Image file transfer method, device and storage medium
By combining a key generated by quantum cryptography with a symmetric encryption algorithm, the image file and the key are encrypted, which solves the problem of reduced security of existing asymmetric encryption algorithms by quantum computers and achieves high security for image file transmission.
Patent Information
- Application Number
- CN202410903477.4
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2024-07-05
- Publication Date
- 2025-10-28
- Estimated Expiration
- 2044-07-05
AI Technical Summary
Existing public-key-based asymmetric encryption algorithms for image file transmission are significantly less secure in the face of quantum computers and cannot effectively guarantee the security of image files.
The mirror file and the key generated by quantum cryptography are encrypted using a quantum secure communication system. The mirror file is then encrypted using a symmetric encryption algorithm, and the encrypted key is further encrypted using the key generated by quantum cryptography to form encrypted data.
It improves the security of image file transmission, prevents the security reduction caused by quantum computers cracking asymmetric encryption algorithms, and ensures the security of encrypted data.
Smart Images

Figure CN118694525B_ABST
Abstract
Description
Technical Field
[0001] This application relates to the field of information security technology, and in particular to a method, apparatus and storage medium for transferring image files. Background Technology
[0002] With the development of cloud computing, container technology has become the preferred method for enterprises to package, deploy, and manage cloud applications. Container technology can package the files that an application depends on into an image file.
[0003] To ensure the security of image files during transmission, image storage encryption technology is typically used.
[0004] Currently, image storage encryption technology typically uses public-key-based asymmetric encryption algorithms to encrypt image files. Cracking asymmetric encryption algorithms is extremely time-consuming, thus ensuring their security. However, quantum computers can significantly reduce the time required to crack asymmetric encryption algorithms, thereby greatly reducing the security of current asymmetric encryption methods. Summary of the Invention
[0005] This application provides a method, apparatus, and storage medium for transmitting image files, which solves the problem of low security when encrypting image files using a public-key-based asymmetric encryption algorithm, and can greatly improve the security of image file encryption.
[0006] To achieve the above objectives, this application adopts the following technical solution:
[0007] In a first aspect, this application provides a method for transferring an image file, applied to a first device. The method includes: sending a first instruction to a quantum secure communication system; the first instruction being used to request a first key; the first key being a key generated based on quantum cryptography; receiving the first key from the quantum secure communication system; generating encrypted data based on the first key; the encrypted data including an image file encrypted based on a second key, and a second key encrypted based on the first key; and sending the encrypted data.
[0008] In conjunction with the first aspect mentioned above, in one possible implementation, the method further includes: generating a second key; the second key being a randomly generated key; encrypting the image file based on the second key and a first encryption algorithm; encrypting the second key based on the first key and a second encryption algorithm; and determining encrypted data based on the encrypted image file and the encrypted second key.
[0009] In conjunction with the first aspect mentioned above, in one possible implementation, the method further includes: uploading encrypted data to a mirror repository.
[0010] In conjunction with the first aspect mentioned above, in one possible implementation, the first encryption algorithm is a symmetric encryption algorithm; the second encryption algorithm is a symmetric encryption algorithm.
[0011] In conjunction with the first aspect mentioned above, in one possible implementation, the first key obtained by the first device is the same as the first key obtained by the second device; the first device and the second device are two devices for transmitting the image file.
[0012] Secondly, this application provides a method for transferring an image file, applied to a second device. The method includes: sending a second instruction to a quantum secure communication system; the second instruction being used to request a first key; the first key being a key generated based on quantum cryptography; receiving the first key from the quantum secure communication system; obtaining encrypted data; the encrypted data including an image file encrypted based on a second key, and a second key encrypted based on the first key; and decrypting the encrypted data based on the first key to determine the image file.
[0013] In conjunction with the second aspect above, in one possible implementation, the method further includes: decrypting a second key encrypted with the first key based on the first key; and decrypting the image file encrypted with the second key based on the decrypted second key to determine the image file.
[0014] In conjunction with the second aspect mentioned above, in one possible implementation, the method further includes: obtaining encrypted data from a mirror repository.
[0015] Thirdly, this application provides a communication system comprising: a first device, a second device, and a quantum secure communication system; the first device is configured to: send a first instruction to the quantum secure communication system; the first instruction is used to request a first key; the first key is a key generated based on quantum cryptography; the second device is configured to: send a second instruction to the quantum secure communication system; the second instruction is used to request the first key; the quantum secure communication system is configured to: send the first key based on the first instruction; send the first key based on the second instruction; the first device is further configured to: receive the first key from the quantum secure communication system; generate encrypted data based on the first key; send the encrypted data; the encrypted data includes an image file encrypted based on the second key, and the second key encrypted based on the first key; the second device is further configured to: receive the first key from the quantum secure communication system; obtain the encrypted data; decrypt the encrypted data based on the first key, and determine the image file.
[0016] In conjunction with the third aspect mentioned above, in one possible implementation, the quantum secure communication system includes a first quantum secure communication device and a first quantum key distribution node; the first device is specifically configured to: send a first instruction to the first quantum secure communication device; the first quantum secure communication device is configured to: send the first instruction to the first quantum key distribution node; the first quantum key distribution node is configured to: send a first key based on the first instruction; the first quantum secure communication device is further configured to: receive the first key and send the first key.
[0017] In conjunction with the third aspect mentioned above, in one possible implementation, the quantum secure communication system further includes a second quantum secure communication device and a second quantum key distribution node; the second device is specifically configured to: send a first instruction to the second quantum secure communication device; the second quantum secure communication device is configured to: send a second instruction to the second quantum key distribution node; the second quantum key distribution node is configured to: send a first key based on the second instruction; the first key in the second quantum key distribution node is shared with the first key of the first quantum key distribution node; the second quantum secure communication device is also configured to: receive the first key and send the first key.
[0018] Fourthly, this application provides a mirror file transfer device, the device comprising: a communication unit and a processing unit; the communication unit is configured to send a first instruction to a quantum secure communication system; the first instruction is configured to request a first key; the first key is a key generated based on quantum cryptography; the communication unit is further configured to receive the first key from the quantum secure communication system; the processing unit is configured to generate encrypted data based on the first key; the encrypted data includes a mirror file encrypted based on a second key, and a second key encrypted based on the first key; the communication unit is further configured to send the encrypted data.
[0019] In conjunction with the fourth aspect above, in one possible implementation, the processing unit is specifically used for: generating a second key; the second key is a randomly generated key; encrypting the image file based on the second key and the first encryption algorithm; encrypting the second key based on the first key and the second encryption algorithm; and determining encrypted data based on the encrypted image file and the encrypted second key.
[0020] In conjunction with the fourth aspect above, in one possible implementation, the communication unit is specifically used to: upload encrypted data to the mirror repository.
[0021] In conjunction with the fourth aspect mentioned above, in one possible implementation, the first encryption algorithm is a symmetric encryption algorithm; the second encryption algorithm is a symmetric encryption algorithm.
[0022] In conjunction with the fourth aspect above, in one possible implementation, the first key obtained by the first device is the same as the first key obtained by the second device; the first device and the second device are two devices for transmitting the image file.
