric key that is physically impossible to steal. This process ensures that the keys obtained by both communicating parties are completely identical, and no third party can obtain any information about the key. In a fiber optic quantum key distribution system, the sender needs to transmit quantum light and synchronization light to the receiver, and both parties need to exchange data for key negotiation.
[0003] Physical signal-based key distribution methods are all limited by distance. For example, the attenuation of quantum channels increases exponentially with distance, while conventional optical fibers typically attenuate by half every 10-15 kilometers. Quantum key distribution, using extremely weak light at the single-photon level, must operate within a finite key generation distance (attenuation) to ensure a good signal-to-noise ratio and thus obtain secure codes. Currently, the typical secure key generation distance for product-level systems is about 100 kilometers, and the furthest distance in laboratories is about 400 kilometers. Wireless channel key generation is also constrained by distance. Therefore, when the distance between the communicating parties exceeds the effective, secure key generation distance, relaying is an important means of extending the distance (using low-loss channels such as those in outer space is another optional method).
[0004] Existing QKD systems adopt a construction model of independent equipment deployment, such as... Figure 1As shown, both the sender and receiver need to deploy a quantum key distribution device and a symmetric encryption device, both of which are independent devices. The key generated by the quantum key distribution device needs to be transmitted to the symmetric encryption device via a network cable or other external connection. Because the key is transmitted externally, its security during transmission is significantly compromised. Furthermore, the quantum key distribution device and the symmetric encryption device require independent channels. For example, in fiber optic scenarios, the quantum key distribution device's quantum channel, synchronization channel, and negotiation channel require at least one independent fiber (or one wavelength), while the symmetric encryption device also requires one independent fiber (or one wavelength). This results in high requirements for fiber optic infrastructure resources during actual deployment, which cannot be met in many scenarios. Finally, because the quantum key distribution device and the symmetric encryption device operate completely independently, in large-scale network scenarios, the quantum key distribution device cannot be aware of the routing addresses of the sender and receiver of the symmetric encryption device's business data. Therefore, to ensure that the symmetric encryption device can quickly obtain the key from the quantum key distribution device when needed, the quantum key distribution device often adopts an end-to-end pre-produced key scheme. Before the actual initiation of an encrypted service, the quantum key distribution (QKD) device utilizes trusted relay technology to complete end-to-end key distribution between symmetric encryption devices using a pre-defined strategy. In a QKD network, the more symmetric encryption devices are deployed, the more exponentially the relationship between them grows. If all symmetric encryption devices need to pre-produce keys, the burden on the QKD network will increase rapidly, hindering its large-scale adoption. Summary of the Invention
[0005] To address the aforementioned shortcomings of existing technologies, this invention discloses an encrypted communication method based on the integration of quantum key distribution and communication. By simultaneously implementing quantum key distribution and communication functions in the receiving device, relay device, and transmitting device, business data and session keys are allowed to be transmitted in encrypted form throughout the entire process outside of the receiving and transmitting devices, which can effectively ensure the security of session keys and business data.
[0006] Specifically, the quantum key distribution and communication integration-based encrypted communication method of the present invention may include a sending-end encryption step, a relay transmission step, and a receiving-end decryption step;
[0007] The sending-end encryption step, the relay transmission step, and the receiving-end decryption step are implemented using the sending-end device, the relay device, and the receiving-end device, respectively.
[0008] The transmitting device includes QKD board, QKX board, random number board, encryption / decryption board, communication service board and optical interface board;
[0009] The relay equipment includes first and second QKD boards, QKX boards, optical amplifier boards, first and second communication service boards, and first and second optical interface boards;
[0010] The receiving device includes QKD board, QKX board, encryption / decryption board, communication service board and optical interface board;
[0011] In the transmitting end encryption step, the transmitting device generates a key encryption key K between itself and the first QKD board of the adjacent relay device using a QKD board. 1_2 ; Generate a session key using a random number generator; encrypt business data using the session key using an encryption / decryption generator to generate ciphertext business data; encrypt key K using a QKX generator. 1_2 The session key is encrypted to generate session key ciphertext; the service data ciphertext and session key ciphertext are converted into physical optical signals using a communication service board; and the physical optical signals are output to the fiber optic link using an optical interface board.
