Encrypted communication method integrating quantum key and national secret CPE access device
Through the two-stage key negotiation process, the shortcomings of traditional national secret IPSec encryption technology in wireless access and quantum computer attacks are solved, wireless secure access and multiple encryption protection are realized, and the security and reliability of data transmission are improved.
Patent Information
- Application Number
- CN202311748214.2
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2023-12-18
- Publication Date
- 2025-09-02
- Estimated Expiration
- 2043-12-18
AI Technical Summary
The national secret IPSec encryption technology in traditional wired access networks cannot meet the network compatibility needs of wireless access scenarios, and cannot resist the attacks of quantum computers. The key negotiation process cannot self-identify whether it is monitored.
The encrypted communication method with fused quantum keys is adopted, and the quantum key is fused through a two-stage key negotiation process, including the first stage main mode key negotiation and the second stage fast mode key negotiation, the quantum key distribution device is used to obtain the quantum key plaintext, and multiple encryption is performed in service data transmission, and a multi-layer key protection system and key destruction mechanism are adopted.
It realizes wireless secure access, improves the complexity of keys, prevents the key from being cracked, improves the security and reliability of data transmission, and uses multi-level encryption protection and key destruction mechanism to ensure the security of keys.
Smart Images

Figure CN117857026B_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the field of cryptographic application technology, and in particular to an encryption communication method integrating quantum keys and a national cryptographic CPE access device. Background Art
[0002] With users' increasing demands for high data confidentiality and high data transmission rates, and the continuous development of quantum technology, the traditional national secret IPSec encryption technology in wired access networks is difficult to meet these needs. The main problems are as follows:
[0003] (1) Wired access devices do not have good network compatibility and cannot meet various wireless access scenarios.
[0004] (2) The keys negotiated through the IPSec protocol cannot resist attacks from quantum computers, which may lead to key cracking and data leakage.
[0005] (3) Physically, the traditional key negotiation process cannot self-identify whether it is being monitored.
[0006] Patent application publication number CN115277186A proposes adhering to the IPSec VPN technical specifications and procedures of the Cryptography Administration. After completing the first phase of IKE main mode key negotiation, the negotiated working key SKEYID_d is XORed with the quantum key QK obtained from the QKD quantum key distribution server. The result is used as the new working key SKEYID_dQK, replacing the original SKEYID_d. This is then used to further negotiate the IPSec SA security policy and derived session keys. This solution only incorporates quantum key technology during the first phase of key negotiation. Patent application publication number CN113132102A proposes a quantum key protection method based on three layers of keys, using the same third-layer key as the encryption material. Summary of the Invention
[0007] The technical problem to be solved by the present invention is how to improve the complexity of the key and realize secure data transmission.
[0008] The present invention solves the above technical problems through the following technical means:
[0009] In a first aspect, the present invention proposes an encryption communication method integrating quantum keys, which is applied to a communication initiator, and the method comprises:
[0010] Conduct the first phase of the main mode key negotiation process with the communication responder, and exchange the secure storage media identification of both communicating parties;
[0011] Based on the secure storage medium identifiers of both communicating parties, a key request is sent to a quantum key distribution device to obtain the first quantum key plaintext corresponding to the communication initiator;
[0012] Performing a second-phase quick mode key negotiation process with the communication responder to obtain a second-phase session key, and fusing the first quantum key plaintext corresponding to the communication initiator with the second-phase session key to obtain a temporary session key;
[0013] Applying again to the quantum key distribution device to obtain a quantum key, and fusing the obtained quantum key with the temporary session key to obtain a service data encryption and decryption key;
[0014] The business data encryption and decryption key is used to encrypt the business data for secure transmission.
[0015] Furthermore, the step of sending a key request to a quantum key distribution device to obtain a quantum key plaintext based on the secure storage medium identifiers of both communicating parties includes:
[0016] Sending a key request to the quantum key distribution device so that the quantum key distribution device generates a key response, wherein the key request carries information including secure storage medium identifiers and communication unique identifiers of both communicating parties;
[0017] receiving the key response returned by the quantum key distribution device, wherein the key response carries information including quantum key ciphertexts of both communicating parties and quantum key protection factor index ciphertexts of both communicating parties;
[0018] Decrypt the first quantum key ciphertext corresponding to the communication initiator to obtain the first quantum key plaintext corresponding to the communication initiator.
[0019] Furthermore, the first quantum key ciphertext corresponding to the communication initiator is protected by a first quantum key protection factor index ciphertext, and the second quantum key ciphertext corresponding to the communication responder is protected by a second quantum key protection factor index ciphertext. The first quantum key protection factor index ciphertext and the second quantum key protection factor index ciphertext are protected by a device key.
[0020] Furthermore, the communication initiator is pre-installed with a quantum key protection factor and a device key, and the decryption of the quantum key ciphertext corresponding to the communication initiator to obtain the quantum key plaintext corresponding to the communication initiator includes:
[0021] Mapping the second quantum key protection factor index ciphertext to the index of the second quantum key protection factor preset in the communication initiator using a linear hash algorithm to obtain an index value;
[0022] Obtaining a corresponding first quantum key protection factor ciphertext based on the index value, calling the preset device key to decrypt the first quantum key protection factor ciphertext to obtain the corresponding first quantum key protection factor;
[0023] The first quantum key protection factor is used as a key to decrypt the first quantum key ciphertext corresponding to the communication initiator to obtain the first quantum key plaintext corresponding to the communication initiator.
[0024] Furthermore, performing a second-phase quick mode key negotiation process with the communication responder to obtain a second-phase session key, and fusing the quantum key plaintext with the second-phase session key to obtain a temporary session key, including:
[0025] Performing a second-phase quick mode key negotiation process with the communication responder, sending a first encrypted data packet to the communication responder, where the first encrypted data packet carries information including a second quantum key ciphertext corresponding to the communication responder, a second quantum key protection factor index ciphertext corresponding to the communication responder, and a first quantum key plaintext corresponding to the communication initiator, so that the communication responder obtains a second-phase session key and decrypts the second quantum key ciphertext and the second quantum key protection factor index ciphertext to obtain the second quantum key plaintext corresponding to the communication responder;
[0026] receiving a second encrypted data packet returned by the communication responder, where the second encrypted data packet carries a quantum key usage identifier;
[0027] Accept and parse the quantum key usage identifier carried by the second encrypted data packet, and perform an XOR operation on the first quantum key plaintext and the second-stage session key to obtain the temporary session key.
[0028] Furthermore, an extended payload is added to the first encrypted data packet, and the extended payload encapsulates a hash value of the second quantum key ciphertext, the second quantum key protection factor index ciphertext, and the first quantum key plaintext. The method further includes:
[0029] receiving a second encrypted data packet returned by the communication responder, wherein an extended payload is added to the second encrypted data packet for carrying a quantum key usage identifier, and the second encrypted data packet is generated by the communication responder when a hash value of the first quantum key plaintext is compared with a hash value of the second quantum key plaintext and the two are consistent;
[0030] A negotiation termination message returned by the communication responder is received, where the negotiation termination message is generated by the communication responder when a hash value of the first quantum key ciphertext is compared with a hash value of the second quantum key ciphertext and the hash value is inconsistent.
[0031] Furthermore, the re-applying to the quantum key distribution device to obtain a quantum key, and fusing the obtained quantum key with the temporary session key to obtain a service data encryption and decryption key, includes:
[0032] Parsing a third data packet, where the third data packet carries information including the temporary session key and negotiation material information;
[0033] Generate a communication cookie based on the negotiation material information, and request the quantum key distribution device to obtain a third quantum key ciphertext and a third quantum key protection factor index ciphertext based on the communication cookie;
[0034] decrypting the third quantum key ciphertext and the third quantum key protection factor index ciphertext to obtain a corresponding quantum key;
[0035] An XOR operation is performed on the acquired quantum key and the temporary session key to obtain the service data encryption and decryption key.
[0036] Furthermore, before performing the first phase main mode key negotiation process with the communication responder, the method further includes:
[0037] Requesting the quantum key distribution apparatus to preset a device key and a preset quantum key protection factor.
[0038] Furthermore, before performing the first phase main mode key negotiation process with the communication responder, the method further includes:
[0039] Obtain the IP address assigned by the 5G private network base station, and use the IP address as the wireless communication address for communicating with the communication responder.
[0040] Furthermore, the method further comprises:
[0041] Based on the received key destruction trigger instruction, the quantum key protection factor and the device key are set to zero, and the key destruction trigger instruction is generated when the communication initiator disassembles.