[0023] Fifthly, this application provides a mirror file transfer device, the device comprising: a communication unit and a processing unit; the communication unit is configured to send a second instruction to a quantum secure communication system; the second instruction is configured to request a first key; the first key is a key generated based on quantum cryptography; the communication unit is further configured to receive the first key from the quantum secure communication system; the communication unit is further configured to acquire encrypted data; the encrypted data includes a mirror file encrypted based on a second key, and a second key encrypted based on the first key; the processing unit is configured to decrypt the encrypted data based on the first key to determine the mirror file.
[0024] In conjunction with the fifth aspect above, in one possible implementation, the processing unit is specifically used for: decrypting a second key encrypted based on the first key; and decrypting an image file encrypted based on the second key based on the decrypted second key to determine the image file.
[0025] In conjunction with the fifth aspect above, in one possible implementation, the communication unit is specifically used to: retrieve encrypted data from the mirror repository.
[0026] In a sixth aspect, this application provides a mirror file transfer apparatus, the apparatus comprising: a processor and a communication interface; the communication interface and the processor are coupled, the processor being configured to run computer programs or instructions to implement the mirror file transfer method as described in the first aspect, any possible implementation of the first aspect, the second aspect, and any possible implementation of the second aspect.
[0027] In a seventh aspect, this application provides a computer-readable storage medium storing instructions that, when executed on a terminal, cause the terminal to perform the image file transfer method described in the first aspect, any possible implementation of the first aspect, the second aspect, and any possible implementation of the second aspect.
[0028] Eighthly, this application provides a computer program product containing instructions that, when the computer program product is run on a mirror file transfer device, causes the mirror file transfer device to perform the mirror file transfer method as described in the first aspect, any possible implementation of the first aspect, the second aspect, and any possible implementation of the second aspect.
[0029] Ninthly, this application provides a chip including a processor and a communication interface, the communication interface being coupled to the processor, the processor being used to run computer programs or instructions to implement the image file transfer method described in the first aspect, any possible implementation of the first aspect, the second aspect, and any possible implementation of the second aspect.
[0030] Specifically, the chip provided in this application also includes a memory for storing computer programs or instructions.
[0031] It should be noted that the aforementioned computer instructions may be stored, in whole or in part, on a computer-readable storage medium. This computer-readable storage medium may be packaged together with the processor of the device, or it may be packaged separately from the processor of the device; this application does not impose any limitation on this.
[0032] The descriptions of aspects two through nine in this application can be referenced to the detailed description of aspect one; and the beneficial effects of the descriptions of aspects two through nine can be referenced to the analysis of the beneficial effects of aspect one, which will not be repeated here.
[0033] In this application, the name of the aforementioned image file transfer device does not limit the device or functional module itself. In actual implementation, these devices or functional modules may appear under other names. As long as the function of each device or functional module is similar to that of this application, it falls within the scope of the claims of this application and its equivalents.
[0034] These or other aspects of this application will become more readily apparent in the following description.
[0035] The above solution offers at least the following advantages: Based on the above technical solution, the image file transfer method provided in this application involves a first device sending a first instruction to a quantum secure communication system, requesting a first key. A second device also sends a second instruction to the quantum secure communication system, requesting the first key. The first device, based on the requested first key, generates an image file encrypted with a second key, and encrypted data using the second key encrypted with the first key, and sends the encrypted data. The second device obtains the encrypted data and, based on the requested first key, decrypts the encrypted data to determine the image file. Since the first key is generated using quantum cryptography, the true randomness of quantum cryptography fundamentally guarantees encryption security. Compared to current public-key-based asymmetric encryption algorithms, this reduces the time required to crack asymmetric encryption algorithms, thus reducing security. The above technical solution can significantly improve the security of image file encryption. Attached Figure Description
[0036] Figure 1 A schematic diagram of a mirror image composition provided for an embodiment of this application;
[0037] Figure 2 A schematic diagram illustrating the determination of a mirror model provided in an embodiment of this application;
[0038] Figure 3 A schematic diagram illustrating another method for determining a mirror model, as provided in an embodiment of this application;
[0039] Figure 4 A schematic diagram of the architecture of a quantum secure communication system provided in this application embodiment;
[0040] Figure 5 This is a schematic diagram illustrating a mirror file transfer method provided in an embodiment of this application.
[0041] Figure 6 This application provides a schematic diagram of the architecture of a communication system.
[0042] Figure 7 This is a schematic diagram of the architecture of another communication system provided in an embodiment of this application;
[0043] Figure 8 A schematic diagram of the hardware structure of a mirror file transfer device provided in an embodiment of this application;
[0044] Figure 9 A flowchart illustrating a method for transferring image files provided in this application embodiment;
[0045] Figure 10 A schematic diagram illustrating a method for transferring mirror files provided in an embodiment of this application;
[0046] Figure 11 A flowchart illustrating another image file transfer method provided in this application embodiment;
[0047] Figure 12 This is a schematic diagram of the structure of a mirror file transfer device provided in an embodiment of this application;
[0048] Figure 13 This is a schematic diagram of another image file transfer device provided in an embodiment of this application. Detailed Implementation
[0049] The technical solutions of the embodiments of this application will be clearly and completely described below with reference to the accompanying drawings. Obviously, the described embodiments are only some embodiments of this application, and not all embodiments. Based on the embodiments of this application, all other embodiments obtained by those skilled in the art without creative effort are within the scope of protection of this application.
[0050] In this article, the term "and / or" is merely a description of the relationship between related objects, indicating that there can be three relationships. For example, A and / or B can represent three situations: A exists alone, A and B exist simultaneously, and B exists alone.
[0051] The terms "first" and "second," etc., used in the specification and drawings of this application are used to distinguish different objects or to distinguish different treatments of the same object, rather than to describe a specific order of objects.
[0052] Furthermore, the terms "comprising" and "having," and any variations thereof, used in the description of this application are intended to cover non-exclusive inclusion. For example, a process, method, system, product, or apparatus that includes a series of steps or units is not limited to the steps or units listed, but may optionally include other steps or units not listed, or may optionally include other steps or units inherent to such process, method, product, or apparatus.
[0053] It should be noted that in the embodiments of this application, the words "exemplary" or "for example" are used to indicate examples, illustrations, or explanations. Any embodiment or design scheme described as "exemplary" or "for example" in the embodiments of this application should not be construed as being more preferred or advantageous than other embodiments or design schemes. Specifically, the use of the words "exemplary" or "for example" is intended to present the relevant concepts in a specific manner.
[0054] In the description of this application, unless otherwise stated, "a plurality of" means two or more.
[0055] The following explanations of the terms used in the embodiments of this application are provided to facilitate the reader's understanding.
[0056] (1) Open Container Initiative (OCI) image specifications
[0057] Images can be generated according to different specifications. Common image specifications include the open-source Container Engine (Docker) image specification and the OCI image specification. Docker has defined image specification v2, which was implemented in Docker version 1.10 (Docker 1.10), and image specification v2 has become the de facto standard. The OCI image specification 1.0 released by OCI is essentially based on image specification v2, therefore the two are compatible or similar in most cases. In addition to defining image specifications, OCI has also defined runtime specifications and distribution specifications. The establishment of the OCI image specification is of great significance in promoting the openness, collaboration, standardization, and interoperability of container images.
[0058] The OCI image specification states that an image consists of an image index, manifest, configuration, and image layer files. The following details each component of an image:
[0059] Image index: Formatted as application / vnd.oci.image.index.v1+json. The image index is optional; it specifies a set of related images supporting different architecture platforms (e.g., ARM and AMD processors, Linux and Windows architecture systems), applicable to one or more platforms. Users do not need to specify the operating system and platform; they can rely entirely on the client to obtain the correct image version.
