Quantum random number based authentication interaction method, network login and management device

By leveraging the collaborative work of quantum random number beacons and management devices to generate and verify unpredictable quantum random number blocks, the security deficiencies of network login devices are addressed, enabling secure authentication and fast login for local area networks, thereby enhancing network security and management efficiency.

CN118282615BActive Publication Date: 2026-08-25JINAN INST OF QUANTUM TECH
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202211721327.9
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2022-12-30
Publication Date
2026-08-25
Estimated Expiration
2042-12-30

AI Technical Summary

Technical Problem

Existing network login devices lack sufficient security, allowing unauthorized users to gain access to the local area network by obtaining passwords, resulting in wasted computing resources and information security threats. Existing verification methods cannot fully guarantee security.

Method used

An authentication interaction method based on quantum random numbers is adopted. Through the collaborative work of network login devices, quantum random number beacons and management devices, unpredictable quantum random number blocks are generated and verified to build user profiles and verification databases, thereby realizing secure authentication for registration, updates and login.

Benefits of technology

It improves the security of local area networks, prevents unauthorized users from logging in, ensures fast login for legitimate users, and prevents attacks by falsifying information through the unpredictability of quantum random numbers, thereby enhancing network security and management efficiency.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN118282615B_ABST
    Figure CN118282615B_ABST
Patent Text Reader

Abstract

The application is suitable for the field of quantum communication technology, and relates to an authentication interaction method based on quantum random numbers and a network login and management device. The application constructs a local area network connected with a terminal device, a network login device, a quantum random number beacon and a management device of a user, sends an application to the quantum random number beacon based on a login device information vector of the network login device, receives the quantum random number beacon to continuously generate a first quantum random number block and a second quantum random number block and forwards the first quantum random number block and the second quantum random number block to the management device, the management device feeds back a registration authentication result according to the received information, so that the user obtains a login key, and the management device constructs a user profile, a verification library and a response library and the like for subsequent user updating and login verification, realizes registration, updating and login and the like of the authentication interaction based on the local area network, and due to unpredictability and verifiability of the quantum random number block, information forged by an attacker cannot pass the verification of the management device, so that the security of the local area network is improved.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This application relates to the field of quantum communication technology, and in particular to an authentication interaction method, network login and management device based on quantum random numbers. Background Technology

[0002] Currently, with the development of information technology, using network login devices to build local area networks (LANs) within a small area has become a common phenomenon in network applications. However, existing network login devices, such as routers, often have security vulnerabilities. Existing routers allow users to log in with a password, meaning that even unauthorized users can access the LAN if they obtain the password. This easily leads to a waste of LAN computing and bandwidth resources and threatens the information security of other users on the LAN. Current network interaction verification methods, such as registration, login, and update verification, cannot completely guarantee security. Some data generated during registration, login, and update processes can be used by third parties to pass verification. Therefore, improving the security of network interaction processes has become an urgent problem to be solved. Summary of the Invention

[0003] In view of this, embodiments of this application provide an authentication interaction method, network login and management device based on quantum random numbers to address the problem of how to improve the security of network interaction processes.

[0004] In a first aspect, embodiments of this application provide an authentication interaction method based on quantum random numbers. The authentication interaction method is applied to any network login device in a local area network. The network login device is connected to at least one terminal device for user use, a quantum random number beacon, and a management device. The authentication interaction method includes:

[0005] After receiving a registration request from any terminal device, the user identity information of the corresponding user and the first user device information of the terminal device are extracted, and an application is sent to the quantum random number beacon based on the login device information of the network login device. The quantum random number beacon is used to continuously generate the first quantum random number block and the second quantum random number block when the application is received.

[0006] The system receives the first quantum random number block and the second quantum random number block, sends all quantum random number blocks, the first user equipment information, and the user identity information to the management device, and the management device obtains the registration authentication result based on the received information, feeds back the registration authentication result to the network login device, and associates the first user equipment information, the first quantum random number block, and the user identity information to construct the user's user profile, and stores the second quantum random number block in the verification database.

[0007] Upon receiving the registration and authentication result, the system feeds back the preset login key to the terminal device, calculates the first response information based on the first quantum random number block and the first user device information, and stores the first response information in the response database.

[0008] Secondly, embodiments of this application provide an authentication interaction method based on quantum random numbers. The authentication interaction method is applied to a management device connected to the network login device described in the first aspect above. The authentication interaction method includes:

[0009] Receive all quantum random number blocks, the first user equipment information, and the user identity information;

[0010] Based on all quantum random number blocks, the first user device information, and the user identity information, the registration authentication result is obtained, and the registration authentication result is fed back to the network login device;

[0011] The user profile of the user is constructed by associating the first user equipment information, the first quantum random number block and the user identity information.

[0012] The second quantum random number block is stored in the verification library.

[0013] Thirdly, embodiments of this application provide a network login device, which is any network login device in a local area network. The network login device is connected to at least one terminal device for user use, a quantum random number beacon, and a management device. The network login device includes:

[0014] The beacon application module is used to extract the user identity information of the corresponding user and the first user device information of the terminal device after receiving a registration request sent by any terminal device, and send an application to the quantum random number beacon based on the login device information of the network login device. The quantum random number beacon is used to continuously generate a first quantum random number block and a second quantum random number block when it receives the application.

