Quantum secure communication methods, devices, systems, equipment, media and products
By determining addresses and distributing quantum keys based on user attribute information through the business platform, the problem of excessive load on user equipment and service centers in group secure communication is solved, and group quantum secure communication with differentiated communication needs is realized.
Patent Information
- Application Number
- CN202410581882.9
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2024-05-11
- Publication Date
- 2026-01-06
- Estimated Expiration
- 2044-05-11
AI Technical Summary
In group secure communication scenarios, existing technologies require the distribution of symmetric quantum keys to each user and all other users, which leads to an excessive processing load on user devices and quantum cryptography service centers, making it impossible to meet the differentiated communication needs of different users.
The system receives quantum secure communication requests from users through the business platform, determines the address of the target recipient based on user attribute information, and sends a quantum key distribution request to the quantum cryptography service center, thereby optimizing the quantum secure communication process and simplifying the quantum key distribution process.
It realizes group quantum secure communication, meets the differentiated communication needs of different users, optimizes the quantum secure communication process, and reduces the processing load of the quantum cryptography service center.
Smart Images

Figure CN118802135B_ABST
Abstract
Description
Technical Field
[0001] This disclosure relates to the field of communication technology, and more specifically, to a quantum secure communication method, apparatus, system, device, medium, and product. Background Technology
[0002] QKD networks can serve cryptographic application clients on user networks and provide them with shared quantum key pairs to achieve secure communication between the two ends.
[0003] In related technologies, a quantum cryptography service center can obtain quantum random numbers generated by QKD network node devices or local quantum random number generators, and then generate symmetric quantum keys. These quantum keys are then provided to upper-layer applications to meet the cryptographic requirements of business applications at both ends of the communication. The related technologies utilize a quantum cryptography service layer composed of quantum cryptography service centers to connect business applications with the QKD network, providing quantum keys for quantum cryptography applications. However, the considered business application scenarios are relatively simple, only describing the processing flow of point-to-point secure communication in general business from a broad perspective. For more complex application scenarios, such as group secure communication, the interaction process using existing technologies is too cumbersome. It requires distributing symmetric quantum keys between each user and all other users to establish an end-to-end secure channel. The large number of quantum keys required significantly increases the encryption and decryption pressure on the user devices at both points, as well as the processing load on the quantum cryptography service center and the QKD network. Therefore, how to distribute quantum keys to users with quantum secure communication needs in real time and effectively is one of the urgent problems to be solved to expand the application scope of quantum communication. Summary of the Invention
[0004] This disclosure provides at least one quantum secure communication method, apparatus, system, device, medium, and product.
[0005] In a first aspect, embodiments of this disclosure provide a quantum secure communication method applied to a service platform, including:
[0006] Receive a quantum secure communication request sent by a business user; wherein the quantum secure communication request includes at least: first attribute information of the destination receiver;
[0007] If the business user is determined to be a legitimate user, the address information of the target recipient is determined based on the first attribute information of the target recipient in the quantum secure communication request.
[0008] The quantum key distribution request message is sent to the quantum cryptography service center, carrying the address information of the destination recipient and the address information of the business user; wherein, the quantum key distribution request message is used to request the quantum cryptography service center to issue quantum keys to the destination recipient and the business user.
[0009] In one optional implementation, determining the address information of the target receiver based on the first attribute information of the target receiver in the quantum secure communication request includes:
[0010] Obtain attribute structure information that matches the business user; wherein, the attribute structure information is used to indicate the attribute information of the user group that has been created;
[0011] Based on the attribute structure information, the relevant users of the first attribute information are determined in the created user group;
[0012] The address information of the relevant user is queried from the user information table, and the queried address information is determined as the address information of the target recipient.
[0013] In one optional implementation, sending a quantum key distribution request message carrying the address information of the destination recipient and the address information of the business user to the quantum cryptography service center includes:
[0014] Determine the service type identifier in the quantum secure communication request; wherein the service type identifier is used to indicate the order in which the quantum cryptography service center issues quantum keys to the service user and the destination receiver;
[0015] Determine the key requirements of the business users for quantum keys;
[0016] Based on the service type identifier, the key requirement information, the address information of the destination recipient, and the address information of the service user, a quantum key distribution request message is formed and sent to the quantum cryptography service center.
[0017] In one optional implementation, the method further includes:
[0018] After sending the quantum key distribution request message to the quantum cryptography service center, the system receives a quantum key distribution response from the quantum cryptography service center; wherein the quantum key distribution response is used to indicate whether the quantum cryptography service center has successfully distributed the quantum key to the business user and the target recipient.
[0019] The quantum key distribution response is forwarded to the business user.
[0020] In an optional implementation, before receiving a quantum-secured communication request from a service user, the method further includes:
[0021] After detecting successful user registration, the attribute information of the registered user is determined based on the attribute structure information;
[0022] Determine the user information of the registered user; wherein the user information includes at least one of the following: user account, user password, device address information;
[0023] The user information table is determined based on the attribute information and user information of the registered users.
[0024] In one optional implementation, determining the attribute information of a registered user based on the attribute structure information includes:
[0025] Detect the group join request from the business user; wherein the group join request carries the group to be joined by the business user;
[0026] If the group to be joined is detected to be an already created user group, the attribute information of the registered user is determined based on the attribute information of the group to be joined.
[0027] In one optional implementation, determining the attribute information of a registered user based on the attribute structure information includes:
[0028] If it is detected that the group to be joined does not belong to an existing user group, the attribute information of the group to be joined is extracted from the group joining application;
[0029] The extracted attribute information is identified as the attribute information of the registered user, and the extracted attribute information is added to the attribute structure information.
[0030] In one optional implementation, sending a quantum key distribution request message carrying the address information of the destination recipient and the address information of the business user to the quantum cryptography service center includes:
[0031] The address information of the quantum cryptography service center to which the business user belongs is parsed in the quantum secure communication request, and the quantum key distribution request message is sent to the quantum cryptography service center to which the user belongs based on the address information.
[0032] Secondly, this disclosure also provides a quantum secure communication method, applied in a quantum cryptography service center, comprising:
[0033] The system receives a quantum key distribution request message from a service platform, carrying the address information of the destination recipient and the address information of the service user; the address information of the destination recipient is determined by the service platform based on the first attribute information of the destination recipient in the quantum secure communication request.
[0034] The quantum key is distributed to the destination recipient and the business user based on the quantum key distribution request message.
[0035] In one optional implementation, the step of issuing the quantum key to the destination recipient and the service user based on the quantum key distribution request message includes:
[0036] The quantum key is encrypted to obtain an encrypted quantum key;
[0037] The encrypted quantum key is issued to the target recipient and the business user.
[0038] In one optional implementation, the key distribution request includes at least the following information: the key requirement information of the business user for the quantum key, the business type identifier, the address information of the destination receiver, and the address information of the business user; wherein, the business type identifier is used to indicate the order in which the quantum cryptography service center requests the distribution of the quantum key to the business user and the destination receiver.
[0039] In one optional implementation, the step of distributing the quantum key to the destination recipient and the service user based on the quantum key distribution request message includes:
[0040] If it is determined that the business user has reached the key distribution order, based on the key requirement information of the business user for quantum keys in the quantum key distribution request message, it is determined whether there are available quantum keys in the key storage pool;
[0041] If the existence of the available quantum key is determined, the quantum key is distributed to the destination recipient and the service user respectively based on the address information in the quantum key distribution request message.
[0042] In one optional implementation, the method further includes:
[0043] Determine the service type identifier in the quantum key distribution request message;
[0044] Based on the service type identifier, determine whether the key distribution order for the service user has been reached.
[0045] In one optional implementation, the step of distributing the quantum key to the destination recipient and the service user based on the quantum key distribution request message includes:
[0046] If it is determined that the quantum cryptography service center to which the destination recipient belongs is different from the quantum cryptography service center to which the business user belongs, the quantum key is issued through negotiation between the quantum cryptography service centers. The quantum key is issued to the destination recipient through the quantum cryptography service center to which the destination recipient belongs, and to the business user through the quantum cryptography service center to which the business user belongs.