[0060] The manifest, in the format application / vnd.oci.image.manifest.v1+json, is a JSON-formatted description file that lists the image's configuration and layer files. The image manifest specification has three main goals. The first is image content addressing, using hash operations to generate unique identifiers (identitydocuments, IDs) for the image content; the second is allowing multi-architecture images; and the third is conversion to the OCI runtime specification.
[0061] Configuration: The format is application / vnd.oci.image.config.v1+json. The configuration is a JSON-formatted description file that describes basic information about the container image, such as creation date and author. Locally, a summary of the configuration serves as the identifier for the local image.
[0062] Layer files: The formats are application / vnd.oci.image.layer.v1.tar (tar format), application / vnd.oci.image.layer.v1.tar+gzip (gzip compression), and application / vnd.oci.image.Layer.v1.tar+zstd (zstd compression). Layer files are the content of the image, i.e., the files contained within the image, generally in binary data file format. An image can have one or more layer files, which together constitute the image file.
[0063] The mirror index is the entry point for the mirror referenced files, such as... Figure 1 As shown, the image index file provides guidance on listings for different platforms, which in turn guides you through the image's configuration and layer files.
[0064] (2) Container Image
[0065] Container images can be built from text files (Dockerfiles) that create images of Linux architecture systems, and then stored locally using tools like Skopeo.
[0066] The contents of the Dockerfile are as follows:
[0067] FROM scratch # Create from an empty image
[0068] MAINTAINER Tintin #Mirror Creator Information
[0069] ADD . / rootfs-CentOS7.9.tar.gz / # Add the compressed file to the root directory
[0070] Based on my-centos7.9:v0, build my-centos7.9:v1 using the following Dockerfile:
[0071] FROM my-centos7.9:v0 # Create based on my-centos7.9:v0
[0072] MAINTAINER Tintin-1 #Mirror Creator Information
[0073] RUN echo "Hello Tintin"> / root / tintin.txt # Create the tintin.txt file in the root directory.
[0074] like Figure 2 As shown, the process of determining the image model of my-centos7.9:v0 may include: first determining the index (index.json), then determining the corresponding manifest, and then further determining the configuration and layer files from the manifest.
[0075] The manifest name can be: 3de3dac6627775e0ee21a735c289b3d2, b2714792285caf93f06044999178fb3. The configuration name can be: 1015af5913b2f4e8236a4a8f8c3d9cf178, 5d7de05327f7358d26bfb1cd37af. The layer file name can be: 211aef66f65333821c90a1f7ab4cc, 552233351ff4bd4da23acfed46e613a096f.
[0076] like Figure 3 As shown, the process of determining the image model of my-centos7.9:v1 may include: based on the image model of my-centos7.9:v0, generating layer file 2 parallel to layer file 1 based on the generation process of layer file 1.
[0077] The name of layer file 2 can be 876be2c729783dc484d672e6a3cbb9dfc70183ff339844a219a6a99a158c23ec.
[0078] Comparing the image models my-centos7.9:v0 and my-centos7.9:v1, we can see that the content and name of layer file 1 remain unchanged. Unzipping the newly added layer file 2 reveals its content, root / tintin.txt.
[0079] (3) Quantum key distribution technology
[0080] Quantum secure communication based on quantum key distribution (QKD) can address the security challenges posed by quantum computing and has now entered the stage of industrial-scale application. QKD is a mature and practically applicable quantum communication technology that has been tested both theoretically and practically. It can securely distribute keys between communicating parties by transmitting quantum states and has been proven to have "information-theoretical security" (also known as "unconditional security"). As long as the fundamental principles of quantum physics are not violated, no matter how powerful the attacker's computing power (including quantum computers) is, it cannot affect the security of QKD.
[0081] like Figure 4 As shown, the quantum secure communication system consists of two parts: a QKD network layer and a user network layer. In the QKD network layer, multiple QKD nodes are connected via QKD links to form a QKD network. QKD links are typically built on public fiber optic networks or satellite links, providing the necessary quantum and classical channels for long-distance quantum key negotiation. The quantum channel transmits optical quantum signals carrying quantum state information, while the classical channel transmits classical signals related to post-key processing operations such as basis vector alignment and error checking. QKD nodes obtain end-to-end symmetric keys through QKD key negotiation and trusted key relay processing, and perform full lifecycle key management, meeting the needs of secure communication for upper-layer users in large-scale environments such as wide-area and metropolitan areas.
[0082] like Figure 4 As shown, during secure data transmission, quantum secure communication device A in the user network layer accesses the corresponding QKD service node (i.e., QKD node A) through the access key (Ak) interface, and quantum secure communication device B accesses the corresponding QKD service node (i.e., QKD node B) through the Ak interface, requesting to obtain the session key Ks required for communication with the peer. Subsequently, quantum secure communication devices A and B can verify the authenticity of the peer's user identity based on the session key Ks and encrypt the plaintext data sent by the user, ensuring the security of user information communication on traditional network public channels.
[0083] With the development of cloud computing, cloud-native technologies have entered a period of rapid growth. Today, cloud-native technologies, represented by containers, immutable infrastructure, microservices, service meshes, and declarative application programming interfaces (APIs), are widely adopted in digital business environments across various industries. Among these, container technology has become the preferred method for enterprises to package, deploy, and manage cloud applications. Container technology can package the files that an application depends on into an image file. With the help of container technology, the startup, deployment, and operation of applications are becoming increasingly convenient.
[0084] Container technology specifically packages the engine, system libraries, configuration files, and workloads running on containers required for application execution into an image file. Key technologies employed in the design of image files include tiered storage, copy-on-write, content addressing, and federated mounting. These key technologies give container technology advantages such as fast download and easy deployment, including convenient portability, lightweight design, and high stability.
[0085] The advantages of easy portability, lightweight design, and high stability will be explained below.
[0086] (1) Easy to port
[0087] Container technology packages and encapsulates all the files that an application depends on to run. Therefore, image files are easily portable in computing environments, reducing the complexity of environment adaptation processes.
[0088] (2) Lightweight
[0089] Because image files are stored in layers, different image layers can share the underlying image layer files. The copy-on-write and union mount technology for image files allows changes to the image file to be implemented by modifying only the topmost image layer, thus saving storage space and enabling rapid copying of container image files.
[0090] (3) High stability
[0091] Image files are content-addressable, avoiding conflicts and achieving isolation between different images. Furthermore, once built, image files become read-only, forming part of an immutable infrastructure and ensuring image stability.
[0092] The security risks of image files can be divided into the security risks of the image itself, the risks of image management, and the risks of image repositories.
[0093] Among the security risks inherent in Docker images themselves, the leakage of sensitive information from these images is escalating. Researchers have discovered tens of thousands of images containing exposed sensitive data and source code in public image repositories (such as Docker Hub). Analysis of some source code images revealed multiple valid private keys and API keys within them. This leaked sensitive data could lead to consequences such as man-in-the-middle attacks and identity forgery.