[0012] In the relay transmission step, the relay terminal uses the first QKD board to generate a key encryption key K between itself and the upstream adjacent transmitting device or relay device. i_j Using the second QKD board, a key encryption key K is generated between the device and its downstream adjacent receiving or relay device. j_k And encrypt the key K i_j With K j_k Perform an XOR operation to generate the encryption key XOR value K. i_j ⊕K j_k Let i = 1, ..., N, j = i+1, k = j+1; Using the first optical interface board, the physical optical signal carrying the session key ciphertext is sent to the first communication service board to be converted into session key ciphertext, and the physical optical signal carrying the service data ciphertext is sent to the optical amplifier board for amplification; Using the QKX board, the XOR value of the key encryption key is XORed with the session key ciphertext to generate a new session key ciphertext; Using the second communication service board, the new session key ciphertext is converted into a physical optical signal; Using the second optical interface board, the physical optical signals from the optical amplifier board and the second communication service board are wavelength division multiplexed and output to the optical fiber link;
[0013] In the receiving-end decryption step, the receiving terminal uses the QKD board to generate a key encryption key K between itself and the upstream adjacent relay device. (N-1)_N The physical optical signal is transmitted to the communication service board via the optical interface board to be converted into session key ciphertext and service data ciphertext; the key K is encrypted using the QKX board. (N-1)_N The session key is obtained by performing an XOR operation with the session key ciphertext; the session key is then used with an encryption / decryption board to decrypt the business data ciphertext, thus obtaining the business data.
[0014] Furthermore, communication service boards are used to convert QKD negotiated data and physical optical signals, and optical interface boards are used to perform wavelength division multiplexing and demultiplexing of physical optical signals, quantum optical signals and synchronous optical signals.
[0015] Preferably, the random number board is implemented based on a physical noise source or a quantum noise source.
[0016] Furthermore, the encryption / decryption board adopts a one-time encryption / decryption method.
[0017] Furthermore, the QKX board uses an XOR encryption method.
[0018] Furthermore, in the transmitting device, the key encryption key is stored locally in an encrypted manner using a local key.
[0019] Furthermore, in the originating device, the key encryption key is destroyed after use.
[0020] Furthermore, in the relay device, the key encryption key K i_j and key encryption key K j_k Encrypt the key XOR value K with the key i_j ⊕K j_k It is saved locally in the form of [data / format].
[0021] Furthermore, the encryption / decryption board employs a symmetric cryptographic algorithm.
[0022] Furthermore, the communication service board generates a data transmission route by parsing the transceiver address information, and selects an output port for digital signals or physical optical signals based on the data transmission route. Attached Figure Description
[0023] The specific embodiments of the present invention will be described in further detail below with reference to the accompanying drawings.
[0024] To more clearly illustrate the technical solutions in the embodiments of the present invention or the prior art, the drawings used in the description of the embodiments or the prior art will be briefly introduced below. Obviously, the drawings described below are only some embodiments of the present invention. For those skilled in the art, other drawings can be obtained based on these drawings without creative effort.
[0025] Figure 1 This illustrates a prior art QKD system;
[0026] Figure 2 The present invention schematically illustrates an encrypted communication system and method based on the integrated design of quantum key distribution and communication. Detailed Implementation
[0027] In the following description, exemplary embodiments of the present invention will be described in detail with reference to the accompanying drawings. The following embodiments are provided by way of example in order to fully convey the spirit of the invention to those skilled in the art. Therefore, the invention is not limited to the embodiments disclosed herein.
[0028] Figure 2 An encrypted communication system and method based on the integrated design of quantum key distribution and communication are shown according to the present invention.