[0015] The first sending module is used to receive the first quantum random number block and the second quantum random number block, send all quantum random number blocks, the first user equipment information and the user identity information to the management device, and the management device is used to obtain the registration authentication result based on the received information, feed back the registration authentication result to the network login device, associate the first user equipment information, the first quantum random number block and the user identity information to construct the user's user profile, and store the second quantum random number block in the verification database.

[0016] The registration feedback module is used to receive the registration authentication result, feed back the preset login key to the terminal device, calculate the first response information based on the first quantum random number block and the first user device information, and store the first response information in the response database.

[0017] Fourthly, embodiments of this application provide a management device connected to the network login device as described in the third aspect, the management device comprising:

[0018] The first receiving module is used to receive all quantum random number blocks, the first user equipment information, and the user identity information;

[0019] The registration and authentication module is used to obtain the registration and authentication result based on all quantum random number blocks, the first user device information and the user identity information, and to feed back the registration and authentication result to the network login device;

[0020] The profile building module is used to associate the first user device information, the first quantum random number block and the user identity information to build the user profile of the user;

[0021] The information storage module is used to store the second quantum random number block into the verification database.

[0022] The beneficial effects of this application embodiment compared with the prior art are as follows: This application constructs a local area network connecting the user's terminal device, network login device, quantum random number beacon, and management device. Upon user registration and update requests, the login device sends an application to the quantum random number beacon based on the login device information of the network login device. The quantum random number beacon continuously generates a first quantum random number block and a second quantum random number block and forwards them to the management device. Based on the received information, the registration authentication result is fed back, enabling the network login device to feed back the preset login key to the user. The management device constructs user profiles, verification databases, and response databases for subsequent user updates and login verification, realizing authentication of interactions such as registration, update, and login based on this local area network. Due to the unpredictability and verifiability of the quantum random number blocks, information forged by attackers cannot pass the verification of the management device, thereby improving the security of the local area network. Attached Figure Description

[0023] To more clearly illustrate the technical solutions in the embodiments of this application, the drawings used in the description of the embodiments or the prior art will be briefly introduced below. Obviously, the drawings described below are only some embodiments of this application. For those skilled in the art, other drawings can be obtained based on these drawings without creative effort.

[0024] Figure 1This is a schematic diagram of the registration interaction of an authentication interaction method based on quantum random numbers provided in Embodiment 1 of this application;

[0025] Figure 2 This is an interactive diagram illustrating the example of user A submitting a registration, provided in Embodiment 1 of this application.

[0026] Figure 3 This is a schematic diagram of the update interaction of an authentication interaction method based on quantum random numbers provided in Embodiment 2 of this application;

[0027] Figure 4 This is a login interaction diagram of an authentication interaction method based on quantum random numbers provided in Embodiment 3 of this application;

[0028] Figure 5 This is a schematic diagram of the structure of a network login device provided in Embodiment 4 of this application;

[0029] Figure 6 This is a schematic diagram of the structure of a management device provided in Embodiment 5 of this application. Detailed Implementation

[0030] In the following description, specific details such as particular system architectures and techniques are set forth for illustrative purposes and not for limitation, in order to provide a thorough understanding of the embodiments of this application. However, those skilled in the art will understand that this application may also be implemented in other embodiments without these specific details. In other instances, detailed descriptions of well-known systems, apparatuses, circuits, and methods have been omitted so as not to obscure the description of this application with unnecessary detail.

[0031] It should be understood that, when used in this application specification and the appended claims, the term "comprising" indicates the presence of the described features, integrals, steps, operations, elements and / or components, but does not exclude the presence or addition of one or more other features, integrals, steps, operations, elements, components and / or a collection thereof.

[0032] Furthermore, in the description of this application and the appended claims, the terms "first," "second," "third," etc., are used only to distinguish descriptions and should not be construed as indicating or implying relative importance. The terms "comprising," "including," "having," and their variations all mean "including but not limited to," unless otherwise specifically emphasized.

[0033] It should be understood that the sequence number of each step in the following embodiments does not imply the order of execution. The execution order of each process should be determined by its function and internal logic, and should not constitute any limitation on the implementation process of the embodiments of this application.

[0034] To illustrate the technical solution of this application, specific embodiments are described below.

[0035] The local area network system upon which this application is based consists of at least one terminal device, at least one network login device, a quantum random number beacon, and a management device. The terminal device is used by the user, the management device is used by the administrator, and the network login device connects the terminal device, the quantum random number beacon, and the management device, thereby enabling data interaction among the four devices.

[0036] Users are ordinary users of the local area network (LAN) system, possessing usage rights but not control. The LAN system allows users to perform operations such as registration, updates, and logins. Registration requires meeting certain registration conditions, updates require meeting certain update conditions, and logins require meeting certain login conditions before information can be transmitted within the LAN system. Each user's terminal device has a unique device information code, which is the user's device information.

[0037] Network login devices have limited storage and computing capabilities, and can detect and extract user identity information and user device information from user requests. Multiple network login devices can be set up in a local area network.

[0038] When a request is received, a network login device requests a quantum random number block from a quantum random number beacon; this network login device is the applicant. The principle of the quantum random number beacon is based on quantum mechanics to generate quantum random numbers based on Bell state measurements. The generated quantum random numbers are unpredictable and verifiable. Specifically, after receiving a request, the quantum random number beacon generates a quantum random number and then appends a timestamp of the current time, the applicant's device information (i.e., the login device's login device information), and the hash value of the previous quantum random number block. The aforementioned quantum random number, timestamp, device information, and hash value constitute the quantum random number block. The hash value can be used to detect whether two random number blocks are consecutive, and the timestamp and device information can be used for subsequent verification. The random number blocks are unpredictable, and the beacon can verify whether the quantum random numbers in the random number block were generated by the beacon.