[0042] In a second aspect, the present invention proposes an encryption communication method integrating quantum keys, which is applied to a communication responder, and the method comprises:
[0043] Receiving a first encrypted data packet sent by a communication initiator, where the first encrypted data packet carries information including a second quantum key ciphertext corresponding to a communication responder and a second quantum key protection factor index ciphertext corresponding to the communication responder;
[0044] Obtain the second-stage session key and decrypt the second quantum key ciphertext and the second quantum key protection factor index ciphertext to obtain the second quantum key plaintext corresponding to the communication responder;
[0045] The second quantum key plaintext is combined with the second-stage session key to obtain a temporary session key;
[0046] Applying again to the quantum key distribution device to obtain a quantum key, and fusing the obtained quantum key with the temporary session key to obtain a service data encryption and decryption key;
[0047] The business data sent by the communication initiator is decrypted using the business data encryption and decryption key.
[0048] Furthermore, the second quantum key ciphertext is protected by a corresponding quantum key protection factor index ciphertext, and the quantum key protection factor index ciphertext is protected by a device key.
[0049] Furthermore, the communication responder is pre-installed with a quantum key protection factor and a device key, and the obtaining of the second-stage session key and decryption of the second quantum key ciphertext and the second quantum key protection factor index ciphertext to obtain the second quantum key plaintext corresponding to the communication responder includes:
[0050] Mapping the second quantum key protection factor index ciphertext to the index of the second quantum key protection factor preset in the communication responder using a linear hash algorithm to obtain an index value;
[0051] Obtaining a corresponding second quantum key protection factor ciphertext based on the index value, calling the preset device key to decrypt the second quantum key protection factor ciphertext to obtain the corresponding second quantum key protection factor;
[0052] The second quantum key protection factor is used as a key to decrypt the second quantum key ciphertext corresponding to the communication responder to obtain the second quantum key plaintext corresponding to the communication responder.
[0053] Furthermore, the information carried by the second encrypted data packet further includes a hash value of the first quantum key plaintext corresponding to the communication initiator, and the method further includes:
[0054] Calculating a hash value of the second quantum key ciphertext, and comparing the hash value of the second quantum key ciphertext with the hash value of the first quantum key plaintext;
[0055] If they are consistent, generating a second encrypted data packet, wherein an extended payload is added to the second encrypted data packet to carry the quantum key usage identifier;
[0056] If they are inconsistent, the key negotiation process ends.
[0057] Furthermore, the re-applying to the quantum key distribution device to obtain a quantum key, and fusing the obtained quantum key with the temporary session key to obtain a service data encryption and decryption key, includes:
[0058] Parsing a third data packet, where the third data packet carries information including the temporary session key and negotiation material information;
[0059] Generate a communication cookie based on the negotiation material information, and request the quantum key distribution device to obtain a third quantum key ciphertext and a third quantum key protection factor index ciphertext based on the communication cookie;
[0060] decrypting the third quantum key ciphertext and the third quantum key protection factor index ciphertext to obtain a corresponding quantum key;
[0061] An XOR operation is performed on the acquired quantum key and the temporary session key to obtain the service data encryption and decryption key.
[0062] Furthermore, before receiving the first encrypted data packet sent by the communication initiator, the method further includes:
[0063] Perform the first phase of the main mode key negotiation process with the communication initiator, and exchange the secure storage medium identifiers of the two communicating parties.
[0064] Furthermore, before receiving the first encrypted data packet sent by the communication initiator, the method further includes:
[0065] Obtain the IP address assigned by the 5G private network base station, and use the IP address as the wireless communication address for communicating with the communication initiator.
[0066] Furthermore, the method further comprises:
[0067] Based on the received key destruction trigger instruction, the quantum key protection factor and the device key are set to zero, and the key destruction trigger instruction is generated when the communication responder is disassembled.
[0068] In a third aspect, the present invention proposes a national secret CPE access device, the device comprising:
[0069] The key negotiation module includes a first key negotiation submodule, a key request submodule, and a second key negotiation submodule. The first key negotiation submodule is used to perform a first-phase main mode key negotiation process with a communication responder and exchange secure storage medium identifiers of both communicating parties. The key request submodule is used to send a key request to a quantum key distribution device based on the secure storage medium identifiers of both communicating parties to obtain a first quantum key plaintext corresponding to the communication initiator. The second key negotiation submodule is used to perform a second-phase quick mode key negotiation process with the communication responder to obtain a second-phase session key and fuse the first quantum key plaintext corresponding to the communication initiator with the second-phase session key to obtain a temporary session key.
[0070] The KQTED module is used to re-apply to the quantum key distribution device to obtain the quantum key, merge the obtained quantum key with the temporary session key to obtain the business data encryption and decryption key, and use the business data encryption and decryption key to encrypt and securely transmit the business data.
[0071] Furthermore, the key request submodule includes:
[0072] a first key requesting unit, configured to send a key request to the quantum key distribution device so that the quantum key distribution device generates a key response, wherein the key request carries information including secure storage medium identifiers and communication unique identifiers of both communicating parties;
[0073] A key response receiving unit, configured to receive the key response returned by the quantum key distribution device, wherein the key response carries information including the quantum key ciphertext of both communicating parties and the quantum key protection factor index ciphertext of both communicating parties;
[0074] The first decryption unit is used to decrypt the first quantum key ciphertext corresponding to the communication initiator to obtain the first quantum key plaintext corresponding to the communication initiator.
[0075] Furthermore, the first quantum key ciphertext corresponding to the communication initiator is protected by a first quantum key protection factor index ciphertext, and the second quantum key ciphertext corresponding to the communication responder is protected by a second quantum key protection factor index ciphertext. The first quantum key protection factor index ciphertext and the second quantum key protection factor index ciphertext are protected by a device key.
[0076] Furthermore, the apparatus further includes a national secret cryptographic component and a QT secure eSIM card, wherein the secure storage area of the national secret cryptographic component stores a device key, and the QT secure eSIM card stores a quantum key protection factor. The first decryption unit specifically includes:
[0077] A mapping subunit, configured to map the quantum key protection factor index ciphertext to the index of the quantum key protection factor preset in the QT secure eSIM card using a linear hash algorithm to obtain an index value;
[0078] A first decryption subunit is configured to obtain a quantum key protection factor ciphertext corresponding to the QT secure eSIM card based on the index value, and call the device key preset in the national secret cryptographic component to decrypt the quantum key protection factor ciphertext to obtain a corresponding quantum key protection factor;
[0079] The second decryption subunit is used to use the first quantum key protection factor as a key to decrypt the first quantum key ciphertext corresponding to the communication initiator to obtain the first quantum key plaintext corresponding to the communication initiator.
[0080] Furthermore, the second key agreement submodule includes:
[0081] a first encrypted data packet sending unit, configured to perform a second-phase quick mode key negotiation process with the communication responder, and send a first encrypted data packet to the communication responder, wherein the first encrypted data packet carries information including a second quantum key ciphertext corresponding to the communication responder, a second quantum key protection factor index ciphertext corresponding to the communication responder, and a first quantum key plaintext corresponding to the communication initiator, so that the communication responder obtains the second-phase session key and decrypts the second quantum key ciphertext and the second quantum key protection factor index ciphertext to obtain the second quantum key plaintext corresponding to the communication responder;
[0082] A second encrypted data packet receiving unit is configured to receive a second encrypted data packet returned by the communication responder, where the second encrypted data packet carries a quantum key usage identifier;
[0083] The first key fusion unit is used to receive and parse the quantum key usage identifier carried by the second encrypted data packet, and perform an XOR operation on the first quantum key plaintext and the second-stage session key to obtain the temporary session key.
[0084] Furthermore, the KQTED module includes:
[0085] a parsing unit, configured to parse a third data packet, wherein the third data packet carries information including the temporary session key and negotiation material information;
[0086] a second key requesting unit, configured to generate a communication cookie based on the negotiation material information, and request the quantum key distribution device to obtain a third quantum key ciphertext and a third quantum key protection factor index ciphertext based on the communication cookie;
[0087] A second key decryption unit is used to decrypt the third quantum key ciphertext and the third quantum key protection factor index ciphertext to obtain a corresponding quantum key;
[0088] The second key fusion unit is used to perform an XOR operation on the acquired quantum key and the temporary session key to obtain the service data encryption and decryption key.
[0089] Furthermore, the device also includes a 5G module, which is used to obtain the IP address allocated by the 5G private network base station and use the IP address as the wireless communication address for communicating with the communication responder.
[0090] Furthermore, the device further comprises:
[0091] The key destruction module is used to reset the quantum key protection factor stored in the QT secure eSIM card and the device key stored in the national secret cryptographic component to zero based on the received key destruction trigger instruction. The key destruction trigger instruction is generated when the national secret CPE access device is disassembled.
[0092] In a fourth aspect, the present invention proposes an encrypted communication system integrating quantum keys, the system comprising a national secret CPE access device A, a quantum key distribution device, and a national secret CPE access device B, wherein the national secret CPE access device A and the national secret CPE access device B are respectively connected to the quantum key distribution device; wherein the national secret CPE access device A comprises:
[0093] A key negotiation module is configured to perform a first-phase main mode key negotiation process with the national secret CPE access device B, exchange secure storage medium identifiers of both communicating parties, and perform a second-phase quick mode key negotiation process with the national secret CPE access device B, obtain a second-phase session key, and fuse the first quantum key plaintext with the second-phase session key to obtain a temporary session key.