[0029] An encrypted communication system for implementing the encrypted communication method of the present invention may include a transmitting device, a relay device, and a receiving device. The transmitting device, relay device, and receiving device all integrate quantum key distribution and communication functions.
[0030] The transmitting device connects to the information source and is mainly used to receive communication service data, generate a session key to encrypt the service data to generate ciphertext of the service data, and simultaneously perform encrypted relay transmission of the session key.
[0031] exist Figure 2 In the example, the transmitting device may include QKD board, QKX board, random number board, encryption / decryption board, communication service board, and optical interface board.
[0032] The relay device is set up between the transmitting and receiving devices and is mainly used for encrypted relay transmission of session keys.
[0033] exist Figure 2 In the example, the relay equipment may include QKD boards, QKX boards, optical amplifier boards, communication service boards, and optical interface boards. The QKD boards, communication service boards, and optical interface boards can be configured in pairs, i.e., first and second QKD boards, first and second communication service boards, and first and second optical interface boards, to allow simultaneous provision of optical path connection ports at both ends, thereby establishing a relay link.
[0034] The receiving device connects to the destination and is mainly used to obtain the session key based on encrypted relay transmission. It uses the session key to decrypt the ciphertext of the business data to obtain the communication business data, and then sends the business data to the destination, thereby completing the encrypted communication process.
[0035] exist Figure 2 In the example, the receiving device may include QKD board, QKX board, encryption / decryption board, communication service board, and optical interface board.
[0036] In this invention, the QKD board is used to generate a shared quantum key with the QKD board of the peer (adjacent device) via quantum key distribution, and provides it as a key encryption key to the QKX board. In the transmitting device, the key encryption key can be stored locally in an encrypted manner using a local key.
[0037] A random number generator is used to generate random numbers, which serve as the session key K and are provided to the encryption / decryption generator and the QKX generator, respectively. Preferably, the random number generator can be implemented based on a physical noise source or a quantum noise source to provide truly random numbers.
[0038] Encryption / decryption cards are used to encrypt and decrypt business data using a session key K and a symmetric cryptographic algorithm. For example, in the transmitting device, the encryption / decryption card can use the session key K to encrypt business data and generate ciphertext. In the receiving device, the encryption / decryption card can use the session key K to decrypt the ciphertext to obtain the plaintext business data.
[0039] The QKX board can encrypt the session key using a key encryption key to generate session key ciphertext for encrypted relay transmission of the session key. Preferably, the QKX board can use a one-time key method to encrypt the session key.
[0040] Communication service boards are used to convert digital signals into physical optical signals and vice versa. They can also parse transceiver address information to generate data transmission routes, allowing the correct communication port to be selected based on these routes.
[0041] For example, the communication service board in the transmitting device can convert ciphertext of service data from the encryption / decryption board, ciphertext of the session key from the QKX board, and QKD negotiation data from the QKD board into physical optical signals. Correspondingly, the communication service board in the receiving device can convert the physical optical signals into ciphertext of service data, ciphertext of the session key, and QKD negotiation data, and send these ciphertexts to the encryption / decryption board, QKX board, and QKD board respectively according to the data transmission route.
[0042] Optical interface boards are used for wavelength division multiplexing and demultiplexing of physical optical signals, quantum optical signals, and synchronous optical signals. Therefore, they allow connections between transmitting devices and relay devices, between adjacent relay devices, and between relay devices and receiving devices through a single optical fiber channel.
[0043] Optical amplifier boards are used to amplify the physical optical signals that carry encrypted service data.
[0044] The following is combined Figure 2The encrypted communication system shown herein describes the encrypted communication method according to the present invention, which may include a sending-end encryption step, a relay transmission step, and a receiving-end decryption step.
[0045] The encryption step at the sending end is primarily implemented using the sending device. In this step, the QKD board (local QKD board) in the sending device (node 1) and the peer QKD board (e.g., the first QKD board) in the adjacent relay device (node 2) generate a shared quantum key K using a quantum key distribution process. 1_2 , which serves as the encryption key between nodes 1 and 2.
