A key update method and device for an external service
By automatically updating keys using quantum key distribution technology, the problem of low key update efficiency in external business is solved, and efficient and secure key management is achieved.
Patent Information
- Application Number
- CN202410695542.9
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2024-05-31
- Publication Date
- 2026-01-20
- Estimated Expiration
- 2044-05-31
AI Technical Summary
In existing external connection services, the key update process requires manual intervention, resulting in low key update efficiency.
Quantum key distribution technology is used to negotiate and generate quantum key pairs with external devices through quantum key distribution equipment, and the keys are automatically updated by XOR operation using key components, reducing human intervention.
Automatic key updates are implemented, improving update efficiency, reducing the risk of key cracking and leakage, and enhancing system security and stability.
Smart Images

Figure CN118449689B_ABST
Abstract
Description
TECHNICAL FIELD
[0001] The present application relates to the field of information security, in particular to a key updating method and device for external connection business. BACKGROUND
[0002] At present, there are a large number of businesses of financial institutions that need to rely on the cooperation of third-party institutions to complete. In order to meet the needs of business confidentiality, the key distribution needs to be performed across institutions for external connection business, and the business information is encrypted by the distributed key.
[0003] The existing external connection institutions all adopt a star network mode, each bank institution is interconnected with a central end payment institution, and each node is deployed with an encryption machine for data encryption and decryption. The key used for encryption and decryption is periodically imported into the encryption machine by manual distribution. For example, the payment institution prepares a password envelope for key update, which is delivered to the commercial bank by a dedicated person; the commercial bank and the payment institution respectively import the password envelope components into the encryption machine to generate a new key by a dedicated person; after the import is completed at the commercial bank and the payment institution, the key verification function is initiated through the business key management system. After the verification is completed, the key table is updated, and the new key is used as the data encryption key for data encryption and decryption. Since manual intervention is required in the key update process, the efficiency of key update is reduced. SUMMARY
[0004] In view of the problems in the prior art, the embodiments of the present application provide a key updating method and device for external connection business, which can at least partially solve the problems in the prior art.
[0005] In a first aspect, the present application provides a key updating method for external connection business, comprising:
[0006] sending a key update request to a local quantum key distribution device, the key update request being triggered based on a key update time strategy of a business system;
[0007] receiving a quantum key pair returned by the local quantum key distribution device, the quantum key pair being obtained by the local quantum key distribution device and an external quantum key distribution device after quantum key pair negotiation;
[0008] obtaining a new key according to the quantum key pair and a key component, wherein the key component is preset.
[0009] Further, the obtaining of the new key according to the quantum key pair and the key component comprises:
[0010] reconstructing the quantum key pair according to the key component to obtain the new key.
[0011] Further, the key reconstruction of the quantum key pair according to the key component comprises:
[0012] XOR operation is performed on the quantum key pair and the key component.
[0013] Further, the number of bits of the key component is greater than or equal to 128 bits.
[0014] Further, before sending the key update request to the local quantum key distribution device, the key update method for the external connection service provided by the embodiment further comprises:
[0015] A secure channel is established with the local quantum key distribution device through a security protocol.
[0016] Further, the obtaining of the new key according to the quantum key pair and the key component comprises:
[0017] Key reconstruction is performed on the quantum key pair according to the key component to generate an intermediate key;
[0018] If the intermediate key passes the verification, the intermediate key is taken as the new key.
[0019] Further, the key update method for the external connection service provided by the embodiment further comprises:
[0020] The new key is pushed to the local service server.
[0021] In a second aspect, the present application provides a key update device for an external connection service, comprising:
[0022] A sending module is configured to send a key update request to a local quantum key distribution device, wherein the key update request is triggered based on a key update time strategy of a service system;
[0023] A receiving module is configured to receive a quantum key pair returned by the local quantum key distribution device, wherein the quantum key pair is obtained by the local quantum key distribution device after quantum key pair negotiation with an external quantum key distribution device;
[0024] An obtaining module is configured to obtain a new key according to the quantum key pair and a key component, wherein the key component is preset.