[0094] A key request module is used to send a key request to the quantum key distribution device based on the secure storage medium identifiers of the two communicating parties to obtain the first quantum key plaintext corresponding to the communication initiator;
[0095] The KQTED module is used to re-apply to the quantum key distribution device to obtain the quantum key, and merge the obtained quantum key with the temporary session key to obtain the business data encryption and decryption key, and use the business data encryption and decryption key to encrypt the business data and securely transmit it to the national secret CPE access device B.
[0096] The advantages of the present invention are:
[0097] (1) The present invention integrates quantum keys to enable the national secret CPE access device to access the quantum key distribution device, realize wireless secure access, obtain quantum keys, and integrate quantum keys into the IPSec negotiation process to prevent the keys from being received during the negotiation process, thereby causing the encrypted data to be cracked, realize multiple encryption protection of the business plane and the kernel plane, and improve the security of the data transmission process; compared with the traditional technology that only integrates quantum keys in the first stage of key negotiation, the present invention also performs a second-stage fast mode key negotiation process with the communication responder, and improves the key complexity through two-stage key fusion.
[0098] (2) In the extended payload of the first data packet in the second phase of key negotiation in the fast mode, the present invention encapsulates the secondary encrypted quantum key material through hashing and sends it to the KQTED module for final IPSec service encryption and decryption. By merging the two-stage keys, the key complexity is improved, so that even if the key of any stage is cracked, the ciphertext cannot be obtained, thereby maximizing the encryption reliability.
[0099] (3) The present invention obtains the quantum key ciphertext of both parties and the quantum key protection factor index ciphertext of both parties by initiating communication and carrying communication materials, achieving a one-time one-key, instant use, and instant destruction multiple encryption guarantee, thereby improving the security of the encrypted channel.
[0100] (4) The present invention adopts a multi-layer key protection system, uses a QT secure eSIM card to store quantum key protection factors, uses device keys to protect quantum key protection factors, uses quantum key protection factors to protect quantum keys, and uses quantum keys to protect session keys. By integrating quantum keys at multiple levels, multiple encryption protections are achieved, thereby improving the security of data transmission. The system also generates a communication cookie based on the negotiation material information, and requests the quantum key distribution device to obtain the third quantum key ciphertext and the third quantum key protection factor index ciphertext based on the communication cookie. At the same time, after the responding party receives the information carried by the data packet, it compares the reliability of the keys of the two communicating parties through encryption and decryption. Compared with the traditional method of using the same third-layer key as encryption material, the encryption key used in the present invention is obtained by decrypting the ciphertext obtained by the communicating party, and each encryption is obtained independently without using repeated keys, thereby ensuring the security of encryption.
[0101] (5) The present invention sets a key destruction mechanism, which resets the quantum key protection factor and the device key to zero when the key destruction mechanism is triggered to ensure key security.
[0102] Additional aspects and advantages of the present invention will be set forth in part in the description which follows and, in part, will be obvious from the description which follows, or may be learned through practice of the present invention. BRIEF DESCRIPTION OF THE DRAWINGS
[0103] Figure 1 This is a flow chart of an encryption communication method integrating quantum keys proposed in one embodiment of the present invention;
[0104] Figure 2 This is a hierarchical diagram of a key protection system proposed in one embodiment of the present invention;
[0105] Figure 3 This is a diagram of the principle of quantum key fusion in one embodiment of the present invention;
[0106] Figure 4 This is a schematic diagram of the process of integrating quantum keys into an encryption device in one embodiment of the present invention;
[0107] Figure 5 1 is a flow chart of another encryption communication method integrating quantum keys proposed in one embodiment of the present invention;
[0108] Figure 6 This is a schematic diagram of the structure of a national secret CPE access device proposed in one embodiment of the present invention;
[0109] Figure 7 This is an overall schematic diagram of the interaction of the national encryption CPE access device in one embodiment of the present invention;
[0110] Figure 8 This is a schematic diagram of quantum key interaction in an encryption communication system that integrates quantum keys proposed in one embodiment of the present invention. DETAILED DESCRIPTION
[0111] To make the objectives, technical solutions, and advantages of the embodiments of the present invention more clear, the technical solutions in the embodiments of the present invention will be clearly and completely described below in conjunction with the embodiments of the present invention. Obviously, the described embodiments are only part of the embodiments of the present invention, not all of the embodiments. All other embodiments obtained by ordinary technicians in this field based on the embodiments of the present invention without making any creative efforts shall fall within the scope of protection of the present invention.
[0112] Example 1
[0113] like Figure 1 As shown, the first embodiment of the present invention discloses an encryption communication method integrating quantum keys, which is applied to a communication initiator. The method includes the following steps:
[0114] S101, performing the first phase main mode key negotiation process with the communication responder, exchanging secure storage medium identifiers of both communicating parties;
[0115] It should be noted that the IPSec initiator and responder in this embodiment complete the IKE first phase main mode key negotiation process based on the national secret digital certificate in accordance with the "GM / T 0022 IPSec VPN Technical Specification". In this process, the two parties exchange the identifiers of the corresponding secure storage media, which is used to store the key.
[0116] Specifically, the secure storage medium in this embodiment may be a QT secure eSIM card.
[0117] S102. Based on the secure storage medium identifiers of both communicating parties, a key request is sent to a quantum key distribution device to obtain a quantum key plaintext.
[0118] It should be noted that this embodiment requests the quantum key distribution device to obtain the quantum key ciphertexts and quantum key protection factor index ciphertexts of the two communicating parties based on the secure storage medium identifiers of the two communicating parties.
[0119] S103, performing a second-phase quick mode key negotiation process with the communication responder, obtaining a second-phase session key, and fusing the first quantum key plaintext corresponding to the communication initiator with the second-phase session key to obtain a temporary session key;
[0120] S104: re-apply to the quantum key distribution device to obtain a quantum key, and merge the obtained quantum key with the temporary session key to obtain a service data encryption and decryption key;
[0121] S105: Use the business data encryption and decryption key to encrypt the business data for secure transmission.
[0122] This embodiment integrates quantum keys to enable the national secret CPE access device to connect to the quantum key distribution device, achieve wireless secure access, obtain quantum keys, and integrate quantum keys into the IPSec negotiation process. Multiple encryption protections on the business plane and kernel plane improve the security of the data transmission process; at the same time, the "ready-to-use, destroyed after use" characteristics of quantum keys are used to improve the security of the encrypted channel.
[0123] In one embodiment, step S102: sending a key request to a quantum key distribution device to obtain a quantum key plaintext based on the secure storage medium identifiers of both communicating parties, includes the following steps:
[0124] S121. Send a key request to the quantum key distribution device so that the quantum key distribution device generates a key response, wherein the key request carries information including secure storage medium identifiers and communication unique identifiers of both communicating parties;
[0125] It should be noted that the communication initiator obtains the secure storage medium identifiers of both parties according to the first stage, where the responder's secure storage medium identifier is QT_PEER_eSIM_SN and the initiator's secure storage medium identifier is QT_LOCAL_eSIM_SN, and generates the unique communication identifier SESSION_RDKEY through the national secret cryptographic component.
[0126] S122. Receive the key response returned by the quantum key distribution device, where the key response carries information including the quantum key ciphertexts of both communicating parties and the quantum key protection factor index ciphertexts of both communicating parties;
[0127] Specifically, the quantum key ciphertexts of the communicating parties include the first quantum key ciphertext 16Byte corresponding to the initiator: QT_ECKEY_S, and the second quantum key ciphertext 16Byte corresponding to the responder: QT_ECKEY_R; the quantum key protection factor index ciphertexts of the communicating parties include the first quantum key protection factor index ciphertext corresponding to the initiator: QT_PRE_KEY_ECINDEX_S, and the second quantum key protection factor index ciphertext corresponding to the responder: QT_PRE_KEY_ECINDEX_R.
[0128] S123. Decrypt the first quantum key ciphertext corresponding to the communication initiator to obtain the first quantum key plaintext corresponding to the communication initiator.
[0129] It should be noted that the communication initiator decrypts the first quantum key ciphertext to obtain the first quantum key plaintext, and the communication responder decrypts the second quantum key ciphertext to obtain the second quantum key ciphertext.
[0130] In one embodiment, if Figures 2 to 3 As shown, the first quantum key ciphertext corresponding to the communication initiator is protected by the first quantum key protection factor index ciphertext, and the second quantum key ciphertext corresponding to the communication responder is protected by the second quantum key protection factor index ciphertext. The first quantum key protection factor index ciphertext and the second quantum key protection factor index ciphertext are protected by the device key.
[0131] Specifically, the first quantum key ciphertext is protected by the first quantum key protection factor index ciphertext, the second quantum key ciphertext is protected by the second quantum key protection factor index ciphertext, and the first quantum key protection factor index ciphertext and the second quantum key protection factor index ciphertext are respectively protected by the device key.
