Quantum access control system entity identity authentication method
Patent Information
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- CHINA TELECOM QUANTUM TECH CO LTD
- Filing Date
- 2024-06-21
- Publication Date
- 2026-08-07
AI Technical Summary
[0003]本发明实施例的目的在于提供一种量子门禁系统实体身份鉴别方法,以解决传统的门禁系统安全性仍然不足的问题
[0034]与相关技术相比,本发明实施例至少具有以下优点:本发明实施例提供的一种量子门禁系统实体身份鉴别方法,应用于量子门禁系统,量子门禁系统可以包括国密CPU卡、国密读卡器、门禁系统、门禁控制器和量子密码服务平台,国密CPU卡、国密读卡器和门禁系统通过量子密码服务平台分别预充注有对应的量子密钥,并且,国密CPU卡、国密读卡器和所述门禁系统分别具有对应的电子标签,门禁系统绑定国密CPU卡的电子标签与国密读卡器的电子标签得到辅助信息,并将辅助信息存储于门禁系统的后台,具体地,首先,量子密码服务平台根据辅助信息、电子标签和量子密钥生成加密身份凭据,并将加密身份凭据下发给门禁系统,门禁系统根据绑定关系将加密身份凭据分发给对应的国密读卡器,国密读卡器则可以对加密身份凭据进行解密,得到解密后的身份凭据和随机数,其中,身份凭据为根据国密CPU卡对应的电子标签和随机数生成;随后,当待鉴别的国密CPU卡贴向国密读卡器时,所述国密读卡器读取待鉴别的国密CPU卡的鉴别电子标签,并根据鉴别电子标签将对应的随机数发送至待鉴别的所述国密CPU卡,待鉴别的国密CPU卡则可以使用随机数和本地的鉴别电子标签生成鉴别身份凭据并发送至国密读卡器,国密读卡器通过对比鉴别身份凭据和身份凭据,可以确定该国密CPU卡是否具有打开门禁系统控制的门的权限,进而确定是否告知门禁系统下的门禁控制器下发开锁指令控制门打开,实现了国密CPU卡和国密读卡器等实体之间的身份认证。本发明实施例通过借助量子密钥增强了实体之间的身份鉴别难度,具备高安全性、可扩展性和实用性,符合国密标准。
Smart Images

Figure CN118644923B_ABST
Abstract
Description
Technical Field
[0001] The embodiments of the present invention relate to the technical field of security application products, and in particular to a method for entity identification in a quantum access control system, a quantum access control system, an electronic device, and a computer-readable storage medium. Background Technology
[0002] With the continuous advancement of science and technology, access control systems have become an important component of security management. Currently, traditional access control systems identify users using cards and card readers; once authentication is successful, the system can control the opening of the door. However, while traditional access control systems improve security to some extent, they still fall short of full security requirements. Summary of the Invention
[0003] The purpose of this invention is to provide a quantum access control system entity identification method to address the problem of insufficient security in traditional access control systems. The specific technical solution is as follows:
[0004] In a first aspect of this invention, a method for entity identification in a quantum access control system is provided. The quantum access control system includes a national cryptographic CPU card, a national cryptographic card reader, an access control system, an access control controller, and a quantum cryptography service platform. The national cryptographic CPU card, the national cryptographic card reader, and the access control system are each pre-loaded with a corresponding quantum key via the quantum cryptography service platform. Each of the national cryptographic CPU card, the national cryptographic card reader, and the access control system has a corresponding electronic tag. The access control system binds the electronic tag of the national cryptographic CPU card to the electronic tag of the national cryptographic card reader to obtain auxiliary information, and stores the auxiliary information in the background of the access control system. The method includes:
[0005] The quantum cryptography service platform generates a random number, and generates an encrypted identity credential based on the random number, the auxiliary information, the electronic tag, and the quantum key corresponding to the national cryptographic card reader determined based on the auxiliary information, and sends the encrypted identity credential to the access control system;
[0006] The access control system distributes the encrypted identity credentials to the corresponding national cryptographic card reader according to the binding relationship;
[0007] The national cryptographic card reader decrypts the encrypted identity credential to obtain a decrypted identity credential and a random number; the identity credential is generated based on the electronic tag of the national cryptographic CPU card and the random number is generated by the quantum cryptography service platform;
[0008] When the national cryptographic CPU card to be identified is placed on the national cryptographic card reader, the national cryptographic card reader reads the identification electronic tag of the national cryptographic CPU card to be identified, and sends the corresponding random number to the national cryptographic CPU card to be identified according to the identification electronic tag.
[0009] The national cryptographic CPU card to be authenticated uses the random number and the local authentication electronic tag to generate an authentication credential, and sends the authentication credential to the national cryptographic card reader;
[0010] The national cryptographic card reader compares the authentication credential with the identity credential to determine whether to instruct the access control controller to issue an unlocking command to open the door.
[0011] Optionally, the quantum access control system also includes a quantum-secure U-shield, which is inserted into the backend of the access control system and is used to protect the information exchanged between the access control system and the quantum cryptography service platform.
[0012] Optionally, the national cryptographic CPU card, the national cryptographic card reader, and the quantum-secure U-shield of the access control system are pre-charged with a first quantum key, a second quantum key, and a third quantum key respectively through the quantum cryptography service platform; the national cryptographic CPU card, the national cryptographic card reader, and the quantum-secure U-shield of the access control system correspond to a first electronic tag, a second electronic tag, and a third electronic tag respectively; the quantum cryptography service platform generates a random number, and generates an encrypted identity credential based on the random number, the auxiliary information, the electronic tag, and the quantum key corresponding to the national cryptographic card reader determined based on the auxiliary information, and sends the encrypted identity credential to the access control system, including:
[0013] The access control system uses the third quantum key to encrypt the first electronic tag and the auxiliary information, and sends the encrypted first electronic tag and the auxiliary information to the quantum cryptography service platform;
[0014] The quantum cryptography service platform determines the third quantum key corresponding to the quantum security U-shield of the access control system based on the third electronic tag, and uses the third quantum key to decrypt the encrypted first electronic tag and the auxiliary information to obtain the decrypted first electronic tag and the auxiliary information;
[0015] The quantum cryptography service platform determines the first quantum key corresponding to the national cryptographic CPU card based on the first electronic tag. The quantum cryptography service platform generates a random number. After generating an identity credential based on the first quantum key corresponding to the first electronic tag and the random number, the platform encrypts the identity credential and the random number with the second quantum key corresponding to the second electronic tag corresponding to the first electronic tag according to the auxiliary information to obtain an encrypted identity credential. The encrypted identity credential is then sent to the access control system.
[0016] Optionally, the national cryptographic card reader compares the authentication credential with the identity credential to determine whether to instruct the access control controller to issue an unlocking command to open the door, including:
[0017] The national cryptographic card reader compares the authentication credential with the identity credential.
[0018] If the authentication credential matches the identity credential, the national cryptographic card reader sends a successful comparison result to the access control controller, so that the access control controller issues an unlocking command to control the door to open based on the successful comparison result;
[0019] If the authentication credentials do not match, the national cryptographic card reader will issue an error message.