[0025] In a third aspect, the present application provides a computer device, comprising a memory, a processor and a computer program stored in the memory, wherein the processor executes the program to implement the key update method for the external connection service according to any one of the above embodiments.
[0026] In a fourth aspect, the present application provides a computer readable storage medium storing computer programs / instructions, which, when executed by a processor, implement the key updating method for external connection services according to any one of the above embodiments.
[0027] In a fifth aspect, the present application provides a computer program product comprising computer programs / instructions, which, when executed by a processor, implement the key updating method for external connection services according to any one of the above embodiments.
[0028] The key updating method for external connection services provided by the embodiments of the present application can send a key updating request to a local quantum key distribution device, the key updating request being triggered based on a key updating time policy of a service system; receive a quantum key pair returned by the local quantum key distribution device, the quantum key pair being obtained by the local quantum key distribution device and an external quantum key distribution device after quantum key pair negotiation; and obtain a new key according to the quantum key pair and a key component, thereby realizing automatic updating of the key, reducing manual participation, and improving the updating efficiency of the key. BRIEF DESCRIPTION OF DRAWINGS
[0029] In order to more clearly illustrate the technical solutions in the embodiments of the present application or the prior art, the following will briefly introduce the drawings needed to be used in the embodiments or prior art description. Obviously, the drawings in the following description are only some embodiments of the present application, and for those skilled in the art, other drawings can also be obtained from these drawings without creative labor. In the drawings:
[0030] Figure 1 is a structural schematic diagram of the key updating system for external connection services provided by the first embodiment of the present application.
[0031] Figure 2 is a flow schematic diagram of the key updating method for external connection services provided by the second embodiment of the present application.
[0032] Figure 3 is a flow schematic diagram of the key updating method for external connection services provided by the third embodiment of the present application.
[0033] Figure 4 is a flow interaction diagram of the key updating method for external connection services provided by the fourth embodiment of the present application.
[0034] Figure 5 is a structural schematic diagram of the key updating device for external connection services provided by the fifth embodiment of the present application.
[0035] Figure 6 is a structural schematic diagram of the key updating device for external connection services provided by the sixth embodiment of the present application.
[0036] Figure 7 is a structural schematic diagram of a key updating device for external connection business provided by a seventh embodiment of the application.
[0037] Figure 8 is a structural schematic diagram of a key updating device for external connection business provided by an eighth embodiment of the application.
[0038] Figure 9 is a structural schematic diagram of an electronic device provided by a ninth embodiment of the application. DETAILED DESCRIPTION
[0039] To make the objects, technical solutions, and advantages of the embodiments of the application clearer, further detailed descriptions of the embodiments of the application are given below with reference to the drawings. Here, the illustrative embodiments of the application and their descriptions are used to explain the application but are not used as limitations of the application. It should be noted that the embodiments in the present application and the features in the embodiments can be combined with each other at will without conflicts.
[0040] The information collected in the technical solutions in the present application is information and data authorized by users or authorized by all parties, and the collection, storage, use, processing, transmission, provision, disclosure, and application of the relevant data all comply with relevant laws, regulations, and standards of countries and regions, necessary security measures are taken, public order and good customs are not violated, and corresponding operation portals are provided for users to choose authorization or refusal.
[0041] Corresponding operation portals are provided for users to choose to agree or refuse the automatic decision result; if the user chooses to refuse, the expert decision process is entered.
[0042] To facilitate understanding of the technical solutions provided by the present application, the related content of the technical solutions of the present application is described first.
[0043] External connection business generally refers to relevant business activities of contact, communication, and cooperation between enterprises or organizations and external units, institutions, partners, etc. For a bank, external connection business includes but is not limited to transfer business, agency business, foreign exchange business, etc.