[0046] In this quantum key distribution process, the QKD board in the transmitting device is directly connected to the optical interface board to send quantum optical signals and synchronization optical signals. At the same time, the optical interface board is used to transmit and receive physical optical signals carrying QKD negotiation data, and the communication service board is used to realize the mutual conversion between QKD negotiation data and physical optical signals.
[0047] The QKD board encrypts the key K. 1_2 The key is sent to the QKX board for storage. Preferably, the key encryption key K12 can be stored in an encrypted manner using a local key. The key encryption key can be destroyed after use.
[0048] When the information source transmits service data to the transmitting device, the encrypted communication service is triggered. Therefore, the random number board generates a random number to be used as the session key K, and transmits the session key K to the encryption / decryption board and the QKX board respectively.
[0049] The encryption / decryption board uses the session key K and a symmetric cryptographic algorithm to encrypt the business data, generate ciphertext of the business data, and send it to the communication service board.
[0050] The QKX board uses a key to encrypt key K. 1_2 Perform a one-pad XOR encryption operation on the session key K to generate the session key ciphertext K⊕K12 and send it to the communication service board.
[0051] The communication service board receives encrypted service data, encrypted session keys, and QKD negotiation data. It also parses the transceiver address information to generate a data transmission route, converts the digital signal into a physical optical signal based on the data transmission route, and selects the correct output port.
[0052] The optical interface board receives physical optical signals sent by the communication service board, as well as quantum optical signals and synchronization optical signals sent by the QKD board. It performs wavelength division multiplexing to combine the signals and outputs them to the same optical fiber link to be sent to the next node.
[0053] The relay transmission step is mainly implemented using relay equipment. In this step, the first QKD board and its upstream neighboring QKD board generate a key encryption key K through a quantum key distribution process. i_j Simultaneously, the second QKD board and its downstream adjacent QKD board generate a key encryption key K through a quantum key distribution process. j_k And encrypt the key K i_j With K j_k Perform an XOR operation to generate the encryption key XOR value K. i_j ⊕K j_k Let i = 1, ..., N, j = i+1, k = j+1. Therefore, in the relay device, the key encryption key K... i_j and key encryption key K j_k Encrypt the key XOR value K with the key i_j ⊕K j_k The key is stored locally in a specific format, which can avoid the possibility of the encryption key being leaked.
[0054] During the quantum key distribution process of the relay equipment, the first and second QKD boards are directly connected to the first and second optical interface boards to receive quantum optical signals and synchronization optical signals, respectively. At the same time, they use the first or second optical interface boards to transmit and receive physical optical signals carrying QKD negotiation data, and use the first or second communication service boards to realize the mutual conversion between QKD negotiation data and physical optical signals.
[0055] The first and second QKD boards also encrypt the key K respectively. i_j and K j_k The key is sent to the QKX board for storage, whereby the QKX board encrypts the key K. i_j and K j_k Perform an XOR operation to generate the XOR value K of the encryption key. i_j ⊕K j_k And save the XOR value of the encryption key locally.
[0056] The first optical interface board demultiplexes the received optical signal, transmits the physical optical signal carrying the encrypted service data to the optical amplifier board for amplification, and transmits the physical optical signal carrying the session key ciphertext and QKD negotiation data to the first communication service board to convert them into session key ciphertext and QKD negotiation data respectively. The session key ciphertext is then transmitted to the QKX board, and the QKD negotiation data is transmitted to the first QKD board.
[0057] The QKX board selects the correct key encryption key XOR value K based on the data transmission route provided by the first communication service board. i_j ⊕K j_kThe session key ciphertext is XORed with the session key ciphertext to generate a new session key ciphertext, which is then sent to the second communication service board.
[0058] The second communication service board converts the new session key ciphertext and QKD negotiation data into physical optical signals and sends them to the first optical interface board.
[0059] The second optical interface board performs wavelength division multiplexing on the physical optical signals from the optical amplifier board and the second communication service board, as well as the quantum optical signals and synchronization optical signals from the second QKD board, and outputs them to the optical fiber link to continue to the next node.