[0039] The management device is responsible for the management and control of the entire local area network system. There can be multiple administrators in the local area network system. In order to achieve the purpose of fast login, the automatic answering device can also participate in the login management as an administrator. The system achieves secure login through steps such as user registration and key acquisition, login, information update and information synchronization between management devices.

[0040] See Figure 1 This is a registration interaction diagram of an authentication interaction method based on quantum random numbers provided in Embodiment 1 of this application. This authentication interaction method operates in the aforementioned local area network system, such as... Figure 1 As shown, the application in network login devices and management devices includes the following steps:

[0041] Step S101: After receiving a registration request from any terminal device, extract the user's identity information and the terminal device's first user device information, and send an application to the quantum random number beacon based on the login device information of the network login device.

[0042] Step S102: Continuously generate the first quantum random number block and the second quantum random number block.

[0043] This step is performed by a quantum random number beacon. Each quantum random number block includes login device information, a quantum random number, a timestamp, and the hash value of the previous quantum random number block. Of course, if security is a less critical concern, at least one of the login device information, timestamp, and hash value of the previous quantum random number block can be used together with the quantum random number to form a quantum random number block.

[0044] Step S103: Receive the first quantum random number block and the second quantum random number block, and send all quantum random number blocks, the first user equipment information, and the user identity information to the management device.

[0045] Step S104: Receive all quantum random number blocks, first user equipment information, and user identity information.

[0046] Step S105: Based on all quantum random number blocks, the first user device information, and the user identity information, obtain the registration and authentication result, and feed the registration and authentication result back to the network login device.

[0047] Optionally, all quantum random number blocks include login device information, quantum random numbers, timestamps, and the hash value of the previous quantum random number block;

[0048] Based on all the quantum random number blocks, the first user device information, and the user identity information, the registration authentication results include:

[0049] Check whether the user's identity information is legitimate;

[0050] Detect whether the difference between the timestamp in the first quantum random number block and the current time is within a preset range;

[0051] Detect whether the login device information in the first quantum random number block belongs to any network login device in the local area network;

[0052] Check whether the comparison result between the first quantum random number block and the second quantum random number block meets the preset conditions;

[0053] If the user's identity information is found to be valid, the difference is found to be within a preset range, the login device information in the first quantum random number block is found to belong to any network login device in the local area network, and the comparison result between the first quantum random number block and the second quantum random number block meets the preset conditions, then a registration authentication result is generated.

[0054] If all the above tests and verifications are passed, it means that the registration process is legal and compliant. Based on this, a registration authentication result can be given, which proves that the registration was successful and can guide the network login device to issue passwords and other operations.

[0055] Optionally, checking whether the comparison result between the first and second quantum random number blocks meets preset conditions includes:

[0056] Calculate the first hash value of the first quantum random number block, compare the first hash value with the hash value in the second quantum random number block, if the two hash values ​​are the same, compare whether the login device information in the first quantum random number block and the second quantum random number block are the same, and whether the timestamp difference is less than the time threshold.

[0057] If the login device information in the first quantum random number block and the second quantum random number block are the same, and the timestamp difference is less than the time threshold, then the comparison result between the first quantum random number block and the second quantum random number block is determined to meet the preset conditions.

[0058] The verification process for each quantum random number block includes login device information, a quantum random number, a timestamp, and the hash value of the previous quantum random number block. Verification of the quantum random number block involves checking if the two blocks are consecutive, whether the difference between the timestamps in the first and second blocks is less than a time threshold, and whether the login device information is identical. Therefore, verification only succeeds when the quantum random number block meets these conditions. Generally, attackers cannot forge quantum random number blocks, and even if they did, the verification would fail, thus enhancing security during the registration process.

[0059] Step S106: Receive the registration and authentication result, send the preset login key back to the terminal device, calculate the first response information based on the first quantum random number block and the first user equipment information, and store the first response information in the response database.

[0060] The preset login key is pre-set in the management device, which can send the preset login key to each network login device. Furthermore, in the local area network system, the preset login key is uniform.

[0061] Optionally, when calculating the response information, an algorithm based on a one-way hash function can be used, such as using the MD5 algorithm to calculate the response value.

[0062] Step S107: The user profile is constructed by associating the first user equipment information, the first quantum random number block, and the user identity information.

[0063] Step S108: Store the second quantum random number block into the verification library.

[0064] Specifically, steps S101, S103, and S106 are executed by the network login device, step S102 is executed by the quantum random number beacon, and steps S104, S105, S107, and S108 are executed by the management device. Through this interactive process, user registration and password acquisition can be achieved.

[0065] For example, taking user A's registration and key acquisition as an example, such as Figure 2 As shown, the interaction steps are as follows:

[0066] Step 1: User A sends a registration request and identity information to the network login device.

[0067] Step 2: After receiving user A's identity information, the network login device extracts user A's device information UD_A. The network login device connects to a quantum random number beacon, which generates two consecutive quantum random number blocks. Each quantum random number block includes a device code (i.e., the login device information of the network login device), quantum random numbers, a timestamp, and the hash value of the previous quantum random number block. The former of the two quantum random number beacons serves as user A's identification code, denoted as Code_A, and the latter serves as the check code, denoted as Ch_A.