[0132] In one embodiment, the communication initiator is pre-installed with a quantum key protection factor and a device key. Step S123: decrypting the quantum key ciphertext corresponding to the communication initiator to obtain the quantum key plaintext corresponding to the communication initiator includes the following steps:
[0133] S1231. Use a linear hash algorithm to map the first quantum key protection factor index ciphertext to the index of the quantum key protection factor preset in the communication initiator to obtain the index value;
[0134] S1232. Obtain a corresponding first quantum key protection factor ciphertext based on the index value, call the preset device key to decrypt the first quantum key protection factor ciphertext, and obtain a corresponding first quantum key protection factor QT_PRE_KEY_N;
[0135] S1233. Use the first quantum key protection factor QT_PRE_KEY_N as a key to decrypt the first quantum key ciphertext corresponding to the communication initiator to obtain the first quantum key plaintext corresponding to the communication initiator.
[0136] In one embodiment, step S103: performing a second-phase quick mode key negotiation process with the communication responder to obtain a second-phase session key, and fusing the first quantum key plaintext corresponding to the communication initiator with the second-phase session key to obtain a temporary session key, specifically includes the following steps:
[0137] S131, performing a second-phase quick mode key negotiation process with the communication responder, sending a first encrypted data packet to the communication responder, where the first encrypted data packet carries information including a second quantum key ciphertext corresponding to the communication responder, a second quantum key protection factor index ciphertext corresponding to the communication responder, and a first quantum key plaintext corresponding to the communication initiator, so that the communication responder obtains a second-phase session key and decrypts the second quantum key ciphertext and the second quantum key protection factor index ciphertext to obtain the second quantum key plaintext corresponding to the communication responder;
[0138] S132. Receive a second encrypted data packet returned by the communication responder, where the second encrypted data packet carries a quantum key usage identifier;
[0139] S133. Accept and parse the quantum key usage identifier carried by the second encrypted data packet, and perform an XOR operation on the first quantum key plaintext and the second-stage session key to obtain the temporary session key.
[0140] In one embodiment, an extended payload is added to the first encrypted data packet, and the extended payload encapsulates a second quantum key ciphertext, a second quantum key protection factor index ciphertext, and a hash value of the first quantum key plaintext. The method further includes:
[0141] receiving a second encrypted data packet returned by the communication responder, wherein an extended payload is added to the second encrypted data packet for carrying a quantum key usage identifier, and the second encrypted data packet is generated by the communication responder when a hash value of the first quantum key plaintext is compared with a hash value of the second quantum key plaintext and the two are consistent;
[0142] A negotiation termination message returned by the communication responder is received, where the negotiation termination message is generated by the communication responder when a hash value of the first quantum key ciphertext is compared with a hash value of the second quantum key ciphertext and the hash value is inconsistent.
[0143] Specifically, if Figure 4 As shown, the IPSec initiator sends a first encrypted data packet to the communication responder through the second-phase quick mode key negotiation process. The first encrypted data packet adds an extended payload, and encapsulates the second quantum key ciphertext QT_ECKEY_R, the second quantum key protection factor index ciphertext QT_PRE_ECINDEX_R and the hash value HASH(QT_KEY_S) obtained by hashing the first quantum key plaintext in the extended payload and transmits it to the communication responder.
[0144] The communication responder receives the first encrypted data packet, obtains the hash value HASH(QT_KEY_S) of the second-phase session key SESSION_KEY and the first quantum key plaintext, and decrypts it using the same steps as the communication initiator to obtain the second quantum key plaintext QT_KEY_R; then performs a hash operation on the second quantum key plaintext QT_KEY_R to obtain the hash value HASH(QT_KEY_R), and calculates whether HASH(QT_KEY_R) and HASH(QT_KEY_S) are equal; if they are not equal, the negotiation is terminated; if they are equal, a second encrypted data packet is generated and sent to the communication responder. The IPSec initiator receives the second encrypted data packet through the second-phase quick mode key negotiation process. The second encrypted data packet adds an extended payload and carries the quantum key usage identifier.
[0145] The communication initiator accepts and parses the quantum key usage identifier in the second encrypted data packet, and performs an XOR operation on the first quantum key plaintext and the second-stage session key to obtain a temporary session key QT_SESSION_KEY: QT_SESSION_KEY=QT_KEY_R⊕SESSION_KEY, where ⊕ is an XOR operation.
[0146] In one embodiment, step S104: reapplying to the quantum key distribution device to obtain a quantum key, and fusing the obtained quantum key with the temporary session key to obtain a service data encryption and decryption key, includes the following steps:
[0147] S141. Parse a third data packet, where the third data packet carries information including the temporary session key and negotiation material information.
[0148] It should be noted that the negotiation material information includes the IPSec SA communication initiator COOKIE_S and the communication responder COOKIE_R. COOKIE_S represents the IPSec SA communication initiator negotiation material cookie, and COOKIE_R represents the IPSec SA communication responder negotiation material cookie.
[0149] S142. Generate a communication cookie based on the negotiation material information, and request the quantum key distribution device to obtain a third quantum key ciphertext and a third quantum key protection factor index ciphertext based on the communication cookie;
[0150] Specifically, this embodiment generates a communication cookie based on the negotiated material information: SESSION_RD_COOKIE=COOKIE_S⊕COOKIE_R, where ⊕ is an exclusive OR operation.
[0151] S143. Decrypt the third quantum key ciphertext and the third quantum key protection factor index ciphertext to obtain a corresponding quantum key;
[0152] S144. Perform an XOR operation on the acquired quantum key and the temporary session key to obtain the service data encryption and decryption key.
[0153] It should be noted that this embodiment uses SESSION_RD_COOKIE as the unique session identifier for communicating with the quantum key distribution device, and at the same time obtains the 16-byte quantum key ciphertext and quantum key protection factor index ciphertext from the quantum key distribution device, and decrypts them to obtain the quantum key QT_KEY. The quantum key QT_KEY is XORed with the temporary session key QT_SESSION_KEY to obtain the business data encryption and decryption key QT_FIN_KEY: QT_FIN_KEY = QT_KEY⊕QT_SESSION_KEY.
[0154] It should be understood that the specific process of decrypting the third quantum key ciphertext and the third quantum key protection factor index ciphertext in this embodiment is the same as the decryption process of the first quantum key ciphertext and the first quantum key protection factor index ciphertext by the communication responder, so it will not be repeated here.
[0155] This embodiment adopts a multi-layer key protection system, using device keys to protect quantum key protection factors, using quantum key protection factors to protect quantum keys, and using quantum keys to protect session keys. By integrating quantum keys at multiple levels, multiple encryption protections are achieved to improve security during data transmission.
[0156] In one embodiment, before the step S101: performing the first phase main mode key negotiation process with the communication responder, the method further includes the following steps:
[0157] Requesting the quantum key distribution apparatus to preset a device key and a preset quantum key protection factor.
[0158] In one embodiment, before step S101: performing the first phase main mode key negotiation process with the communication responder, the method further includes the following steps:
[0159] Obtain the IP address assigned by the 5G private network base station, and use the IP address as the wireless communication address for communicating with the communication responder.
[0160] It should be understood that the device can support multiple frequency bands at the same time and can also obtain IP addresses allocated by 4G private network base stations, etc.
[0161] In one embodiment, the method further comprises the following steps:
[0162] Based on the received key destruction trigger instruction, the quantum key protection factor and the device key are set to zero, and the key destruction trigger instruction is generated when the communication initiator disassembles.
[0163] This embodiment sets a key destruction mechanism. Once the key destruction mechanism is triggered, the quantum key protection factor and the device key are reset to zero to ensure key security.
[0164] Example 2
[0165] like Figures 4 and 5 As shown, an embodiment of the present invention discloses another encryption communication method integrating quantum keys, which is applied to a communication responder. The method includes the following steps:
[0166] S201. Receive a first encrypted data packet sent by a communication initiator, where the first encrypted data packet carries information including a second quantum key ciphertext corresponding to a communication responder and a second quantum key protection factor index ciphertext corresponding to the communication responder;
[0167] S202, obtaining the second-stage session key and decrypting the second quantum key ciphertext and the second quantum key protection factor index ciphertext to obtain the second quantum key plaintext corresponding to the communication responder;
[0168] S203, fusing the second quantum key plaintext with the second-stage session key to obtain a temporary session key;
[0169] S204: re-apply to the quantum key distribution device to obtain a quantum key, and merge the obtained quantum key with the temporary session key to obtain a service data encryption and decryption key;
[0170] S205: Decrypt the service data sent by the communication initiator using the service data encryption and decryption key.
[0171] This embodiment integrates quantum keys into the IPSec negotiation process, with multiple encryption protections on the service and kernel planes, to enhance security during data transmission. It also leverages the "ready-to-use, immediately destroyed" nature of quantum keys to enhance the security of encrypted channels.