[0094] To ensure the security of container image files during transmission, image storage encryption technology is typically used. This ensures the security of the image file during transfer. Image storage encryption technology is an important means of protecting users' private data security; encrypting the image file guarantees the confidentiality of its data. From the build stage to the runtime stage, the data in the image file remains confidential. Even if the distribution process is compromised, the content of the image file remains confidential. This mechanism can be used to protect encrypted transactions or other confidential materials. Furthermore, when image encryption is combined with key management, authorization, and credential distribution, it can be required that the image only runs on a specific platform, achieving secure and controllable image distribution authorization.
[0095] Currently, image storage encryption technology typically uses public-key-based asymmetric encryption algorithms to encrypt image files. With the development of quantum technology, the security of public-key-based asymmetric encryption algorithms faces significant challenges. Asymmetric encryption algorithms rely on the security of large integer factorization; on a classical computer, breaking an asymmetric encryption algorithm—essentially factoring two large prime numbers—is extremely difficult, thus ensuring its security. However, Shor's algorithm in quantum mechanics can solve this problem in polynomial time complexity on a quantum computer. Once a sufficiently large and stable quantum computer becomes practical, the time required to break asymmetric encryption algorithms can be significantly reduced. This would render public-key-based asymmetric encryption algorithms and other cryptographic systems relying on the large number factorization problem insecure, greatly diminishing the security of current asymmetric encryption algorithms.
[0096] Furthermore, the current encryption process is cumbersome. It uses a private key, a public key, a content encrypting key (CEK), and a lightweight encryption key (LEK). The encryption algorithms used include Block Counting Mode (AES-CTR), Asymmetric Encryption Padding (RSA-OAEP), and Symmetric Encryption Mode (AES-GCM), making the process quite complex. In addition, the key information is stored in the image's manifest file, posing a security vulnerability. Hackers could use this stored key information to attack the encrypted image.
[0097] The following describes the transmission process of an image file based on a public-key asymmetric encryption algorithm.
[0098] A container image contains an index, manifest, configuration, and layer files, with the image layer files occupying the largest amount of data. To improve the efficiency of image encryption without compromising its security, a symmetric encryption algorithm is used to encrypt the image layer data, and an asymmetric encryption algorithm is used to encrypt the key used for the symmetric encryption. The encrypted key is then stored in the manifest file, which is uploaded to the image repository along with the image layer files.
[0099] like Figure 5 As shown, device A creates a public key and a private key for asymmetric encryption. Figure 5Device B transmits an encrypted image to Device A. Device B needs to obtain Device A's public key and randomly generate a 256-bit symmetric encryption key (LEK). It then uses a symmetric encryption algorithm (AES CTR) to encrypt the image layers, resulting in an encrypted image layer file. Next, Device B uses Device A's public key to encrypt the LEK using an asymmetric encryption algorithm (RSA-OAEP), obtaining the encrypted LEK (Wrapped Key). Device B stores the encrypted LEK in its Manifest file. Device B then uploads the encrypted image data (including the Manifest file and the encrypted image layer file) to an image repository. Device A downloads the encrypted image data from the image repository, decrypts the Manifest file using its private key to obtain the LEK, and then uses the LEK to decrypt the encrypted image layer file, obtaining the image layer file.
[0100] In view of this, the image file transmission method provided in this application involves a first device sending a first instruction to a quantum secure communication system, requesting a first key. A second device also sends a second instruction to the quantum secure communication system, requesting the first key. Based on the requested first key, the first device generates an image file encrypted with a second key, and encrypted data using the second key encrypted with the first key, and sends the encrypted data. The second device obtains the encrypted data and decrypts it based on the requested first key to determine the image file. Since the first key is generated using quantum cryptography, the true randomness of quantum cryptography fundamentally guarantees encryption security. Compared to current public-key-based asymmetric encryption algorithms, this reduces the time required to crack asymmetric encryption algorithms, thus reducing security. The above technical solution can significantly improve the security of image file encryption.
[0101] The embodiments of this application will now be described in detail with reference to the accompanying drawings.
[0102] Figure 6 This is a schematic diagram of the architecture of a communication system provided in an embodiment of this application. Figure 6 As shown, the communication system includes: a first device 601, a second device 602, and a quantum secure communication system 603.
[0103] The first device 601 and the quantum secure communication system 603 are connected via a communication link. The second device 602 and the quantum secure communication system 603 are also connected via a communication link. This communication link can be a wired communication link or a wireless communication link; this application does not limit the type of link.
[0104] For example, the first device 601 and the second device 602 involved in this application can be either a terminal or a server. Of course, the above is only an exemplary description of the first device 601 and the second device 602, and the first device 601 and the second device 602 may be other devices in the future. This application embodiment does not impose any limitations on this.
[0105] Optionally, the first device and the second device are two devices that transmit the image file. Furthermore, the first key obtained by the first device is the same as the first key obtained by the second device.
[0106] In one possible implementation, the terminal in this application embodiment can also be a user-side entity used to receive signals, or transmit signals, or both receive and transmit signals. The terminal is used to provide users with one or more of voice services and data connectivity services. The terminal can also be referred to as user equipment (UE), terminal, access terminal, user unit, user station, mobile station, remote station, remote terminal, mobile device, user terminal, wireless communication equipment, user agent, or user device. Terminal 101 can be a vehicle-to-everything (V2X) device, such as a smart car, digital car, unmanned car, driverless car, pilotless car, autonomous car, pure electric vehicle (EV), hybrid electric vehicle (HEV), range-extended electric vehicle (REEV), plug-in hybrid electric vehicle (PHEV), or new energy vehicle. The terminal can also be a device-to-device (D2D) device, such as an electricity meter or a water meter.
[0107] Terminals can also be mobile stations (MS), subscriber units, drones, Internet of Things (IoT) devices, stations (ST) in WLANs, cellular phones, smartphones, cordless phones, wireless data cards, tablets, session initiation protocol (SIP) phones, wireless local loop (WLL) stations, personal digital assistant (PDA) devices, laptop computers, machine-type communication (MTC) terminals, handheld devices with wireless communication capabilities, computing devices or other processing devices connected to a wireless modem, in-vehicle devices, and wearable devices (also known as wearable smart devices). Terminals can also be terminal devices in next-generation communication systems, such as terminal devices in 5G systems or in future PLMNs, and terminal devices in NR systems.
[0108] The first device 601 will be described in detail below.
[0109] In one possible implementation, the first device 601 sends a first instruction to the quantum secure communication system 603 to request a first key. The first device 601 receives the first key from the quantum secure communication system 603 and generates encrypted data based on the first key. The encrypted data is then sent.
[0110] Optionally, the first device 601 is also used to generate a second key (e.g., a 256-bit data encryption key L). The first device 601 encrypts the image file using the second key and encrypts the second key using the first key. Then, the image file encrypted with the second key and the second key encrypted with the first key are packaged and encapsulated as encrypted data.
[0111] The second device 602 will be described in detail below.
[0112] In one possible implementation, the second device 602 sends a second instruction to the quantum secure communication system 603 to request a first key. The second device 602 receives the first key from the quantum secure communication system and obtains encrypted data. Based on the first key, the second device 602 decrypts the encrypted data and determines the image file.
[0113] The following is a detailed introduction to the 603 quantum secure communication system.
[0114] In one possible implementation, the quantum secure communication system 603 is used to send a first key based on a first instruction. The quantum secure communication system 603 is also used to send the first key based on a second instruction.