[0068] Step 3: The network login device transmits user A's user identity information, user device information UD_A, identification code Code_A, and verification code Ch_A to the administrator.

[0069] Step 4: The administrator verifies whether user A's user identity information is legitimate; verifies whether the difference between the timestamp of Code_A and the current time is within the specified range; and verifies whether the device code in the quantum random number block belongs to any network login device in the local area network. Among these, the network login devices are all registered with the administrator, so the validity of the device code can be determined.

[0070] Step 5: The administrator verifies the continuity (i.e., whether Code_A and Ch_A are consecutive) and compares whether their device codes are the same, and whether the timestamp difference is less than the time threshold. Specifically, if the timestamp of the check code is after the timestamp of the identification code, and the difference is less than 10ms, the timestamps are considered to match.

[0071] Step 6: After successful verification, the administrator will send the result back to the network login device, create a user profile for user A, associate the identity information with (UD_A, Code_A), and store Ch_A in the verification database.

[0072] Step 7: The network login device calculates the response Res_A using (UD_A, Code_A), stores Res_A in the response database, and sends the login key Key to user A. Registration is then complete through this process.

[0073] See Figure 3 Embodiment 2 of this application provides an update interaction process for an authentication interaction method based on quantum random numbers, specifically including the following steps:

[0074] Step S301: After receiving an update request from any terminal device, the second user equipment information of the corresponding terminal device is sent to the management device. The management device is used to perform a retrieval based on the second user equipment information, and after a successful retrieval, it sends a successful retrieval result back to the network login device.

[0075] Step S302: Receive the successful retrieval result, send an application to the quantum random number beacon, and receive the first and second update random number blocks fed back by the quantum random number beacon. Send the first and second update random number blocks to the management device, calculate the update response information based on the first and second update random number blocks and the user equipment information, and use the update response information to update the response information in the response database.

[0076] Step S303: After receiving the second user equipment information, all user files are searched according to the second user equipment information. If the first target file corresponding to the second user equipment information is found, the search is determined to be successful, and the search success result is fed back to the network login device. The second user equipment information is the device information of the corresponding terminal device sent by the network login device when an update request is sent based on any terminal device.

[0077] Step S304: Receive the first update random number block and the second update random number block sent by the network login device, update the first target file according to the first update random number block, and update the verification database according to the second update random number block.

[0078] Among them, steps S301 and S302 are executed by the network login device, and steps S303 and S304 are executed by the management device.

[0079] In this application, the administrator uses the corresponding management equipment to manage the entire local area network system. The administrator can perform corresponding information maintenance operations every T1 time or when going offline, which is used to maintain the target file and verification database. Furthermore, the administrator can also connect to the quantum random number beacon through the management equipment to determine the authenticity of the quantum random number block it receives (i.e., whether it was generated by the quantum random number beacon).

[0080] Additionally, a time threshold T2 can be set to filter expired user profiles and verify expired information in the database. T1 can be a short time period, such as 1 hour, and T2 can be a longer time period, such as 30 days. Of course, depending on actual needs, T1 and T2 can also be adjusted to different time intervals.

[0081] The administrator's maintenance procedures are as follows:

[0082] Maintenance 1: Retrieve the first quantum random number block from the user profile, extract user profiles whose timestamps differ from the current time by more than T2, and process these user identification codes to expire. Taking user B as an example, the specific processing method involves calculating the corresponding response information based on the user device information in user B's profile and the first quantum random number block. A deletion marker is added to this response information, which is then sent to all network login devices in the network. Finally, the first quantum random number block in user B's profile is deleted.

[0083] After receiving a response message with a deletion mark, the network login device can detect the deletion mark, search for the response message in the response database, and delete the response message in the response database after retrieval, thus realizing the expiration processing of user profiles.

[0084] Maintenance 2: Check the second quantum random number blocks stored in the verification library, extract the second quantum random number blocks whose timestamp difference from the current time is less than or greater than T2, and delete these second quantum random number blocks to implement the expiration handling of the verification library. Subsequent login attempts show that login is impossible if the user profile does not contain a corresponding first quantum random number block, the verification library does not contain a corresponding second quantum random number block, and the response library does not contain corresponding response information.

[0085] Maintenance 3: Since there are more than one network login device and management device in the local area network system, and after a user registers based on one network login device, the corresponding information is not stored in other network login devices, the administrator periodically performs synchronization processing on the registration information, including: extracting user profiles from the first quantum random number block whose timestamp differs from the current time by less than T1, sending the user profiles to other management devices, and calculating the corresponding response information based on the first quantum random number block in the user profile and the user device information, and sending the response information to all network login devices for synchronization.

[0086] When other administrators receive the sent user profile and second quantum random number block, they verify the user device information and timestamp of the first quantum random number block in the user profile. The user device information must be a legitimate login device in the local area network system, and the timestamp should be within T1 intervals of the current time. Then, they use the hash value of the first quantum random number block to retrieve the sent second quantum random number block and compare the login device information and timestamp. If the verification fails, an error is reported to all other administrators. After successful verification, the administrator checks if the user profile exists. If the received user profile does not exist in the database, a new user profile is saved, and the corresponding second quantum random number block is added to the verification database. If the received user profile already exists in the database, the timestamp order in the first quantum random number blocks of the two profiles is compared. If the timestamp of the already saved user profile is later, no action is taken. If the timestamp of the sent user profile is later, the first quantum random number block in the already saved user profile is updated, and the corresponding second quantum random number block is added to the verification database.