[0172] In one embodiment, the second quantum key ciphertext is protected by a corresponding quantum key protection factor index ciphertext, and the quantum key protection factor index ciphertext is protected by a device key.
[0173] In one embodiment, the communication responder is pre-installed with a quantum key protection factor and a device key. Step S202: obtaining the second-stage session key and decrypting the second quantum key ciphertext and the second quantum key protection factor index ciphertext to obtain the second quantum key plaintext corresponding to the communication responder includes the following steps:
[0174] S221. Use a linear hash algorithm to map the second quantum key protection factor index ciphertext to the index of the quantum key protection factor preset in the communication responder to obtain the index value;
[0175] S222. Obtain a corresponding second quantum key protection factor ciphertext based on the index value, and call the preset device key to decrypt the second quantum key protection factor ciphertext to obtain a corresponding second quantum key protection factor;
[0176] S223. Use the second quantum key protection factor as a key to decrypt the second quantum key ciphertext corresponding to the communication responder to obtain the second quantum key plaintext corresponding to the communication responder.
[0177] In one embodiment, if Figure 4 As shown, the information carried by the second encrypted data packet also includes a hash value of the first quantum key plaintext corresponding to the communication initiator, and the method further includes the following steps:
[0178] Calculating a hash value of the second quantum key ciphertext, and comparing the hash value of the second quantum key ciphertext with the hash value of the first quantum key plaintext;
[0179] If they are consistent, generating a second encrypted data packet, wherein an extended payload is added to the second encrypted data packet to carry the quantum key usage identifier;
[0180] If they are inconsistent, the key negotiation process ends.
[0181] In one embodiment, step S204: reapplying to the quantum key distribution device for obtaining a quantum key, and fusing the obtained quantum key with the temporary session key to obtain a service data encryption and decryption key, includes the following steps:
[0182] Parsing a third data packet, where the third data packet carries information including the temporary session key and negotiation material information;
[0183] Generate a communication cookie based on the negotiation material information, and request the quantum key distribution device to obtain a third quantum key ciphertext and a third quantum key protection factor index ciphertext based on the communication cookie;
[0184] decrypting the third quantum key ciphertext and the third quantum key protection factor index ciphertext to obtain a corresponding quantum key;
[0185] An XOR operation is performed on the acquired quantum key and the temporary session key to obtain the service data encryption and decryption key.
[0186] Before receiving the first encrypted data packet sent by the communication initiator, the method further includes:
[0187] Perform the first phase of the main mode key negotiation process with the communication initiator, and exchange the secure storage medium identifiers of the two communicating parties.
[0188] In one embodiment, before step S201: receiving the first encrypted data packet sent by the communication initiator, the method further includes:
[0189] Obtain the IP address assigned by the 5G private network base station, and use the IP address as the wireless communication address for communicating with the communication initiator.
[0190] In one embodiment, the method further comprises:
[0191] Based on the received key destruction trigger instruction, the quantum key protection factor and the device key are set to zero, and the key destruction trigger instruction is generated when the communication responder is disassembled.
[0192] It should be noted that the encryption communication method integrating quantum keys described in the present invention is applied to the communication responder. The specific technical effects and details can be referred to the above-mentioned method embodiment applied to the communication initiator, which will not be repeated here.
[0193] Example 3
[0194] like Figure 6 As shown, an embodiment of the present invention discloses a national secret CPE access device, the device comprising:
[0195] The key agreement module 11 includes a first key agreement module, a key request submodule, and a second key agreement submodule. The first key agreement submodule is used to perform a first-phase main mode key agreement process with the communication responder and exchange secure storage medium identifiers of the communicating parties. The key request submodule is used to send a key request to the quantum key distribution device based on the secure storage medium identifiers of the communicating parties to obtain the first quantum key plaintext corresponding to the communication initiator. The second key agreement submodule is used to perform a second-phase quick mode key agreement process with the communication responder to obtain the second-phase session key and merge the first quantum key plaintext corresponding to the communication initiator with the second-phase session key to obtain a temporary session key.
[0196] The KQTED module 12 is used to re-apply to the quantum key distribution device to obtain the quantum key, merge the obtained quantum key with the temporary session key to obtain the business data encryption and decryption key, and use the business data encryption and decryption key to encrypt and securely transmit the business data.
[0197] This embodiment integrates quantum keys to enable the national secret CPE access device to connect to the quantum key distribution device, achieve wireless secure access, obtain quantum keys, and integrate quantum keys into the IPSec negotiation process. Multiple encryption protections on the business plane and kernel plane improve the security of the data transmission process; at the same time, the "ready-to-use, destroyed after use" characteristics of quantum keys are used to improve the security of the encrypted channel.
[0198] In one embodiment, the key request submodule includes:
[0199] a first key requesting unit, configured to send a key request to the quantum key distribution device so that the quantum key distribution device generates a key response, wherein the key request carries information including secure storage medium identifiers and communication unique identifiers of both communicating parties;
[0200] A key response receiving unit, configured to receive the key response returned by the quantum key distribution device, wherein the key response carries information including the quantum key ciphertext of both communicating parties and the quantum key protection factor index ciphertext of both communicating parties;
[0201] The first decryption unit is used to decrypt the first quantum key ciphertext corresponding to the communication initiator to obtain the first quantum key plaintext corresponding to the communication initiator.
[0202] In one embodiment, the first quantum key ciphertext corresponding to the communication initiator is protected by a first quantum key protection factor index ciphertext, and the second quantum key ciphertext corresponding to the communication responder is protected by a second quantum key protection factor index ciphertext. The first quantum key protection factor index ciphertext and the second quantum key protection factor index ciphertext are protected by a device key.
[0203] In one embodiment, the apparatus further includes a national secret cryptographic component 13 and a QT secure eSIM card 14. The secure storage area of the national secret cryptographic component 13 stores a device key, and the QT secure eSIM card 14 stores a quantum key protection factor. The first decryption unit specifically includes:
[0204] A mapping subunit, configured to map the quantum key protection factor index ciphertext to the index of the quantum key protection factor preset in the QT secure eSIM card using a linear hash algorithm to obtain an index value;
[0205] A first decryption subunit is configured to obtain a quantum key protection factor ciphertext corresponding to the QT secure eSIM card based on the index value, and call the device key preset in the national secret cryptographic component to decrypt the quantum key protection factor ciphertext to obtain a corresponding quantum key protection factor;
[0206] The second decryption subunit is used to use the first quantum key protection factor as a key to decrypt the first quantum key ciphertext corresponding to the communication initiator to obtain the first quantum key plaintext corresponding to the communication initiator.
[0207] In one embodiment, the second key agreement submodule includes:
[0208] a first encrypted data packet sending unit, configured to perform a second-phase quick mode key negotiation process with the communication responder, and send a first encrypted data packet to the communication responder, wherein the first encrypted data packet carries information including a second quantum key ciphertext corresponding to the communication responder, a second quantum key protection factor index ciphertext corresponding to the communication responder, and a first quantum key plaintext corresponding to the communication initiator, so that the communication responder obtains the second-phase session key and decrypts the second quantum key ciphertext and the second quantum key protection factor index ciphertext to obtain the second quantum key plaintext corresponding to the communication responder;
[0209] A second encrypted data packet receiving unit is configured to receive a second encrypted data packet returned by the communication responder, where the second encrypted data packet carries a quantum key usage identifier;
[0210] The first key fusion unit is used to receive and parse the quantum key usage identifier carried by the second encrypted data packet, and perform an XOR operation on the first quantum key plaintext and the second-stage session key to obtain the temporary session key.
[0211] In one embodiment, the KQTED module 12 includes:
[0212] a parsing unit, configured to parse a third data packet, wherein the third data packet carries information including the temporary session key and negotiation material information;
[0213] a second key requesting unit, configured to generate a communication cookie based on the negotiation material information, and request the quantum key distribution device to obtain a third quantum key ciphertext and a third quantum key protection factor index ciphertext based on the communication cookie;
[0214] A second key decryption unit is used to decrypt the third quantum key ciphertext and the third quantum key protection factor index ciphertext to obtain a corresponding quantum key;
[0215] The second key fusion unit is used to perform an XOR operation on the acquired quantum key and the temporary session key to obtain the service data encryption and decryption key.
[0216] It should be noted that when the National Security CPE access device acts as the communication responder, the second key agreement submodule is also used to decrypt the first encrypted data packet sent by the communication sender to obtain the second quantum key plaintext corresponding to the communication responder; and merge the second quantum key plaintext with the second-stage session key to obtain a temporary session key. Accordingly, the KQTED module re-applies to the quantum key distribution device to obtain a quantum key, and merges the obtained quantum key with the temporary session key to obtain the service data encryption and decryption key of the communication responder.