[0020] Optionally, the quantum cryptography service platform generates a random number, and generates an encrypted identity credential based on the random number, the auxiliary information, the electronic tag, and the quantum key corresponding to the national cryptographic card reader determined based on the auxiliary information, and sends the encrypted identity credential to the access control system, including:
[0021] When the national cryptographic card reader, the access control system, and the quantum cryptography service platform are online, if the access control system obtains new auxiliary information by binding the electronic tag of the national cryptographic CPU card to the electronic tag of the national cryptographic card reader, or if a preset time is reached, the quantum cryptography service platform generates a random number and generates an encrypted identity credential based on the random number, the auxiliary information, the electronic tag, and the quantum key corresponding to the national cryptographic card reader determined based on the auxiliary information, and sends the encrypted identity credential to the access control system.
[0022] The access control system uses the encrypted identity credentials to overwrite the encrypted identity credentials previously issued by the quantum cryptography service platform.
[0023] Optionally, the method further includes:
[0024] When the national cryptographic card reader, the access control system, and the quantum cryptography service platform are offline, when the national cryptographic CPU card to be identified is placed on the national cryptographic card reader, the national cryptographic card reader reads the identification electronic tag of the national cryptographic CPU card to be identified, and sends the random number corresponding to the previous time to the national cryptographic CPU card to be identified according to the identification electronic tag.
[0025] The national cryptographic CPU card to be authenticated uses the previously obtained random number and the local authentication electronic tag to generate an authentication credential, and sends the authentication credential to the national cryptographic card reader;
[0026] The national cryptographic card reader compares the authentication credentials with the previous authentication credentials to determine whether to instruct the access control controller to issue an unlocking command to open the door.
[0027] Optionally, before the quantum cryptography service platform generates a random number, generates an encrypted identity credential based on the random number, the auxiliary information, the electronic tag, and the quantum key corresponding to the national cryptographic card reader determined based on the auxiliary information, and sends the encrypted identity credential to the access control system, the method further includes:
[0028] The access control system determines the user permissions of the national cryptographic CPU card to be bound;
[0029] When the user privileges of the national cryptographic CPU card are ordinary unlocking users, the access control system binds the national cryptographic CPU card with the agreed auxiliary information of the national cryptographic card reader;
[0030] When the user of the national cryptographic CPU card has the privileges of a super administrator, the access control system binds the national cryptographic CPU card with the auxiliary information of all the national cryptographic card readers.
[0031] In a second aspect of the present invention, a quantum access control system is provided, comprising the quantum access control system as described above.
[0032] In another aspect of the present invention, a computer-readable storage medium is also provided, wherein the computer-readable storage medium stores instructions that, when executed on a computer, cause the computer to perform any of the above-described quantum access control system entity identification methods.
[0033] In another aspect of the present invention, a computer program product containing instructions is also provided, which, when run on a computer, causes the computer to execute any of the above-described quantum access control system entity identification methods.
[0034] Compared with related technologies, the embodiments of the present invention have at least the following advantages: The present invention provides a quantum access control system entity identity authentication method, which is applied to a quantum access control system. The quantum access control system may include a national cryptographic CPU card, a national cryptographic card reader, an access control system, an access control controller, and a quantum cryptography service platform. The national cryptographic CPU card, the national cryptographic card reader, and the access control system are pre-charged with corresponding quantum keys through the quantum cryptography service platform. Furthermore, the national cryptographic CPU card, the national cryptographic card reader, and the access control system each have corresponding electronic tags. The access control system binds the electronic tags of the national cryptographic CPU card and the electronic tags of the national cryptographic card reader to obtain auxiliary information, and stores the auxiliary information in the background of the access control system. Specifically, firstly, the quantum cryptography service platform generates encrypted identity credentials based on the auxiliary information, electronic tags, and quantum keys, and sends the encrypted identity credentials to the access control system. The access control system then distributes the encrypted identity credentials to the corresponding entities according to the binding relationship. The invention employs a national cryptographic card reader, which can decrypt encrypted identity credentials to obtain a decrypted identity credential and a random number. The identity credential is generated based on the electronic tag corresponding to the national cryptographic CPU card and the random number. Subsequently, when the national cryptographic CPU card to be authenticated is placed on the national cryptographic card reader, the reader reads the authentication electronic tag of the card and sends the corresponding random number to the card. The card then uses the random number and its local authentication electronic tag to generate an authentication identity credential and sends it to the card reader. By comparing the authentication identity credential with the original identity credential, the card reader can determine whether the national cryptographic CPU card has the authority to open a door controlled by the access control system, and thus determine whether to instruct the access control controller to issue an unlocking command to open the door. This achieves identity authentication between entities such as the national cryptographic CPU card and the national cryptographic card reader. This embodiment of the invention enhances the difficulty of identity authentication between entities by utilizing quantum keys, possessing high security, scalability, and practicality, and conforming to national cryptographic standards. Attached Figure Description
[0035] To more clearly illustrate the technical solutions in the embodiments of the present invention or the prior art, the accompanying drawings used in the description of the embodiments or the prior art will be briefly introduced below.
[0036] Figure 1 This is a flowchart illustrating the steps of an entity identification method for a quantum access control system provided in an embodiment of the present invention.
[0037] Figure 2 This is a functional schematic diagram of a quantum access control system module provided in an embodiment of the present invention;
[0038] Figure 3 This is a timing diagram of an entity identification method for a quantum access control system provided in an embodiment of the present invention;
[0039] Figure 4 This is a flowchart of a key filling process for a cryptographic security module in a quantum access control system provided in an embodiment of the present invention;
[0040] Figure 5 This is a flowchart illustrating the card-reader binding relationship of a quantum access control system provided in an embodiment of the present invention.
[0041] Figure 6 This is a flowchart illustrating the process of issuing encrypted identity credentials in a quantum access control system, as provided in this embodiment of the invention.
[0042] Figure 7 This is a flowchart illustrating the authentication process of a national cryptographic CPU card and a national cryptographic card reader, as provided in an embodiment of the present invention. Detailed Implementation
[0043] The technical solutions of the present invention will now be described with reference to the accompanying drawings in the embodiments of the present invention.
[0044] Reference Figure 1 The above is a flowchart of the steps of a quantum access control system entity identification method provided in an embodiment of the present invention, as follows: Figure 1 As shown, the method may specifically include the following steps:
[0045] Step 101: The quantum cryptography service platform generates a random number, and generates an encrypted identity credential based on the random number, the auxiliary information, the electronic tag, and the quantum key corresponding to the national cryptographic card reader determined based on the auxiliary information, and sends the encrypted identity credential to the access control system.
[0046] In this embodiment of the invention, the quantum access control system may include modules such as a national cryptographic CPU (Central Processing Unit) card, a national cryptographic card reader, an access control system, an access controller, and a quantum cryptography service platform (which may be simply referred to as the cryptographic system). It should be noted that the national cryptographic CPU card and national cryptographic card reader modules in this embodiment refer to smart cards and card readers that conform to the national cryptographic standards established by the state, i.e., smart cards and card readers that comply with national cryptographic standards. For example, national cryptographic standards may include using cryptographic technology for physical access authentication to ensure the authenticity of the identity of personnel entering important areas, etc.
