A communication encryption method, apparatus, device, and storage medium
By obtaining the location zone code value of the terminal and optimizing the selection of quantum encrypted communication links, the problems of reliance on quantum key management centers and failure to consider fiber optic losses in existing technologies are solved, thus achieving efficient and secure quantum encrypted communication.
Patent Information
- Application Number
- CN202410643424.3
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2024-05-22
- Publication Date
- 2026-01-06
- Estimated Expiration
- 2044-05-22
AI Technical Summary
In existing quantum encrypted communication, reliance on a quantum key management center leads to high information exchange latency, and the selection of QKD nodes does not take fiber loss into account, resulting in low communication efficiency.
By obtaining the location zone code value of the terminal, it is determined whether to directly use the target quantum random number to encrypt communication within the same area, or to encrypt through the shortest communication link with the lowest fiber loss in different areas. By combining public key encryption and quantum random number generation, the link selection is optimized.
It improves the efficiency and security of quantum encrypted communication, reduces costs, and ensures the highest transmission speed and efficiency.
Smart Images

Figure CN118473774B_ABST
Abstract
Description
Technical Field
[0001] This application relates to the field of communication technology, and in particular to a communication encryption method, apparatus, device and storage medium. Background Technology
[0002] With the continuous development of quantum technology, quantum and anti-quantum technologies are being used more and more widely in operator networks. Operators have abundant network and data resources. As important infrastructure operators, they need to actively deploy quantum and post-quantum technologies, whether for their own network needs or for the output of external capabilities. Currently, the main directions or products of quantum technology are in quantum cryptography.
[0003] Quantum key generation includes quantum random number generators (QRNGs) and quantum key distribution (QKD). In related technologies, when the two parties needing quantum communication are in the same area, a QRNG combined with a key management center is used to inject quantum keys offline, enabling encrypted communication. When the two parties are in different areas, a QKD network is used for key distribution. However, QKD-based key generation involves multiple QKD nodes, and most methods select nodes based on the shortest distance. Both of these methods are inefficient. QRNG-based key generation relies on a key management center, increasing latency and reducing communication efficiency. QKD-based key generation only considers the shortest distance, resulting in an overly broad selection range and inefficient node selection. Therefore, improving the communication efficiency of quantum encrypted communication is a pressing technical problem that needs to be solved. Summary of the Invention
[0004] This application provides a communication encryption method, apparatus, device, and storage medium, which improves the communication efficiency of quantum-encrypted communication between a first terminal and a second terminal.
[0005] In a first aspect, this application provides a communication encryption method applied to a first terminal. The method includes: when the first terminal communicates with a second terminal, obtaining the location area code (LAC) value of the second terminal; when the LAC values of the first terminal and the second terminal indicate that the first terminal and the second terminal are in the same area, performing encrypted communication with the second terminal based on a target quantum random number; the target quantum random number is a quantum random number encrypted based on the public key corresponding to the second terminal; when the LAC values of the first terminal and the second terminal indicate that the first terminal and the second terminal are in different areas, performing encrypted communication with the second terminal through a target communication link; the target communication link is the communication link with the shortest distance and lowest fiber loss between the first terminal and the second terminal.
[0006] The communication encryption method provided in this application allows for encrypted communication between the first terminal and the second terminal when they are in the same area. The first terminal directly uses a target quantum random number to achieve encrypted communication, avoiding reliance on a quantum key management center and improving the communication efficiency of quantum encrypted communication. Furthermore, the first terminal can encrypt the quantum random number using the public key corresponding to the second terminal, and only the private key of the second terminal can decrypt it, ensuring the security of quantum communication. When the first terminal and the second terminal are in different areas, the first terminal can achieve quantum encrypted communication with the second terminal through a target communication link. This target communication link considers not only the transmission distance between the first and second terminals but also the fiber optic loss between them, making it the fastest and most efficient communication link for communication between the two terminals. This improves the communication efficiency of quantum encrypted communication and reduces costs.
[0007] One possible implementation involves encrypted communication with a second terminal via a target communication link, including: identifying multiple QKD nodes within a target area; the target area being a circular region with a diameter equal to the straight-line distance between the first and second terminals; identifying multiple communication links between the first and second terminals based on the multiple QKD nodes; identifying a target communication link among the multiple communication links; and communicating with the second terminal based on the target communication link.
[0008] Another possible implementation involves determining the target communication link among multiple communication links, including: determining the shortest distance algorithm complexity for each of the multiple communication links; determining the fiber loss and the number of QKD nodes for each of the multiple communication links; determining the average node fiber loss for each link based on the fiber loss and the number of QKD nodes for each link; and determining the communication link with the smallest product of the average node fiber loss and the shortest distance algorithm complexity among the multiple communication links as the target communication link.
[0009] Another possible implementation involves encrypted communication between the target quantum random number and the second terminal, including: generating a quantum random number using a QRNG chip; determining the public key corresponding to the second terminal; encrypting the quantum random number based on the public key corresponding to the second terminal to obtain the target quantum random number; and encrypting the communication process between the first terminal and the second terminal based on the target quantum random number.
[0010] Another possible implementation involves determining the public key corresponding to the second terminal, including: if the second terminal exists in the LAC friend list of the first terminal, querying the public key corresponding to the second terminal in the LAC friend list; the LAC friend list is used to store the public key corresponding to the second terminal and the second terminal that has communicated with the first terminal more than a preset threshold within a preset period; if the second terminal does not exist in the LAC friend list of the first terminal, generating the public key corresponding to the second terminal based on the postquantum cryptography (PQC) algorithm.
[0011] Another possible implementation method includes: constructing an LAC friend and family list; and periodically updating the LAC friend and family list based on the number of communications between the first terminal and the second terminal.
[0012] Secondly, this application provides a communication encryption device, which includes an acquisition module and a communication module.