[0047] Thirdly, this disclosure also provides a quantum secure communication system, including: terminal equipment belonging to a business user, a business platform, and a quantum cryptography service center;
[0048] The terminal device is configured to send a quantum secure communication request to the service platform; wherein the quantum secure communication request includes at least: first attribute information of the destination receiver;
[0049] The service platform is configured to receive quantum secure communication requests sent by service users; if the service user is determined to be a legitimate user, the platform determines the address information of the target recipient based on the first attribute information of the target recipient in the quantum secure communication request; and sends a quantum key distribution request message carrying the address information of the target recipient and the address information of the service user to the quantum cryptography service center.
[0050] The quantum cryptography service center is configured to distribute the quantum key to the target recipient and the business user based on the quantum key distribution request message.
[0051] In one optional implementation, the terminal device is configured to encrypt sensitive data based on the quantum key and send the encrypted sensitive data to the target recipient.
[0052] Fourthly, embodiments of this disclosure also provide a quantum secure communication device, configured on a service platform, comprising:
[0053] The first receiving unit is used to receive a quantum secure communication request sent by a service user; wherein the quantum secure communication request includes at least: first attribute information of the destination receiver;
[0054] The determining unit is configured to, when determining that the service user is a legitimate user, determine the address information of the destination recipient based on the first attribute information of the destination recipient in the quantum secure communication request;
[0055] The sending unit is configured to send a quantum key distribution request message to the quantum cryptography service center, carrying the address information of the destination recipient and the address information of the service user; wherein the quantum key distribution request message is used to request the quantum cryptography service center to issue quantum keys to the destination recipient and the service user.
[0056] Fifthly, embodiments of this disclosure also provide a quantum secure communication device, located in a quantum cryptography service center, comprising:
[0057] The second receiving unit is used to receive a quantum key distribution request message sent by the service platform, which carries the address information of the destination recipient and the address information of the service user; wherein, the address information of the destination recipient is determined by the service platform based on the first attribute information of the destination recipient in the quantum secure communication request;
[0058] A key distribution unit is used to distribute quantum keys to the destination receiver and the service user based on the quantum key distribution request message.
[0059] In a sixth aspect, embodiments of this disclosure also provide an electronic device, including: a processor, a memory, and a bus, wherein the memory stores machine-readable instructions executable by the processor, and when the electronic device is running, the processor communicates with the memory via the bus, and when the machine-readable instructions are executed by the processor, the steps of the first aspect above, or any possible implementation of the first aspect, are performed.
[0060] In a seventh aspect, embodiments of this disclosure also provide a computer-readable storage medium storing a computer program that, when executed by a processor, performs the steps of the first aspect or any possible implementation thereof.
[0061] Eighthly, embodiments of this disclosure also provide a computer program product, characterized in that the computer program product is stored in a storage medium, and the program product is executed by at least one processor to implement the steps of the first aspect above, or any possible implementation of the first aspect.
[0062] This disclosure provides a quantum secure communication method, apparatus, system, device, medium, and product. In an embodiment of this disclosure, firstly, a quantum secure communication request sent by a service user is received; the quantum secure communication request includes at least: first attribute information of the target receiver; then, if the service user is determined to be a legitimate user, the address information of the target receiver is determined based on the first attribute information of the target receiver in the quantum secure communication request; finally, a quantum key distribution request message carrying the address information of the target receiver and the address information of the service user is sent to a quantum cryptography service center; wherein, the quantum key distribution request message is used to request the quantum cryptography service center to issue quantum keys to the target receiver and the service user.
[0063] In the above embodiments, by sending a secure communication request carrying the first attribute information of the destination recipient to the business platform, so that the business platform can determine the address information of all destination recipients based on the first attribute information, the different quantum secure communication needs of users with different attributes in a group can be met in actual business application scenarios. This disclosed technical solution addresses the different quantum secure communication needs of different users in group communication scenarios by combining user attributes with the quantum secure communication process and triggering the quantum cryptography service center to distribute quantum keys through the business platform. This enables group quantum secure communication, optimizes existing quantum secure communication mechanisms, simplifies the quantum secure communication process, and reduces the processing load of the quantum cryptography service center.
[0064] To make the above-mentioned objects, features and advantages of this disclosure more apparent and understandable, preferred embodiments are described below in detail with reference to the accompanying drawings. Attached Figure Description
[0065] To more clearly illustrate the technical solutions of the embodiments of this disclosure, the accompanying drawings used in the embodiments will be briefly described below. These drawings are incorporated in and constitute a part of this specification. They illustrate embodiments conforming to this disclosure and, together with the specification, serve to explain the technical solutions of this disclosure. It should be understood that the following drawings only show some embodiments of this disclosure and should not be considered as limiting the scope. Those skilled in the art can obtain other related drawings based on these drawings without creative effort.
[0066] Figure 1 A flowchart of a quantum secure communication method provided by an embodiment of this disclosure is shown;
[0067] Figure 2 A flowchart of a user registration method provided by an embodiment of this disclosure is shown;
[0068] Figure 3 This diagram illustrates a structural schematic of attribute structure information provided in an embodiment of the present disclosure.
[0069] Figure 4 A flowchart of another quantum secure communication method provided by an embodiment of this disclosure is shown;
[0070] Figure 5 An interactive flowchart of a quantum secure communication method provided in an embodiment of this disclosure is shown;
[0071] Figure 6 A schematic diagram of the structure of a quantum secure communication system provided in an embodiment of this disclosure is shown;
[0072] Figure 7A schematic diagram of another quantum secure communication system provided in an embodiment of this disclosure is shown;
[0073] Figure 8 A schematic diagram of a quantum secure communication device provided in an embodiment of this disclosure is shown;
[0074] Figure 9 A schematic diagram of another quantum secure communication device provided in an embodiment of this disclosure is shown;
[0075] Figure 10 A schematic diagram of an electronic device provided in an embodiment of the present disclosure is shown. Detailed Implementation
[0076] To make the objectives, technical solutions, and advantages of the embodiments of this disclosure clearer, the technical solutions of the embodiments of this disclosure will be clearly and completely described below with reference to the accompanying drawings. Obviously, the described embodiments are only a part of the embodiments of this disclosure, and not all of them. The components of the embodiments of this disclosure described and shown in the accompanying drawings can generally be arranged and designed in various different configurations. Therefore, the following detailed description of the embodiments of this disclosure provided in the accompanying drawings is not intended to limit the scope of the claimed disclosure, but merely represents selected embodiments of this disclosure. All other embodiments obtained by those skilled in the art based on the embodiments of this disclosure without inventive effort are within the scope of protection of this disclosure.
[0077] It should be noted that similar labels and letters in the following figures indicate similar items. Therefore, once an item is defined in one figure, it does not need to be further defined and explained in subsequent figures.
[0078] In this document, the term "and / or" merely describes a relationship, indicating that three relationships can exist. For example, A and / or B can represent three cases: A alone, A and B simultaneously, and B alone. Furthermore, the term "at least one" in this document means any combination of at least two of any one or more elements. For example, including at least one of A, B, and C can mean including any one or more elements selected from the set consisting of A, B, and C.
[0079] QKD networks can serve cryptographic application clients on user networks, providing them with shared quantum key pairs to achieve secure communication between the two ends. However, with the rapid proliferation and development of diversified upper-layer services, the pressure on QKD networks to interface and adapt with these services is gradually increasing.
[0080] In related technologies, a quantum cryptography service center can obtain quantum random numbers generated by QKD network node devices or local quantum random number generators, and then generate symmetric quantum keys. These quantum keys are then provided to upper-layer applications to meet the cryptographic requirements of business applications at both ends of the communication. The related technology utilizes a quantum cryptography service layer composed of quantum cryptography service centers to connect services with the QKD network, providing quantum keys for quantum cryptography applications.