[0047] Reference Figure 2This is a functional diagram of different modules of a quantum access control system provided in an embodiment of the present invention. The working content of each module of the quantum access control system (quantum secure access control system) is as follows: access control system, used to store, manage, and authorize user information; national cryptographic CPU card, the entity being authenticated; national cryptographic card reader, the terminal device for authenticating other entities; quantum cryptography service platform, including quantum cryptography service platform, quantum random number generator, quantum key exchange, and quantum key filling machine, used to provide key services.
[0048] Specifically, the national cryptographic CPU card stores a quantum security key (quantum key). This quantum key is a symmetric key, generated by a quantum random number generator in the quantum cryptography service platform and stored within a quantum exchange. A quantum key filling machine fills the cryptographic security module of the national cryptographic CPU card with the symmetric key. The quantum key filled into each national cryptographic CPU card and the quantum key built into the quantum exchange cryptographic machine form a symmetric key pair. Each national cryptographic CPU card has its own unique identifier (also known as an electronic tag), and each quantum key has its own serial number. By providing the electronic tag of the national cryptographic CPU card and the serial number of the quantum key, the corresponding symmetric key can be found within the quantum exchange cryptographic machine.
[0049] The national cryptographic card reader, as a module used for entity identity authentication in this embodiment of the invention, mainly includes the following functions: First, it internally stores encrypted identity credentials (ciphertext identity credentials) pre-generated and issued daily by the access control system; Second, when a user's card (national cryptographic CPU card) is placed on the national cryptographic card reader, the national cryptographic card reader needs to exchange information with the user's national cryptographic CPU card, wherein the encrypted identity credential comparison is performed on the national cryptographic card reader.
[0050] As a back-end management system for business operations, the access control system can insert a quantum security U-shield. Through the quantum security U-shield, the unlocking relationship between the new national cryptographic CPU card and different national cryptographic card readers can be completed, and the quantum cryptographic system can be informed which national cryptographic card readers use quantum keys to encrypt which specific information.
[0051] In this embodiment of the invention, the national cryptographic CPU card, the national cryptographic card reader, and the access control system are each pre-loaded with corresponding quantum keys through a quantum cryptography service platform. Furthermore, each of the national cryptographic CPU card, the national cryptographic card reader, and the access control system has a corresponding electronic tag. The access control system binds the electronic tag of the national cryptographic CPU card to the electronic tag of the national cryptographic card reader to obtain auxiliary information, which is then stored in the access control system's backend. Specifically, assuming the electronic tag of the national cryptographic CPU card is A and the electronic tag of the national cryptographic card reader is B, the auxiliary information could be the unlocking relationship binding A and B. Further, the auxiliary information is also used to inform the quantum cryptography service platform which national cryptographic card readers' quantum keys encrypt which national cryptographic CPU card's corresponding card identity credentials. For example, assuming the auxiliary information is the unlocking relationship binding A and B, the quantum cryptography service platform can determine, based on the auxiliary information, that A's identity credentials are encrypted using the quantum key corresponding to B.
[0052] In practical applications, upon initial use, the access control system needs to establish a binding relationship between the national cryptographic CPU card and the national cryptographic card reader. This binding relationship is used to locate the national cryptographic CPU card bound to the card reader, specifically the unique identifier (electronic tag) of the CPU card and the unique identifier (electronic tag) of the card reader paired with it. This information is stored in the access control system's backend. When the access control system needs to request encrypted identity credentials from the quantum cryptography service platform, this binding relationship can be communicated to the platform. The quantum key recharged into the card reader encrypts the identity credentials of the paired national cryptographic CPU card; this information is referred to as auxiliary information. The auxiliary information and the electronic tag of the national cryptographic CPU card can be encrypted using a quantum security U-shield and uploaded to the quantum cryptography service platform, thereby ensuring data security.
[0053] The national cryptographic card reader can send auxiliary information to the quantum cryptography service platform. The platform can then generate encrypted identity credentials based on the auxiliary information, the national cryptographic CPU card, the national cryptographic card reader, and the corresponding electronic tags and quantum keys of the access control system. These encrypted identity credentials are then distributed to the access control system for entity authentication. Specifically, the quantum cryptography service platform generates identity credentials based on the card information (electronic tag), random number, and quantum key corresponding to the national cryptographic CPU card submitted by the access control system. It then determines the national cryptographic card reader bound to the CPU card based on the auxiliary information and finally encrypts the identity credentials using the quantum key corresponding to the card reader.
[0054] Step 102: The access control system distributes the encrypted identity credentials to the corresponding national cryptographic card reader according to the binding relationship.
[0055] After the access control system receives the encrypted identity credentials issued by the quantum cryptography service platform, it can distribute the encrypted identity credentials to each corresponding national cryptographic card reader based on the auxiliary information.
[0056] Step 103: The national cryptographic card reader decrypts the encrypted identity credential to obtain the decrypted identity credential and a random number; the identity credential is generated based on the electronic tag of the national cryptographic CPU card and the random number is generated by the quantum cryptography service platform.
[0057] In this embodiment of the invention, the national cryptographic card reader can use a locally pre-charged quantum key to decrypt the encrypted identity credential and obtain the identity credential. The identity credential includes the electronic tag corresponding to the national cryptographic CPU card, a random number, and the quantum key corresponding to the national cryptographic CPU card.
[0058] Step 104: When the national cryptographic CPU card to be identified is placed on the national cryptographic card reader, the national cryptographic card reader reads the identification electronic tag of the national cryptographic CPU card to be identified, and sends the corresponding random number to the national cryptographic CPU card to be identified according to the identification electronic tag.
[0059] Step 105: The national cryptographic CPU card to be authenticated uses the random number and the local authentication electronic tag to generate an authentication credential, and sends the authentication credential to the national cryptographic card reader.
[0060] Step 106: The national cryptographic card reader compares the authentication credential with the identity credential to determine whether to instruct the access control controller to issue an unlocking command to control the door to open.
[0061] When physical identity verification is required, the national cryptographic CPU card to be verified is placed against the national cryptographic card reader, and the card's unique identifier, i.e., the electronic tag, is sent to the reader. After recognizing the electronic tag, the national cryptographic card reader sends the corresponding salt (random number) to the national cryptographic CPU card. The national cryptographic CPU card uses its pre-charged quantum key to encrypt the electronic tag and the salt to obtain the identity verification credential, which is then sent to the national cryptographic card reader. The national cryptographic card reader completes physical verification locally by comparing the identity verification credential with the identity verification credential, and the electronic tag verification is successful. If the successful comparison result of the identity verification credential and the identity verification credential is notified to the access control controller, the access control controller issues an unlocking command to open the door.
[0062] The embodiments of the present invention enhance the difficulty of identity authentication between entities by using quantum keys and random numbers, and have high security, scalability and practicality, and comply with national cryptographic standards.