[0087] like Figure 3 As shown, based on the above registration and authentication interaction process, taking user A's information update as an example, the steps for user A to update information are as follows:

[0088] Step 1: User A sends an information update request to the network login device.

[0089] Step 2: After receiving user A's identity information, the network login device extracts user A's device information UD_A and sends it to the administrator.

[0090] Step 3: The administrator retrieves the user profile and verifies user A's identity information and device information UD_A. Upon successful verification, the administrator sends a confirmation message to the network login device.

[0091] Step 4: The network login device connects to the quantum random number beacon. The quantum random number beacon generates two consecutive random number blocks. The former is used as the new identification code for user A, denoted as Code_A1; the latter is used as the check code, denoted as Ch_A1.

[0092] Step 5: The network login device transmits Code_A1 and Ch_A1 to the administrator. The administrator verifies the continuity of Code_A1 and Ch_A1 and compares their timestamps with the device code. After successful verification, the administrator updates the identification code Code_A1 in the user profile and adds Ch_A1 to the verification database.

[0093] Step 6: The network login device uses (UD_A, Code_A1) to calculate the new response Res_A1 and saves it to the response database. Subsequently, the new response Res_A1 can be broadcast to other network login devices in the network. At this point, the administrator no longer needs to configure the function to send response information to other network login devices. The update operation is completed through the above process.

[0094] This application's maintenance mechanism enables timely updates to new user profiles, allowing the user to log in from any network login device on the local area network. Secondly, it clears expired identification codes and response values, enhancing network security while minimizing the storage space required by network login devices. Finally, the regular broadcasts by legitimate network administrators allow other administrators to assess the administrator's security. Therefore, the maintenance process is a crucial aspect of ensuring local area network security.

[0095] See Figure 4 Embodiment 3 of this application provides a login interaction process for an authentication interaction method based on quantum random numbers, specifically including the following steps:

[0096] Step S401: After obtaining the login password sent by any user's terminal device, verify the login password, and after successful verification, send the third user device information of the corresponding terminal device to the management device.

[0097] Step S402: After receiving the third user equipment information, determine the second target file corresponding to the third user equipment information from all user files, and determine the quantum random number block in the second target file as the target random number block.

[0098] Step S403: Calculate the target hash value of the target random number block. If the corresponding quantum random number block is found in the verification database based on the target hash value, calculate the second response information based on the target random number block and the third user equipment information, and send the target random number block and the second response information to the network login device.

[0099] Step S404: Receive the target random number block and the second response information; detect whether the login device information in the target random number block belongs to any network login device in the local area network; if the login device information in the target random block belongs to any network login device in the local area network, search the response database for a response that matches the second response information; and when a corresponding response is found, send a successful login verification message to the terminal device.

[0100] Among them, steps S401 and S404 are executed by the network login device, and steps S402 and S403 are executed by the management device.

[0101] In the above process, after the user provides the login password, they enter the network login device and management device for verification. The verification is based on the previously registered and updated stored data. In other words, if the login information matches the stored data, the login can be successful.

[0102] like Figure 4 As shown, based on the above registration and authentication interaction process, taking user A's login as an example, the steps for user A to log in are as follows:

[0103] Step 1: User A submits the login password Key to the network login device.

[0104] Step 2: After the network login device verification key is passed, the user device information UD_A is extracted and transmitted to the administrator.

[0105] Step 3: The administrator finds the user profile through UD_A, extracts the identification code Code_A, and if Code_A does not exist, the verification is terminated and a notification is sent to the user that the identity information has expired.

[0106] Step 4: The administrator calculates the hash value of Code_A and searches for it in the verification database. If no result is found, the verification process is terminated, and a login verification failure message is sent to the user.

[0107] Step 5: After successful verification, the administrator uses (UD_A, Code_A) to calculate the response Res_A.

[0108] Step 6: The administrator transmits Code_A and Res_A to the network login device.

[0109] Step 7: The network login device verifies whether the device code in the first quantum random number block of Code_A originates from a legitimate network login device and searches for Res_A in the response database. If either fails, the verification process terminates and a verification failure message is sent to the user; if both succeed, the user passes the verification and logs in successfully. The login process is completed by following these steps.

[0110] If a network attacker attempts to infiltrate a local area network via a network login device, and only possesses the login password, the administrator will disconnect the attacker because the user profile cannot be retrieved. Even if the attacker forges a user profile and manages to link to a quantum random number beacon to obtain random number blocks to disguise as identification and verification codes, transmitting them to the management device via the network login device, the administrator will still detect the invalid device code during the aforementioned maintenance phase.

[0111] If a network attacker attacks the network through an administrator and stores fake user profiles, the unpredictability of the quantum random number blocks generated by the quantum random number beacon makes it impossible to construct matching identification and verification codes. Furthermore, even if a forged verification code is obtained through the quantum random number beacon, it's impossible to construct a valid timestamp and a device code consistent with the network login device. This is because during maintenance, when the administrator sends user profiles to other administrators, those administrators can promptly detect the forgery by checking the continuity of the identification and verification codes, and the device code and timestamp.