[0013] The acquisition module is used to acquire the LAC value of the second terminal when the first terminal communicates with the second terminal; the communication module is used to perform encrypted communication with the second terminal based on a target quantum random number when the LAC values of the first terminal and the second terminal indicate that the first terminal and the second terminal are in the same area; the target quantum random number is a quantum random number encrypted based on the public key corresponding to the second terminal; the communication module is also used to perform encrypted communication with the second terminal through a target communication link when the LAC values of the first terminal and the second terminal indicate that the first terminal and the second terminal are in different areas; the target communication link is the communication link with the shortest distance and lowest fiber loss between the first terminal and the second terminal.
[0014] One possible implementation is that the communication module is specifically used to: determine multiple QKD nodes within a target area; the target area is a circular area with a diameter equal to the straight-line distance between the first terminal and the second terminal; determine multiple communication links between the first terminal and the second terminal based on the multiple QKD nodes; determine a target communication link among the multiple communication links; and communicate with the second terminal based on the target communication link.
[0015] Another possible implementation involves the communication module specifically used to: determine the shortest distance algorithm complexity for each of the multiple communication links; determine the fiber loss and the number of QKD nodes for each of the multiple communication links; determine the average node fiber loss for each link based on the fiber loss and the number of QKD nodes for each communication link; and determine the communication link with the smallest product of the average node fiber loss and the shortest distance algorithm complexity among the multiple communication links as the target communication link.
[0016] Another possible implementation involves the communication module specifically used to: call the QRNG chip to generate quantum random numbers; determine the public key corresponding to the second terminal; encrypt the quantum random numbers based on the public key corresponding to the second terminal to obtain the target quantum random number; and encrypt the communication process between the first terminal and the second terminal based on the target quantum random number.
[0017] Another possible implementation is that, if the second terminal exists in the LAC friend list of the first terminal, the communication module is specifically used to query the public key corresponding to the second terminal in the LAC friend list; the LAC friend list is used to store the public key corresponding to the second terminal and the second terminal that has communicated with the first terminal more than a preset threshold within a preset period; if the second terminal does not exist in the LAC friend list of the first terminal, the public key corresponding to the second terminal is generated based on the PQC algorithm.
[0018] Another possible implementation includes a construction module and an update module. The construction module is used to construct the LAC friend and family list. The update module is used to periodically update the LAC friend and family list based on the number of communications between the first terminal and the second terminal.
[0019] Thirdly, this application provides an electronic device comprising: a processor and a memory; the memory storing processor-executable instructions; when the processor is configured to execute the instructions, causing the electronic device to implement the method of the first aspect described above.
[0020] Fourthly, this application provides a computer-readable storage medium comprising: computer software instructions; which, when executed in an electronic device, cause the electronic device to implement the method described in the first aspect.
[0021] Fifthly, this application provides a computer program product that, when run on a computer, causes the computer to perform the steps of the relevant method described in the first aspect above, so as to implement the method of the first aspect above.
[0022] The beneficial effects of the second to fifth aspects mentioned above are described in the corresponding description of the first aspect and will not be repeated here. Attached Figure Description
[0023] Figure 1 This application provides a schematic diagram of the application environment for a communication encryption method.
[0024] Figure 2 A flowchart illustrating a communication encryption method provided in this application;
[0025] Figure 3 A flowchart illustrating another communication encryption method provided in this application;
[0026] Figure 4 A flowchart illustrating another communication encryption method provided in this application;
[0027] Figure 5 A schematic diagram of encrypted communication between a first terminal and a second terminal is provided in this application;
[0028] Figure 6 A flowchart illustrating another communication encryption method provided in this application;
[0029] Figure 7 A flowchart illustrating another communication encryption method provided in this application;
[0030] Figure 8 Another schematic diagram of encrypted communication between a first terminal and a second terminal provided in this application;
[0031] Figure 9 A flowchart illustrating another communication encryption method provided in this application;
[0032] Figure 10 Another schematic diagram of encrypted communication between a first terminal and a second terminal provided in this application;
[0033] Figure 11 A schematic diagram of the composition of a communication encryption device provided in this application;
[0034] Figure 12 This is a schematic diagram of the composition of an electronic device provided in this application. Detailed Implementation
[0035] The technical solutions of the embodiments of this application will be clearly and completely described below with reference to the accompanying drawings. Obviously, the described embodiments are only some embodiments of this application, and not all embodiments. Based on the embodiments of this application, all other embodiments obtained by those skilled in the art without creative effort are within the scope of protection of this application.
[0036] It should be noted that in the embodiments of this application, the words "exemplarily" or "for example" are used to indicate examples, illustrations, or explanations. Any embodiment or design scheme described as "exemplarily" or "for example" in the embodiments of this application should not be construed as being more preferred or advantageous than other embodiments or design schemes. Specifically, the use of the words "exemplarily" or "for example" is intended to present the relevant concepts in a specific manner.
[0037] To facilitate a clear description of the technical solutions of the embodiments of this application, the terms "first" and "second" are used in the embodiments of this application to distinguish the same or similar items with essentially the same function and effect. Those skilled in the art can understand that the terms "first" and "second" are not intended to limit the quantity or execution order.
[0038] With the continuous development of quantum technology, quantum communication is developing rapidly. In particular, the formation of the global landscape of post-quantum technology has accelerated the application of quantum and anti-quantum technologies in operator networks. Operators have abundant network and data resources. As important infrastructure operators, they need to actively deploy quantum and post-quantum technologies, both for their own network needs and for the output of external capabilities. At present, operators are actively deploying quantum technology, and the main technical or product directions are in quantum cryptography, mainly around the integration of QRNG and QKD, to achieve secure key distribution through the operator's network.