[0063] In one embodiment of the present invention, the national cryptographic CPU card, the national cryptographic card reader, and the quantum security U-shield of the access control system are pre-charged with a first quantum key, a second quantum key, and a third quantum key respectively through the quantum cryptography service platform; the national cryptographic CPU card, the national cryptographic card reader, and the quantum security U-shield of the access control system correspond to a first electronic tag, a second electronic tag, and a third electronic tag respectively; step 101, the quantum cryptography service platform generates a random number, and generates an encrypted identity credential based on the random number, the auxiliary information, the electronic tag, and the quantum key corresponding to the national cryptographic card reader determined based on the auxiliary information, and sends the encrypted identity credential to the access control system, including:
[0064] The access control system uses the third quantum key to encrypt the first electronic tag and the auxiliary information, and sends the encrypted first electronic tag and the auxiliary information to the quantum cryptography service platform;
[0065] The quantum cryptography service platform determines the third quantum key corresponding to the quantum security U-shield of the access control system based on the third electronic tag, and uses the third quantum key to decrypt the encrypted first electronic tag and the auxiliary information to obtain the decrypted first electronic tag and the auxiliary information;
[0066] The quantum cryptography service platform determines the first quantum key corresponding to the national cryptographic CPU card based on the first electronic tag. The quantum cryptography service platform generates a random number. After generating an identity credential based on the first quantum key corresponding to the first electronic tag and the random number, the platform encrypts the identity credential and the random number with the second quantum key corresponding to the second electronic tag corresponding to the first electronic tag according to the auxiliary information to obtain an encrypted identity credential. The encrypted identity credential is then sent to the access control system.
[0067] In this embodiment of the invention, the quantum cryptography service platform decrypts the encrypted auxiliary information and the electronic tag of the national cryptographic CPU card. It obtains the identity credential using a random number generated by an encrypted quantum random number generator and the electronic tag of the national cryptographic CPU card. Based on the access control system's information in the auxiliary information, the quantum key of the national cryptographic card reader is used to encrypt the corresponding national cryptographic CPU card's identity credential. The identity credential and salt are encrypted using the quantum key charged to the national cryptographic card reader, resulting in an encrypted identity credential, which is then sent to the access control system. Subsequently, the access control system issues the encrypted identity credential to the corresponding national cryptographic card reader based on the auxiliary information. The national cryptographic card reader decrypts the encrypted identity credential using its own corresponding quantum key to obtain the identity credential.
[0068] Reference Figure 3This is a flowchart illustrating a quantum access control system entity identity authentication method provided in this embodiment of the invention. The authentication process for the authenticity of personnel identity in the access control system is roughly divided into three main processes: key filling, authorization, and card-reader (national cryptographic CPU card-national cryptographic reader) identity authentication.
[0069] Reference Figure 4 This is a schematic diagram illustrating the key filling process of a cryptographic security module in a quantum access control system provided in this embodiment of the invention. The national cryptographic CPU card, national cryptographic card reader, and quantum security U-shield need to be filled with keys at the quantum key filling machine. Each of the national cryptographic CPU card, national cryptographic card reader, and quantum security U-shield only needs to be filled with a fixed quantum key, for example, the filled quantum keys are the first quantum key, the second quantum key, and the third quantum key, which can be represented by Ka, Kb, and Kd, respectively. Furthermore, in this embodiment of the invention, to illustrate the unlocking relationship between the national cryptographic CPU card and the national cryptographic card reader, the national cryptographic CPU card, national cryptographic card reader, and quantum security U-shield correspond to electronic tags, i.e., the first electronic tag, the second electronic tag, and the third electronic tag are represented by UID, MID, and UCID, respectively.
[0070] The authorization process can be divided into two steps: card-reader relationship binding and issuance of encrypted identity credentials. The first step, card-reader relationship binding, establishes an unlocking relationship between a national cryptographic CPU card and a national cryptographic card reader. The access control system is equipped with a quantum-secure U-shield and compatible quantum middleware (middleware SDK). The quantum-secure U-shield uses its quantum key Kd to encrypt the UID and auxiliary information θc, and then sends the encrypted UID and other information to the cryptographic system.
[0071] The second step involves issuing identity credentials. The cryptographic system locates the quantum key Kd of the quantum security U-shield based on its electronic tag, and uses Kd to decrypt the UID and auxiliary information ciphertext of all national cryptographic CPU cards. It then finds the corresponding national cryptographic CPU card's quantum key Ka and uses the salt for encryption, thereby generating identity credentials for all national cryptographic CPU cards. Based on the auxiliary information θc sent by the access control system, the system informs the quantum cryptographic service platform of the corresponding national cryptographic card reader's quantum key Kb to encrypt the corresponding identity credentials. The system then finds the corresponding national cryptographic card reader, encrypts the salt and identity credentials together to generate ciphertext identity credentials, and sends them to the access control system. The access control system then issues them to the corresponding national cryptographic card reader based on the bound unlocking relationship.
[0072] Reference Figure 5The diagram shown is a flowchart illustrating the card-reader binding relationship of a quantum access control system provided in this embodiment of the invention. After the national cryptographic CPU card completes key charging, the access control system needs to manually enter the unlocking relationship between the national cryptographic CPU card and the national cryptographic card reader (for example, the unlocking relationship between national cryptographic CPU card A and national cryptographic card reader B can be UIDA-MIDB). If the user is a super administrator, the user can set the user permissions for the national cryptographic CPU card in the access control system. The super administrator user has the permission to open all doors, while ordinary unlocking users only have the permission to open one or a few doors.
[0073] Reference Figure 6 The diagram shown is a flowchart of a quantum access control system for issuing encrypted identity credentials in an embodiment of the present invention. The national cryptographic CPU card completes the card-reader unlocking relationship binding. The access control system stores the unlocking relationship between the national cryptographic CPU card and the national cryptographic reader. The access control system uses the quantum key Kd of the quantum security U-shield to encrypt the auxiliary information θc at a fixed time every day to apply for the encrypted identity credentials corresponding to the national cryptographic CPU card.
[0074] The cryptographic system uses the symmetric key Kd to decrypt and obtain auxiliary information θc and the electronic tag UID. The auxiliary information θc informs the quantum cryptography service platform which national cryptographic CPU cards' identity credentials need to be encrypted using the national cryptographic card reader's quantum key. The identity credentials are calculated daily using a salt that is updated daily to determine the identity credentials of all national cryptographic CPU cards. The identity credentials and salt are then encrypted using the corresponding national cryptographic card reader's quantum key and sent to the access control system. After obtaining the encrypted identity credentials for all national cryptographic CPU cards, the access control system issues encrypted identity credentials to the corresponding national cryptographic card reader based on the unlocking relationship. Each national cryptographic card reader obtains the identity credentials for authentication.