[0115] Optional, such as Figure 7 As shown, the quantum secure communication system 603 includes a first quantum secure communication device 6031 and a first quantum key distribution node 6032.
[0116] The first quantum secure communication device 6031 is connected to the first device 601 via a communication link. The first quantum secure communication device 6031 is also connected to the first quantum key distribution node 6032 via a communication link.
[0117] In one possible implementation, the first quantum secure communication device 6031 receives a first instruction from the first device 601 and, based on the first instruction, sends a first instruction to the first quantum key distribution node 6032. The first quantum key distribution node 6032, based on the first instruction, sends a first key. The first quantum secure communication device 6031 receives the first key and sends the first key.
[0118] Optional, such as Figure 7 As shown, the quantum secure communication system also includes a second quantum secure communication device 6033 and a second quantum key distribution node 6034.
[0119] Specifically, the second quantum secure communication device 6033 is connected to the second device 602 via a communication link. The second quantum secure communication device 6033 is also connected to the second quantum key distribution node 6034 via a communication link. The second quantum secure communication device 6033 is connected to the first quantum secure communication device 6031 via a communication link. The second quantum key distribution node 6034 is connected to the first quantum key distribution node 6032 via a communication link.
[0120] In one possible implementation, the second quantum secure communication device 6033 receives a second instruction from the second device 602 and, based on the second instruction, sends a second instruction to the second quantum key distribution node 6034. The second quantum key distribution node 6034, based on the second instruction, sends a first key. The second quantum secure communication device 6033 receives the first key and sends the first key back.
[0121] It should be noted that the first key in the second quantum key distribution node 6034 is shared with the first key in the first quantum key distribution node.
[0122] Optional, such as Figure 7As shown, the communication system may also include a mirror repository 604.
[0123] The mirror repository 604 is connected to the first device 601 via a communication link. The mirror repository 604 is also connected to the second device 602 via a communication link.
[0124] In one possible implementation, the mirror repository 604 is used to store the encrypted data sent by the first device 601. The mirror repository 604 is also used to send the encrypted data to the second device 602.
[0125] For example, the image repository 604 involved in this application can be a public image repository or a private image repository. Of course, the above is only an exemplary description of the image repository 604, and the image repository 604 may also be other image repositories or storage devices with image storage functions in the future. This application embodiment does not impose any restrictions on this.
[0126] When implemented in hardware, the various modules of the communication system can be integrated into, for example... Figure 8 The image file transfer device shown is implemented on a hardware structure. Specifically, as... Figure 8 As shown, the basic hardware structure of the image file transfer device is introduced.
[0127] Figure 8 This is a schematic diagram of the hardware structure of a mirror file transfer device provided in an embodiment of this application. Figure 8 As shown, the image file transfer device includes at least one processor 801, a communication line 802, and at least one communication interface 804, and may also include a memory 803. The processor 801, memory 803, and communication interface 804 are connected via the communication line 802.
[0128] The processor 801 may be a central processing unit (CPU), an application-specific integrated circuit (ASIC), or one or more integrated circuits configured to implement the embodiments of this application, such as one or more digital signal processors (DSPs), or one or more field-programmable gate arrays (FPGAs).
[0129] Communication line 802 may include a path for transmitting information between the aforementioned components.
[0130] The communication interface 804 is used to communicate with other devices or communication networks. It can use any transceiver-like device, such as Ethernet, radio access network (RAN), wireless local area network (WLAN), etc.
[0131] The memory 803 may be a read-only memory (ROM) or other type of static storage device capable of storing static information and instructions, random access memory (RAM) or other type of dynamic storage device capable of storing information and instructions, or electrically erasable programmable read-only memory (EEPROM), compact disc read-only memory (CD-ROM) or other optical disc storage, optical disc storage (including compressed optical discs, laser discs, optical discs, digital universal optical discs, Blu-ray discs, etc.), magnetic disk storage media or other magnetic storage devices, or any other medium capable of including or storing desired program code in the form of instructions or data structures and accessible by a computer, but not limited thereto.
[0132] In one possible design, the memory 803 can exist independently of the processor 801, meaning the memory 803 can be an external memory of the processor 801. In this case, the memory 803 can be connected to the processor 801 via a communication line 802 to store execution instructions or application code, and its execution is controlled by the processor 801 to implement the image file transfer method provided in the following embodiments of this application. In another possible design, the memory 803 can also be integrated with the processor 801, meaning the memory 803 can be an internal memory of the processor 801. For example, the memory 803 can be a cache, used to temporarily store some data and instruction information.
[0133] As one possible implementation, processor 801 may include one or more CPUs, for example Figure 8 CPU0 and CPU1 in the image. As another possible implementation, the image file transfer device may include multiple processors, such as... Figure 8 The image file transfer device includes processors 801 and 807. As another possible implementation, the image file transfer device may also include an output device 805 and an input device 806.
[0134] It should be noted that the various embodiments of this application can be referenced or learned from each other. For example, the same or similar steps, method embodiments, system embodiments and device embodiments can be referenced from each other without limitation.
[0135] Figure 9 A flowchart illustrating a method for transferring mirror files provided in this application embodiment, which can be applied to, for example... Figure 6 The communication system shown. For example... Figure 9 As shown, the method includes the following S901-S907.
[0136] S901, the first device sends a first command to the quantum secure communication system. Correspondingly, the quantum secure communication system receives the first command from the first device.
[0137] The first instruction is used to request the first key; the first key is a key generated based on quantum cryptography.
[0138] Optionally, the first key can be a 256-bit customer master key (CMK) generated based on quantum cryptography.
[0139] In one possible implementation, the S901 implementation process can be as follows: Figure 10 As shown, the first device sends a first command to the first quantum secure communication device in the quantum secure communication system. Correspondingly, the first quantum secure device receives the first command.
[0140] In another possible implementation, the S901 process can be as follows: the first device sends a first instruction to the access network device. The access network device receives the first instruction and then sends the first instruction to the quantum secure communication system.
[0141] Furthermore, in some possible implementations, the access network device can send the first command to the quantum secure communication system via transparent transmission. Alternatively, the access network device can also send the first command to the quantum secure communication system via relay transmission. Or, the access network device can also send the first command to the quantum secure communication system via encrypted transmission.
[0142] In another possible implementation, where there is a direct communication link between the first device and the quantum secure communication system, without the need for information relay through an access network device, the first device can send a first instruction to the quantum secure communication system through this direct communication link.
[0143] Of course, the above is only an exemplary description of transmitting the first instruction. The implementation process of transmitting the first instruction can also be implemented in the future by other transmission methods, and this application embodiment does not impose any restrictions on this.
[0144] S902, the quantum secure communication system sends a first key to the first device based on a first instruction. Correspondingly, the first device receives the first key from the quantum secure communication system.
[0145] One possible implementation is, such as Figure 10 As shown, when the first device sends a first instruction to the first quantum secure communication device in the quantum secure communication system, the first quantum secure communication device sends the first instruction to the first quantum key distribution node. Correspondingly, the first quantum key distribution node receives the first instruction from the first quantum secure communication device. Based on the first instruction, the first quantum key distribution node sends a first key. Correspondingly, the first quantum secure communication device receives the first key. The first quantum secure communication device sends the first key. Correspondingly, the first device receives the first key.
[0146] In another possible implementation, the quantum secure communication system sends a first key to the access network device. The access network device receives the first key and sends it to a first device. The first device receives the first key.