[0039] In the field of quantum communication, quantum key generation includes QRNG and QKD. QKD, due to its higher cost, is less flexible and less widely adopted than QRNG. However, in quantum key applications, operators typically combine both methods. When the two parties needing a quantum call are in the same area, QRNG is used, combined with a key management center, to perform offline quantum key injection, ultimately achieving encrypted communication. When the two parties needing a call are in different areas, a QKD network is used for key distribution. QKD-based key generation involves multiple QKD nodes, primarily employing a trusted relay-based quantum key distribution method, selecting nodes based on minimum distance. However, both methods have two main drawbacks: First, QRNG-based key generation relies excessively on a quantum key management center, increasing the risk of information leakage, as well as increasing latency and development costs, and reducing communication efficiency. Second, when generating keys based on the QKD method, only the shortest distance optimal method is considered without further refining the optimization range. This results in an excessively large optimal range selection, increasing the computational load. At the same time, the impact of fiber attenuation on the link is not considered, causing the QKD node selection to fail to reach the optimal link, thus affecting key negotiation and generation.
[0040] In summary, there is an urgent need for a method to improve the communication efficiency of quantum encrypted communication. Based on this, this application provides a communication encryption method. In this method, when the first terminal and the second terminal are in the same area, the first terminal directly achieves encrypted communication with the second terminal using a target quantum random number, avoiding reliance on a quantum key management center and improving the communication efficiency of quantum encrypted communication. Furthermore, the first terminal can encrypt the quantum random number using the public key corresponding to the second terminal, and only the private key of the second terminal can decrypt it, ensuring the security of quantum communication. When the first terminal and the second terminal are in different areas, the first terminal can achieve quantum encrypted communication with the second terminal through a target communication link. This target communication link considers not only the transmission distance between the first and second terminals but also the fiber optic loss between them, making the target communication link for communication between the first and second terminals not only the fastest but also the most efficient, thereby improving the communication efficiency of quantum encrypted communication and reducing costs.
[0041] The communication encryption method provided in this application can be applied to, for example... Figure 1 The application environment shown. For example... Figure 1 As shown, the application environment includes a first terminal 101 and a second terminal 102. The first terminal 101 and the second terminal 102 are interconnected.
[0042] In some embodiments, the first terminal 101 and the second terminal 102 can be devices with wireless transceiver capabilities, such as mobile phones, tablets, wearable devices, in-vehicle devices, augmented reality (AR) / virtual reality (VR) devices, laptops, ultra-mobile personal computers (UMPCs), netbooks, personal digital assistants (PDAs), etc. This application does not limit the specific device form of the first terminal 101 and the second terminal 102. Figure 1 The example shown uses the first terminal 101 and the second terminal 102 as mobile terminals.
[0043] In some embodiments, when the first terminal 101 communicates with the second terminal 102, the first terminal 101 can obtain the LAC value of the second terminal 102. Therefore, the first terminal 101 can determine whether the first terminal 101 and the second terminal 102 are in the same region based on their respective LAC values. If the first terminal 101 and the second terminal 102 are in the same region, the first terminal 101 performs encrypted communication with the second terminal 102 based on a target quantum random number. If the first terminal 101 and the second terminal 102 are in different regions, the first terminal 101 performs encrypted communication with the second terminal 102 based on the target quantum random number.
[0044] Figure 2 This is a flowchart illustrating a communication encryption method provided in an embodiment of this application. Figure 2 As shown, the communication encryption method provided in this application can be implemented through the aforementioned first terminal, and specifically includes the following steps:
[0045] S201. When the first terminal communicates with the second terminal, obtain the LAC value of the second terminal.
[0046] In some embodiments, when the first terminal communicates with the second terminal, the first terminal can obtain the LAC value of the second terminal so that the first terminal can determine whether the first terminal and the second terminal are in the same area based on its own LAC value and the LAC value of the second terminal.
[0047] For example, when the first terminal communicates with the second terminal, the second terminal can use its own LAC value as part of its routing information, and based on the routing information, determine the first terminal with which it is communicating through the core network. Thus, the first terminal can obtain the second terminal's LAC value from the core network.
[0048] It should be understood that when the first or second terminal moves to a new area during communication, its LAC value will change accordingly. The first terminal can reacquire and update the second terminal's LAC value and compare it with its own LAC value.
[0049] S202, when the LAC values of the first terminal and the second terminal indicate that the first terminal and the second terminal are in the same region, encrypted communication is performed with the second terminal based on the target quantum random number.
[0050] The target quantum random number is a quantum random number encrypted with the public key corresponding to the second terminal.
[0051] In some embodiments, after the first terminal obtains the LAC value of the second terminal, the first terminal can compare its own LAC value with the LAC value of the second terminal to determine whether the first terminal and the second terminal are in the same area. Thus, if the LAC values of the first terminal and the second terminal indicate that the first terminal and the second terminal are in the same area, encrypted communication can be performed with the second terminal based on the target quantum random number.
[0052] For example, the first terminal can match the LAC value of the first terminal with the LAC value of the second terminal. If the LAC values of the first terminal and the second terminal successfully match, the first terminal and the second terminal are in the same area. Therefore, the first terminal can call its own QRNG chip to generate a quantum random number. This quantum random number serves as the encryption key for communication between the first terminal and the second terminal. The quantum random number is then encrypted based on the public key corresponding to the second terminal to obtain the target quantum random number, thus realizing quantum encrypted communication between the first terminal and the second terminal. The same area can be the coverage area of the same base station or the same geographical area. Relevant personnel can set this based on actual conditions; this application embodiment does not limit this.
[0053] It should be understood that the first terminal generates quantum random numbers using its own QRNG chip to encrypt the communication process between the first and second terminals. This ensures that the quantum random number key does not leave either terminal, enhancing the security of the quantum random number. Furthermore, the first terminal generates quantum random numbers only when communicating with the second terminal, achieving on-demand generation of the quantum random number key. The quantum random number is then encrypted using the private key corresponding to the second terminal to obtain the target quantum random number, ensuring the confidentiality of the target quantum random number transmission and achieving reliable communication between the first and second terminals. Additionally, the target quantum random number encrypted using the public key corresponding to the second terminal can only be decrypted using the private key on the second terminal, guaranteeing the security of the communication between the first and second terminals.