[0044] Figure 1 is a structural schematic diagram of a key updating system for external connection business provided by a first embodiment of the application, as shown in Figure 1 The key updating system for external connection business provided by the embodiments of the application includes a plurality of financial cipher machines 1 and a plurality of quantum key distribution devices 2, wherein:
[0045] Each quantum key distribution device 2 corresponds to at least one financial cipher machine 1;
[0046] The quantum key distribution devices 2 are connected in communication through a quantum key distribution network.
[0047] Specifically, each quantum key distribution device 2 corresponds to a financial institution. Each quantum key distribution device 2 can access the quantum key distribution network through bare optical fiber. Each quantum key distribution device 2 corresponds to at least one financial cryptographic machine 1. Each quantum key distribution device 2 is communicatively connected to the corresponding financial cryptographic machine 1 through a secure protocol. The financial cryptographic machine 1 can be communicatively connected to a business server of a business system. The financial institution includes but is not limited to commercial banks, payment institutions, etc.
[0048] The key update system for external connection services provided by the embodiment of the application can enable the financial cryptographic machine to obtain the key for encrypting data through the sub-key distribution device according to the demand of the business system, and automatically realize the key update of the external connection services through the quantum key distribution network, thereby replacing the existing manual symmetric key distribution mode and improving the efficiency of the key update of the external connection services.
[0049] The following will take the financial cryptographic machine as an example to describe the specific implementation process of the key update method for external connection services provided by the embodiment of the application. It can be understood that the execution subject of the key update method for external connection services provided by the embodiment of the application is not limited to the financial cryptographic machine.
[0050] Figure 2 is the flowchart of the key update method for external connection services provided by the second embodiment of the application, as shown in Figure 2 The key update method for external connection services provided by the embodiment of the application comprises the following steps.
[0051] S201, sending a key update request to a local quantum key distribution device, the key update request being triggered based on a key update time strategy of a business system;
[0052] Specifically, the financial cryptographic machine sends a key update request to the local quantum key distribution device, and the key update request is used to trigger the update of the key of the external connection services of the business system of the key. The key update request is triggered based on the key update time strategy of the business system. The key update time strategy of the business system is preset, and is set according to actual needs, which is not limited by the embodiment of the application.
[0053] For example, the key update time strategy of the business system a is that the key is updated every 6 hours. The business server corresponding to the business system a will send a key update application to the financial cryptographic machine every 6 hours. After receiving the key update application, the financial cryptographic machine will send a key update request to the local quantum key distribution device.
[0054] S202, receiving a quantum key pair returned by the local quantum key distribution device, the quantum key pair being obtained after quantum key pair negotiation between the local quantum key distribution device and an external quantum key distribution device;
[0055] Specifically, after receiving the key update request, the local quantum key distribution device negotiates a quantum key with an external quantum key distribution device, and generates a quantum key pair after successful negotiation, i.e., a quantum key pair. The local quantum key distribution device sends the quantum key pair to the financial password machine. The specific process of quantum key negotiation is a prior art, which is not described here.
[0056] It can be understood that the financial institution to which the external quantum key distribution device belongs has an external connection business with the financial institution to which the local quantum key distribution device belongs.
[0057] S203, obtaining a new key according to the quantum key pair and a key component, wherein the key component is preset.
[0058] Specifically, after the financial password machine receives the quantum key pair, it can generate a new key according to the quantum key pair and a key component. The key type is preset, and is set according to actual needs, which is not limited by the embodiment of the application. In order to improve the reliability of the generated key, the key component can be updated regularly. The key generation algorithm is selected according to actual needs, which is not limited by the embodiment of the application.