[0081] Existing technical solutions propose a quantum cryptography service layer composed of quantum cryptography service centers to connect services with the QKD network and provide quantum keys for quantum cryptography applications. However, the applicable business application scenarios of existing technical solutions are relatively limited, only describing the processing flow of point-to-point secure communication in general services from a broad perspective. If this solution is adopted in group secure communication scenarios, it is necessary to distribute symmetric quantum keys to each user and all other users to establish an end-to-end secure channel. The required number of quantum keys is large, which will greatly increase the encryption and decryption pressure on the two user devices and the processing load of the quantum cryptography service center and the QKD network. Therefore, it cannot be directly applied.
[0082] In addition, group quantum secure communication scenarios involve multi-party communication, and different types of users may have different secure communication needs. For example, in an instant messaging client group, a leader sends an encrypted file, allowing only users with specific attributes (department leaders or team leaders) to decrypt the file content. Existing quantum secure communication mechanisms cannot directly address this type of problem. Therefore, how to design a mechanism that enables users to effectively and in real-time obtain quantum keys to meet the differentiated communication needs of different users in actual business is a problem that urgently needs to be solved.
[0083] Based on the above research, this disclosure provides a quantum secure communication method, apparatus, system, device, medium, and product. The technical solution of this disclosure addresses the different quantum secure communication needs of different users in group communication scenarios. It combines user attributes with the quantum secure communication process and triggers the distribution of quantum keys by the quantum cryptography service center through the business platform. This enables group quantum secure communication, optimizes existing quantum secure communication mechanisms, simplifies the quantum secure communication process, and reduces the processing load of the quantum cryptography service center.
[0084] To facilitate understanding of this embodiment, a quantum secure communication method disclosed in this disclosure will first be described in detail. The execution subject of the quantum secure communication method provided in this disclosure is generally an electronic device with a certain computing power. In some possible implementations, this quantum secure communication method can be implemented by a processor calling computer-readable instructions stored in memory.
[0085] See Figure 1The diagram shows a flowchart of a quantum secure communication method provided in an embodiment of this disclosure. The method includes steps S101 to S103, wherein:
[0086] S101: Receive a quantum secure communication request sent by a service user; wherein the quantum secure communication request includes at least: first attribute information of the destination receiver.
[0087] When there is a quantum-secure communication requirement between business user A and user with attribute I, business user A can send a quantum-secure communication request to the business platform through a terminal device. The quantum-secure communication request must include at least the first attribute information of the destination receiver, which can be understood as the user corresponding to attribute I.
[0088] In addition, the quantum secure communication request also carries the following information: relevant information of business user A, such as user A's account password, source device A's address information, etc.; the quantum cryptography service center to which the business user belongs (e.g., quantum cryptography service center A), business information (e.g., business type identifier), key stream QoS (e.g., key quantity, key rate, key arrival time, etc.).
[0089] S102: If the business user is determined to be a legitimate user, the address information of the destination recipient is determined based on the first attribute information of the destination recipient in the quantum secure communication request.
[0090] After receiving a quantum secure communication request, the business platform can verify whether the business user is a legitimate user. If the business user is verified to be a legitimate user, the address information of the destination recipient can be determined based on the first attribute information in the quantum secure communication request.
[0091] Here, the following methods can be used to verify whether a business user is a legitimate user, specifically including:
[0092] First, retrieve the user information table pre-stored in the business platform; then, determine whether the business user is a legitimate user based on the user information table.
[0093] In practice, it can be determined whether the relevant information for the business user exists in the user information table. If it exists, the business user can be identified as a legitimate user. Furthermore, if the information exists, it can be further verified whether the relevant information for the business user in the user information table matches the relevant information for the business user carried in the quantum secure communication request. If they match, the business user is identified as a legitimate user. Conversely, if it is determined that the relevant information for the business user does not exist in the user information table, and / or if the relevant information for the business user in the user information table does not match the relevant information for the business user carried in the quantum secure communication request, then the business user is identified as an illegitimate user. If the business user is identified as illegitimate, the business platform can return a quantum secure communication request response message to the business user carrying "Request Failed (Illegal User)" information.
[0094] Here, the business platform can determine the address information of the destination recipient based on the user information table and the first attribute information; wherein, the user information table is a table of relevant information of registered users that is stored in the business platform in advance.
[0095] S103: Send a quantum key distribution request message to the quantum cryptography service center, carrying the address information of the destination recipient and the address information of the business user; wherein, the quantum key distribution request message is used to request the quantum cryptography service center to issue quantum keys to the destination recipient and the business user.
[0096] After determining the address information of the target recipient, a quantum key distribution request message can be sent to the quantum key service center; the quantum key distribution request message carries the address information of the target recipient and the address information of the business user.
[0097] After receiving the quantum key distribution request message, the quantum key service center can distribute the same quantum key to each destination receiver and business user. Then, the business user and the destination receiver can use this quantum key to transmit data.
[0098] In the above embodiments, by sending a secure communication request carrying the first attribute information of the destination recipient to the business platform, so that the business platform can determine the address information of all destination recipients based on the first attribute information, the different quantum secure communication needs of users with different attributes in a group can be met in actual business application scenarios. This disclosed technical solution addresses the different quantum secure communication needs of different users in group communication scenarios by combining user attributes with the quantum secure communication process and triggering the quantum cryptography service center to distribute quantum keys through the business platform. This enables group quantum secure communication, optimizes existing quantum secure communication mechanisms, simplifies the quantum secure communication process, and reduces the processing load of the quantum cryptography service center.
[0099] In an optional implementation, before the service platform receives a quantum-secure communication request from a service user, the method further includes the following steps:
[0100] Step S1011: After detecting successful user registration, determine the attribute information of the registered user based on the attribute structure information;
[0101] Step S1012: Determine the user information of the registered user; wherein the user information includes at least one of the following: user account, user password, device address information;
[0102] Step S1013: Determine the user information table based on the attribute information and user information of the registered users.
[0103] When a user first accesses the system, such as Figure 2 As shown, business users can initiate a registration request to the business platform via their terminal devices. This registration request includes the user's account, password, real-name information, and MAC address. Upon receiving the registration request, the business platform compares the real-name information with an authoritative data source to verify its authenticity and consistency. If the verification of the real-name information's authenticity and consistency is successful, registration is considered successful. At this point, attribute information can be assigned to the registered user based on this attribute structure information, the registered user's attribute information and user information can be recorded, and a registration success response message can be sent to the business user. If the verification of the real-name information's authenticity and consistency fails, a registration failure response message can be sent to the business user.
[0104] After successful registration, users can apply to join a group by sending a group join request to the business platform. This request can be to join an existing user group or to create a new user group. At this point, the business platform or group administrator can assign attribute information to the registered user based on the existing attribute structure information.
[0105] Here, the attribute structure information includes at least one level of user attributes; that is, the attribute structure information can be an attribute tree structure or other structural information, which this disclosure does not specifically limit. The attribute structure information is information pre-constructed based on various types of attributes. In addition, if the existing attribute structure information does not contain the user attributes that made the application, they can be added to the existing attribute structure information.
[0106] For example, this attribute structure information can be established based on the company's existing organizational structure, or it can be established according to the group user attribute information (such as the group member's group role or geographical location, city, age, gender, hobbies, etc.), or it can be constructed according to other types of attributes. No specific limitations are made here, as long as it can be implemented.
[0107] For example, suppose an organization's existing organizational structure is as follows: Figure 3 As shown, users A through J complete registration on the business platform (i.e., registration on the communication app) and attribute assignment, entering the same group and forming an attribute tree structure. Among them, the XX unit includes department A, department B, department C, and department D; department A includes groups A and B, department B includes groups C and D, department C includes groups E and F, and department D contains user J, as shown... Figure 3 As shown, the attributes of each department and each user group to which each department belongs can be classified into attributes A to J.