[0054] S203. When the LAC values of the first terminal and the second terminal indicate that the first terminal and the second terminal are in different areas, encrypted communication is performed with the second terminal through the target communication link.
[0055] The target communication link is the communication link with the shortest distance and lowest fiber loss between the first terminal and the second terminal.
[0056] In some embodiments, after the first terminal obtains the LAC value of the second terminal, the first terminal can compare its own LAC value with the LAC value of the second terminal to determine whether the first terminal and the second terminal are in the same area. Thus, if the LAC values of the first terminal and the second terminal indicate that the first terminal and the second terminal are in different areas, encrypted communication can be performed with the second terminal through the target communication link.
[0057] For example, the first terminal can match the LAC value of the first terminal with the LAC value of the second terminal. If the LAC value of the first terminal fails to match the LAC value of the second terminal, the first terminal and the second terminal are in different regions. Thus, the first terminal can determine the target communication link with the shortest distance and lowest fiber loss between the first terminal and the second terminal based on multiple QKD nodes between the first terminal and the second terminal and the fiber loss between every two nodes. The first terminal can then conduct quantum encrypted communication with the second terminal through the target communication link.
[0058] The technical solutions provided by the above embodiments bring at least the following beneficial effects. In the communication encryption method provided in this application, when the first terminal and the second terminal are in the same area, the first terminal directly achieves encrypted communication between the first terminal and the second terminal through a target quantum random number, avoiding reliance on a quantum key management center and improving the communication efficiency of quantum encrypted communication. Furthermore, the first terminal can also encrypt the quantum random number using the public key corresponding to the second terminal, and only the private key of the second terminal can decrypt it, ensuring the security of quantum communication. When the first terminal and the second terminal are in different areas, the first terminal can achieve quantum encrypted communication with the second terminal through a target communication link. The target communication link considers not only the transmission distance between the first terminal and the second terminal but also the fiber optic loss between them, making the target communication link for communication between the first terminal and the second terminal not only the fastest in transmission speed but also the highest in transmission efficiency, thereby improving the communication efficiency of quantum encrypted communication and reducing costs.
[0059] In one possible implementation, when the first terminal and the second terminal are in the same area, the first terminal can determine a target quantum random number based on the quantum random number and the public key corresponding to the second terminal, thereby encrypting the communication process between the first terminal and the second terminal based on the target quantum random number. Specifically, as shown... Figure 3 As shown, S202 can be specifically implemented as S2021-S2024.
[0060] S2021, Use the QRNG chip to generate quantum random numbers.
[0061] In some embodiments, when the first terminal and the second terminal are in the same area, the first terminal can call its own QRNG chip to generate quantum random numbers.
[0062] For example, the first terminal can call the QRNG chip integrated in its own subscriber identity module (SIM) card to generate quantum random numbers based on the inherent randomness of the quantum system. The inherent randomness of the quantum system includes quantum entanglement, quantum vacuum fluctuations, quantum radioactive decay, quantum decoherence, etc., which can be set by relevant administrators based on actual conditions; this application embodiment does not limit this.
[0063] S2022. Determine the public key corresponding to the second terminal.
[0064] In some embodiments, after the first terminal calls the QRNG chip to generate quantum random numbers, it can also determine the public key corresponding to the second terminal so as to encrypt the quantum random numbers based on the public key corresponding to the second terminal.
[0065] For example, the first terminal stores a list of LAC (Local Account Registry) contacts. This list stores second terminals that have communicated with the first terminal more than a preset threshold, along with their corresponding public keys. Therefore, if a second terminal exists in the LAC contact list, the first terminal can query the public key corresponding to that second terminal. If a second terminal does not exist in the LAC contact list, the first terminal can generate the public key corresponding to the second terminal based on the PQC (Programmable Qualification Code) algorithm. The preset period and preset threshold are set by relevant administrators according to actual circumstances; for example, the preset period could be one month, one week, or one quarter, and the preset threshold could be 10, 15, or 20. This embodiment does not limit these settings.
[0066] It should be understood that the public-private key pair generated by the first terminal based on the PQC algorithm is a pair between the first terminal and the second terminal. The public key is used by the first terminal in the encryption process of the quantum random number, while the private key is stored in the second terminal so that the second terminal can decrypt the target quantum random number based on the private key.
[0067] S2023. Encrypt the quantum random number based on the public key corresponding to the second terminal to obtain the target quantum random number.
[0068] In some embodiments, after the first terminal determines the public key corresponding to the second terminal, it can encrypt the quantum random number based on the public key corresponding to the second terminal to obtain the target quantum random number, so as to encrypt the communication process between the first terminal and the second terminal based on the target quantum random number.
[0069] S2024. Encrypt the communication process between the first terminal and the second terminal based on the target quantum random number.
[0070] In some embodiments, the first terminal encrypts a quantum random number based on the public key corresponding to the second terminal to obtain a target quantum random number. The communication process between the first terminal and the second terminal can be encrypted based on the target quantum random number to realize quantum encrypted communication between the first terminal and the second terminal.
[0071] In another possible implementation, if a second terminal exists in the LAC friend / family list, the first terminal can query the public key corresponding to the second terminal in the LAC friend / family list. If a second terminal does not exist in the LAC friend / family list, the first terminal can generate the public key corresponding to the second terminal based on the PQC algorithm. Specifically, as follows... Figure 4 As shown, S2022 can be specifically implemented as S2022a-S2022b.
[0072] S2022a. If a second terminal exists in the LAC friend / family list of the first terminal, query the public key corresponding to the second terminal in the LAC friend / family list.
[0073] The LAC friend and family list is used to store the public keys of the second terminal and the second terminal that have communicated with the first terminal more than a preset threshold within a preset period.