[0060] When an optical signal is transmitted via an optical fiber link and reaches the receiving device after passing through one or more relay devices, the receiving device performs the receiving decryption step.
[0061] In the receiving-end decryption step, the QKD board (local QKD board) in the receiving device (node Z, z=N) and the second QKD board in the adjacent relay device (node Y, y=N-1) generate a shared quantum key Kyz, i.e., K, through the quantum key distribution process. (N-1)_N This serves as the encryption key between node N and node N-1. In this quantum key distribution process, the QKD board in the transmitting device is directly connected to the optical interface board to send quantum optical signals and synchronization optical signals. Simultaneously, it uses the optical interface board to transmit and receive physical optical signals carrying QKD negotiation data, and utilizes the communication service board to achieve the mutual conversion between QKD negotiation data and physical optical signals. See also... Figure 2 It can also be seen that the first QKD board in the relay device of node Y also generates a shared quantum key Kxy with the second QKD device of the upstream adjacent relay device through the quantum key distribution process.
[0062] The second QKD board encrypts the key K. (N-1)_N The key is sent to the QKX board for storage. Preferably, the encryption key K can be stored in an encrypted manner using a local key. (N-1)_N .
[0063] The optical interface board demultiplexes the received optical signal and transmits the physical optical signal carrying the service data ciphertext, session key ciphertext, and QKD negotiation data to the communication service board to convert them into service data ciphertext, session key ciphertext, and QKD negotiation data, respectively. The service data ciphertext is then transmitted to the encryption / decryption board, the session key ciphertext is transmitted to the QKX board, and the QKD negotiation data is transmitted to the QKD board.
[0064] The QKX board selects the correct encryption key K based on the data transmission route provided by the communication service board. (N-1)_NThe session key ciphertext is decrypted to restore the session key K, and then sent to the encryption / decryption board.
[0065] The encryption / decryption board uses the session key K and a symmetric cryptographic algorithm to decrypt the encrypted business data, generate the plaintext business data, and send it to the destination, thus completing this encrypted communication service.
[0066] In summary, by employing the encrypted communication method of this invention, which enables the receiving device, relay device, and transmitting device to simultaneously possess quantum key distribution and communication functions, business data and session keys can be transmitted in encrypted form throughout the entire process outside of the receiving and transmitting devices, effectively ensuring the security of session keys and business data. Specifically, the encryption key is stored in encrypted form in both the receiving and transmitting devices and destroyed after decryption and use; in the relay device, the encryption keys generated by different QKD boards are XORed and then encrypted before storage, thereby greatly reducing the time when the encryption key appears in plaintext form and lowering security requirements.
[0067] Meanwhile, because the QKX board can relay the session key by selecting the correct key XOR value based on the transmission routing information while encrypting the transmission of business data, it is easy to extend to complex topologies.
[0068] Furthermore, in the encrypted communication method of this invention, since key relay and encrypted transmission of service data are performed simultaneously, end-to-end key relay is not required beforehand, thereby greatly reducing network complexity. Moreover, key relay and service data share the same sender and receiver addresses, allowing them to be transmitted along the same path within a single data packet or along different paths in different data packet types. By selecting appropriate wavelengths, the physical optical signal, quantum optical signal, and synchronization optical signal carrying classical service data are combined, achieving co-fiber transmission and significantly reducing the system's requirements for fiber optic resources.
[0069] Although the present invention has been described above with reference to the accompanying drawings and specific embodiments, those skilled in the art will readily recognize that the above embodiments are merely exemplary and used to illustrate the principles of the present invention. They do not limit the scope of the present invention. Those skilled in the art can make various combinations, modifications and equivalent substitutions to the above embodiments without departing from the spirit and scope of the present invention.