[0108] It should be noted that the attribute structure information established due to different organizational structures, different numbers of users or other factors may be different. However, the method of forming attribute structure information by assigning attributes to users in a group, and using this attribute structure information to achieve fine-grained segmentation of users of quantum secure communication services, all fall within the scope of protection of this application, and will not be described in detail here.
[0109] After determining the attribute information of registered users, their user information can be determined; this user information includes at least one of the following: user account, user password, and device address information. Subsequently, the business platform records the attribute information assigned to the user, along with the user account, user password, device MAC address, and other user information, thus forming a user information table.
[0110] By searching the user information table, specific users and terminal devices with confidential communication needs can be located through attributes, so that each user corresponds to a unique identifier and corresponding attributes.
[0111] In addition, new users also need to establish a connection with the Quantum Cryptography Service Center through pre-installed secure media (such as cryptographic modules that have been registered and issued by the Quantum Cryptography Service Center) or software platform registration, and inform the Quantum Cryptography Service Center of the unique identifier of the user terminal device, such as the cryptographic module number or device address, so that the Quantum Cryptography Service Center can issue quantum keys to specific users.
[0112] It should be noted that the above-mentioned methods for establishing connections between business users and business platforms and quantum cryptography service centers are merely embodiments listed for the convenience of understanding the technical solutions disclosed herein. In actual development and implementation, connections can also be established through other means. Furthermore, the device identifiers and other information corresponding to the users stored in the backend databases of both parties are unique, so as to locate specific users, assign attributes to them, or distribute quantum keys. The technical solutions disclosed herein do not impose specific limitations on this, and the implementation shall prevail.
[0113] By creating a user information table, a mapping relationship between user address information and attribute information can be established, thereby enabling the rapid determination of user address information based on attribute information and improving the processing efficiency of quantum secure communication.
[0114] In an optional implementation, step S1011 above, which determines the attribute information of the registered user based on the attribute structure information, specifically includes the following steps:
[0115] Step S1: Detect the group joining request of the business user; wherein, the group joining request carries the group to be joined by the business user;
[0116] Step S2: If the group to be joined is detected to be an already created user group, the attribute information of the registered user is determined based on the attribute information of the group to be joined.
[0117] Step S3: If it is detected that the group to be joined does not belong to an existing user group, extract the attribute information of the group to be joined from the group joining application;
[0118] Step S4: The extracted attribute information is identified as the attribute information of the registered user, and the extracted attribute information is added to the attribute structure information.
[0119] In this embodiment of the disclosure, a group joining request initiated by a business user can be detected; wherein the group joining request carries the business user's group to be joined and / or the attribute information of the group to be joined.
[0120] Here, based on the group to be joined and / or its attribute information, it can be determined whether the group to be joined is an already created user group in the attribute structure information; if so, the attribute information of the group to be joined can be used as the attribute information of the registered user. For example, such as Figure 3 As shown, if a registered user wants to join department AA group, then attribute E can be identified as the attribute information of the registered user.
[0121] If it is determined that the group to be joined does not belong to an existing user group, the attribute information of the registered user can be determined based on the attribute information of the group to be joined. For example, Figure 3 As shown, if a registered user wants to join the department CG group (attribute K), then it can be determined that attribute K is the attribute information of the registered user. At this time, it is also necessary to add the extracted attribute information to the attribute structure information, that is, to create a new user group under department C, namely group G, and set the attribute of the group to K, and set the registered user to be a user of group G.
[0122] In an optional implementation, step S102 above determines the address information of the target receiver based on the first attribute information of the target receiver in the quantum secure communication request, specifically including the following steps:
[0123] Step S11: Obtain attribute structure information matching the business user; wherein, the attribute structure information is used to indicate the attribute information of each created user group;
[0124] Step S12: Based on the attribute structure information, determine the relevant users of the first attribute information in the created user group;
[0125] Step S13: Query the address information of the relevant user in the user information table, and determine the queried address information as the address information of the destination recipient.
[0126] In this embodiment of the disclosure, the business platform can store multiple attribute structure information. Here, attribute structure information matching the business user can be obtained. For example, the attribute structure information of each registered user can be recorded in the user information table, and then the attribute structure information matching the business user can be found based on the user information table.
[0127] Then, the first attribute information can be found in the attribute structure information, and the relevant users of the first attribute information can be found in the created user groups based on the attribute structure information.
[0128] For example, if business user A (with the attribute "Department AA Group", hereinafter referred to as "Attribute E") sends certain data that can only be decrypted by relevant members of Department CF Group (hereinafter referred to as "Attribute J"), then the business platform can determine the relevant users of Attribute J, for example, the relevant users are user H and user I.
[0129] After identifying the relevant users, the business platform can search the user information table and determine the address information of the target recipient based on the address information of the relevant user H and user I.
[0130] The above processing method can quickly determine the user's address information based on attribute information, thereby improving the processing efficiency of quantum secure communication.
[0131] In an optional implementation, step S103 above, which involves sending a quantum key distribution request message to the quantum cryptography service center, carrying the address information of the destination recipient and the address information of the service user, specifically includes the following steps:
[0132] Step S21: Determine the service type identifier in the quantum secure communication request; wherein the service type identifier is used to indicate the order in which the quantum cryptography service center issues quantum keys to the service user and the destination receiver;
[0133] Step S22: Determine the key requirement information of the business user for quantum keys;
[0134] Step S23: Based on the service type identifier, the key requirement information, the address information of the destination recipient, and the address information of the service user, form the quantum key distribution request message and send the quantum key distribution request message to the quantum cryptography service center.
[0135] In this embodiment of the disclosure, as described above, the quantum secure communication request carries a service type identifier, which determines the order in which the quantum cryptography service center distributes quantum keys to the service user and the destination receiver. Subsequently, the key requirement information of the service user for the quantum keys, such as keystream QoS information, can be determined based on the quantum secure communication request. Next, a quantum key distribution request message carrying the service type identifier, key requirement information, address information of the destination receiver, and address information of the service user can be generated and sent to the quantum cryptography service center.
[0136] Here, the address information of the quantum cryptography service center to which the business user belongs can be parsed in the quantum secure communication request, and the quantum key distribution request message can be sent to the quantum cryptography service center to which the user belongs based on the address information.
[0137] In practical implementation, the quantum cryptography service center to which the business user belongs can be extracted from the quantum secure communication request. Then, the address information of the quantum cryptography service center can be determined. For example, it can be determined that the quantum cryptography service center to which business user A belongs is quantum cryptography service center A. At this time, a quantum key distribution request message can be sent to the quantum cryptography service center according to the address information.
[0138] Here, when the quantum cryptography service center to which the business user and the destination recipient belong are the same, the quantum key distribution request message can be sent to the quantum cryptography service center to which the business user belongs; when the quantum cryptography service center to which the business user and the destination recipient belong are different, the quantum key distribution request message can be sent to the quantum cryptography service center to which the business user belongs separately; or, the quantum key distribution request message can be sent only to the quantum cryptography service center to which the business user belongs.
[0139] After receiving the quantum key distribution request message, the quantum cryptography service center can respond to the quantum key distribution request message and distribute the quantum key to the target recipient and the business user. The specific distribution process will be described in the following embodiments.
[0140] In an optional implementation, the method further includes the following steps:
[0141] Step S1041: After sending the quantum key distribution request message to the quantum cryptography service center, receive the quantum key distribution response sent by the quantum cryptography service center; wherein, the quantum key distribution response is used to indicate whether the quantum cryptography service center has successfully distributed the quantum key to the business user and the target recipient;
[0142] Step S1042: Forward the quantum key distribution response to the business user.
[0143] In this embodiment of the disclosure, after distributing quantum keys to business users and target recipients, the quantum cryptography service center can return a quantum key distribution response message to the business platform.
[0144] Here, if both the business user and the destination receiver successfully receive the distributed quantum key, a quantum key distribution response message carrying "key distribution successful" is returned to the business platform. If either the business user or the destination receiver fails to receive the key, a quantum key distribution response message carrying "key distribution failed" is returned to the business platform.