[0074] In some embodiments, if a second terminal exists in the LAC family and friends list of the first terminal, the first terminal can directly query the public key corresponding to the second terminal from the LAC family and friends list.
[0075] S2022b: If the second terminal is not in the LAC friend / family list of the first terminal, generate the public key corresponding to the second terminal based on the PQC algorithm.
[0076] In some embodiments, if the second terminal is not present in the LAC friend / family list of the first terminal, the first terminal may generate the public key corresponding to the second terminal based on the PQC algorithm.
[0077] For example, the first terminal can invoke the key generation part of the PQC algorithm to generate a public-private key pair for both the first and second terminals. The public-private key pair includes a private key and a public key. The first terminal can encrypt the generated private key, send it to the second terminal, and then delete it to ensure that only the second terminal possesses the private key. The first terminal can also use the generated public key as the corresponding public key for the second terminal. The PQC algorithm includes any of the following: lattice-based encryption algorithms, multivariate quadratic polynomial algorithms, hash-based encryption algorithms, or code-based encryption algorithms, etc.
[0078] It should be understood that Figure 5 This application provides a schematic diagram of encrypted communication between a first terminal and a second terminal. Figure 5This describes a quantum-encrypted communication process between a first terminal and a second terminal when they are located in the same area. Figure 5 As shown, terminal A is the first terminal, and terminal B is the second terminal. Terminal A carries a QRNG1 chip and the PQC algorithm. Terminal A's LAC family list includes LAC-public key B (the public key corresponding to terminal B), LAC-public key 2, LAC-public key 3, LAC-public key 4, LAC-public key 5... LAC-public key n (the public keys corresponding to multiple terminals communicating with terminal A within the same area). Terminal B carries a QRNG2 chip and the PQC algorithm. Terminal B's LAC family list includes LAC-public key A (the public key corresponding to terminal A), LAC-public key b, LAC-public key c, LAC-public key d, LAC-public key e... LAC-public key m (the public keys corresponding to multiple terminals communicating with terminal B within the same area). When terminal A and terminal B communicate encrypted, terminal A can generate a quantum random number based on the QRNG1 chip and encrypt it using the LAC-public key B from the LAC friend list, thus obtaining the target quantum random number to encrypt the communication process between terminal A and terminal B. If LAC-public key B does not exist in terminal A's LAC friend list, terminal A can generate LAC-public key B using the PQC algorithm. Similarly, when terminal B and terminal A communicate encrypted, terminal B can generate a quantum random number based on the QRNG2 chip and encrypt it using the LAC-public key A from the LAC friend list, thus obtaining the target quantum random number to encrypt the communication process between terminal B and terminal A. If LAC-public key A does not exist in terminal B's LAC friend list, terminal B can generate LAC-public key A using the PQC algorithm.
[0079] In another possible implementation, where the first terminal and the second terminal are located in different areas, the first terminal can determine the target communication link with the shortest distance and lowest fiber loss between the first and second terminals based on multiple QKD nodes between the first and second terminals and the fiber loss between every two nodes. This target communication link allows for quantum encrypted communication with the second terminal. Specifically, for example... Figure 6 As shown, S203 can be specifically implemented as S2031-S2034.
[0080] S2031. Identify multiple QKD nodes within the target area.
[0081] The target area is a circular region with a diameter equal to the straight-line distance between the first terminal and the second terminal.
[0082] In some embodiments, when the first terminal and the second terminal are in different regions, the first terminal can determine the target region based on the straight-line distance between the first terminal and the second terminal, and thus determine multiple QKD nodes within the target region based on the target region.
[0083] For example, the first terminal can use the straight-line distance between the first terminal and the second terminal as the diameter, and the positions of the first terminal and the second terminal as points on the circle, draw a circle on the map where the first terminal and the second terminal are located, and determine the area where the circle is located as the target area, thereby determining multiple QKD nodes within the target area.
[0084] It should be understood that the first terminal selects multiple QKD nodes within the target area as the communication link between the first terminal and the second terminal, while QKD nodes within the target area are not selected as the communication link between the first terminal and the second terminal. This narrows the scope of the communication link between the first terminal and the second terminal and reduces the complexity.
[0085] S2032. Based on multiple QKD nodes, determine multiple communication links between the first terminal and the second terminal.
[0086] In some embodiments, after the first terminal determines multiple QKD nodes in the target area, it can determine multiple communication links between the first terminal and the second terminal based on the multiple QKD nodes.
[0087] For example, the first terminal can determine multiple communication links between the first terminal and the second terminal based on a path search algorithm and multiple QKD nodes. The path search algorithm includes any of the following: depth-first search, breadth-first search, Bellman-Ford algorithm, Dijkstra's algorithm, backtracking, etc., and this application embodiment does not limit the specific algorithm used.
[0088] S2033. Determine the target communication link among multiple communication links.
[0089] In some embodiments, after the first terminal determines multiple communication links between the first terminal and the second terminal, it can determine the target communication link among the multiple communication links based on the fiber loss of the multiple links and the number of QKD nodes on the links.
[0090] For example, the first terminal can first determine the shortest distance algorithm complexity for each of the multiple communication links, and then determine the fiber loss and the number of QKD nodes for each of the multiple communication links. Based on the fiber loss and the number of QKD nodes for each communication link, the first terminal can determine the average node fiber loss for each link. Therefore, based on the average node fiber loss and the shortest distance algorithm complexity for each communication link, the first terminal can determine the target communication link from the multiple communication links.
[0091] S2034. Based on the target communication link, communicate with the second terminal.
[0092] In some embodiments, the first terminal determines a target communication link among multiple communication links, and quantum encrypted communication between the first terminal and the second terminal can be realized through the target communication link.
[0093] In another possible implementation, the first terminal can determine the target communication link based on the fiber loss, the number of QKD nodes, and the shortest distance algorithm complexity of each of the multiple communication links. Specifically, such as... Figure 7 As shown, S2033 can be specifically implemented as S2033a-S2033d.