[0112] This application utilizes quantum random number beacons to construct a local area network (LAN) architecture. This not only prevents unauthorized users from logging into the LAN, enhancing network security, but also allows authorized users to log in with just a password, ensuring quick login. Furthermore, user logins have a time limit; exceeding a set period requires re-authentication to prevent exploitation by network attackers due to unchanging keys. The quantum random number blocks generated by the quantum random number beacons can ensure fast login for authenticated users while preventing unauthorized logins, thus maintaining the security of the LAN.

[0113] For the interaction methods corresponding to Embodiments 1, 2, and 3 above, please refer to... Figure 5 This is a schematic diagram of the structure of a network login device provided in Embodiment 4 of this application. The network login device connects the user's terminal device, a quantum random number beacon, and a management device. The network login device includes:

[0114] The beacon application module 51 is used to extract the user's user identity information and the first user device information of the terminal device after receiving the registration request sent by the terminal device, and send an application to the quantum random number beacon based on the login device information of the network login device. The quantum random number beacon is used to continuously generate the first quantum random number block and the second quantum random number block when the application is received.

[0115] The first sending module 52 is used to receive the first quantum random number block and the second quantum random number block, send all quantum random number blocks, the first user equipment information and the user identity information to the management device, the management device is used to obtain the registration and authentication result based on the received information, feed back the registration and authentication result to the network login device, associate the first user equipment information, the first quantum random number block and the user identity information to construct the user's user profile, and store the second quantum random number block in the verification library.

[0116] The registration feedback module 53 is used to receive the registration authentication result, generate a login key and feed the login key back to the terminal device, calculate the first response information based on the first quantum random number block and the first user equipment information, and store the first response information in the response database.

[0117] Optionally, the network login device also includes:

[0118] The second sending module is used to send the second user equipment information of the corresponding terminal device to the management device after receiving an update request from any terminal device. The management device is used to perform a retrieval based on the second user equipment information and to send the retrieval success result back to the network login device after a successful retrieval.

[0119] The response information update module is used to receive successful retrieval results, send requests to the quantum random number beacon, and receive the first and second update random number blocks fed back by the quantum random number beacon. It sends the first and second update random number blocks to the management device, calculates the updated response information based on the first and second update random number blocks and the user equipment information, and uses the updated response information to update the response information in the response database.

[0120] Optionally, the network login device also includes:

[0121] The third sending module is used to verify the login password after obtaining the login password sent by any user using the terminal device, and after the verification is successful, send the third user device information of the corresponding terminal device to the management device. The management device is used to determine the target random number block based on the third user device information and calculate the second response information based on the third user device information and the target random number block and feed it back to the network login device.

[0122] The login verification module is used to receive a target random number block and a second response information, detect whether the login device information in the target random number block belongs to any network login device in the local area network, and if the login device information in the target random number block belongs to any network login device in the local area network, it searches the response database to see if there is a response information that matches the second response information, and when a corresponding response information is found, it sends a message to the terminal device that the login verification is successful.

[0123] It should be noted that the information interaction and execution process between the above modules are based on the same concept as the method embodiments of this application. For details on their specific functions and technical effects, please refer to the method embodiments section, and they will not be repeated here.

[0124] For the interaction methods corresponding to Embodiments 1, 2, and 3 above, please refer to... Figure 6 This is a schematic diagram of the structure of a management device provided in Embodiment 5 of this application. The management device is connected to the network login device of Embodiment 4 above. The management device includes:

[0125] The first receiving module 61 is used to receive all quantum random number blocks, first user equipment information and user identity information;

[0126] The registration and authentication module 62 is used to obtain the registration and authentication result based on all quantum random number blocks, the first user device information and the user identity information, and to feed back the registration and authentication result to the network login device.

[0127] The profile construction module 63 is used to associate the first user device information, the first quantum random number block and the user identity information to construct the user profile;

[0128] The information storage module 64 is used to store the second quantum random number block into the verification library.

[0129] Optionally, the management equipment may also include:

[0130] The second receiving module is used to retrieve all user files based on the second user equipment information after receiving the second user equipment information. If the first target file corresponding to the second user equipment information is found, the retrieval is determined to be successful, and the retrieval success result is fed back to the network login device. The second user equipment information is the device information of the corresponding terminal device sent by the network login device based on the update request sent by any terminal device.

[0131] The management information update module is used to receive a first update random number block and a second update random number block sent by the network login device, update the first target file according to the first update random number block, and update the verification database according to the second update random number block.

[0132] Optionally, the management equipment may also include:

[0133] The third receiving module is used to determine the second target file corresponding to the third user equipment information from all user files after receiving the third user equipment information, determine the quantum random number block in the second target file as the target random number block, and the third user equipment information is the login password sent by the network login device based on the terminal device used by any user, and the device information of the corresponding terminal device sent when the login password is verified.

[0134] The calculation feedback module is used to calculate the target hash value of the target random number block. If the corresponding quantum random number block is found in the verification library based on the target hash value, the second response information is calculated based on the target random number block and the third user equipment information, and the target random number block and the second response information are sent to the network login device.

[0135] Optionally, all quantum random number blocks include login device information, quantum random numbers, timestamps, and the hash value of the previous quantum random number block;

[0136] Registration and authentication module 62 includes:

[0137] The first detection unit is used to detect whether the user's identity information is legal;

[0138] The second detection unit is used to detect whether the difference between the timestamp in the first quantum random number block and the current time is within a preset range;

[0139] The third detection unit is used to detect whether the login device information in the first quantum random number block belongs to any network login device in the local area network.