[0059] The key update method for external connection business provided by the embodiment of the application can send a key update request to the local quantum key distribution device, the key update request being triggered based on a key update time strategy of a business system; receive a quantum key pair returned by the local quantum key distribution device, the quantum key pair being obtained after quantum key pair negotiation between the local quantum key distribution device and an external quantum key distribution device; and obtain a new key according to the quantum key pair and a key component, thereby realizing automatic updating of the key, reducing manual participation, and improving the updating efficiency of the key. In addition, the obtained quantum key pair is processed twice, thereby improving the reliability of the key.
[0060] On the basis of the above embodiments, further, obtaining a new key according to the quantum key pair and a key component includes:
[0061] Reconstructing the quantum key pair according to the key component to obtain the new key.
[0062] Specifically, the financial password machine reconstructs the quantum key pair according to the key component, and takes the reconstructed key as the new key. Since the quantum key pair is obtained by negotiation with an external quantum key distribution device, there is a risk of being cracked and leaked in theory. By reconstructing the quantum key pair according to the key component, the risk of cracking the new key is reduced, and since the key reconstruction is performed locally, the risk of key leakage is also reduced.
[0063] On the basis of the above embodiments, further, the key reconstruction of the quantum key pair according to the key component comprises:
[0064] XOR operation is performed on the quantum key pair and the key component.
[0065] Specifically, the financial password machine can perform XOR operation on the quantum key pair and the key component to complete the key reconstruction. By performing key reconstruction through XOR algorithm, the implementation is easy and the calculation speed is fast.
[0066] On the basis of the above embodiments, further, the number of bits of the key component is greater than or equal to 128 bits. The higher the number of bits of the key, the higher the security of encryption, which improves the difficulty of key cracking.
[0067] On the basis of the above embodiments, further, before sending a key update request to the local quantum key distribution device, the method further comprises:
[0068] A secure channel is established with the local quantum key distribution device through a security protocol.
[0069] Specifically, the financial password machine can establish a secure channel with the local quantum key distribution device through a security protocol, improve the security of communication between the financial password machine and the local quantum key distribution device, and further ensure the security of the quantum key pair sent by the local quantum key distribution device to the financial password machine. The security protocol is selected according to actual needs, which is not limited by the embodiments of the present application.
[0070] Figure 3 is a flowchart of the key update method of the external connection service provided by the third embodiment of the present application, as shown in Figure 3 On the basis of the above embodiments, further, the new key is obtained according to the quantum key pair and the key component, comprising:
[0071] S301, reconstructing the quantum key pair according to the key component to generate an intermediate key;
[0072] Specifically, the financial cryptomachine can perform key reconstruction on the quantum key pair according to the key component, and take the reconstructed key as an intermediate key.
[0073] S302, if the intermediate key passes the verification, the intermediate key is taken as the new key.
[0074] Specifically, after obtaining the intermediate key, the financial cryptomachine performs verification on the intermediate key, and after the intermediate key passes the verification, the intermediate key is taken as the new key.
[0075] For example, the financial cryptomachine can generate a first verification code (HMAC) according to the new key, and then send the verification code to the local quantum key distribution device. The local quantum key distribution device encrypts the verification code through the agreed symmetric key to obtain first verification data, and then sends the first verification data to the quantum key distribution network. At the same time, the external quantum key distribution device also receives the second verification code generated by the corresponding financial cryptomachine based on the new key, and then encrypts the verification code through the agreed symmetric key to obtain second verification data, and sends the second verification data to the quantum key distribution network. The verification device in the quantum key distribution network can verify the first verification data and the second verification data. If the first verification data and the second verification data match, the verification passes. The local quantum key distribution device and the external quantum key distribution device are sent verification pass information.
[0076] On the basis of the above-mentioned embodiments, further, the key update method for external connection service provided by the embodiments of the present application further comprises:
[0077] Push the new key to the local service server.
[0078] Specifically, after obtaining the new key, the financial cryptomachine sends the new key to the local service server. The local service server can encrypt service data through the new key.
[0079] The specific implementation process of the key update method for external connection service provided by the embodiments of the present application will be described below taking the key update process of external connection service c between payment institution A and commercial bank B as an example.