[0094] S2033a, Determine the algorithm complexity of the shortest distance for each of the multiple communication links.
[0095] In some embodiments, the first terminal may determine the shortest distance algorithm complexity for each of the multiple communication links.
[0096] For example, the first terminal can determine the number of QKD nodes for each communication link and the distance between every two adjacent QKD nodes, thereby determining the shortest distance algorithm complexity for each communication link based on the shortest distance algorithm, the number of QKD nodes for each communication link, and the distance between every two adjacent QKD nodes.
[0097] S2033b, Determine the fiber loss and the number of QKD nodes for each of the multiple communication links.
[0098] In some embodiments, the first terminal determines the shortest distance algorithm complexity for each of the multiple communication links, and may also determine the fiber loss and the number of QKD nodes for each of the multiple communication links.
[0099] For example, the first terminal can determine the type, length, refractive index, and other parameters of the optical fiber link in each communication link, and determine the attenuation coefficient of the optical fiber based on the type and refractive index of the optical fiber link. Therefore, based on the attenuation coefficient and the length of the optical fiber link, the optical fiber loss of each communication link can be calculated. The first terminal can also count the number of QKD nodes in each communication link.
[0100] S2033c: Determine the average node fiber loss for each link based on the fiber loss of each communication link and the number of QKD nodes.
[0101] In some embodiments, after the first terminal determines the fiber loss and the number of QKD nodes in each of the multiple communication links, it can determine that the ratio of the fiber loss to the number of QKD nodes in each communication link is the average node fiber loss of each link.
[0102] S2033d: Determine the communication link with the smallest product of average node fiber loss and shortest distance algorithm complexity among multiple communication links as the target communication link.
[0103] In some embodiments, after the first terminal determines the average node fiber loss of each link, it can determine the communication link with the smallest product of average node fiber loss and shortest distance algorithm complexity among multiple communication links as the target communication link.
[0104] It should be understood that Figure 8 This application provides another schematic diagram of encrypted communication between a first terminal and a second terminal. Figure 8 This describes a quantum-encrypted communication process between a first terminal and a second terminal when the latter are located in different regions. Figure 8As shown, point 1 (i.e., point A) represents the location of the first terminal, point 3 (i.e., point B) represents the location of the second terminal, and points 2, 4, 5, 6, 7, 8, 9, 10, 11, 12, and 13 are QKD nodes between the first and second terminals. From point 1 to point 3, a circle is drawn with the straight-line distance between A and B as its diameter to define the target area. The QKD nodes within the target area include points 2, 4, 5, 6, and 7. Points 2, 4, 5, 6, and 7 can form three communication links: the first is point 1-point 2-point 3, the second is point 1-point 5-point 4-point 3, and the third is point 1-point 5-point 6-point 7-point 3. For these three communication links, the shortest path algorithm has a complexity of O(m*n), where n represents the number of nodes and m represents the number of edges. The shortest path algorithm has a maximum complexity of m*n and a minimum complexity of m. The shortest path algorithm complexities for these three communication links are O1(2*3), O2(3*4), and O3(4*5), respectively, which are O1(6), O2(12), and O3(20). Additionally, the fiber losses for these three communication links are 9dB, 7dB, and 4dB, respectively. The product of the average node fiber loss and the shortest distance algorithm complexity for these three communication links is: O1(6)*9 / 3 = 18, O2(12)*7 / 4 = 21, and O3(20)*4 / 5 = 16. Therefore, the third link, from point 1 to point 5 to point 6 to point 7 to point 3, is the target communication link. It can be seen that the communication link with the fewest QKD nodes and the lowest shortest distance algorithm complexity has the highest fiber loss. Choosing the communication link with the fewest QKD nodes as the target communication link will affect the quantum key generation rate. Among these three communication links, the third path, which has the most QKD nodes, has the lowest fiber loss and the smallest total computation. The third path can ensure the stable transmission of quantum keys.
[0105] In another possible implementation, before the first terminal establishes encrypted communication with the second terminal based on the target quantum random number, it can also construct and periodically update the LAC (Learning Access Control) friend / family list, so that the device can determine the public key corresponding to the second terminal based on the LAC friend / family list. Therefore, as... Figure 9 As shown, prior to S202, the communication encryption method provided in this application embodiment further includes the following S901-S902:
[0106] S901. Build the LAC friend and family list.
[0107] In some embodiments, the first terminal may construct an LAC (Location-Based Association) friend / family list based on the number of communications between the first terminal and multiple second terminals within the same area.
[0108] For example, the first terminal can count the number of times each second terminal in the same area communicates with the first terminal within a preset period, and build an LAC family and friends list based on the second terminals whose number of communications is greater than a preset threshold.
[0109] S902. Based on the number of communications between the first terminal and the second terminal, periodically update the LAC friend and family list.
[0110] In some embodiments, after the first terminal constructs the LAC (Location and Friend List), it can also periodically update the LAC list based on the number of communications between the first terminal and the second terminal.
[0111] For example, in each preset period, the first terminal can count the number of times each second terminal in the same area communicates with the first terminal within the preset period, and then update the LAC family and friends list based on the second terminal whose number of communication is greater than a preset threshold.
[0112] The technical solutions provided by the above embodiments bring at least the following beneficial effects. In the communication encryption method provided in this application, when the first terminal and the second terminal are in the same area, the first terminal directly achieves encrypted communication between the first terminal and the second terminal through a target quantum random number, avoiding reliance on a quantum key management center and improving the communication efficiency of quantum encrypted communication. Furthermore, the first terminal can also encrypt the quantum random number using the public key corresponding to the second terminal, and only the private key of the second terminal can decrypt it, ensuring the security of quantum communication. When the first terminal and the second terminal are in different areas, the first terminal can achieve quantum encrypted communication with the second terminal through a target communication link. The target communication link considers not only the transmission distance between the first terminal and the second terminal but also the fiber optic loss between them, making the target communication link for communication between the first terminal and the second terminal not only the fastest in transmission speed but also the highest in transmission efficiency, thereby improving the communication efficiency of quantum encrypted communication and reducing costs.