[0140] The fourth detection unit is used to detect whether the comparison result between the first quantum random number block and the second quantum random number block meets the preset conditions;

[0141] The authentication result generation unit is used to generate a registration authentication result if the user's identity information is found to be legitimate, the difference is found to be within a preset range, the login device information in the first quantum random number block is found to belong to any network login device in the local area network, and the comparison result between the first quantum random number block and the second quantum random number block meets the preset conditions.

[0142] Optionally, the fourth detection unit includes:

[0143] The hash value comparison subunit is used to calculate the first hash value of the first quantum random number block, compare the first hash value with the hash value in the second quantum random number block, and if the two hash values ​​are the same, compare whether the timestamp and login device information in the first quantum random number block and the second quantum random number block are the same.

[0144] The information comparison unit is used to determine that the comparison result between the first quantum random number block and the second quantum random number block meets the preset conditions if the timestamp and login device information in the first quantum random number block and the second quantum random number block are the same.

[0145] It should be noted that the information interaction and execution process between the above modules are based on the same concept as the method embodiments of this application. For details on their specific functions and technical effects, please refer to the method embodiments section, and they will not be repeated here.

[0146] The implementation of all or part of the processes in the methods of the above embodiments can also be accomplished by a computer program product. When the computer program product is run on a computer device, it enables the computer device to execute the steps in the above method embodiments.

[0147] In the above embodiments, the descriptions of each embodiment have different focuses. For parts that are not described in detail or recorded in a certain embodiment, please refer to the relevant descriptions of other embodiments.

[0148] Those skilled in the art will recognize that the units and algorithm steps of the various examples described in conjunction with the embodiments disclosed herein can be implemented in electronic hardware, or a combination of computer software and electronic hardware. Whether these functions are implemented in hardware or software depends on the specific application and design constraints of the technical solution. Those skilled in the art can use different methods to implement the described functions for each specific application, but such implementation should not be considered beyond the scope of this application.

[0149] The above embodiments are only used to illustrate the technical solutions of this application, and are not intended to limit them. Although this application has been described in detail with reference to the foregoing embodiments, those skilled in the art should understand that modifications can still be made to the technical solutions described in the foregoing embodiments, or equivalent substitutions can be made to some of the technical features. Such modifications or substitutions do not cause the essence of the corresponding technical solutions to deviate from the spirit and scope of the technical solutions of the embodiments of this application, and should all be included within the protection scope of this application.

Claims

1. A quantum random number-based authentication interaction method, characterized in that, The authentication interaction method is applied to any network login device in a local area network, wherein the network login device is connected to at least one terminal device for user use, a quantum random number beacon, and a management device, and the authentication interaction method includes: After receiving a registration request from any terminal device, the user identity information of the corresponding user and the first user device information of the terminal device are extracted, and an application is sent to the quantum random number beacon based on the login device information of the network login device. The quantum random number beacon is used to continuously generate the first quantum random number block and the second quantum random number block when the application is received. All quantum random number blocks include login device information, quantum random number, timestamp and hash value of the previous quantum random number block. The system receives the first quantum random number block and the second quantum random number block, sends all quantum random number blocks, the first user equipment information, and the user identity information to the management device, and the management device obtains the registration authentication result based on the received information, feeds back the registration authentication result to the network login device, and associates the first user equipment information, the first quantum random number block, and the user identity information to construct the user's user profile, and stores the second quantum random number block in the verification database. Upon receiving the registration and authentication result, the system feeds back the preset login key to the terminal device, calculates the first response information based on the first quantum random number block and the first user device information, and stores the first response information in the response database. The registration and authentication results obtained based on the received information include: Check whether the user's identity information is valid; Detect whether the difference between the timestamp in the first quantum random number block and the current time is within a preset range; Detect whether the login device information in the first quantum random number block belongs to the network login device; Detect whether the comparison result between the first quantum random number block and the second quantum random number block meets the preset conditions; If the user identity information is detected to be valid, the difference is detected to be within a preset range, the login device information in the first quantum random number block is detected to belong to any network login device in the local area network, and the comparison result between the first quantum random number block and the second quantum random number block is detected to meet the preset conditions, then a registration authentication result is generated. Detecting whether the comparison result between the first quantum random number block and the second quantum random number block meets the preset conditions includes: Calculate the first hash value of the first quantum random number block, compare the first hash value with the hash value in the second quantum random number block, if the two hash values ​​are the same, compare whether the login device information in the first quantum random number block and the second quantum random number block are the same, and whether the timestamp difference is less than the time threshold; If the login device information in the first quantum random number block and the second quantum random number block are the same, and the timestamp difference is less than the time threshold, then it is determined that the comparison result between the first quantum random number block and the second quantum random number block meets the preset conditions.

2. The authentication interaction method according to claim 1, characterized in that, The authentication interaction method further includes: After receiving an update request from any terminal device, the management device sends the second user device information of the corresponding terminal device to the management device. The management device is used to perform a retrieval based on the second user device information and, upon successful retrieval, sends a successful retrieval result back to the network login device. Upon receiving the successful retrieval result, an application is sent to the quantum random number beacon, and the first and second update random number blocks are received from the quantum random number beacon. The first and second update random number blocks are sent to the management device, and update response information is calculated based on the first update random number block and the second user equipment information. The update response information is then used to update the response information in the response database.