[0147] S903, The first device generates encrypted data based on the first key.
[0148] The encrypted data includes an image file encrypted with a second key, and a second key encrypted with a first key.
[0149] One possible implementation is, such as Figure 10 As shown, the first device randomly generates a second key. The first device encrypts the image file using the second key and a first encryption algorithm. The first device encrypts the second key using the first key and a second encryption algorithm. The first device determines the encrypted data based on the encrypted image file and the encrypted second key.
[0150] Specifically, the process by which the first device determines the encrypted data can be referred to the embodiments shown in S1101-S1104, and will not be repeated here.
[0151] In another possible implementation, the first device can directly encrypt the image file based on the first key to determine that the encrypted image file is encrypted data.
[0152] Optionally, after the first device generates encrypted data, an encryption identifier is added to the annotations parameter in the image manifest corresponding to the image file to indicate that the image file has been encrypted.
[0153] The encryption identifier includes a field identifier indicating the source of the key (e.g., the key originates from a quantum secure communication system), a key length identifier (e.g., the key length can be 256 bits), and a string representing the encrypted second key.
[0154] Optionally, the image file is the image layer file in the image data, which also includes the image index, image manifest, and configuration file.
[0155] Optionally, the image file can also contain all data in the image data, including image layer files, image index, image manifest, and configuration files.
[0156] S904. The first device sends encrypted data. Correspondingly, the second device receives the encrypted data.
[0157] One possible implementation is, such as Figure 10 As shown, the first device uploads encrypted data to the image repository. The second device retrieves the encrypted data from the image repository.
[0158] Optionally, the first device can upload the encrypted data, image index, image manifest, and configuration files to the image repository. The second device retrieves the encrypted data, image index, image manifest, and configuration files from the image repository.
[0159] Optionally, the first device can also upload the encrypted data to a storage device or similar device. Correspondingly, the second device can also retrieve the encrypted data from the storage device; this application does not limit this.
[0160] S905, the second device sends a second command to the quantum secure communication system. Correspondingly, the quantum secure communication system receives the second command from the second device.
[0161] The second instruction is used to request the first key; the first key is a key generated based on quantum cryptography.
[0162] In one possible implementation, the S905 implementation process can be as follows: Figure 10 As shown, the second device sends a second command to the second quantum secure communication device in the quantum secure communication system. Correspondingly, the second quantum secure device receives the second command.
[0163] In another possible implementation, the S905 process can be as follows: the second device sends a second command to the access network device. The access network device receives the second command and then sends the second command to the quantum secure communication system.
[0164] Furthermore, in some possible implementations, the access network device can send the second command to the quantum secure communication system via transparent transmission. Alternatively, the access network device can also send the second command to the quantum secure communication system via relay transmission. Alternatively, the access network device can also send the second command to the quantum secure communication system via encrypted transmission.
[0165] In another possible implementation, where there is a direct communication link between the second device and the quantum secure communication system, without the need for information relay through an access network device, the second device can send a second command to the quantum secure communication system through this direct communication link.
[0166] Of course, the above is only an exemplary description of transmitting the second instruction. The implementation process of transmitting the second instruction can also be implemented in the future through other transmission methods, and this application embodiment does not impose any restrictions on this.
[0167] S906. Based on the second instruction, the quantum secure communication system sends the first key to the second device. Correspondingly, the second device receives the first key from the quantum secure communication system.
[0168] One possible implementation is, such as Figure 10 As shown, when the second device sends a second instruction to the second quantum secure communication device in the quantum secure communication system, the second quantum secure communication device sends the second instruction to the second quantum key distribution node. Correspondingly, the second quantum key distribution node receives the second instruction from the second quantum secure communication device. Based on the second instruction, the second quantum key distribution node sends a first key. Correspondingly, the second quantum secure communication device receives the first key. The second quantum secure communication device sends the first key. Correspondingly, the second device receives the first key.
[0169] In another possible implementation, the quantum secure communication system sends a first key to an access network device. The access network device receives the first key and then sends it to a second device. The second device receives the first key.
[0170] S907 and the second device decrypt the encrypted data based on the first key to determine the image file.
[0171] Optionally, before the second device decrypts the encrypted data, it determines that the image file is an encrypted image based on the encryption identifier in the annotation parameters of the encrypted data. After determining that the image file is an encrypted image, the second device decrypts the encrypted data based on the first key to confirm the image file. The image file, image index, image manifest, and configuration file together form complete image data.
[0172] In one possible implementation, the process of the second device in S907 decrypting the encrypted data based on the first key and determining the image file can be specifically implemented through the following steps 1-2.
[0173] Step 1: The second device decrypts the second key, which is encrypted based on the first key, using the first key.
[0174] In one possible implementation, the second device decrypts the second key, which is encrypted based on the first key, using the first key and the first encryption algorithm.
[0175] For example, the first encryption algorithm includes at least one of the following: block counting mode algorithm, asymmetric encryption padding algorithm and symmetric encryption algorithm, Advanced Encryption Standard (AES) algorithm, second encryption standard core algorithm, or third encryption standard core algorithm. Of course, the above is merely an exemplary description of the first encryption algorithm, and the first encryption algorithm may also include other algorithms, such as symmetric algorithms, international data encryption algorithms, digital signature algorithms, asymmetric encryption algorithms, hash algorithms, etc. This application embodiment does not impose any limitations on these.
[0176] It is understandable that the Advanced Encryption Standard (AES), the second Encryption Standard (DSS) core algorithm, or the third Encryption Standard (DSS) core algorithm are all symmetric algorithms. That is, when using the above three algorithms, the same key is required for encryption and decryption.
[0177] Step 2: The second device decrypts the image file encrypted with the second key after decryption to determine the image file.
[0178] One possible implementation is, such as Figure 10 As shown, the second device decrypts the image file encrypted with the second key using the second encryption algorithm after decryption, and determines the unencrypted image file.
[0179] It is understood that the second encryption algorithm can be the same as the first encryption algorithm in step 1 of S907 above. You can refer to the description of the first encryption algorithm in step 1 of S907 above for understanding. The second encryption algorithm will not be described again here.
[0180] In another possible implementation, the process by which the second device in S907 decrypts the encrypted data and determines the image file based on the first key may also include: if the encrypted data only includes the image file encrypted based on the first key, the second device decrypts the encrypted data based on the first key and determines the image file.
[0181] Based on the above technical solution, the image file transfer method provided in this application involves a first device sending a first instruction to a quantum secure communication system, requesting a first key. A second device also sends a second instruction to the quantum secure communication system, requesting the first key. Based on the requested first key, the first device generates an image file encrypted with a second key, and encrypted data using the second key encrypted with the first key, and sends the encrypted data. The second device obtains the encrypted data and decrypts it based on the requested first key to determine the image file. Since the first key is generated using quantum cryptography, and the quantum secure communication system uses random numbers and various keys generated based on quantum cryptography principles, it possesses "true randomness," fundamentally guaranteeing the security of the cryptographic system. Compared to current public-key-based asymmetric encryption algorithms, this reduces the time required to crack asymmetric encryption algorithms, thus reducing security. The above technical solution can significantly improve the security of image file encryption.
[0182] As one possible embodiment of this application, combined with Figure 9 ,like Figure 11 As shown, the process of the first device generating encrypted data based on the first key in S903 can be specifically implemented through the following S1101-S1104.