[0145] After receiving the quantum key distribution response, the business platform can return a quantum key distribution response to the business user. If the business user is not a legitimate user or the key distribution failed, the quantum key distribution response will include a "request failed" message, indicating the reason for the failure; otherwise, it will include a "request successful" message. In actual system implementation, messages such as "request successful," "illegal user," and "request failed (key distribution failed)" can be replaced with numbers; no specific restrictions are imposed here, only what is feasible to implement.
[0146] Next, business users can use the issued quantum key to encrypt the data and send it to the group of the designated APP of the destination recipient through the transport layer protocol. Only users with the corresponding quantum key can decrypt and obtain the data.
[0147] It should be noted that before sending encrypted data, business users need to synchronize the encryption method with the target recipient. The synchronization method can include agreeing to use a fixed encryption method, negotiating the encryption method through the business platform, or including encryption method information when sending encrypted data. No specific restrictions are made here. The data sent by the business user to the target recipient can be any data such as text messages, files, voice streams, and video streams.
[0148] See Figure 4 The diagram shows a flowchart of a quantum secure communication method provided in an embodiment of this disclosure. The method includes steps S401 to S402, wherein:
[0149] Step S401: Receive a quantum key distribution request message sent by the service platform, carrying the address information of the destination recipient and the address information of the service user; the address information of the destination recipient is determined by the service platform based on the first attribute information of the destination recipient in the quantum secure communication request.
[0150] Here, the key distribution request includes at least the following information: the key requirement information of the business user for the quantum key, the business type identifier, the address information of the destination receiver, and the address information of the business user; wherein, the business type identifier is used to indicate the order in which the quantum cryptography service center requests the distribution of the quantum key to the business user and the destination receiver.
[0151] In this embodiment of the disclosure, after receiving a quantum secure communication request sent by a business user, the business platform can determine whether the business user is a legitimate user. If the user is determined to be a legitimate user, the platform can determine the address information of the target recipient based on the first attribute information of the target recipient in the quantum secure communication request, and send a quantum key distribution request message carrying the address information of the target recipient and the address information of the business user to the quantum cryptography service center.
[0152] Step S402: Based on the quantum key distribution request message, the quantum key is sent to the destination receiver and the service user.
[0153] After receiving the quantum key distribution request message, the quantum key service center can distribute the same quantum key to each destination receiver and business user. Then, the business user and the destination receiver can use this quantum key to transmit data.
[0154] In the above embodiments, by sending a secure communication request carrying the first attribute information of the destination recipient to the business platform, so that the business platform can determine the address information of all destination recipients based on the first attribute information, the different quantum secure communication needs of users with different attributes in a group can be met in actual business application scenarios. This disclosed technical solution addresses the different quantum secure communication needs of different users in group communication scenarios by combining user attributes with the quantum secure communication process and triggering the quantum cryptography service center to distribute quantum keys through the business platform. This enables group quantum secure communication, optimizes existing quantum secure communication mechanisms, simplifies the quantum secure communication process, and reduces the processing load of the quantum cryptography service center.
[0155] In an optional implementation, step S402 above, which sends the quantum key to the destination receiver and the service user based on the quantum key distribution request message, specifically includes the following steps:
[0156] First, the quantum key is encrypted to obtain an encrypted quantum key;
[0157] Then, the encrypted quantum key is sent to the target recipient and the business user.
[0158] In this embodiment of the disclosure, based on the address information of the relevant users (business users and destination recipients) carried in the quantum key distribution request message, the quantum cryptography service center can establish a connection with the relevant users and distribute quantum keys to the relevant users with quantum secure communication needs using a passive "push" method.
[0159] During the distribution of quantum keys, methods such as wireless physical layer security can be used to encrypt the quantum keys, ensuring secure transmission in ciphertext form. Alternatively, offline encryption via wired methods can be employed. This step is for illustrative purposes only; specific operations can also be performed according to the procedures defined in the CCSA industry standard "Quantum Key Distribution (QKD) Network Ak Interface Technical Requirements Part 1: Application Programming Interface (API)". The specific encryption method for the quantum keys is not limited here; the method that can be implemented is the standard.
[0160] For example, the quantum key obtained by the quantum cryptography service center can be a symmetric key generated between two QKD devices, or a group quantum key generated between QKD terminal devices; the quantum cryptography service center can transmit the same ciphertext of quantum key A (i.e., the encrypted quantum key) to both the request initiating user A (business user) and the receiving user B (destination receiver).
[0161] In an optional implementation, step S402 above, which sends the quantum key to the destination receiver and the service user based on the quantum key distribution request message, specifically includes the following steps:
[0162] First, after determining that the business user has reached the key distribution order, based on the key requirement information of the business user for quantum keys in the quantum key distribution request message, it is determined whether there are available quantum keys in the key storage pool;
[0163] Secondly, if it is determined that the available quantum key exists, the quantum key is distributed to the destination recipient and the service user respectively based on the address information in the quantum key distribution request message.
[0164] In this embodiment of the disclosure, after the quantum cryptography service center receives the quantum key distribution request message, the quantum cryptography service center can perform overall orchestration management based on the service type identifier. In specific implementation, firstly, the priority of providing services to this service user can be determined based on the service type identifier, and then the priority can be used to determine whether the service user has reached the key distribution order.
[0165] If the service user is determined to have reached the key distribution order based on the service type identifier, it can be determined that services can be provided to that service user. At this point, it can be determined whether there are sufficient available quantum keys in the key storage pool based on the service user's key requirement information for quantum keys (e.g., key stream QoS information).
[0166] If the quantum key exists, the same quantum key is issued to the relevant user; otherwise, a quantum key is requested from the quantum random number generator or QKD network, and after obtaining a sufficient number of quantum keys, the quantum key is distributed to the relevant user.
[0167] It should be noted that the key storage pool here refers to quantum keys obtained from the quantum random number generator or QKD network during off-peak hours, and these quantum keys have a certain validity period and are automatically destroyed after expiration. In addition, the quantum keys can be symmetric quantum keys obtained by the quantum cryptography service center from the QKD network or QRNG, or group quantum keys obtained from the QKD network.
[0168] In an optional implementation, the method can determine the key distribution order by:
[0169] First, determine the service type identifier in the quantum key distribution request message;
[0170] Secondly, based on the service type identifier, it is determined whether the key distribution order for the service user has been reached.
[0171] In this embodiment of the disclosure, the service type identifier is used to indicate the order in which the quantum cryptography service center issues quantum keys to the service user and the destination recipient.
[0172] Based on this, the priority for providing services to this service user can be determined according to the service type identifier carried in the quantum key distribution request message, and thus, whether the service user has reached the key distribution order can be determined based on this priority. For example, if it is determined that services can be provided to this service user based on the priority, the key distribution order for the service user can be determined. At this time, the quantum cryptography service center can distribute quantum keys to both the service user and the destination receiver.
[0173] In an optional implementation, step S402 above, which sends the quantum key to the destination receiver and the service user based on the quantum key distribution request message, specifically includes the following steps:
[0174] If it is determined that the quantum cryptography service center to which the destination recipient belongs is different from the quantum cryptography service center to which the business user belongs, the quantum key is issued through negotiation between the quantum cryptography service centers. The quantum key is issued to the destination recipient through the quantum cryptography service center to which the destination recipient belongs, and to the business user through the quantum cryptography service center to which the business user belongs.
[0175] As described above, business users and target recipients may belong to different quantum cryptography service centers. In this case, before distributing the quantum key, the quantum cryptography service centers can negotiate and verify the key, and then the negotiated quantum key will be distributed by the quantum cryptography service center to which the relevant user belongs.