[0080] A payment institution is deployed with a first business system, a first financial cryptographic machine (hereinafter referred to as HSM1) and a first quantum key distribution device (hereinafter referred to as QKD1); a commercial bank B is deployed with a second business system, a second financial cryptographic machine (hereinafter referred to as HSM2) and a second quantum key distribution device (hereinafter referred to as QKD2). QKD1 and QKD2 are connected to a quantum key distribution network (hereinafter referred to as QKDN) through bare optical fibers. The first financial cryptographic machine and the first quantum key distribution device establish a secure channel through a security protocol to realize quantum key import of the financial cryptographic machine. The second financial cryptographic machine and the second quantum key distribution device establish a secure channel through a security protocol to realize secure import of the quantum key of the financial cryptographic machine. Through the modification of the financial cryptographic machine and the business system, the financial cryptographic machine can actively call the output interface of the quantum key according to the demand of the business system to obtain the quantum key for data encryption, so as to replace the existing manual distribution of symmetric key through the quantum key distribution network.
[0081] QKD1 and QKD2 are connected to QKDN and obtain a unique device ID of the whole network, such as the device ID of QKD1 being 420100001 and the device ID of QKD2 being 420100002. The first business system and the second business system can initiate quantum key application of any two nodes through the device identification; QKD1 can identify different financial cryptographic machines through APP-ID, such as APP1 corresponding to HSM1; QKD2 can identify different financial cryptographic machines through APP-ID, such as APP2 corresponding to HSM2.
[0082] As shown in Figure 4 , the c key update method of the external connection business between the payment institution A and the commercial bank B is as follows.
[0083] First step, inter-institution quantum key application. The server of the first business system sends a key update application to HSM1 to initiate an inter-institution quantum key application. The key update application can carry the business identification of the external connection business c.
[0084] Second step, send key update request. After receiving the key update application, HSM1 sends a key update request to QKD1, which can include the business identification of the external connection business c and APP1.
[0085] Third step, initiate quantum key agreement. QKD1 and QKD2 will conduct quantum key pair negotiation to obtain a quantum key pair k12.
[0086] Fourth step, send quantum key pair. QKD1 sends the quantum key pair k12 to HSM1, and QKD2 sends the quantum key pair k12 to HSM2.
[0087] The fifth step is to perform key reconstruction. The HSM1 performs key reconstruction on the quantum key pair k12 according to the key component k1 to obtain a new key k a . The HSM2 performs key reconstruction on the quantum key pair k12 according to the key component k2 to obtain a new key k b .
[0088] The sixth step is to push the new key. After obtaining k a , the HSM1 pushes to the server of the first business system. After obtaining k b , the HSM2 pushes k b to the server of the second business system. Thus, the key update of the external connection business is completed.
[0089] By modifying the encryption machine and the business system, the quantum key distribution technology is used to replace the manual distribution of the symmetric key of the financial external connection business, which greatly reduces the personnel maintenance cost. The quantum key distribution technology and the quantum network are used to solve the symmetric key distribution problem of the financial external connection business across institutions, which can improve the update frequency of the key, reduce the risk of business system interruption, improve the security of the system, and improve the stability of the business system.
[0090] Figure 5 is a structural schematic diagram of the key update device for the external connection business provided by the fifth embodiment of the present application, as shown in Figure 5 , the key update device for the external connection business provided by the embodiment of the present application comprises a sending module 501, a receiving module 502 and an obtaining module 503, wherein:
[0091] The sending module 501 is configured to send a key update request to a local quantum key distribution device, and the key update request is triggered based on a key update time strategy of a business system; the receiving module 502 is configured to receive a quantum key pair returned by the local quantum key distribution device, and the quantum key pair is obtained by the local quantum key distribution device and an external quantum key distribution device after quantum key pair negotiation; and the obtaining module 503 is configured to obtain a new key according to the quantum key pair and a key component, wherein the key component is preset.