[0217] It should be noted that this embodiment adopts a multi-layer key protection system:
[0218] The device key is the pre-set root key of the national secret CPE access device, and the device key is stored in the secure storage area of the national secret cryptographic component; the quantum key protection factor is distributed by the national secret CPE access device through the quantum key distribution device and stored in the QT secure eSIM card, which is used to protect the quantum key; the quantum key is the key distributed by the quantum key distribution device, which is obtained online and can be used immediately, and is used to be integrated with the session key; the session key is the key generated by the key negotiation module through the IPSec protocol, which is integrated with the quantum key to protect business data.
[0219] In one embodiment, the device further includes a 5G module 15 for obtaining an IP address assigned by a 5G private network base station, and using the IP address as a wireless communication address for communicating with a communication responder.
[0220] In one embodiment, the apparatus further comprises:
[0221] The key destruction module 16 is used to reset the quantum key protection factor stored in the QT secure eSIM card and the device key stored in the national secret cryptographic component to zero based on the received key destruction trigger instruction. The key destruction trigger instruction is generated when the national secret CPE access device is disassembled.
[0222] Specifically, the overall interaction process of the national secret CPE access device proposed in this embodiment is as follows: Figure 7 As shown, its composition is as follows:
[0223] (1) Key destruction module:
[0224] This module is an independent hardware physical module. When the national secret CPE access device is forcibly dismantled, the module is triggered to set the quantum key protection factor in the QT secure eSIM card to zero and the device key in the national secret cryptographic component to zero to ensure key security.
[0225] (2) National secret code components
[0226] Provide the required algorithm support for national encryption CPE access devices and store device keys in their secure storage area.
[0227] (3) QT secure eSIM card
[0228] One is used to store quantum key protection factors, with 20M quantum key protection factors stored in the quantum key distribution device each time, and the other is used for 5G private network access.
[0229] (4) 5G module
[0230] The 5G module is used to uniquely read and identify the QT secure eSIM card, obtain the quantum key protection factor in the QT secure eSIM card through the 5G module driver, and issue instructions to dial for 5G communication;
[0231] (5) KQTED module
[0232] This module is used to secondary integrate quantum keys and perform encryption and decryption of business data;
[0233] (6) Key negotiation module
[0234] The key negotiation module negotiates the working key and session key through the IPSec protocol, and integrates the quantum key with the session key.
[0235] The security suite consists of a key destruction module, national secret cryptographic components and a QT secure eSIM card.
[0236] It should be noted that other embodiments or implementation methods of the national secret CPE access device described in the present invention can refer to the above-mentioned method embodiments 1 and 2, which will not be repeated here.
[0237] Example 4
[0238] like Figure 8As shown, an embodiment of the present invention discloses an encrypted communication system integrating quantum keys, the system comprising a national secret CPE access device A, a quantum key distribution device, and a national secret CPE access device B, wherein the national secret CPE access device A and the national secret CPE access device B are respectively connected to the quantum key distribution device; wherein the national secret CPE access device A comprises:
[0239] The key negotiation module includes a first key negotiation submodule, a key request submodule, and a second key negotiation submodule. The first key negotiation submodule is used to perform a first-phase main mode key negotiation process with a communication responder and exchange secure storage medium identifiers of both communicating parties. The key request submodule is used to send a key request to a quantum key distribution device based on the secure storage medium identifiers of both communicating parties to obtain a first quantum key plaintext corresponding to the communication initiator. The second key negotiation submodule is used to perform a second-phase quick mode key negotiation process with the communication responder to obtain a second-phase session key and fuse the first quantum key plaintext corresponding to the communication initiator with the second-phase session key to obtain a temporary session key.
[0240] The KQTED module is used to re-apply to the quantum key distribution device to obtain the quantum key, and merge the obtained quantum key with the temporary session key to obtain the business data encryption and decryption key, and use the business data encryption and decryption key to encrypt the business data and securely transmit it to the national secret CPE access device B.
[0241] Specifically, if Figure 8 As shown in the figure, the communication process between the national secret CPE access device A and the national secret CPE access device B is as follows:
[0242] (1) National CPE access devices A and B initialize the device key.
[0243] (2) National CPE access devices A and B pre-install quantum key protection factors into their respective QT secure eSIM cards through quantum key distribution devices.
[0244] (3) The 5G module sends instructions to obtain the IP address assigned by the 5G private network base station, which is used as the wireless communication address.
[0245] (4) Key negotiation integrating quantum keys
[0246] S1 and national cryptographic CPE access devices A and B complete the IKE phase 1 main mode key negotiation process based on the national cryptographic digital certificate in accordance with the "GM / T 0022 IPSec VPN Technical Specification". During this process, the two parties exchange QT secure eSIM card identifiers.
[0247] S2. The national secret CPE access device A obtains the QT secure eSIM card identifiers of both parties (responder identifier: QT_PEER_eSIM_SN, initiator identifier: QT_LOCAL_eSIM_SN) according to the first stage, and generates a unique communication identifier (SESSION_RDKEY) through the national secret cryptographic component of the national secret CPE access device.
[0248] S3. The national cryptographic CPE access device A carries three identifiers QT_PEER_eSIM_SN, QT_LOCAL_eSIM_SN and SESSION_RDKEY to the quantum key distribution device to obtain the quantum key ciphertext of the communicating parties (16 bytes for the initiator: QT_ECKEY_S, 16 bytes for the responder: QT_ECKEY_R) and the quantum key protection factor index ciphertext (initiator: QT_PRE_KEY_ECINDEX_S, responder: QT_PRE_KEY_ECINDEX_R).
[0249] The quantum key ciphertext is protected by the quantum key protection factor index ciphertext, and the quantum key protection factor index ciphertext in S3 is protected by the device key in the national secret cryptographic component.
[0250] S4. Index the ciphertext according to the quantum key protection factor and map it to the index of the quantum key protection factor of the QT secure eSIM card using a linear hash algorithm.
[0251] S5. Obtain the 16-byte quantum key protection factor ciphertext according to the obtained index value, and decrypt it using the device key to obtain the corresponding quantum key protection factor (QT_PRE_KEY_N).
[0252] S6. Use QT_PRE_KEY_N as the key in SM4 CBC mode to decrypt the quantum key ciphertext and obtain the first quantum key plaintext QT_KEY_S.
[0253] S7. The national encryption CPE access device A goes through the second-stage quick mode key negotiation process. The first encrypted data packet adds an extended payload, and the hash operation of QT_ECKEY_R, QT_PRE_ECINDEX_R and the first quantum key plaintext is used to obtain HASH (QT_KEY_S) and encapsulate it in the extended payload for transmission.
[0254] S8. The national cryptographic CPE access device B receives the first data packet, obtains the second-stage session key (SESSION_KEY) and the initiator's HASH (QT_KEY_S), and repeats steps S4, S5, and S6 to obtain the second quantum key plaintext QT_KEY_R.
[0255] S9. Perform a hash operation on the second quantum key plaintext QT_KEY_R to obtain HASH(QT_KEY_R), and calculate whether HASH(QT_KEY_R) and HASH(QT_KEY_S) are equal; if they are not equal, terminate the negotiation.
[0256] S10. When they are equal, the national encryption CPE access device B generates a second encrypted data packet through the second-stage quick mode key negotiation process. The second encrypted data packet adds an extended payload and carries the quantum key usage identifier.
[0257] S11. The national cryptographic CPE access device A receives and parses the quantum key usage identifier in the second encrypted data packet, and performs an XOR operation (QT_SESSION_KEY=QT_KEY_R⊕SESSION_KEY) on the first quantum key plaintext and the second-stage session key to obtain QT_SESSION_KEY.
[0258] S12. In the second phase of the quick mode key negotiation process, the national cryptographic CPE access devices A and B send the temporary session key QT_SESSION_KEY and negotiation material information obtained by both communicating parties to their respective KQTED modules in the third data packet.
[0259] (5) KQTED module integrates quantum key
[0260] S13. The KQTED module receives the third data packet through NETLINK (the data packet transmission module in the KQTED module), parses it to obtain QT_SESSION_KEY, COOKIE_S of the national encryption CPE access device A, and COOKIE_R of the national encryption CPE access device B.
[0261] S14. Add COOKIE_S to COOKIE_R to obtain SESSION_RD_COOKIE.
[0262] S15. Use SESSION_RD_COOKIE as the unique session identifier for communicating with the quantum key distribution device, and simultaneously obtain the 16-byte quantum key ciphertext and quantum key protection factor index ciphertext from the quantum key distribution device.
[0263] S16. Repeat S4, S5, and S6 to obtain the quantum key plaintext (QT_KEY), and convert QT_KEY⊕QT_SESSION_KEY to obtain QT_FIN_KEY.
[0264] S17. Use QT_FIN_KEY as the business data encryption and decryption key.
[0265] Throughout this specification, reference to terms such as "one embodiment," "some embodiments," "examples," "specific examples," or "some examples" means that a specific feature, structure, material, or characteristic described in conjunction with that embodiment or example is included in at least one embodiment or example of the present invention. In this specification, schematic representations of the above terms do not necessarily refer to the same embodiment or example. Furthermore, the specific features, structures, materials, or characteristics described may be combined in any suitable manner in any one or more embodiments or examples.