[0176] See Figure 5 The diagram shown is an interactive flowchart of a quantum secure communication method provided in an embodiment of this disclosure. In this embodiment, it is assumed that the service user is service user A, and the destination receivers are service user F and service user H. Figure 5 As shown, the method includes the following steps:
[0177] S1, the terminal device to which the business user belongs sends a quantum secure communication request to the business platform; the quantum secure communication request includes at least: relevant information of business user A, first attribute information of the destination receiver, quantum cryptography service center to which business user A belongs, business information and key stream QoS;
[0178] S2, the business platform determines whether the business user is a legitimate user; if the user is legitimate, proceed to step S3; otherwise, proceed to step S9.
[0179] S3, the business platform determines the address information of the destination recipient based on the first attribute information of the destination recipient in the quantum secure communication request;
[0180] S4, the business platform sends a quantum key distribution request message to the quantum cryptography service center; the quantum key distribution request message carries the address information of the destination recipient and the business user, the business type identifier, and the key stream QoS;
[0181] The quantum key distribution request message is used to request the quantum cryptography service center to issue a quantum key to the target recipient and the business user.
[0182] S5, the quantum cryptography service center determines whether there is a usable quantum key in the key storage pool; if it is not found, proceed to S6, otherwise proceed to S7;
[0183] S6, the quantum cryptography service center obtains quantum keys through a quantum random number generator or a QKD network;
[0184] S7, the quantum cryptography service center transmits the quantum key to the relevant device based on the received address information, specifically including the following steps:
[0185] S711 sends an encrypted quantum key to business user A;
[0186] S712, Service User A sends a quantum key transmission response;
[0187] S721, sends an encrypted quantum key to business user F;
[0188] S722, Service User F sends a quantum key transmission response;
[0189] S731 sends an encrypted quantum key to business user H;
[0190] S732, Service User H sends a quantum key transmission response;
[0191] S8, the quantum cryptography service center sends a quantum key distribution response to the business platform; the quantum key distribution response is used to indicate whether the key distribution was successful or failed.
[0192] S9, the service platform forwards the quantum key distribution response to the terminal device to which the service user belongs; the quantum key distribution response is used to indicate whether the key distribution was successful or failed;
[0193] S10, business user A transmits encrypted data to business user F and business user H.
[0194] As can be seen from the above description, the technical solution disclosed herein proposes a processing method for distributing quantum keys based on user attributes to a quantum cryptography service center and realizing group quantum secure communication without changing the existing quantum secure communication system architecture.
[0195] First, new users register with the business application and quantum cryptography service center. Based on the existing attribute structure information of the groups to be created or joined by the users, rules are established, and the business platform or group administrator assigns attribute information to the new users. Then, when a user in the group has a need for quantum secure communication, they send a quantum secure communication request carrying the target receiver's attribute information to the business platform. The business platform parses the request message, obtains the relevant user terminal device information, and triggers the quantum cryptography service center to issue quantum keys to the relevant terminal devices. Finally, after all the terminal devices involved in the group receive the quantum keys, they decrypt the encrypted content and obtain the confidential data, thus achieving the purpose of group quantum secure communication. Only the user with the corresponding quantum key can decrypt the data senter's data. Furthermore, this disclosed technical solution further clarifies the architectural relationship between the QKD network or quantum random number generator, the quantum cryptography service center, the business application platform, and multiple user terminals, providing a reference for practical deployment.
[0196] See Figure 6 The diagram shown is a structural schematic of a quantum secure communication system provided in an embodiment of this disclosure. Figure 6 As shown, the quantum secure communication system includes: terminal equipment 61 belonging to the business user, business platform 62, and quantum cryptography service center 63.
[0197] The terminal device is configured to send a quantum secure communication request to the business platform; wherein the quantum secure communication request includes at least: the first attribute information of the destination receiver;
[0198] The business platform is configured to receive quantum secure communication requests sent by business users; if the business user is determined to be a legitimate user, the platform determines the address information of the target recipient based on the first attribute information of the target recipient in the quantum secure communication request; and sends a quantum key distribution request message carrying the address information of the target recipient and the address information of the business user to the quantum cryptography service center.
[0199] The quantum cryptography service center is configured to distribute the quantum key to the target recipient and the business user based on the quantum key distribution request message.
[0200] In existing quantum secure communication systems, a quantum cryptography service center provides quantum keys to users within a region. This disclosure uses an example where all users are located in the same service area. The architecture of a group quantum secure communication system based on user attributes is as follows: Figure 7 As shown.
[0201] The role of a quantum QKD network or quantum random number generator is to provide quantum keys, while the quantum key service center is responsible for the access authentication of business users and the acquisition, storage, management and distribution of quantum keys.
[0202] The application platform for quantum cryptography services interfaces with the quantum cryptography service center to parse users' quantum secure communication requests. At the same time, based on the coarse and fine granular user attributes divided according to different business needs, it analyzes and transforms them into unique address information that can identify user devices, and provides it to the quantum cryptography service center.
[0203] After authenticating users, the quantum cryptography service center can securely distribute quantum keys to users with confidential communication needs based on business requirements and address information. The data sender uses the received quantum key to encrypt sensitive data and sends it to the data receiver, achieving secure data transmission.
[0204] This disclosed technical solution assigns corresponding attributes to quantum secure communication users based on the existing attributes of group users, realizing fine-grained user segmentation and management, enhancing user access security, and ensuring that changes such as users leaving or joining the group do not affect the overall group quantum secure communication process.
[0205] The technical solution disclosed herein utilizes the attribute information of users with secure communication needs to trigger the real-time distribution of quantum keys and follows the "one-time pad" rule, ensuring the freshness of the quantum keys and precisely defining the decryptable range of encrypted data.
[0206] In this disclosed technical solution, data is transmitted from the sender to the receiver in the form of quantum key encryption, encrypting the file from the source. This ensures that the data is encrypted throughout the entire transmission process. Attackers can only intercept the ciphertext of the data, and without the corresponding quantum key, they cannot obtain the plaintext of the transmitted data, thus guaranteeing data security.
[0207] The disclosed technical solution is based on a flexible quantum secure communication system architecture that uses user attribute information. With the construction of quantum cryptography centers and the increase in business application users, it can be further expanded to support more complex secure communication scenarios.
[0208] Those skilled in the art will understand that, in the above-described method of the specific implementation, the order in which each step is written does not imply a strict execution order and does not constitute any limitation on the implementation process. The specific execution order of each step should be determined by its function and possible internal logic.
[0209] Based on the same inventive concept, this disclosure also provides a quantum secure communication device corresponding to the quantum secure communication method. Since the principle of the device in this disclosure is similar to that of the quantum secure communication method described above, the implementation of the device can refer to the implementation of the method, and the repeated parts will not be described again.
[0210] Reference Figure 8 The diagram shown is a schematic representation of a quantum secure communication device according to an embodiment of this disclosure. The device includes: a first receiving unit 81, a determining unit 82, and a transmitting unit 83; wherein,
[0211] The first receiving unit 81 is used to receive a quantum secure communication request sent by a service user; wherein the quantum secure communication request includes at least: first attribute information of the destination receiver;
[0212] Determining unit 82 is used to determine the address information of the destination recipient based on the first attribute information of the destination recipient in the quantum secure communication request when the service user is determined to be a legitimate user.
[0213] The sending unit 83 is used to send a quantum key distribution request message to the quantum cryptography service center, carrying the address information of the destination recipient and the address information of the service user; wherein, the quantum key distribution request message is used to request the quantum cryptography service center to issue quantum keys to the destination recipient and the service user.
[0214] In one possible implementation, the determining unit is further configured to: acquire attribute structure information matching the service user; wherein the attribute structure information is used to indicate the attribute information of each created user group; determine the relevant user of the first attribute information in the created user group based on the attribute structure information; query the address information of the relevant user in the user information table, and determine the queried address information as the address information of the destination recipient.
[0215] In one possible implementation, the sending unit is further configured to: determine a service type identifier in the quantum secure communication request; wherein the service type identifier is used to indicate the order in which the quantum cryptography service center distributes quantum keys to the service user and the destination receiver; determine the key requirement information of the service user for the quantum key; based on the service type identifier, the key requirement information, the address information of the destination receiver, and the address information of the service user, form the quantum key distribution request message, and send the quantum key distribution request message to the quantum cryptography service center.