[0183] S1101, The first device generates the second key.
[0184] The second key is a randomly generated 256-bit data encryption key.
[0185] In one possible implementation, the first device randomly generates a second key (e.g., a 256-bit data encryption key) through a key management system. Of course, the above is merely one exemplary method for generating the second key. The second key can also be generated using the mkpasswd utility, the dd command, and other data encryption key generation methods; this application does not limit the scope of such generation.
[0186] S1102. The first device encrypts the image file based on the second key and the first encryption algorithm.
[0187] The explanation of the first encryption algorithm is for reference to the description of the first encryption algorithm in S901 above, and will not be repeated here.
[0188] In one possible implementation, where the image file is an image layer file in the image data, and the image data also includes an image index, an image manifest, and a configuration file, in order to meet the requirements of the OCI image format, the first device encrypts only the image file in the image data based on the second key and the first encryption algorithm.
[0189] In another possible implementation, where the image file can also be all data in the image data, including image layer files, image index, image manifest, and configuration files, the first device encrypts all data in the image data based on the second key and the first encryption algorithm.
[0190] S1103. The first device encrypts the second key based on the first key and the second encryption algorithm.
[0191] The second encryption algorithm can be the same as the first encryption algorithm in step 1 of S907 above. You can refer to the description of the first encryption algorithm in step 1 of S907 above for understanding. The second encryption algorithm will not be described again here.
[0192] In one possible implementation, the first device encrypts the second key based on the first key and the second encryption algorithm.
[0193] S1104. The first device determines the encrypted data based on the encrypted image file and the encrypted second key.
[0194] In one possible implementation, the first device packages and encapsulates the encrypted image file and the encrypted second key to determine the encrypted data. The encrypted data is then packaged and encapsulated again with the image index, image manifest, and configuration file to form the image data.
[0195] Based on the above technical solution, the first device generates a second key. The first device encrypts the image file using the second key and the first encryption algorithm. The first device encrypts the second key using the first key and the second encryption algorithm. The first device determines the encrypted data based on the encrypted image file and the encrypted second key. Compared to the current method of storing key information in the image's manifest file, which poses security risks, the above technical solution can encrypt the second key using quantum key distribution. Although it is still stored in the image repository, the security of the key in the image repository can be greatly improved due to the security of the quantum security system.
[0196] This application embodiment can divide the image file transfer device into functional modules or functional units according to the above method example. For example, each function can be divided into a separate functional module or functional unit, or two or more functions can be integrated into one processing module. The integrated module can be implemented in hardware or in software functional modules or functional units. The module or unit division in this application embodiment is illustrative and only represents one logical functional division; other division methods may be used in actual implementation.
[0197] like Figure 12The diagram shown is a schematic diagram of the structure of a mirror file transfer device 120 provided in an embodiment of this application. The mirror file transfer device 120 includes a communication unit 1201 and a processing unit 1202.
[0198] The communication unit 1201 is used to send a first instruction to the quantum secure communication system; the first instruction is used to request a first key; the first key is a key generated based on quantum cryptography.
[0199] The communication unit 1201 is also used to receive the first key from the quantum secure communication system.
[0200] The processing unit 1202 is used to generate encrypted data based on a first key; the encrypted data includes an image file encrypted based on a second key, and a second key encrypted based on the first key.
[0201] The communication unit 1201 is also used to send encrypted data.
[0202] In one possible implementation, the processing unit 1202 is specifically used for: generating a second key; the second key is a randomly generated key; encrypting the image file based on the second key and a first encryption algorithm; encrypting the second key based on the first key and a second encryption algorithm; and determining encrypted data based on the encrypted image file and the encrypted second key.
[0203] In one possible implementation, the communication unit 1201 is specifically used to upload encrypted data to the mirror repository.
[0204] In one possible implementation, the first encryption algorithm is a symmetric encryption algorithm; the second encryption algorithm is a symmetric encryption algorithm.
[0205] In one possible implementation, the first key obtained by the first device is the same as the first key obtained by the second device; the first device and the second device are two devices that transmit the image file.
[0206] In one possible implementation, the mirror file transfer device 120 may further include a storage unit 1203. Figure 12 (shown in dashed box) The storage unit 1203 stores a program or instruction. When the processing unit 1202 executes the program or instruction, the image file transfer device 120 can perform the image file transfer method described in the above method embodiment.
[0207] like Figure 13 The diagram shown is a schematic diagram of the structure of a mirror file transfer device 130 provided in an embodiment of this application. The mirror file transfer device 130 includes a communication unit 1301 and a processing unit 1302.
[0208] The communication unit 1301 is used to send a second instruction to the quantum secure communication system; the second instruction is used to request a first key; the first key is a key generated based on quantum cryptography.
[0209] The communication unit 1301 is also used to receive the first key from the quantum secure communication system.
[0210] The communication unit 1301 is also used to acquire encrypted data; the encrypted data includes an image file encrypted based on a second key, and a second key encrypted based on a first key.
[0211] Processing unit 1302 is used to decrypt encrypted data and determine the image file based on the first key.
[0212] In one possible implementation, the processing unit 1302 is specifically used to: decrypt a second key encrypted based on the first key; and decrypt an image file encrypted based on the second key based on the decrypted second key to determine the image file.
[0213] In one possible implementation, the communication unit 1301 is specifically used to: retrieve encrypted data from the mirror repository.
[0214] In one possible implementation, the mirror file transfer device 130 may further include a storage unit 1303. Figure 13 (shown in dashed box) The storage unit 1303 stores a program or instruction. When the processing unit 1302 executes the program or instruction, the image file transfer device 130 can perform the image file transfer method described in the above method embodiment.
[0215] Through the above description of the embodiments, those skilled in the art will clearly understand that, for the sake of convenience and brevity, only the division of the above functional modules is used as an example. In practical applications, the above functions can be assigned to different functional modules as needed, that is, the internal structure of the device can be divided into different functional modules to complete all or part of the functions described above. The specific working process of the system, device, and unit described above can be referred to the corresponding process in the foregoing method embodiments, and will not be repeated here.
[0216] This application provides a computer program product containing instructions that, when run on a computer, cause the computer to execute the image file transfer method described in the above method embodiments.
[0217] This application also provides a computer-readable storage medium storing instructions that, when executed on a computer, cause the computer to perform the image file transfer method in the method flow shown in the above method embodiments.
[0218] The computer-readable storage medium may be, for example, but not limited to, an electrical, magnetic, optical, electromagnetic, infrared, or semiconductor system, apparatus, or device, or any combination thereof. More specific examples (a non-exhaustive list) of computer-readable storage media include: electrical connections having one or more wires; portable computer disks; hard disks; random access memory (RAM); read-only memory (ROM); erasable programmable read-only memory (EPROM); registers; hard disks; optical fibers; portable compact disc read-only memory (CD-ROM); optical storage devices; magnetic storage devices; or any suitable combination thereof; or any other form of computer-readable storage medium known in the art. An exemplary storage medium is coupled to a processor, enabling the processor to read information from and write information to the storage medium. Of course, the storage medium may also be a component of the processor. The processor and the storage medium may reside in an application-specific integrated circuit (ASIC). In the embodiments of this application, the computer-readable storage medium can be any tangible medium that contains or stores a program that can be used by or in conjunction with an instruction execution system, apparatus, or device.