[0092] Specifically, the sending module 501 sends a key update request to a local quantum key distribution device, and the key update request is used to trigger the update of the key of the external connection business of the business system. The key update request is triggered based on a key update time strategy of a business system, and the key update time strategy of the business system is preset and set according to actual needs, which is not limited in the embodiment of the present application.
[0093] The local quantum key distribution device, after receiving the key update request, performs quantum key negotiation with an external quantum key distribution device, and generates a pair of quantum keys, i.e., a quantum key pair, in the local quantum key distribution device and the external quantum key distribution device after the negotiation is successful. The local quantum key distribution device sends the quantum key pair to the receiving module 502.
[0094] After the obtaining module 503 receives the quantum key pair, a new key can be generated according to the quantum key pair and the key component. In this case, the key classification is preset, and is set according to actual needs, which is not limited in the embodiment of the application. In order to improve the reliability of the generated key, the key component can be updated regularly. The key generation algorithm is selected according to actual needs, which is not limited in the embodiment of the application.
[0095] The key update device for external connection services provided in the embodiment of the application can send a key update request to a local quantum key distribution device, the key update request is triggered based on a key update time policy of a service system; receive a quantum key pair returned by the local quantum key distribution device, the quantum key pair is obtained after the local quantum key distribution device performs quantum key negotiation with an external quantum key distribution device; and obtain a new key according to the quantum key pair and a key component, so that the automatic update of the key is realized, the manual participation is reduced, and the update efficiency of the key is improved. In addition, the obtained quantum key pair is processed twice, and the reliability of the key is improved.
[0096] On the basis of the above-mentioned embodiments, further, the obtaining module 503 is specifically used for:
[0097] Performing key reconstruction on the quantum key pair according to the key component to obtain the new key.
[0098] On the basis of the above-mentioned embodiments, further, the obtaining module 503 is specifically used for:
[0099] Performing exclusive or operation on the quantum key pair and the key component.
[0100] On the basis of the above-mentioned embodiments, further, the number of bits of the key component is greater than or equal to 128 bits.
[0101] Figure 6 is a structural schematic diagram of the key update device for external connection services provided in the sixth embodiment of the application, as Figure 6 shown, on the basis of the above-mentioned embodiments, further, the key update device for external connection services provided in the embodiment of the application further includes an establishing module 504, wherein:
[0102] The establishing module 504 is configured to establish a secure channel with the local quantum key distribution device through a secure protocol.
[0103] Figure 7 is a structure diagram of the key updating device for external service provided by the seventh embodiment of the present application, as Figure 7 shown, on the basis of the above embodiments, further, the obtaining module 503 includes a generating unit 5031 and a checking unit 5032, wherein:
[0104] The generating unit 5031 is configured to perform key reconstruction on the quantum key pair according to the key components to generate an intermediate key; and the checking unit 5032 is configured to, if the intermediate key passes the check, take the intermediate key as the new key.
[0105] Figure 8 is a structure diagram of the key updating device for external service provided by the eighth embodiment of the present application, as Figure 8 shown, on the basis of the above embodiments, further, the key updating device for external service provided by the embodiments of the present application further includes a pushing module 505, wherein:
[0106] The pushing module 505 is configured to push the new key to the local service server.
[0107] The embodiments of the device provided by the embodiments of the present application can be specifically used to execute the processing procedures of the above-mentioned method embodiments, and the functions thereof will not be repeated here, and the detailed description can be referred to the above-mentioned method embodiments.
[0108] It should be noted that the key updating method and device for external service provided by the embodiments of the present application can be used in the financial field, and can also be used in any technical field other than the financial field, and the application field of the key updating method and device for external service provided by the embodiments of the present application is not limited.