[0216] In one possible implementation, the device is further configured to: after sending the quantum key distribution request message to the quantum cryptography service center, receive a quantum key distribution response sent by the quantum cryptography service center; wherein the quantum key distribution response is used to indicate whether the quantum cryptography service center has successfully distributed the quantum key to the business user and the destination recipient; and forward the quantum key distribution response to the business user.
[0217] In one possible implementation, the device is further configured to: determine the attribute information of the registered user based on the attribute structure information before receiving a quantum secure communication request sent by a service user and after detecting successful user registration; determine the user information of the registered user; wherein the user information includes at least one of the following: user account, user password, device address information; and determine the user information table based on the attribute information of the registered user and the user information of the registered user.
[0218] In one possible implementation, the device is further configured to: detect the group joining request of the business user; wherein the group joining request carries the group to be joined by the business user; and if the group to be joined is detected to be an already created user group, determine the attribute information of the registered user based on the attribute information of the group to be joined.
[0219] In one possible implementation, the device is further configured to: extract attribute information of the group to be joined from the group joining application when it is detected that the group to be joined does not belong to an existing user group; determine the extracted attribute information as the attribute information of the registered user; and add the extracted attribute information to the attribute structure information.
[0220] In one possible implementation, the sending unit is further configured to: parse the address information of the quantum cryptography service center to which the service user belongs in the quantum secure communication request, and send the quantum key distribution request message to the quantum cryptography service center to which the user belongs based on the address information.
[0221] Reference Figure 9The diagram shown is a schematic representation of a quantum secure communication device according to an embodiment of this disclosure. The device includes: a second receiving unit 91 and a key distribution unit 92; wherein,
[0222] The second receiving unit 91 is used to receive a quantum key distribution request message sent by the service platform, which carries the address information of the destination recipient and the address information of the service user; wherein, the address information of the destination recipient is determined by the service platform based on the first attribute information of the destination recipient in the quantum secure communication request;
[0223] The key distribution unit 92 is used to distribute quantum keys to the destination receiver and the service user based on the quantum key distribution request message.
[0224] In one possible implementation, the key distribution unit is further configured to: encrypt the quantum key to obtain an encrypted quantum key; and distribute the encrypted quantum key to the target receiver and the service user.
[0225] In one possible implementation, the key distribution request includes at least the following information: the business user's key requirement information for the quantum key, the business type identifier, the address information of the destination receiver, and the address information of the business user; wherein, the business type identifier is used to indicate the order in which the quantum cryptography service center requests the distribution of the quantum key to the business user and the destination receiver.
[0226] In one possible implementation, the key distribution unit is further configured to: if it is determined that the service user has reached the key distribution order, determine whether there is a usable quantum key in the key storage pool based on the key requirement information of the service user for the quantum key in the quantum key distribution request message; if it is determined that there is a usable quantum key, distribute the quantum key to the destination receiver and the service user respectively based on the address information in the quantum key distribution request message.
[0227] In one possible implementation, the device is further configured to: determine a service type identifier in the quantum key distribution request message; and determine whether the key distribution order for the service user has been reached based on the service type identifier.
[0228] In one possible implementation, the key distribution unit is further configured to: when it is determined that the quantum cryptography service center to which the destination recipient belongs is inconsistent with the quantum cryptography service center to which the business user belongs, to negotiate the distribution of the quantum key between the quantum cryptography service centers, to distribute the quantum key to the destination recipient through the quantum cryptography service center to which the destination recipient belongs, and to distribute the quantum key to the business user through the quantum cryptography service center to which the business user belongs.
[0229] The processing flow of each module in the device and the interaction flow between each module can be referred to the relevant descriptions in the above method embodiments, and will not be detailed here.
[0230] Corresponding to Figure 1 In addition to the quantum secure communication method, this disclosure also provides an electronic device 1000, such as... Figure 10 The diagram shown is a structural schematic of an electronic device 1000 provided in an embodiment of this disclosure, including:
[0231] The system includes a processor 101, a memory 102, and a bus 103. The memory 102 stores execution instructions and includes main memory 1021 and external memory 1022. The main memory 1021, also called internal memory, temporarily stores computational data in the processor 101, as well as data exchanged with external memory such as a hard disk. The processor 101 exchanges data with the external memory 1022 through the main memory 1021. When the electronic device 1000 is running, the processor 101 communicates with the memory 102 through the bus 103, causing the processor 101 to execute the following instructions:
[0232] Receive a quantum secure communication request sent by a business user; wherein the quantum secure communication request includes at least: first attribute information of the destination receiver;
[0233] If the business user is determined to be a legitimate user, the address information of the target recipient is determined based on the first attribute information of the target recipient in the quantum secure communication request.
[0234] The quantum key distribution request message is sent to the quantum cryptography service center, carrying the address information of the destination recipient and the address information of the business user; wherein, the quantum key distribution request message is used to request the quantum cryptography service center to issue quantum keys to the destination recipient and the business user.
[0235] Alternatively, execute the following command:
[0236] The system receives a quantum key distribution request message from a service platform, carrying the address information of the destination recipient and the address information of the service user; the address information of the destination recipient is determined by the service platform based on the first attribute information of the destination recipient in the quantum secure communication request.
[0237] The quantum key is distributed to the destination recipient and the business user based on the quantum key distribution request message.
[0238] This disclosure also provides a computer-readable storage medium storing a computer program, which, when executed by a processor, performs the steps of the quantum secure communication method described in the above-described method embodiments. The storage medium can be either volatile or non-volatile computer-readable storage.
[0239] This disclosure also provides a computer program product carrying program code. The program code includes instructions that can be used to execute the steps of the quantum secure communication method described in the above method embodiments. For details, please refer to the above method embodiments, which will not be repeated here.
[0240] The aforementioned computer program product can be implemented through hardware, software, or a combination thereof. In one optional embodiment, the computer program product is specifically embodied in a computer storage medium; in another optional embodiment, the computer program product is specifically embodied in a software product, such as a software development kit (SDK), etc.
[0241] Those skilled in the art will clearly understand that, for the sake of convenience and brevity, the specific working processes of the systems and devices described above can be referred to the corresponding processes in the foregoing method embodiments, and will not be repeated here. In the several embodiments provided in this disclosure, it should be understood that the disclosed systems, devices, and methods can be implemented in other ways. The device embodiments described above are merely illustrative. For example, the division of units is only a logical functional division; in actual implementation, there may be other division methods. Furthermore, multiple units or components may be combined or integrated into another system, or some features may be ignored or not executed. Another point is that the displayed or discussed mutual coupling or direct coupling or communication connection may be through some communication interfaces; the indirect coupling or communication connection of devices or units may be electrical, mechanical, or other forms.
[0242] The units described as separate components may or may not be physically separate. The components shown as units may or may not be physical units; that is, they may be located in one place or distributed across multiple network units. Some or all of the units can be selected to achieve the purpose of this embodiment according to actual needs.
[0243] In addition, the functional units in the various embodiments of this disclosure can be integrated into one processing unit, or each unit can exist physically separately, or two or more units can be integrated into one unit.
[0244] If the aforementioned functions are implemented as software functional units and sold or used as independent products, they can be stored in a processor-executable, non-volatile, computer-readable storage medium. Based on this understanding, the technical solution of this disclosure, in essence, or the part that contributes to the prior art, or a portion of the technical solution, can be embodied in the form of a software product. This computer software product is stored in a storage medium and includes several instructions to cause a computer device (which may be a personal computer, server, or network device, etc.) to execute all or part of the steps of the methods described in the various embodiments of this disclosure. The aforementioned storage medium includes various media capable of storing program code, such as USB flash drives, portable hard drives, read-only memory (ROM), random access memory (RAM), magnetic disks, or optical disks.