[0266] Furthermore, the terms "first" and "second" are used for descriptive purposes only and should not be construed as indicating or implying relative importance or implicitly specifying the number of the technical features being referred to. Thus, a feature defined as "first" or "second" may explicitly or implicitly include at least one such feature. In the description of the present invention, "plurality" means at least two, such as two, three, etc., unless otherwise specifically defined.
[0267] Although the embodiments of the present invention have been shown and described above, it will be understood that the above embodiments are illustrative and are not to be construed as limitations on the present invention. A person skilled in the art may change, modify, replace and modify the above embodiments within the scope of the present invention.
Claims
1. A quantum key encryption communication method, characterized in that: Applied to a communication initiator, the method includes: Conduct the first phase of the main mode key negotiation process with the communication responder, and exchange the secure storage media identification of both communicating parties; Based on the secure storage medium identifiers of the communicating parties, a key request is sent to a quantum key distribution device to obtain a quantum key plaintext, including decrypting a first quantum key ciphertext and a first quantum key protection factor index ciphertext corresponding to the communication initiator returned by the quantum key distribution device, and decrypting the first quantum key ciphertext and the first quantum key protection factor index ciphertext to obtain a first quantum key plaintext corresponding to the communication initiator, wherein the first quantum key ciphertext is protected by the first quantum key protection factor index ciphertext, and the first quantum key protection factor index ciphertext is protected by the device key; Performing a second-phase quick mode key negotiation process with the communication responder to obtain a second-phase session key, and fusing the first quantum key plaintext corresponding to the communication initiator with the second-phase session key to obtain a temporary session key; Re-applying to the quantum key distribution device for obtaining a quantum key, and fusing the obtained quantum key with the temporary session key to obtain a service data encryption and decryption key, including: parsing a third data packet, where the third data packet is generated by the communication initiator and carries information including the temporary session key and negotiation material information, where the negotiation material information includes the communication initiator negotiation material and the communication responder negotiation material; fusing the communication initiator negotiation material with the communication responder negotiation material to generate a communication cookie, and requesting the quantum key distribution device to obtain a third quantum key ciphertext and a third quantum key protection factor index ciphertext based on the communication cookie; decrypting the third quantum key ciphertext and the third quantum key protection factor index ciphertext to obtain a corresponding quantum key; performing an XOR operation on the obtained quantum key and the temporary session key to obtain the service data encryption and decryption key; The business data encryption and decryption key is used to encrypt the business data for secure transmission.
2. The encryption communication method integrating quantum key according to claim 1, wherein: The method of sending a key request to a quantum key distribution device to obtain a quantum key plaintext based on the secure storage medium identifiers of both communicating parties includes: Sending a key request to the quantum key distribution device so that the quantum key distribution device generates a key response, wherein the key request carries information including secure storage medium identifiers and communication unique identifiers of both communicating parties; receiving the key response returned by the quantum key distribution device, wherein the key response carries information including quantum key ciphertexts of both communicating parties and quantum key protection factor index ciphertexts of both communicating parties; Decrypt the first quantum key ciphertext corresponding to the communication initiator to obtain the first quantum key plaintext corresponding to the communication initiator.
3. The encryption communication method integrating quantum key according to claim 1, wherein: The communication initiator is pre-installed with a quantum key protection factor and a device key, and the decryption of the quantum key ciphertext corresponding to the communication initiator to obtain the quantum key plaintext corresponding to the communication initiator includes: Mapping the first quantum key protection factor index ciphertext to the index of the first quantum key protection factor preset in the communication initiator using a linear hash algorithm to obtain an index value; Obtaining a corresponding first quantum key protection factor ciphertext based on the index value, calling the preset device key to decrypt the first quantum key protection factor ciphertext to obtain the corresponding first quantum key protection factor; The first quantum key protection factor is used as a key to decrypt the first quantum key ciphertext corresponding to the communication initiator to obtain the first quantum key plaintext corresponding to the communication initiator.
4. The encryption communication method integrating quantum key according to claim 1, wherein: The second-stage quick mode key negotiation process is performed with the communication responder to obtain the second-stage session key, and the quantum key plaintext and the second-stage session key are combined to obtain a temporary session key, including: Performing a second-phase quick mode key negotiation process with the communication responder, sending a first encrypted data packet to the communication responder, where the first encrypted data packet carries information including a second quantum key ciphertext corresponding to the communication responder, a second quantum key protection factor index ciphertext corresponding to the communication responder, and a first quantum key plaintext corresponding to the communication initiator, so that the communication responder obtains a second-phase session key and decrypts the second quantum key ciphertext and the second quantum key protection factor index ciphertext to obtain the second quantum key plaintext corresponding to the communication responder; receiving a second encrypted data packet returned by the communication responder, where the second encrypted data packet carries a quantum key usage identifier; Accept and parse the quantum key usage identifier carried by the second encrypted data packet, and perform an XOR operation on the first quantum key plaintext and the second-stage session key to obtain the temporary session key.
5. The encryption communication method integrating quantum key according to claim 4, characterized in that: An extended payload is added to the first encrypted data packet, and the extended payload encapsulates a second quantum key ciphertext, a second quantum key protection factor index ciphertext, and a hash value of the first quantum key plaintext. The method further includes: receiving a second encrypted data packet returned by the communication responder, wherein an extended payload is added to the second encrypted data packet for carrying a quantum key usage identifier, and the second encrypted data packet is generated by the communication responder when a hash value of the first quantum key plaintext is compared with a hash value of the second quantum key plaintext and the two are consistent; A negotiation termination message returned by the communication responder is received, where the negotiation termination message is generated by the communication responder when a hash value of the first quantum key ciphertext is compared with a hash value of the second quantum key ciphertext and the hash value is inconsistent.
6. The encryption communication method integrating quantum key according to claim 1, wherein: Before performing the first phase main mode key negotiation process with the communication responder, the method further includes: Requesting the quantum key distribution apparatus to preset a device key and a preset quantum key protection factor.
7. The encryption communication method integrating quantum key according to claim 1, wherein: Before performing the first phase main mode key negotiation process with the communication responder, the method further includes: Obtain the IP address assigned by the 5G private network base station, and use the IP address as the wireless communication address for communicating with the communication responder.
8. The encryption communication method integrating quantum key according to claim 1, wherein: The method further comprises: Based on the received key destruction trigger instruction, the quantum key protection factor and the device key are set to zero, and the key destruction trigger instruction is generated when the communication initiator disassembles.
9. A quantum key encryption communication method, characterized in that: Applied to a communication responder, the method includes: receiving a first encrypted data packet sent by a communication initiator, where the first encrypted data packet carries information including a second quantum key ciphertext corresponding to the communication responder and a second quantum key protection factor index ciphertext corresponding to the communication responder, wherein the second quantum key ciphertext is protected by the corresponding second quantum key protection factor index ciphertext, and the second quantum key protection factor index ciphertext is protected by a device key; Obtain the second-stage session key and decrypt the second quantum key ciphertext and the second quantum key protection factor index ciphertext to obtain the second quantum key plaintext corresponding to the communication responder; The second quantum key plaintext is combined with the second-stage session key to obtain a temporary session key; Re-applying to the quantum key distribution device for obtaining a quantum key, and fusing the obtained quantum key with the temporary session key to obtain a service data encryption and decryption key, including: parsing a third data packet, where the third data packet is generated by the communication responder and carries information including the temporary session key and negotiation material information, where the negotiation material information includes the communication initiator negotiation material and the communication responder negotiation material; fusing the communication initiator negotiation material with the communication responder negotiation material to generate a communication cookie, and requesting the quantum key distribution device to obtain a third quantum key ciphertext and a third quantum key protection factor index ciphertext based on the communication cookie; decrypting the third quantum key ciphertext and the third quantum key protection factor index ciphertext to obtain a corresponding quantum key; performing an XOR operation on the obtained quantum key and the temporary session key to obtain the service data encryption and decryption key; The business data sent by the communication initiator is decrypted using the business data encryption and decryption key.
10. The encryption communication method integrating quantum key according to claim 9, characterized in that: The communication responder is pre-installed with a quantum key protection factor and a device key, and the step of obtaining the second-stage session key and decrypting the second quantum key ciphertext and the second quantum key protection factor index ciphertext to obtain the second quantum key plaintext corresponding to the communication responder includes: Mapping the second quantum key protection factor index ciphertext to the index of the second quantum key protection factor preset in the communication responder using a linear hash algorithm to obtain an index value; Obtaining a corresponding second quantum key protection factor ciphertext based on the index value, calling the preset device key to decrypt the second quantum key protection factor ciphertext to obtain the corresponding second quantum key protection factor; The second quantum key protection factor is used as a key to decrypt the second quantum key ciphertext corresponding to the communication responder to obtain the second quantum key plaintext corresponding to the communication responder.