[0219] Since the image file transfer device, computer-readable storage medium, and computer program product in the embodiments of this application can be applied to the above method, the technical effects that can be obtained can also be referred to the above method embodiments. The embodiments of this application will not be repeated here.
[0220] In the several embodiments provided in this application, it should be understood that the disclosed systems, devices, and methods can be implemented in other ways. For example, the device embodiments described above are merely illustrative; for instance, the division of units is only a logical functional division, and in actual implementation, there may be other division methods. For example, multiple units or components may be combined or integrated into another system, or some features may be ignored or not executed. Furthermore, the mutual coupling or direct coupling or communication connection shown or discussed may be through some interfaces; the indirect coupling or communication connection between devices or units may be electrical, mechanical, or other forms.
[0221] It should be understood that the various forms of processes shown above can be used to rearrange, add, or delete steps. For example, the steps described in this disclosure can be executed in parallel, sequentially, or in different orders, as long as the desired result of the technical solution of this disclosure can be achieved, and this is not limited herein.
[0222] The specific embodiments described above do not constitute a limitation on the scope of protection of this disclosure. Those skilled in the art should understand that various modifications, combinations, sub-combinations, and substitutions can be made according to design requirements and other factors. Any modifications, equivalent substitutions, and improvements made within the spirit and principles of this disclosure should be included within the scope of protection of this disclosure.
[0223] The units described as separate components may or may not be physically separate. The components shown as units may or may not be physical units; that is, they may be located in one place or distributed across multiple network units. Some or all of the units can be selected to achieve the purpose of this embodiment according to actual needs.
[0224] In addition, the functional units in the various embodiments of this application can be integrated into one processing unit, or each unit can exist physically separately, or two or more units can be integrated into one unit.
[0225] The above are merely specific embodiments of this application, but the scope of protection of this application is not limited thereto. Any variations or substitutions within the technical scope disclosed in this application should be included within the scope of protection of this application. Therefore, the scope of protection of this application should be determined by the scope of the claims.
Claims
1. A method for transferring mirror files, characterized in that, Applied to a first device, the method includes: A first instruction is sent to the quantum secure communication system; the first instruction is used to request a first key; the first key is a key generated based on quantum cryptography. Receive the first key from the quantum secure communication system; Based on the first key, encrypted data is generated; the encrypted data includes an image file encrypted based on a second key, and the second key encrypted based on the first key; Send the encrypted data.
2. The method according to claim 1, characterized in that, The step of generating encrypted data based on the first key includes: Generate the second key; the second key is a randomly generated key; The image file is encrypted based on the second key and the first encryption algorithm; Based on the first key and the second encryption algorithm, the second key is encrypted; The encrypted data is determined based on the encrypted image file and the encrypted second key.
3. The method according to claim 1, characterized in that, Sending the encrypted data includes: The encrypted data is uploaded to the mirror repository.
4. The method according to claim 2, characterized in that, The first encryption algorithm is a symmetric encryption algorithm; the second encryption algorithm is the same as the symmetric encryption algorithm.
5. The method according to claim 1, characterized in that, The first key obtained by the first device is the same as the first key obtained by the second device; the first device and the second device are two devices that transmit the image file.
6. A method for transferring mirror files, characterized in that, Applied to a second device, the method includes: A second instruction is sent to the quantum secure communication system; the second instruction is used to request a first key; the first key is a key generated based on quantum cryptography. Receive the first key from the quantum secure communication system; Obtain encrypted data; the encrypted data includes an image file encrypted based on a second key, and a second key encrypted based on a first key; Based on the first key, the encrypted data is decrypted to determine the image file.
7. The method according to claim 6, characterized in that, The step of decrypting the encrypted data based on the first key includes: Based on the first key, the second key encrypted based on the first key is decrypted; Based on the decrypted second key, the image file encrypted with the second key is decrypted to determine the image file.
8. The method according to claim 6, characterized in that, The acquisition of encrypted data includes: The encrypted data is obtained from the mirror repository.
9. A communication system, characterized in that, The system includes a first device, a second device, and a quantum secure communication system; The first device is configured to: send a first instruction to the quantum secure communication system; the first instruction is used to request a first key; the first key is a key generated based on quantum cryptography; The second device is configured to: send a second instruction to the quantum secure communication system; the second instruction is used to request the first key; The quantum secure communication system is configured to: send the first key based on the first instruction; and send the first key based on the second instruction. The first device is further configured to: receive a first key from the quantum secure communication system; generate encrypted data based on the first key; and send the encrypted data; the encrypted data includes an image file encrypted based on a second key, and the second key encrypted based on the first key; The second device is further configured to: receive the first key from the quantum secure communication system; acquire encrypted data; decrypt the encrypted data based on the first key to determine the image file.
10. The system according to claim 9, characterized in that, The quantum secure communication system includes a first quantum secure communication device and a first quantum key distribution node; The first device is specifically configured to send a first instruction to the first quantum secure communication device; The first quantum secure communication device is configured to send the first instruction to the first quantum key distribution node; The first quantum key distribution node is configured to: send the first key based on the first instruction; The first quantum secure communication device is further configured to: receive the first key and send the first key.
11. The system according to claim 10, characterized in that, The quantum secure communication system also includes a second quantum secure communication device and a second quantum key distribution node; The second device is specifically configured to send a first instruction to the second quantum secure communication device; The second quantum secure communication device is configured to send the second instruction to the second quantum key distribution node; The second quantum key distribution node is configured to: send the first key based on the second instruction; the first key in the second quantum key distribution node is shared with the first key of the first quantum key distribution node; The second quantum secure communication device is further configured to: receive the first key and send the first key.
12. A mirror file transfer device, characterized in that, The device includes a communication unit and a processing unit; The communication unit is used to send a first instruction to the quantum secure communication system; the first instruction is used to request a first key; the first key is a key generated based on quantum cryptography. The communication unit is also used to receive the first key from the quantum secure communication system; The processing unit is configured to generate encrypted data based on the first key; the encrypted data includes an image file encrypted based on a second key, and the second key encrypted based on the first key; The communication unit is also used to send the encrypted data.
13. A mirror file transfer device, characterized in that, The device includes a communication unit and a processing unit; The communication unit is used to send a second instruction to the quantum secure communication system; the second instruction is used to request a first key; the first key is a key generated based on quantum cryptography. The communication unit is also used to receive the first key from the quantum secure communication system; The communication unit is also used to acquire encrypted data; the encrypted data includes an image file encrypted based on a second key, and a second key encrypted based on a first key; The processing unit is used to decrypt the encrypted data based on the first key and determine the image file.
14. A mirror file transfer device, characterized in that, include: A processor and a communication interface; the communication interface is coupled to the processor, the processor being configured to run computer programs or instructions to implement the image file transfer method as described in any one of claims 1-5 or 6-8.
15. A computer-readable storage medium, characterized in that, The computer-readable storage medium stores instructions that, when executed by a computer, perform the image file transfer method as described in any one of claims 1-5 or 6-8.
16. A computer program product, characterized in that, The computer program product includes computer instructions that, when executed on a computer, cause the computer to perform the image file transfer method as described in any one of claims 1-5 or 6-8.
Citation Information
Patent Citations
File signature method and device of operating system and file verification method and device of operating system
CN105989306A
Container mirror image construction method and device
CN114995949A