[0245] Finally, it should be noted that the above-described embodiments are merely specific implementations of this disclosure, used to illustrate the technical solutions of this disclosure, and not to limit it. The protection scope of this disclosure is not limited thereto. Although this disclosure has been described in detail with reference to the foregoing embodiments, those skilled in the art should understand that any person skilled in the art can still modify or easily conceive of changes to the technical solutions described in the foregoing embodiments, or make equivalent substitutions for some of the technical features, within the scope of the technology disclosed in this disclosure. Such modifications, changes, or substitutions do not cause the essence of the corresponding technical solutions to deviate from the spirit and scope of the technical solutions of the embodiments of this disclosure, and should all be covered within the protection scope of this disclosure. Therefore, the protection scope of this disclosure should be determined by the protection scope of the claims.
Claims
1. A method of quantum secure communication, characterized by, The application is applied to a service platform, and comprises: receiving a quantum secure communication request sent by a service user; wherein the quantum secure communication request at least comprises first attribute information of a destination receiver; in a case where it is determined that the service user is a legal user, determining address information of the destination receiver based on the first attribute information of the destination receiver in the quantum secure communication request; sending, to a quantum cryptography service center, a quantum key distribution request message carrying the address information of the destination receiver and address information of the service user; wherein the quantum key distribution request message is used to request the quantum cryptography service center to issue quantum keys to the destination receiver and the service user.
2. The method of claim 1, wherein, The method further comprises: after sending the quantum key distribution request message to the quantum cryptography service center, receiving a quantum key distribution response sent by the quantum cryptography service center; wherein the quantum key distribution response is used to indicate whether the quantum cryptography service center successfully issues quantum keys to the service user and the destination receiver; forwarding the quantum key distribution response to the service user. Before receiving the quantum secure communication request sent by the service user, the method further comprises:
3. The method of claim 1, wherein, after detecting that a user is successfully registered, determining attribute information of the registered user based on the attribute structure information; determining user information of the registered user; wherein the user information comprises at least one of the following: a user account, a user password, and device address information; determining the user information table based on the attribute information of the registered user and the user information of the registered user. The method further comprises:
4. The method of claim 1, wherein, detecting a group entry application of the service user; wherein the group entry application carries a to-be-joined group of the service user. 5. The method of claim 2, wherein, 6. The method of claim 5, wherein, In a case where it is detected that the to-be-joined group is an already-created user group, attribute information of the registered user is determined based on attribute information of the to-be-joined group.
7. The method of claim 6, wherein, The determining the attribute information of the registered user based on the attribute structure information comprises: In a case where it is detected that the to-be-joined group does not belong to an already-created user group, attribute information of the to-be-joined group is extracted from the group entry application; The extracted attribute information is determined as the attribute information of the registered user, and the extracted attribute information is added to the attribute structure information.
8. The method of claim 1, wherein, The sending of the quantum key distribution request message carrying the address information of the destination receiver and the address information of the service user to the quantum cryptography service center comprises: The address information of the quantum cryptography service center to which the service user belongs is parsed from the quantum secure communication request, and the quantum key distribution request message is sent to the quantum cryptography service center to which the service user belongs based on the address information.
9. A quantum secure communication method, characterized by, Applied to a quantum cryptography service center, comprising: Receiving a quantum key distribution request message sent by a service platform and carrying address information of a destination receiver and address information of a service user; the address information of the destination receiver is determined by the service platform based on first attribute information of the destination receiver in a quantum secure communication request; Based on the quantum key distribution request message, quantum keys are distributed to the destination receiver and the service user.
10. The method of claim 9, wherein, The distribution of the quantum keys to the destination receiver and the service user based on the quantum key distribution request message comprises: The quantum keys are encrypted to obtain encrypted quantum keys; The encrypted quantum keys are distributed to the destination receiver and the service user.
11. The method of claim 9, wherein, The key distribution request comprises at least the following information: key demand information of the service user for quantum keys, a service type identifier, address information of the destination receiver, and address information of the service user; wherein the service type identifier is used to indicate the order of requesting the quantum cryptography service center to distribute quantum keys to the service user and the destination receiver.
12. The method according to any one of claims 9 to 11, characterized in that, The distribution of the quantum keys to the destination receiver and the service user based on the quantum key distribution request message comprises: In a case where it is determined that the service user reaches the key distribution order, it is determined whether there is an available quantum key in a key storage pool based on the key demand information of the service user for quantum keys in the quantum key distribution request message; In a case where it is determined that there is the available quantum key, the quantum key is distributed to the destination receiver and the service user respectively based on the address information in the quantum key distribution request message.
13. The method of claim 12, wherein, The method further comprises: Determining the service type identifier in the quantum key distribution request message; Determining whether the service user reaches the key distribution order based on the service type identifier.
14. The method of claim 9, wherein, The distribution of the quantum keys to the destination receiver and the service user based on the quantum key distribution request message comprises: In a case where it is determined that the quantum cryptography service center to which the destination receiver belongs is inconsistent with the quantum cryptography service center to which the service user belongs, the quantum key is issued through negotiation between the quantum cryptography service centers, the quantum key is issued to the destination receiver through the quantum cryptography service center to which the destination receiver belongs, and the quantum key is issued to the service user through the quantum cryptography service center to which the service user belongs.
15. A quantum secure communication system, characterized by, Comprise: a terminal device, a service platform and a quantum cryptography service center to which the service user belongs; the terminal device is configured to send a quantum secure communication request to the service platform; wherein the quantum secure communication request at least comprises first attribute information of a destination receiver; the service platform is configured to receive the quantum secure communication request sent by the service user; in a case where it is determined that the service user is a legal user, determine address information of the destination receiver based on the first attribute information of the destination receiver in the quantum secure communication request; send a quantum key distribution request message carrying the address information of the destination receiver and the address information of the service user to the quantum cryptography service center; the quantum cryptography service center is configured to issue the quantum key to the destination receiver and the service user based on the quantum key distribution request message.
16. The system of claim 15, wherein, the terminal device is configured to encrypt sensitive data based on the quantum key, and send the encrypted sensitive data to the destination receiver.
17. A quantum secure communication device, comprising: provided in the service platform, comprising: a first receiving unit configured to receive a quantum secure communication request sent by a service user; wherein the quantum secure communication request at least comprises first attribute information of a destination receiver; a determining unit configured to, in a case where it is determined that the service user is a legal user, determine address information of the destination receiver based on the first attribute information of the destination receiver in the quantum secure communication request; a sending unit configured to send a quantum key distribution request message carrying the address information of the destination receiver and the address information of the service user to a quantum cryptography service center; wherein the quantum key distribution request message is used to request the quantum cryptography service center to issue a quantum key to the destination receiver and the service user.
18. A quantum secure communication device, comprising: provided in the quantum cryptography service center, comprising: a second receiving unit configured to receive a quantum key distribution request message carrying address information of a destination receiver and address information of a service user sent by a service platform; wherein the address information of the destination receiver is determined by the service platform based on first attribute information of the destination receiver in a quantum secure communication request; a key issuing unit configured to issue a quantum key to the destination receiver and the service user based on the quantum key distribution request message.
19. An electronic device, comprising: comprise: a processor, a memory and a bus, the memory stores machine readable instructions executable by the processor, when the electronic device is running, the processor and the memory communicate through the bus, the machine readable instructions are executed by the processor to execute the steps of the quantum secure communication method in any one of claims 1 to 14.
20. A computer-readable storage medium, characterized in that, The computer readable storage medium stores a computer program, and the computer program is run by the processor to execute the steps of the quantum secure communication method according to any one of claims 1 to 13.
21. A computer program product, characterised in that, The computer program product is stored in a storage medium, and the program product is executed by at least one processor to implement the steps of the quantum secure communication method according to any one of claims 1 to 14.
Citation Information
Patent Citations
Quantum key transmission control method and system
CN104660602A
Method suitable for secret key management and rapid synchronization of quantum secret key distribution system
CN108616357A