[0075] After completing the charging and authorization, the following will be combined with Figure 7 The execution process of the embodiments of the present invention will be described in detail below, specifically referring to... Figure 7 The following is a flowchart of a quantum access control system unlocking process provided in this embodiment of the invention: A national cryptographic CPU card A is affixed to a national cryptographic card reader; the national cryptographic card reader reads the card; the national cryptographic CPU card A sends an electronic tag UIDA to the card reader; the national cryptographic card reader sends a salt (random number Rd) to the national cryptographic CPU card A; the national cryptographic CPU card A uses the quantum key Ka and the salt to encrypt and obtain an authentication credential, and then sends the authentication credential back to the national cryptographic card reader; the national cryptographic card reader receives the authentication credential and searches locally for a corresponding credential; if a corresponding credential is found, it can control the access control controller to issue an unlocking command to open the door.
[0076] This invention utilizes electronic tags corresponding to the national cryptographic CPU card, national cryptographic card reader, and quantum security U-shield, as well as quantum cryptography corresponding to the national cryptographic CPU card, national cryptographic card reader, and quantum security U-shield, to generate identity credentials through multiple encryptions for transmission and authentication. This provides extremely high security, effectively protecting user rights and ensuring the safety of users' lives and property.
[0077] In one embodiment of the present invention, the method may further include:
[0078] When the national cryptographic card reader, the access control system, and the quantum cryptography service platform are offline, when the national cryptographic CPU card to be identified is placed on the national cryptographic card reader, the national cryptographic card reader reads the identification electronic tag of the national cryptographic CPU card to be identified, and sends the random number corresponding to the previous time to the national cryptographic CPU card to be identified according to the identification electronic tag.
[0079] The national cryptographic CPU card to be authenticated uses the previously obtained random number and the local authentication electronic tag to generate an authentication credential, and sends the authentication credential to the national cryptographic card reader;
[0080] The national cryptographic card reader compares the authentication credentials with the previous authentication credentials to determine whether to instruct the access control controller to issue an unlocking command to open the door.
[0081] In this embodiment of the invention, when the national cryptographic card reader, access control system, and quantum cryptography service platform are offline, and the quantum cryptography service platform cannot issue new identity credentials, when the national cryptographic CPU card to be authenticated is placed on the national cryptographic card reader, the national cryptographic card reader reads the authentication electronic tag of the national cryptographic CPU card to be authenticated, and sends the corresponding random number from the previous time to the national cryptographic CPU card to be authenticated based on the authentication electronic tag. In this way, the national cryptographic CPU card can use the random number generated by the quantum cryptography service platform last time and the local authentication electronic tag to generate an authentication identity credential, and send it to the national cryptographic card reader. The national cryptographic card reader can then use the corresponding identity credential from the previous time to verify the authentication identity credential. Thus, door opening can be completed even in an offline state, ensuring a good user experience.
[0082] In one embodiment of the present invention, step 106, in which the national cryptographic card reader compares the authentication credential with the identity credential to determine whether to instruct the access control controller to issue an unlocking command to control the door to open, includes:
[0083] The national cryptographic card reader compares the authentication credential with the identity credential.
[0084] If the authentication credential matches the identity credential, the national cryptographic card reader sends a successful comparison result to the access control controller, so that the access control controller issues an unlocking command to control the door to open based on the successful comparison result;
[0085] If the authentication credentials do not match, the national cryptographic card reader will issue an error message.
[0086] In this embodiment of the invention, after the national cryptographic card reader obtains the authentication credentials of the national cryptographic CPU card to be authenticated, it compares them with other local credentials. If the authentication credentials match the identity credentials, it indicates that the physical authentication is successful. The national cryptographic card reader can then send the successful comparison result to the access control controller, so that the access control controller can issue an unlocking command to control the door to open based on the successful comparison result. Conversely, if the authentication credentials do not match the identity credentials, it indicates that the physical authentication has failed. The national cryptographic card reader will then issue an error message, which can be indicated by playing a voice message such as "Authentication failed".
[0087] In one embodiment of the present invention, the quantum cryptography service platform generates a random number, and generates an encrypted identity credential based on the random number, the auxiliary information, the electronic tag, and the quantum key corresponding to the national cryptographic card reader determined based on the auxiliary information, and sends the encrypted identity credential to the access control system, including:
[0088] When the national cryptographic card reader, the access control system, and the quantum cryptography service platform are online, if the access control system obtains new auxiliary information by binding the electronic tag of the national cryptographic CPU card to the electronic tag of the national cryptographic card reader, or if a preset time is reached, the quantum cryptography service platform generates a random number and generates an encrypted identity credential based on the random number, the auxiliary information, the electronic tag, and the quantum key corresponding to the national cryptographic card reader determined based on the auxiliary information, and sends the encrypted identity credential to the access control system.
[0089] The access control system uses the encrypted identity credentials to overwrite the encrypted identity credentials previously issued by the quantum cryptography service platform.
[0090] In this embodiment of the invention, when online, the cryptographic system generates a random number upon reaching a preset time (e.g., media access), and generates an encrypted identity credential based on the random number, auxiliary information, electronic tag, and quantum key. This encrypted identity credential is then sent to the access control system, which in turn sends it to the corresponding national cryptographic card reader based on the bound unlocking relationship. In this way, the national cryptographic card reader can use the identity credential issued daily by the cryptographic system to verify the authentication credential. Changing the identity credential daily can quickly reduce the potential risk of unauthorized access. If the cryptographic system issues a new identity credential, the previous one is overwritten. Furthermore, when the electronic tag of the national cryptographic CPU card bound to the access control system and the electronic tag of the national cryptographic card reader receive new auxiliary information, the cryptographic system can also be triggered to send an encrypted identity credential to the access control system.
[0091] Specifically, the authorization mode of the quantum access control system in this embodiment of the invention is online authorization, supporting offline unlocking. There are two scenarios for online authorization. One is when a new national cryptographic CPU card needs to be bound to the access control system for unlocking. In this scenario, the access control system manually binds the national cryptographic CPU card to the unlocking relationship, determines the unique identifier (electronic tag) and auxiliary information of the national cryptographic CPU card based on the bound unlocking relationship, encrypts the auxiliary information and electronic tag using a quantum key Kd, and uploads it to the quantum cryptography service platform. The quantum cryptography service platform calculates the encrypted identity credential of the national cryptographic CPU card and securely sends the encrypted identity credential to the access control system. The access control system then sends it to the corresponding national cryptographic card reader based on the bound unlocking relationship. Secondly, the quantum key service system traverses all national cryptographic CPU cards at a fixed time in the early morning when there is network access. Using a new salt (a new random number), it obtains a new identity credential and encrypts the updated identity credential and salt with the quantum key Kb of the national cryptographic card reader. The access control system then distributes the updated encrypted identity credential and salt to the national cryptographic card reader, and can unlock the door in both online and offline states.
[0092] In one embodiment of the present invention, before the quantum cryptography service platform generates a random number, generates an encrypted identity credential based on the random number, the auxiliary information, the electronic tag, and the quantum key corresponding to the national cryptographic card reader determined based on the auxiliary information, and sends the encrypted identity credential to the access control system, the method further includes:
[0093] The access control system determines the user permissions of the national cryptographic CPU card to be bound;
[0094] When the user privileges of the national cryptographic CPU card are ordinary unlocking users, the access control system binds the national cryptographic CPU card with the agreed auxiliary information of the national cryptographic card reader;
[0095] When the user of the national cryptographic CPU card has the privileges of a super administrator, the access control system binds the national cryptographic CPU card with the auxiliary information of all the national cryptographic card readers.