[0113] Furthermore, when the first terminal and the second terminal are located in different areas, the first terminal can select multiple QKD nodes within the target area as communication links between the first and second terminals, narrowing the scope of the communication links and reducing complexity. Moreover, the first terminal can determine the target communication link based on the average node fiber loss and the complexity of the shortest distance algorithm for each communication link. Considering the impact of fiber loss on the communication link, this ensures the security and reliability of communication between the first and second terminals.
[0114] The communication encryption method of this application embodiment will now be described using another specific example. Figure 10 This application provides another schematic diagram of encrypted communication between a first terminal and a second terminal. Figure 10This describes the process in this scheme where the first terminal, based on the LAC value and the QKD node, conducts encrypted communication with the second terminal. For example... Figure 10 As shown, terminal A is the first terminal, and terminal B is the second terminal. Terminal A carries a QRNG1 chip and the PQC algorithm. Terminal A's LAC family list includes LAC-public key B (the public key corresponding to terminal B), LAC-public key 2, LAC-public key 3, LAC-public key 4, LAC-public key 5... LAC-public key n (the public keys corresponding to multiple terminals communicating with terminal A within the same area). Terminal B carries a QRNG2 chip and the PQC algorithm. Terminal B's LAC family list includes LAC-public key A (the public key corresponding to terminal A), LAC-public key b, LAC-public key c, LAC-public key d, LAC-public key e... LAC-public key m (the public keys corresponding to multiple terminals communicating with terminal B within the same area). The QKD nodes between terminal A and terminal B include points 1, 2, 3, 4, 5, 6, 7, 8, and 9. When terminal A and terminal B communicate encrypted, terminal A can determine the target communication link with terminal B based on fiber loss and the complexity of the shortest distance algorithm. It then generates a quantum random number using the QRNG1 chip and encrypts this random number using the LAC-public key B from its LAC friend list, thus obtaining the target quantum random number encrypted communication process between terminal A and terminal B. If LAC-public key B is not present in terminal A's LAC friend list, terminal A can generate LAC-public key B using the PQC algorithm. Similarly, when terminal B and terminal A communicate encrypted, terminal B can determine the target communication link based on fiber loss and the complexity of the shortest distance algorithm. Terminal B can generate a quantum random number using the QRNG2 chip and encrypt it using the LAC-public key A from its LAC friend list, thus obtaining the target quantum random number encrypted communication process between terminal B and terminal A. If LAC-public key A is not present in terminal B's LAC friend list, terminal B can generate LAC-public key A using the PQC algorithm.
[0115] In an exemplary embodiment, this application also provides a communication encryption device. This communication encryption device may include one or more functional modules for implementing the communication encryption method described in the above method embodiments.
[0116] For example, Figure 11 This is a schematic diagram illustrating the composition of a communication encryption device provided in an embodiment of this application. Figure 11 As shown, the communication encryption device includes: an acquisition module 1101 and a communication module 1102.
[0117] The acquisition module 1101 is used to acquire the LAC value of the second terminal when the first terminal communicates with the second terminal. The communication module 1102 is used to perform encrypted communication with the second terminal based on a target quantum random number when the LAC values of the first terminal and the second terminal indicate that the first terminal and the second terminal are in the same area. The target quantum random number is a quantum random number encrypted based on the public key corresponding to the second terminal. The communication module 1102 is also used to perform encrypted communication with the second terminal through a target communication link when the LAC values of the first terminal and the second terminal indicate that the first terminal and the second terminal are in different areas. The target communication link is the communication link with the shortest distance and lowest fiber loss between the first terminal and the second terminal.
[0118] In some embodiments, the communication module 1102 is specifically used to: determine multiple QKD nodes in a target area; the target area is a circular area with a diameter equal to the straight-line distance between the first terminal and the second terminal; determine multiple communication links between the first terminal and the second terminal based on the multiple QKD nodes; determine a target communication link among the multiple communication links; and communicate with the second terminal based on the target communication link.
[0119] In other embodiments, the communication module 1102 is specifically used to: determine the shortest distance algorithm complexity for each of the multiple communication links; determine the fiber loss and the number of QKD nodes for each of the multiple communication links; determine the average node fiber loss for each link based on the fiber loss and the number of QKD nodes for each communication link; and determine the communication link with the smallest product of the average node fiber loss and the shortest distance algorithm complexity among the multiple communication links as the target communication link.
[0120] In some other embodiments, the communication module 1102 is specifically used to: call the QRNG chip to generate a quantum random number; determine the public key corresponding to the second terminal; encrypt the quantum random number based on the public key corresponding to the second terminal to obtain a target quantum random number; and encrypt the communication process between the first terminal and the second terminal based on the target quantum random number.
[0121] In some other embodiments, the communication module 1102 is specifically used to, when a second terminal exists in the LAC friend list of the first terminal, query the public key corresponding to the second terminal in the LAC friend list; the LAC friend list is used to store the public key corresponding to the second terminal and the second terminal that has communicated with the first terminal more than a preset threshold within a preset period; when a second terminal does not exist in the LAC friend list of the first terminal, generate the public key corresponding to the second terminal based on the PQC algorithm.
[0122] In some other embodiments, the apparatus further includes a construction module 1103 and an update module 1104. The construction module 1103 is used to construct a LAC (Location-Based Account) friend / family list. The update module 1104 is used to periodically update the LAC friend / family list based on the number of communications between the first terminal and the second terminal.