3. The authentication interaction method according to claim 1, characterized in that, The authentication interaction method further includes: After obtaining the login password sent by any user using a terminal device, the login password is verified, and after successful verification, the third user device information of the corresponding terminal device is sent to the management device. The management device is used to determine a target random number block based on the third user device information and to feed back the second response information calculated based on the third user device information and the target random number block to the network login device. The system receives the target random number block and the second response information, detects whether the login device information in the target random number block belongs to any network login device in the local area network, and if it detects that the login device information in the target random number block belongs to any network login device in the local area network, it searches the response database for whether there is a response information that matches the second response information, and when a corresponding response information is found, it sends a successful login verification to the terminal device.

4. A method for authentication and interaction based on quantum random numbers, characterized in that, The authentication interaction method is applied to a management device, the management device being connected to the network login device as described in any one of claims 1 to 3, and the authentication interaction method includes: Receive all quantum random number blocks, the first user equipment information, and the user identity information; Based on all quantum random number blocks, the first user device information, and the user identity information, the registration authentication result is obtained, and the registration authentication result is fed back to the network login device; The user profile of the user is constructed by associating the first user equipment information, the first quantum random number block and the user identity information. The second quantum random number block is stored in the verification library.

5. The authentication interaction method according to claim 4, characterized in that, The authentication interaction method further includes: After receiving the second user equipment information, all user files are searched according to the second user equipment information. If the first target file corresponding to the second user equipment information is found, the search is determined to be successful, and the search success result is fed back to the network login device. The second user equipment information is the device information of the corresponding terminal device sent by the network login device based on the update request sent by any terminal device. The system receives a first update random number block and a second update random number block sent by the network login device, updates the first target file according to the first update random number block, and updates the verification database according to the second update random number block.

6. The authentication interaction method according to claim 4, characterized in that, The authentication interaction method further includes: After receiving the third user equipment information, the second target file corresponding to the third user equipment information is determined from all user files, and the quantum random number block in the second target file is determined as the target random number block. The third user equipment information is the login password sent by the network login device based on the terminal device used by any user, and the device information of the corresponding terminal device sent when the login password is verified. Calculate the target hash value of the target random number block. If a corresponding quantum random number block is found in the verification database based on the target hash value, calculate the second response information based on the target random number block and the third user equipment information, and send the target random number block and the second response information to the network login device.

7. A network login device, characterized in that, The network login device is any network login device in a local area network. The network login device connects to at least one terminal device for user use, a quantum random number beacon, and a management device. The network login device includes: The beacon application module is used to extract the user identity information of the corresponding user and the first user device information of the terminal device after receiving a registration request sent by any terminal device, and send an application to the quantum random number beacon based on the login device information of the network login device. The quantum random number beacon is used to continuously generate a first quantum random number block and a second quantum random number block when receiving the application. All quantum random number blocks include login device information, quantum random number, timestamp and hash value of the previous quantum random number block. The first sending module is used to receive the first quantum random number block and the second quantum random number block, send all quantum random number blocks, the first user equipment information and the user identity information to the management device, and the management device is used to obtain the registration authentication result based on the received information, feed back the registration authentication result to the network login device, associate the first user equipment information, the first quantum random number block and the user identity information to construct the user's user profile, and store the second quantum random number block in the verification database. The registration feedback module is used to receive the registration authentication result, feed back the preset login key to the terminal device, calculate the first response information based on the first quantum random number block and the first user device information, and store the first response information in the response database. The registration and authentication results obtained based on the received information include: Check whether the user's identity information is valid; Detect whether the difference between the timestamp in the first quantum random number block and the current time is within a preset range; Detect whether the login device information in the first quantum random number block belongs to the network login device; Detect whether the comparison result between the first quantum random number block and the second quantum random number block meets the preset conditions; If the user identity information is detected to be valid, the difference is detected to be within a preset range, the login device information in the first quantum random number block is detected to belong to any network login device in the local area network, and the comparison result between the first quantum random number block and the second quantum random number block is detected to meet the preset conditions, then a registration authentication result is generated. Detecting whether the comparison result between the first quantum random number block and the second quantum random number block meets the preset conditions includes: Calculate the first hash value of the first quantum random number block, compare the first hash value with the hash value in the second quantum random number block, if the two hash values ​​are the same, compare whether the login device information in the first quantum random number block and the second quantum random number block are the same, and whether the timestamp difference is less than the time threshold; If the login device information in the first quantum random number block and the second quantum random number block are the same, and the timestamp difference is less than the time threshold, then it is determined that the comparison result between the first quantum random number block and the second quantum random number block meets the preset conditions.

8. A management device, characterized in that, The management device is connected to the network login device as described in claim 7, and the management device includes: The first receiving module is used to receive all quantum random number blocks, the first user equipment information, and the user identity information; The registration and authentication module is used to obtain the registration and authentication result based on all quantum random number blocks, the first user device information and the user identity information, and to feed back the registration and authentication result to the network login device; The profile building module is used to associate the first user device information, the first quantum random number block and the user identity information to build the user profile of the user; The information storage module is used to store the second quantum random number block into the verification database.

Citation Information

Patent Citations

  • Identity authentication method, apparatus and system

    CN108809633A

  • Trusted computing system based on quantum technology

    CN113449343A