[0096] In this embodiment of the invention, each national cryptographic CPU card needs to be bound to a national cryptographic card reader in the access control system. The bound national cryptographic card reader is distinguished according to user permissions. User permissions may include super administrator users and ordinary unlocking users, but are not limited to these.
[0097] If the national cryptographic CPU card belongs to a super administrator user, the access control system should register the card to bind to all national cryptographic card readers. When issuing encrypted identity credentials, the quantum cryptography service platform should be informed that all national cryptographic card readers should encrypt the CPU card's identity credentials. If the CPU card belongs to a regular unlocking user, it should be bound to an agreed-upon national cryptographic card reader. When issuing encrypted identity credentials, the quantum cryptography service platform should be informed that the quantum key of the bound national cryptographic card reader should encrypt the CPU card's identity credentials. This embodiment of the invention allocates different permissions for binding national cryptographic card readers based on different user permissions. Regular unlocking users can only bind to specific national cryptographic card readers, while super administrator users can bind to all national cryptographic card readers. By limiting the binding scope of regular unlocking users, potential security risks can be reduced.
[0098] To enable those skilled in the art to better understand the embodiments of the present invention, a specific example is provided below. Specifically, the present invention discloses a method for entity identity authentication in a quantum access control system. The quantum access control system is an access control system based on a quantum secure key (quantum key), which includes:
[0099] Access control systems are used to store, manage, and authorize user information;
[0100] The national cryptographic CPU card is the entity being authenticated.
[0101] National cryptographic card readers are terminal devices used to identify other entities.
[0102] The quantum-safe U-shield is inserted into the backend of the access control system to protect the information exchanged between the access control system and the quantum cryptography service platform.
[0103] The quantum cryptography service platform, including the quantum cryptography service platform, quantum random number generator, quantum key exchange, and quantum key filling machine, provides key services.
[0104] When authenticating a national cryptographic CPU card, the card is placed against a national cryptographic card reader. The reader reads the card and retrieves its information (electronic tag). The reader then sends a random number to the CPU card as a challenge. The CPU card generates an authentication credential after receiving the random number and sends it to the reader. The reader then performs a verification process on its local machine. If the verification is successful, the access control system issues an unlocking command, and the door opens.
[0105] Specifically, the method for authenticating the country's cryptographic CPU card includes the following steps:
[0106] S1: Recharge: The national cryptographic CPU card, national cryptographic card reader, and quantum security U-shield are recharged with quantum keys at the quantum cryptography service platform.
[0107] S2: Authorization: For initial use, the access control system needs to complete the card-to-national cryptographic reader unlocking relationship binding. This unlocking relationship is used to locate the national cryptographic CPU card bound to the national cryptographic reader, i.e., the electronic tag of the national cryptographic CPU card and the electronic tag of the national cryptographic reader paired with the national cryptographic CPU card. This information is stored in the access control system's backend. When the access control system needs to request identity credentials from the cryptographic service platform, this unlocking relationship can be communicated to the quantum cryptography platform. The national cryptographic reader's quantum key encrypts the identity credentials of the paired national cryptographic CPU card; this information is referred to as auxiliary information. Using the quantum security U-shield auxiliary information and the national cryptographic CPU card's electronic tag, this information is uploaded to the quantum cryptography service platform. The quantum cryptography service platform decrypts the encrypted auxiliary information and electronic tag. Using a random number generated by an encrypted quantum random number generator and the electronic tags of all national cryptographic CPU cards, it obtains the identity credentials. Based on the quantum key of the national cryptographic reader provided by the access control system in the auxiliary information, it uses this key to encrypt the corresponding national cryptographic CPU card's identity credentials. The quantum key charged to the national cryptographic reader is used to encrypt the identity credentials and salt, resulting in the encrypted identity credentials issued to the access control system. The access control system issues encrypted identity credentials to the corresponding national cryptographic card reader based on the unlocking relationship. The national cryptographic card reader uses its own corresponding quantum key to decrypt the encrypted identity credentials and obtain the identity credentials.
[0108] S3: Identity Authentication: The national cryptographic CPU card is attached to the national cryptographic card reader, sending the electronic tag to the reader. After recognizing the electronic tag, the national cryptographic card reader sends a salt to the national cryptographic CPU card. The national cryptographic CPU card uses its pre-charged quantum key to encrypt the electronic tag and the salt, obtaining identity credentials, which are then sent to the national cryptographic card reader. The national cryptographic card reader completes entity authentication locally, and the electronic tag authentication is successful. Subsequently, based on the comparison result, the access control controller can be notified, and the access control controller issues an unlocking command to open the door.
[0109] In a specific example, the S2 method is as follows:
[0110] S201: After being filled with national cryptographic CPU cards A, their electronic tags UIDA are the electronic tags of national cryptographic CPU cards A. N national cryptographic CPU cards A can be represented by a set Ai (i=1,2,3...N), and the set of electronic tags is represented by UIDAi (i=1,2,3...N). The national cryptographic card reader is B, and its electronic tag can be represented by MIDB. M national cryptographic card readers can be represented by a set Bj (j=1,2,3...M). The unlocking relationship between national cryptographic CPU cards and national cryptographic card readers is manually completed in the access control system. The binding relationship between multiple cards and multiple card readers is as follows: UIDAi-MIDBj (i=1,2,3...N, j=1,2,3...M). After the unlocking relationship is bound, it can be stored in the access control system.
[0111] S202: The access control system applies to the quantum cryptography service platform at a fixed time every day to issue identity credentials based on the authorized physical card (national cryptographic CPU card). The identity credential is determined by the national cryptographic CPU card's identifier, salt (random number), and quantum key. It is then encrypted again with the quantum key of the national cryptographic card reader corresponding to the physical card to obtain an encrypted identity credential. The quantum cryptography service platform issues the encrypted identity credential to the access control system. The access control system's backend stores the unlocking relationship between the national cryptographic CPU card and the national cryptographic card reader, and distributes the encrypted identity credential to each national cryptographic card reader according to the physical card-reader binding relationship.
[0112] In a specific example, the S3 method is as follows:
[0113] S301: The national cryptographic CPU card calculates the identity credentials and sends them to the national cryptographic card reader. The national cryptographic card reader uses the identity credentials issued by the cryptographic system every day for verification, and the newly issued identity credentials overwrite the previous identity credentials.
[0114] S302: If the access control system is offline and the password system cannot issue identity credentials, the national cryptographic card reader will use the previous random number, Rd-1, and use the corresponding identity credentials for verification.
[0115] In a specific example, the specific method of S201 is as follows:
[0116] S401: In a specific example, each card needs to be bound to a national cryptographic card reader in the access control system. The bound national cryptographic card reader is distinguished according to user permissions. User permissions can include super administrator users and ordinary unlocking users.