[0123] In an exemplary embodiment, this application also provides an electronic device, which may be the communication encryption device in the above method embodiments. Figure 12 This is a schematic diagram illustrating the composition of an electronic device provided in an embodiment of this application. For example... Figure 12 As shown, the electronic device may include a processor 1201 and a memory 1202; the memory 1202 stores instructions executable by the processor 1201; when the processor 1201 is configured to execute the instructions, it causes the electronic device, network device, or manager to implement the methods described in the foregoing method embodiments.
[0124] In an exemplary embodiment, this application also provides a computer-readable storage medium storing computer program instructions thereon; when the computer program instructions are executed by a computer, the computer causes the computer to implement the method described in the foregoing embodiments. The computer-readable storage medium may be a non-transitory computer-readable storage medium, such as a ROM, random access memory (RAM), CD-ROM, magnetic tape, floppy disk, and optical data storage device.
[0125] In an exemplary embodiment, this application also provides a computer program product that, when run on a computer, causes the computer to execute the aforementioned related method steps to implement the communication encryption method in the above embodiments.
[0126] The above are merely specific embodiments of this application, but the scope of protection of this application is not limited thereto. Any variations or substitutions within the technical scope disclosed in this application should be included within the scope of protection of this application. Therefore, the scope of protection of this application should be determined by the scope of the claims.
Claims
1. A method of communication encryption, characterized by, The method is applied to a first terminal, and comprises the following steps: When the first terminal communicates with a second terminal, obtaining an LAC value of the second terminal; If the LAC value of the first terminal and the LAC value of the second terminal indicate that the first terminal and the second terminal are in the same area, performing encrypted communication with the second terminal based on a target quantum random number; the target quantum random number is a quantum random number encrypted based on a public key corresponding to the second terminal; If the LAC value of the first terminal and the LAC value of the second terminal indicate that the first terminal and the second terminal are in different areas, performing encrypted communication with the second terminal through a target communication link; the target communication link is a communication link between the first terminal and the second terminal with the shortest distance and the lowest fiber loss; The encrypted communication with the second terminal through the target communication link comprises the following steps: Determining a plurality of QKD nodes in a target area; the target area is a circular area with the straight-line distance between the first terminal and the second terminal as the diameter; Based on the plurality of QKD nodes, determining a plurality of communication links between the first terminal and the second terminal; Determining a target communication link in the plurality of communication links; Based on the target communication link, performing communication with the second terminal; The determination of the target communication link in the plurality of communication links comprises the following steps: Respectively determining the shortest distance algorithm complexity of each communication link in the plurality of communication links; Respectively determining the fiber loss and the number of QKD nodes of each communication link in the plurality of communication links; Based on the fiber loss and the number of QKD nodes of each communication link, determining the average node fiber loss of each link; Determining that the communication link with the product of the average node fiber loss and the shortest distance algorithm complexity being the smallest in the plurality of communication links is the target communication link.
2. The method of claim 1, wherein, The encrypted communication with the second terminal based on the target quantum random number comprises the following steps: Calling a QRNG chip to generate the quantum random number; Determining a public key corresponding to the second terminal; Encrypting the quantum random number based on the public key corresponding to the second terminal to obtain a target quantum random number; Encrypting the communication process between the first terminal and the second terminal based on the target quantum random number.
3. The method of claim 2, wherein, The determination of the public key corresponding to the second terminal comprises the following steps: If the second terminal exists in the LAC friend list of the first terminal, querying the public key corresponding to the second terminal in the LAC friend list; the LAC friend list is used to store the public key corresponding to the second terminal when the number of communications between the first terminal and the second terminal within a preset period is greater than a preset threshold; If the second terminal does not exist in the LAC friend list of the first terminal, generating the public key corresponding to the second terminal based on a PQC algorithm.
4. The method of claim 3, wherein, The method further comprises the following steps: Constructing the LAC friend list; Periodically updating the LAC friend list based on the number of communications between the first terminal and the second terminal.
5. A communication encryption device, characterized by, The device is applied to a first terminal, and comprises an obtaining module and a communication module; The acquisition module is configured to acquire the LAC value of the second terminal when the first terminal communicates with the second terminal. The communication module is configured to, in a case where the LAC value of the first terminal and the LAC value of the second terminal indicate that the first terminal and the second terminal are in the same area, perform encrypted communication with the second terminal based on a target quantum random number; the target quantum random number is a quantum random number encrypted based on a public key corresponding to the second terminal. The communication module is further configured to, in a case where the LAC value of the first terminal and the LAC value of the second terminal indicate that the first terminal and the second terminal are in different areas, perform encrypted communication with the second terminal through a target communication link; the target communication link is a communication link between the first terminal and the second terminal with the shortest distance and the lowest fiber loss. The communication module is specifically configured to determine a plurality of QKD nodes in a target area; the target area is a circular area with a straight-line distance between the first terminal and the second terminal as a diameter; determine a plurality of communication links between the first terminal and the second terminal based on the plurality of QKD nodes; determine a target communication link in the plurality of communication links; and perform communication with the second terminal based on the target communication link. The communication module is specifically configured to determine a shortest distance algorithm complexity of each communication link in the plurality of communication links respectively; determine a fiber loss and a number of QKD nodes of each communication link in the plurality of communication links respectively; determine an average node fiber loss of each link based on the fiber loss and the number of QKD nodes of each communication link; and determine that a communication link with a product of the average node fiber loss and the shortest distance algorithm complexity being the smallest in the plurality of communication links is the target communication link.
6. An electronic device, comprising: The electronic device comprises a processor and a memory; The memory stores instructions executable by the processor; The processor is configured to execute the instructions, so that the electronic device implements the method of any one of claims 1-4.
7. A computer-readable storage medium, characterized in that, The computer-readable storage medium comprises computer software instructions; When the computer software instructions are run in the electronic device, the electronic device implements the method of any one of claims 1-4.
Citation Information
Patent Citations
Fiber channel loss measurement system, method and device for light quantum communication business
CN106656320A
Wireless / wired hybrid QKD network based on trusted relay
CN112953710A