11. The encryption communication method integrating quantum key according to claim 9, wherein: The second encrypted data packet carries information further including a hash value of the first quantum key plaintext corresponding to the communication initiator, and the method further includes: Calculating a hash value of the second quantum key ciphertext, and comparing the hash value of the second quantum key ciphertext with the hash value of the first quantum key plaintext; If they are consistent, generating a second encrypted data packet, wherein an extended payload is added to the second encrypted data packet to carry the quantum key usage identifier; If they are inconsistent, the key negotiation process ends.
12. The encryption communication method integrating quantum keys according to claim 9, wherein: Before receiving the first encrypted data packet sent by the communication initiator, the method further includes: Perform the first phase of the main mode key negotiation process with the communication initiator, and exchange the secure storage medium identifiers of the two communicating parties.
13. The encryption communication method integrating quantum key according to claim 9, characterized in that: Before receiving the first encrypted data packet sent by the communication initiator, the method further includes: Obtain the IP address assigned by the 5G private network base station, and use the IP address as the wireless communication address for communicating with the communication initiator.
14. The encryption communication method integrating quantum key according to claim 9, wherein: The method further comprises: Based on the received key destruction trigger instruction, the quantum key protection factor and the device key are set to zero, and the key destruction trigger instruction is generated when the communication responder is disassembled.
15. A national secret CPE access device, characterized in that: The device comprises: A key negotiation module includes a first key negotiation submodule, a key request submodule, and a second key negotiation submodule. The first key negotiation submodule is used to perform a first-phase main mode key negotiation process with a communication responder, and exchange secure storage medium identifiers of both communicating parties. The key request submodule is used to send a key request to a quantum key distribution device based on the secure storage medium identifiers of both communicating parties to obtain a first quantum key plaintext corresponding to the communication initiator, including decrypting the first quantum key ciphertext and the first quantum key protection factor index ciphertext corresponding to the communication initiator returned by the quantum key distribution device, and decrypting the first quantum key ciphertext and the first quantum key protection factor index ciphertext to obtain the first quantum key plaintext corresponding to the communication initiator, wherein the first quantum key ciphertext is protected by the first quantum key protection factor index ciphertext, and the first quantum key protection factor index ciphertext is protected by the device key. The second key negotiation submodule is used to perform a second-phase quick mode key negotiation process with the communication responder, obtain a second-phase session key, and merge the first quantum key plaintext corresponding to the communication initiator with the second-phase session key to obtain a temporary session key. The KQTED module is used to apply to the quantum key distribution device again to obtain a quantum key, merge the obtained quantum key with the temporary session key to obtain a service data encryption and decryption key, and use the service data encryption and decryption key to encrypt and securely transmit the service data; The KQTED module includes: a parsing unit, configured to parse a third data packet, wherein the third data packet is generated by the communication initiator and carries information including the temporary session key and negotiation material information, wherein the negotiation material information includes the negotiation material of the communication initiator and the negotiation material of the communication responder; A second key requesting unit is configured to fuse the negotiation material of the communication initiator and the negotiation material of the communication responder to generate a communication cookie, and request the quantum key distribution device to obtain a third quantum key ciphertext and a third quantum key protection factor index ciphertext based on the communication cookie; A second key decryption unit is used to decrypt the third quantum key ciphertext and the third quantum key protection factor index ciphertext to obtain a corresponding quantum key; The second key fusion unit is used to perform an XOR operation on the acquired quantum key and the temporary session key to obtain the service data encryption and decryption key.
16. The national secret CPE access device according to claim 15, characterized in that: The key request submodule includes: a first key requesting unit, configured to send a key request to the quantum key distribution device so that the quantum key distribution device generates a key response, wherein the key request carries information including secure storage medium identifiers and communication unique identifiers of both communicating parties; A key response receiving unit, configured to receive the key response returned by the quantum key distribution device, wherein the key response carries information including the quantum key ciphertext of both communicating parties and the quantum key protection factor index ciphertext of both communicating parties; The first decryption unit is used to decrypt the first quantum key ciphertext corresponding to the communication initiator to obtain the first quantum key plaintext corresponding to the communication initiator.
17. The national secret CPE access device according to claim 16, characterized in that: The apparatus further includes a national secret cryptographic component and a QT secure eSIM card, wherein the secure storage area of the national secret cryptographic component stores a device key, and the QT secure eSIM card stores a quantum key protection factor. The first decryption unit specifically includes: A mapping subunit, configured to map the quantum key protection factor index ciphertext to the index of the quantum key protection factor preset in the QT secure eSIM card using a linear hash algorithm to obtain an index value; A first decryption subunit is configured to obtain a quantum key protection factor ciphertext corresponding to the QT secure eSIM card based on the index value, and call the device key preset in the national secret cryptographic component to decrypt the quantum key protection factor ciphertext to obtain a corresponding quantum key protection factor; The second decryption subunit is used to use the first quantum key protection factor as a key to decrypt the first quantum key ciphertext corresponding to the communication initiator to obtain the first quantum key plaintext corresponding to the communication initiator.
18. The national secret CPE access device according to claim 15, characterized in that: The second key agreement submodule includes: a first encrypted data packet sending unit, configured to perform a second-phase quick mode key negotiation process with the communication responder, and send a first encrypted data packet to the communication responder, wherein the first encrypted data packet carries information including a second quantum key ciphertext corresponding to the communication responder, a second quantum key protection factor index ciphertext corresponding to the communication responder, and a first quantum key plaintext corresponding to the communication initiator, so that the communication responder obtains the second-phase session key and decrypts the second quantum key ciphertext and the second quantum key protection factor index ciphertext to obtain the second quantum key plaintext corresponding to the communication responder; A second encrypted data packet receiving unit is configured to receive a second encrypted data packet returned by the communication responder, where the second encrypted data packet carries a quantum key usage identifier; The first key fusion unit is used to receive and parse the quantum key usage identifier carried by the second encrypted data packet, and perform an XOR operation on the first quantum key plaintext and the second-stage session key to obtain the temporary session key.
19. The national secret CPE access device according to claim 15, characterized in that: The device also includes a 5G module for obtaining an IP address allocated by a 5G private network base station and using the IP address as a wireless communication address for communicating with a communication responder.
20. The national secret CPE access device according to claim 17, characterized in that: The device further comprises: The key destruction module is used to reset the quantum key protection factor stored in the QT secure eSIM card and the device key stored in the national secret cryptographic component to zero based on the received key destruction trigger instruction. The key destruction trigger instruction is generated when the national secret CPE access device is disassembled.
21. An encryption communication system integrating quantum keys, characterized in that: The system includes a national secret CPE access device A, a quantum key distribution device, and a national secret CPE access device B. The national secret CPE access device A and the national secret CPE access device B are respectively connected to the quantum key distribution device; wherein the national secret CPE access device A includes: A key negotiation module is configured to perform a first-phase main mode key negotiation process with the national secret CPE access device B, exchange secure storage medium identifiers of both communicating parties, and perform a second-phase quick mode key negotiation process with the national secret CPE access device B, obtain a second-phase session key, and fuse the first quantum key plaintext with the second-phase session key to obtain a temporary session key. a key request module, configured to send a key request to a quantum key distribution device based on the secure storage medium identifiers of both communicating parties to obtain a first quantum key plaintext corresponding to the communication initiator, including decrypting the first quantum key ciphertext and the first quantum key protection factor index ciphertext corresponding to the communication initiator returned by the quantum key distribution device, and decrypting the first quantum key ciphertext and the first quantum key protection factor index ciphertext to obtain the first quantum key plaintext corresponding to the communication initiator, wherein the first quantum key ciphertext is protected by the first quantum key protection factor index ciphertext, and the first quantum key protection factor index ciphertext is protected by the device key; The KQTED module is used to re-apply to the quantum key distribution device to obtain a quantum key, merge the obtained quantum key with the temporary session key to obtain a service data encryption and decryption key, and use the service data encryption and decryption key to encrypt the service data and securely transmit it to the national encryption CPE access device B; The KQTED module includes: a parsing unit, configured to parse a third data packet, wherein the third data packet is generated by the communication initiator and carries information including the temporary session key and negotiation material information, wherein the negotiation material information includes the negotiation material of the communication initiator and the negotiation material of the communication responder; A second key requesting unit is configured to fuse the negotiation material of the communication initiator and the negotiation material of the communication responder to generate a communication cookie, and request the quantum key distribution device to obtain a third quantum key ciphertext and a third quantum key protection factor index ciphertext based on the communication cookie; A second key decryption unit is used to decrypt the third quantum key ciphertext and the third quantum key protection factor index ciphertext to obtain a corresponding quantum key; The second key fusion unit is used to perform an XOR operation on the acquired quantum key and the temporary session key to obtain the service data encryption and decryption key.
Citation Information
Patent Citations
Quantum key protection method, device and system based on three-layer key
CN113132102A
Method, gateway device and system for using quantum key in IPSec protocol
CN114285571A
Method for fusing quantum key in national secret IPSec transmission encryption
CN115277186A