[0117] S402: If the user of the national cryptographic CPU card is a super administrator user, then the access control system shall record the user's binding to all national cryptographic card readers, and when issuing encrypted identity credentials, the quantum cryptography service platform shall be informed that all national cryptographic card readers should encrypt the user's identity credentials; if the user of the national cryptographic CPU card is a regular unlocking user, then the user shall be bound to the agreed national cryptographic card reader, and when issuing encrypted identity credentials, the quantum cryptography service platform shall be informed that the quantum key of the bound national cryptographic card reader should encrypt the user's identity credentials.
[0118] In one specific example, the S202 method is as follows:
[0119] S501: The quantum cryptography system does not store the unlocking relationship between the national cryptographic CPU card and the national cryptographic card reader. The access control system needs to inform the quantum cryptography service platform which national cryptographic card readers' quantum keys are used to encrypt the identity credentials of the corresponding national cryptographic CPU cards. The quantum security U-shield of the access control system will encrypt and send the auxiliary information θc to the quantum cryptography service platform. The auxiliary information θc informs the quantum cryptography service platform which national cryptographic CPU cards' identity credentials are used to encrypt by the quantum key of the national cryptographic card reader.
[0120] S502: The quantum key of the quantum-secure U-shield is Kc, and the encrypted information is βm=EnKc[UIDAi,θc], (i=1,2,3...N).
[0121] S503: The quantum cryptography service platform decrypts βm, finds the corresponding symmetric key Kai (i=1,2,3...N) based on the electronic tags of all national cryptographic CPU cards, and calculates the identity credentials (i=1,2,3...N) of all national cryptographic CPU cards based on the salt generated by the quantum random number generator.
[0122] S504: Based on the auxiliary information θc, find the quantum key Kb of the national cryptographic CPU card reader corresponding to the national cryptographic CPU card, encrypt the identity credential to obtain the ciphertext identity credential (i=1,2,3...N), (j=1,2,3...M). This is used to protect the ciphertext sent to the national cryptographic card reader.
[0123] S505: The quantum random number generator of the quantum cryptography service platform updates the random number Rd at a fixed time every day.
[0124] S506: The quantum cryptography service platform uses a pre-distribution method to distribute the identity credentials and random number protection of all national cryptographic CPU cards to the access control system every morning.
[0125] S507: The access control system traverses all national cryptographic CPU cards and, based on the bound unlocking relationship UIDAi-MIDBj (i=1,2,3...N, j=1,2,3...M), accurately sends the encrypted identity credentials and random numbers to a fixed national cryptographic card reader.
[0126] In summary, the advantages of the embodiments of the present invention are that the embodiments of the present invention use a quantum cryptography service platform to enhance the security of traditional security access control systems.
[0127] 1. Provides a novel and more secure method for physical and environmental security entity identification:
[0128] (1) By using a quantum random number generator to generate new random numbers and by using the entity's symmetric key to encrypt the identification of the national cryptographic CPU card, it has higher security than the traditional electronic tag method.
[0129] (2) The access control system uses quantum cryptography service to encrypt and protect the key sensitive information of the card identification and upload it to the quantum cryptography service platform for issuing encrypted identity credentials.
[0130] 2. Compared to traditional standard entity identification methods, the embodiments of this invention have scalability and convenience:
[0131] (1) The embodiments of the present invention support an online authorization mechanism. Newly added national cryptographic CPU cards can be authorized directly in the access control system. When the access control system has a network connection, it will update and issue encrypted identity credentials in real time for identity authentication.
[0132] (2) The cryptographic system updates the salt and ciphertext identity credentials at a fixed time every day and immediately sends them to the access control system for identity authentication. Even when the network is down, identity authentication can be completed using the national cryptographic CPU card and the national cryptographic card reader, which is convenient.
[0133] It should be noted that the embodiments of the present invention may involve the use of user data. In practical applications, user-specific personal data may be used in the scheme described herein within the scope permitted by applicable laws and regulations, provided that it complies with the applicable laws and regulations of the country (e.g., with the user's explicit consent, with the user being properly notified, etc.).
[0134] It should also be noted that, for the sake of simplicity, the method embodiments are all described as a series of actions. However, those skilled in the art should understand that the embodiments of the present invention are not limited to the described order of actions, because according to the embodiments of the present invention, some steps can be performed in other orders or simultaneously. Secondly, those skilled in the art should also understand that the embodiments described in the specification are all preferred embodiments, and the actions involved are not necessarily essential to the embodiments of the present invention.
[0135] This invention also provides a quantum access control system for implementing the entity identity authentication method of the quantum access control system described in any of the above embodiments.
[0136] The above-described quantum access control system embodiment is basically similar to the method embodiment, so the description is relatively simple. For relevant details, please refer to the description of the method embodiment.
[0137] In the above embodiments, implementation can be achieved, in whole or in part, through software, hardware, firmware, or any combination thereof. When implemented in software, it can be implemented, in whole or in part, as a computer program product. The computer program product includes one or more computer instructions. When the computer program instructions are loaded and executed on a computer, all or part of the processes or functions described in the embodiments of the present invention are generated. The computer can be a general-purpose computer, a special-purpose computer, a computer network, or other programmable device. The computer instructions can be stored in a computer-readable storage medium or transmitted from one computer-readable storage medium to another. For example, the computer instructions can be transmitted from one website, computer, server, or data center to another website, computer, server, or data center via wired (e.g., coaxial cable, fiber optic, digital subscriber line (DSL)) or wireless (e.g., infrared, wireless, microwave, etc.) means. The computer-readable storage medium can be any available medium accessible to a computer or a data storage device such as a server or data center that integrates one or more available media. The available medium can be a magnetic medium (e.g., floppy disk, hard disk, magnetic tape), an optical medium (e.g., DVD), or a semiconductor medium (e.g., solid-state disk (SSD)).
[0138] It should be noted that, in this document, relational terms such as "first" and "second" are used only to distinguish one entity or operation from another, and do not necessarily require or imply any such actual relationship or order between these entities or operations. Furthermore, the terms "comprising," "including," or any other variations thereof are intended to cover non-exclusive inclusion, such that a process, method, article, or apparatus that comprises a list of elements includes not only those elements but also other elements not expressly listed, or elements inherent to such a process, method, article, or apparatus. Without further limitations, an element defined by the phrase "comprising one..." does not exclude the presence of other identical elements in the process, method, article, or apparatus that includes said element.
[0139] The various embodiments in this specification are described in a related manner. Similar or identical parts between embodiments can be referred to mutually. Each embodiment focuses on describing the differences from other embodiments. In particular, the system embodiments are basically similar to the method embodiments, so the description is relatively simple; relevant parts can be referred to the descriptions of the method embodiments.
[0140] The above description is merely a preferred embodiment of the present invention and is not intended to limit the scope of protection of the present invention. Any modifications, equivalent substitutions, improvements, etc., made within the spirit and principles of the present invention are included within the scope of protection of the present invention.