[0109] Figure 9 is a structure diagram of the electronic device provided by the ninth embodiment of the present application, as Figure 9As shown, the electronic device can include a processor 901, a communications interface 902, a memory 903, and a communications bus 904, wherein the processor 901, the communications interface 902, and the memory 903 complete mutual communication through the communications bus 904. The processor 901 can invoke a logical instruction in the memory 903 to execute the following method: sending a key update request to a local quantum key distribution device, the key update request being triggered based on a key update time policy of a business system; receiving a quantum key pair returned by the local quantum key distribution device, the quantum key pair being obtained after the local quantum key distribution device and an external quantum key distribution device perform quantum key pair negotiation; obtaining a new key according to the quantum key pair and a key component, wherein the key component is preset.
[0110] In addition, the logical instruction in the memory 903 described above can be implemented in the form of a software functional unit and sold or used as an independent product, and can be stored in a computer readable storage medium. Based on such understanding, the technical solutions of the present application essentially or the part that contributes to the prior art or part of the technical solutions can be embodied in the form of a software product. The computer software product is stored in a storage medium, includes several instructions to make a computer device (which can be a personal computer, a server, or a network device, etc.) execute all or part of the steps of the methods described in various embodiments of the present application. The foregoing storage medium includes: a U disk, a mobile hard disk, a read-only memory (ROM, Read-Only Memory), a random access memory (RAM, Random Access Memory), a magnetic disk or an optical disk, and various media that can store program codes.
[0111] The embodiment discloses a computer program product, which comprises a computer program stored on a computer readable storage medium, and the computer program comprises program instructions. When the program instructions are executed by a computer, the computer can execute the method provided by the above-mentioned method embodiments, for example, comprising: sending a key update request to a local quantum key distribution device, the key update request being triggered based on a key update time policy of a business system; receiving a quantum key pair returned by the local quantum key distribution device, the quantum key pair being obtained after the local quantum key distribution device and an external quantum key distribution device perform quantum key pair negotiation; obtaining a new key according to the quantum key pair and a key component, wherein the key component is preset.
[0112] The embodiment of the present application provides a computer readable storage medium, the computer readable storage medium stores a computer program, the computer program causes the computer to execute the method provided by each method embodiment, for example, comprising: sending a key update request to a local quantum key distribution device, the key update request is triggered based on a key update time strategy of a business system; receiving a quantum key pair returned by the local quantum key distribution device, the quantum key pair is obtained through quantum key pair negotiation between the local quantum key distribution device and an external quantum key distribution device; obtaining a new key according to the quantum key pair and a key component; wherein the key component is preset.
[0113] Those skilled in the art should understand that the embodiments of the present application can be provided as a method, a system, or a computer program product. Therefore, the present application can take the form of an entirely hardware embodiment, an entirely software embodiment, or an embodiment combining software and hardware aspects. Moreover, the present application can take the form of a computer program product implemented on one or more computer-usable storage media (including, but not limited to, disk storage, CD-ROMs, optical storage, etc.) containing computer-usable program code.
[0114] The present application is described with reference to flowcharts and / or block diagrams of the method, device (system), and computer program product according to the embodiments of the present application. It should be understood that each flow and / or block in the flowcharts and / or block diagrams, and the combination of flows and / or blocks in the flowcharts and / or block diagrams can be implemented by computer program instructions. These computer program instructions can be provided to a processor of a general-purpose computer, a special-purpose computer, an embedded processor, or other programmable data processing apparatus to produce a machine, so that the instructions executed by the processor of the computer or other programmable data processing apparatus generate a means for implementing the functions specified in the flowcharts and / or block diagrams. Figure 1 The functions specified in one or more flows and / or blocks. Figure 1 The means for implementing the functions specified in one or more flows and / or blocks.
[0115] These computer program instructions can also be stored in a computer readable storage medium capable of guiding a computer or other programmable data processing apparatus to work in a specific manner, so that the instructions stored in the computer readable storage medium produce a product including instruction means, which implements the functions specified in the flowcharts and / or block diagrams. Figure 1 The functions specified in one or more flows and / or blocks. Figure 1 The means for implementing the functions specified in one or more flows and / or blocks.