Claims
1. An encrypted communication method based on the integration of quantum key distribution and communication, comprising a sending-end encryption step, a relay transmission step, and a receiving-end decryption step; The sending-end encryption step, the relay transmission step, and the receiving-end decryption step are implemented using the sending-end device, the relay device, and the receiving-end device, respectively. The transmitting device includes QKD board, QKX board, random number board, encryption / decryption board, communication service board, and optical interface board; The relay equipment includes first and second QKD boards, QKX boards, optical amplifier boards, first and second communication service boards, and first and second optical interface boards; The receiving device includes QKD board, QKX board, encryption / decryption board, communication service board, and optical interface board; In the transmitting end encryption step, the transmitting device generates a key encryption key K between itself and the first QKD board of the adjacent relay device using a QKD board. 1_2 ; Generate a session key using a random number generator; encrypt business data using the session key using an encryption / decryption generator to generate ciphertext business data; Using the QKX board, key K is encrypted with a key. 1_2 Encrypt the session key to generate session key ciphertext; The communication service board converts the encrypted service data and session key into physical optical signals; the optical interface board outputs the physical optical signals to the fiber optic link. In the relay transmission step, the relay terminal uses the first QKD board to generate a key encryption key K between itself and the upstream adjacent transmitting device or relay device. i_j Using the second QKD board, a key encryption key K is generated between the device and its downstream adjacent receiving or relay device. j_k And encrypt the key K i_j With K j_k Perform an XOR operation to generate the encryption key XOR value K. i_j ⊕K j_k , i=1,...,N, j=i+1, k=j+1; The physical optical signal carrying the session key ciphertext is sent to the first communication service board through the first optical interface board to be converted into session key ciphertext, and the physical optical signal carrying the service data ciphertext is sent to the optical amplifier board for amplification. Using the QKX board, a new session key ciphertext is generated by XORing the key encryption key with the session key ciphertext; the new session key ciphertext is then converted into a physical optical signal using the second communication service board. The physical optical signals from the optical amplifier board and the second communication service board are wavelength divided multiplexed using the second optical interface board and then output to the optical fiber link. In the receiving-end decryption step, the receiving terminal uses the QKD board to generate a key encryption key K between itself and the upstream adjacent relay device. (N-1)_N ; The physical optical signal is sent to the communication service board using the optical interface board to be converted into session key ciphertext and service data ciphertext. Using the QKX board, key K is encrypted with a key. (N-1)_N The session key is obtained by performing an XOR operation with the session key ciphertext; the session key is then used with an encryption / decryption board to decrypt the business data ciphertext to obtain the business data.
2. The encrypted communication method as described in claim 1, wherein, The conversion between QKD negotiated data and physical optical signals is achieved by using communication service boards, and wavelength division multiplexing and demultiplexing of physical optical signals, quantum optical signals and synchronous optical signals are achieved by using optical interface boards.
3. The encrypted communication method as described in claim 1, wherein, The random number board is implemented based on physical noise sources or quantum noise sources.
4. The encrypted communication method as described in claim 1, wherein, The encryption / decryption board uses a one-time key encryption / decryption method.
5. The encrypted communication method as described in claim 1, wherein, The QKX board uses an XOR operation encryption method.
6. The encrypted communication method as described in claim 1, wherein, In the originating device, the key encryption key is stored locally in an encrypted manner using a local key.
7. The encrypted communication method as described in claim 1, wherein, In the originating device, the encryption key is destroyed after use.
8. The encrypted communication method as described in claim 1, wherein, In relay equipment, the key encryption key K i_j and key encryption key K j_k Encrypt the key XOR value K with the key i_j ⊕K j_k It is saved locally in the form of [data / format].
9. The encrypted communication method as described in claim 1, wherein, The encryption / decryption board uses a symmetric cryptography algorithm.
10. The encrypted communication method as described in claim 1, wherein, The communication service board generates a data transmission route by parsing the transceiver address information, and selects the output port for digital signals or physical optical signals based on the data transmission route.
Citation Information
Patent Citations
Encryption communication system based on quantum key distribution and communication integration
CN219018826U