Claims
1. A method for entity identification in a quantum access control system, characterized in that, The quantum access control system includes a national cryptographic CPU card, a national cryptographic card reader, an access control system, an access control controller, and a quantum cryptography service platform. The national cryptographic CPU card, the national cryptographic card reader, and the access control system are each pre-loaded with corresponding quantum keys through the quantum cryptography service platform. Each of the national cryptographic CPU card, the national cryptographic card reader, and the access control system has a corresponding electronic tag. The access control system binds the electronic tag of the national cryptographic CPU card to the electronic tag of the national cryptographic card reader to obtain auxiliary information, and stores the auxiliary information in the background of the access control system. The method includes: The quantum cryptography service platform generates a random number, and generates an encrypted identity credential based on the random number, the auxiliary information, the electronic tag, and the quantum key corresponding to the national cryptographic card reader determined based on the auxiliary information, and sends the encrypted identity credential to the access control system; The access control system distributes the encrypted identity credentials to the corresponding national cryptographic card reader according to the binding relationship; The national cryptographic card reader decrypts the encrypted identity credential to obtain a decrypted identity credential and a random number; the identity credential is generated based on the electronic tag of the national cryptographic CPU card and the random number is generated by the quantum cryptography service platform; When the national cryptographic CPU card to be identified is placed on the national cryptographic card reader, the national cryptographic card reader reads the identification electronic tag of the national cryptographic CPU card to be identified, and sends the corresponding random number to the national cryptographic CPU card to be identified according to the identification electronic tag. The national cryptographic CPU card to be authenticated uses the random number and the local authentication electronic tag to generate an authentication credential, and sends the authentication credential to the national cryptographic card reader; The national cryptographic card reader compares the authentication credential with the identity credential to determine whether to instruct the access control controller to issue an unlocking command to open the door.
2. The method according to claim 1, characterized in that, The quantum access control system also includes a quantum security U-shield, which is inserted into the backend of the access control system and is used to protect the information exchanged between the access control system and the quantum cryptography service platform.
3. The method according to claim 2, characterized in that, The national cryptographic CPU card, the national cryptographic card reader, and the quantum-secure U-shield of the access control system are pre-charged with a first quantum key, a second quantum key, and a third quantum key respectively through the quantum cryptography service platform; the national cryptographic CPU card, the national cryptographic card reader, and the quantum-secure U-shield of the access control system correspond to a first electronic tag, a second electronic tag, and a third electronic tag respectively; the quantum cryptography service platform generates a random number, and generates an encrypted identity credential based on the random number, the auxiliary information, the electronic tag, and the quantum key corresponding to the national cryptographic card reader determined based on the auxiliary information, and sends the encrypted identity credential to the access control system, including: The access control system uses the third quantum key to encrypt the first electronic tag and the auxiliary information, and sends the encrypted first electronic tag and the auxiliary information to the quantum cryptography service platform; The quantum cryptography service platform determines the third quantum key corresponding to the quantum security U-shield of the access control system based on the third electronic tag, and uses the third quantum key to decrypt the encrypted first electronic tag and the auxiliary information to obtain the decrypted first electronic tag and the auxiliary information; The quantum cryptography service platform determines the first quantum key corresponding to the national cryptographic CPU card based on the first electronic tag. The quantum cryptography service platform generates a random number. After generating an identity credential based on the first quantum key corresponding to the first electronic tag and the random number, the platform encrypts the identity credential and the random number with the second quantum key corresponding to the second electronic tag corresponding to the first electronic tag according to the auxiliary information to obtain an encrypted identity credential. The encrypted identity credential is then sent to the access control system.
4. The method according to claim 1, characterized in that, The national cryptographic card reader compares the authentication credential with the identity credential to determine whether to instruct the access control controller to issue an unlocking command to open the door, including: The national cryptographic card reader compares the authentication credential with the identity credential. If the authentication credential matches the identity credential, the national cryptographic card reader sends a successful comparison result to the access control controller, so that the access control controller issues an unlocking command to control the door to open based on the successful comparison result; If the authentication credentials do not match, the national cryptographic card reader will issue an error message.
5. The method according to claim 1, characterized in that, The quantum cryptography service platform generates a random number, and generates an encrypted identity credential based on the random number, the auxiliary information, the electronic tag, and the quantum key corresponding to the national cryptographic card reader determined based on the auxiliary information, and sends the encrypted identity credential to the access control system, including: When the national cryptographic card reader, the access control system, and the quantum cryptography service platform are online, if the access control system obtains new auxiliary information by binding the electronic tag of the national cryptographic CPU card to the electronic tag of the national cryptographic card reader, or if a preset time is reached, the quantum cryptography service platform generates a random number and generates an encrypted identity credential based on the random number, the auxiliary information, the electronic tag, and the quantum key corresponding to the national cryptographic card reader determined based on the auxiliary information, and sends the encrypted identity credential to the access control system. The access control system uses the encrypted identity credentials to overwrite the encrypted identity credentials previously issued by the quantum cryptography service platform.
6. The method according to claim 5, characterized in that, The method further includes: When the national cryptographic card reader, the access control system, and the quantum cryptography service platform are offline, when the national cryptographic CPU card to be identified is placed on the national cryptographic card reader, the national cryptographic card reader reads the identification electronic tag of the national cryptographic CPU card to be identified, and sends the random number corresponding to the previous time to the national cryptographic CPU card to be identified according to the identification electronic tag. The national cryptographic CPU card to be authenticated uses the previously obtained random number and the local authentication electronic tag to generate an authentication credential, and sends the authentication credential to the national cryptographic card reader; The national cryptographic card reader compares the authentication credentials with the previous authentication credentials to determine whether to instruct the access control controller to issue an unlocking command to open the door.
7. The method according to claim 1, characterized in that, Before the quantum cryptography service platform generates a random number, and generates an encrypted identity credential based on the random number, the auxiliary information, the electronic tag, and the quantum key corresponding to the national cryptographic card reader determined based on the auxiliary information, and before sending the encrypted identity credential to the access control system, the method further includes: The access control system determines the user permissions of the national cryptographic CPU card to be bound; When the user privileges of the national cryptographic CPU card are ordinary unlocking users, the access control system binds the national cryptographic CPU card with the agreed auxiliary information of the national cryptographic card reader; When the user of the national cryptographic CPU card has the privileges of a super administrator, the access control system binds the national cryptographic CPU card with the auxiliary information of all the national cryptographic card readers.
8. A quantum access control system, characterized in that, Including the quantum access control system as described in any one of claims 1 to 7.
9. An electronic device, characterized in that, It includes a processor, a communication interface, a memory, and a communication bus, wherein the processor, the communication interface, and the memory communicate with each other through the communication bus; Memory, used to store computer programs; A processor, when executing a program stored in memory, implements the steps of the method described in any one of claims 1-7.
10. A computer-readable storage medium having a computer program stored thereon, characterized in that, When the program is executed by the processor, it implements the method as described in any one of claims 1-7.
Citation Information
Patent Citations
Data transmission protection method, intelligent card, server, and communication system
CN106603496A
Access control unlocking method, access control system and readable storage medium
CN116543488A