[0116] These computer program instructions can also be loaded into a computer or other programmable data processing apparatus, so that a series of operation steps are executed on the computer or other programmable data processing apparatus to produce a computer-implemented process, so that the instructions executed on the computer or other programmable data processing apparatus provide a means for implementing the functions specified in the flowcharts and / or block diagrams. Figure 1one or more processes and / or blocks Figure 1 the steps of the functions specified in the one or more blocks.
[0117] In the description of the present specification, the description of the terms "one embodiment", "one specific embodiment", "some embodiments", "for example", "exemplary", "specific example", or "some examples" etc. means that the specific features, structures, materials or characteristics described in connection with the embodiment or example are included in at least one embodiment or example of the present application. In the present specification, the illustrative expressions of the above terms do not necessarily refer to the same embodiment or example. Moreover, the specific features, structures, materials or characteristics described can be combined in any appropriate manner in one or more embodiments or examples.
[0118] The specific embodiments described above further illustrate the objects, technical solutions and advantages of the present application. It should be understood that the above description is only a specific embodiment of the present application and is not intended to limit the protection scope of the present application. Any modification, equivalent replacement, improvement, etc. made within the spirit and principle of the present application should be included in the protection scope of the present application.
Claims
1. A key update method for external connection services, characterized in that, include: Send a key update request to the local quantum key distribution device, the key update request being triggered based on the key update time policy of the business system; Receive the quantum key pair returned by the local quantum key distribution device, wherein the quantum key pair is obtained by the local quantum key distribution device after quantum key pair negotiation with the external quantum key distribution device; A new key is obtained based on the quantum key pair and key components; wherein the key components are preset.
2. The method according to claim 1, characterized in that, The step of obtaining a new key based on the quantum key pair and key components includes: The quantum key pair is reconstructed based on the key components to obtain the new key.
3. The method according to claim 2, characterized in that, The step of reconstructing the quantum key pair based on the key components includes: Perform an XOR operation on the quantum key pair and the key components.
4. The method according to claim 1, characterized in that, The key component has a bit length greater than or equal to 128 bits.
5. The method according to claim 1, characterized in that, Before sending a key update request to the local quantum key distribution device, the following is also included: A secure channel is established with the local quantum key distribution device through a security protocol.
6. The method according to claim 1, characterized in that, The step of obtaining a new key based on the quantum key pair and key components includes: The quantum key pair is reconstructed based on the key components to generate an intermediate key; If the intermediate key passes the verification, then the intermediate key will be used as the new key.
7. The method according to any one of claims 1 to 6, characterized in that, Also includes: The new key is pushed to the local business server.
8. A key update device for external connection services, characterized in that, include: The sending module is used to send a key update request to the local quantum key distribution device. The key update request is triggered based on the key update time policy of the business system. The receiving module is used to receive the quantum key pair returned by the local quantum key distribution device, wherein the quantum key pair is obtained by the local quantum key distribution device and the external quantum key distribution device after quantum key pair negotiation; The acquisition module is used to obtain a new key based on the quantum key pair and the key components; wherein the key components are preset.
9. A computer device, comprising a memory, a processor, and a computer program stored in the memory, characterized in that, The processor executes the computer program to implement the steps of the method according to any one of claims 1 to 7.
10. A computer-readable storage medium, characterized in that, The computer-readable storage medium stores a computer program / instructions that, when executed by a processor, implement the steps of the method according to any one of claims 1 to 7.
11. A computer program product, comprising a computer program / instructions, characterized in that, When the computer program / instructions are executed by the processor, they implement the steps of the method according to any one of claims 1 to 7.
Citation Information
Patent Citations
Quantum key filling and updating method and quantum key distribution system
CN116015631A
Data center and encryption service system and encryption service method thereof
CN117728981A