Data security transmission method and device, network equipment and terminal
By using wireless key generation and encryption technology, the online distribution and secure transmission of sensitive data such as quantum keys on terminal devices have been achieved, solving the problem of frequent key additions and improving the user experience.
Patent Information
- Application Number
- CN202310900255.2
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2023-07-21
- Publication Date
- 2026-01-30
- Estimated Expiration
- 2043-07-21
AI Technical Summary
In existing technologies, the distribution and deployment of quantum keys on terminal devices requires frequent re-addition, which leads to inconvenience in use.
By leveraging the wireless key generation and encryption capabilities between the first device and the terminal, online distribution and secure transmission of sensitive data such as quantum keys can be achieved, avoiding offline refilling.
It enables the secure distribution of sensitive data such as quantum keys on terminal devices, avoiding the inconvenience caused by frequent re-addition.
Smart Images

Figure CN118827080B_ABST
Abstract
Description
Technical Field
[0001] This invention relates to the field of network security technology, and in particular to a data security transmission method, apparatus, network device, and terminal. Background Technology
[0002] Currently, quantum secure communication technology based on quantum key distribution has entered the practical application stage and has been applied in multiple fields, providing security guarantees for industry users.
[0003] To meet the application requirements of quantum keys in mobile terminals, the current main method is to inject a certain amount of pre-generated quantum keys into terminal security media such as Universal Subscriber Identity Module (USIM) cards and Trans-flash (TF) cryptographic cards through offline filling, and then distribute them to mobile terminal users.
[0004] Because the storage space reserved for quantum-related services on the terminal security medium is limited, the number of keys that can be filled in a single filling is also limited. Therefore, after the pre-installed keys are used up, quantum mobile terminal users are usually required to bring their terminal security medium to a designated branch of the service operator to connect with the quantum key filling device to replenish the quantum keys. However, the frequent filling causes inconvenience to users. Summary of the Invention
[0005] The purpose of this invention is to provide a data security transmission method, device, network equipment, and terminal to solve the problem that the distribution and deployment of important data (such as quantum keys) with high confidentiality requirements on terminal devices in the prior art requires frequent re-addition, causing inconvenience in use.
[0006] One embodiment of the present invention provides a data secure transmission method applied to a first device, wherein the method includes:
[0007] The first device receives a first message sent by the second device; the first message includes first information sent by the second device to the first terminal;
[0008] The first device uses a first key to encrypt and / or protect the integrity of all or part of the first message;
[0009] The first device sends the first message, after encryption and / or integrity protection, to the first terminal.
[0010] Optionally, in the data secure transmission method, the first key includes one or more of the following:
[0011] The key generated by the first device and the first terminal based on wireless physical layer key generation technology or a key derived therefrom;
[0012] A key or a further derived key is generated based on the key generated by the first device and the first terminal using wireless key generation technology and a fifth key; wherein, the fifth key is a key distributed by the key distribution center to the first device and the first terminal, or the fifth key is a key pre-shared between the first device and the first terminal;
[0013] The key generated based on the fifth key and the first parameter, or a key further derived therefrom; the first parameter is a common parameter in the wireless physical layer key generation process between the first device and the first terminal.
[0014] Optionally, in the data secure transmission method, the first information includes a second key for use by the first terminal.
[0015] Optionally, in the data secure transmission method, the first device uses a first key to encrypt and / or protect the integrity of all or part of the first message, including:
[0016] The first device uses the first key to encrypt and / or protect the integrity of the first information.
[0017] Optionally, in the data secure transmission method, the first device uses a first key to encrypt and / or protect the integrity of all or part of the first message, including:
[0018] If the first device has the first key available, the first device uses the first key to encrypt and / or protect the integrity of all or part of the first message.
[0019] Optionally, the data secure transmission method further includes:
[0020] If the first device does not have a usable first key, after receiving the first message, the first device will send the first message to the first terminal; or, the first device will send a second message to the second device; the second message is used to indicate that the transmission of the first message or the first information failed.
[0021] Optionally, the data secure transmission method further includes:
[0022] If the first device does not have a usable first key, the first device generates a first key that can be shared with the first terminal.
[0023] Optionally, in the data secure transmission method, all or part of the received first message is encrypted and / or protected for integrity using a third key.
[0024] The third key is a shared key between the second device and the first terminal.
[0025] Optionally, in the data secure transmission method, the received first message, after being encrypted and / or protected for integrity by the third key in whole or in part, is further encrypted and / or protected for integrity by the fourth key.
[0026] The fourth key is a shared key between the first device and the second device.
[0027] Optionally, the data secure transmission method further includes:
[0028] The first device receives a third message sent by the first terminal, wherein all or part of the content of the third message is encrypted and / or protected for integrity by the first key;
[0029] The first device sends the third message to the second device.
[0030] Optionally, in the data secure transmission method, the first device includes a first module and a second module;
[0031] The first device receives a first message sent by the second device, including:
[0032] The first module receives the first message sent by the second device;
[0033] Wherein, the first device uses a first key to encrypt and / or protect the integrity of all or part of the first message, including:
[0034] The first module sends an encryption request to the second module to request encryption and / or integrity protection of all or part of the first message;
[0035] The second module uses the first key to encrypt and / or protect the integrity of all or part of the first message;
[0036] The first device sends the encrypted and / or integrity-protected first message to the first terminal, including:
[0037] The first module or the second module sends the first message, after encryption and / or integrity protection, to the first terminal.
[0038] Optionally, in the data secure transmission method, after the second module encrypts and / or protects the integrity of all or part of the first message using the first key, the method further includes:
[0039] The second module sends a first response message for the encryption request to the first module; wherein the first response message includes the first message after encryption and / or integrity protection; wherein, after receiving the first response message, the first module sends the first message after encryption and / or integrity protection to the first terminal;
[0040] Alternatively, the second module may send the first message, after encryption and / or integrity protection, to the first terminal.
[0041] Optionally, the data secure transmission method further includes:
[0042] After receiving the first message sent by the second device, the first module sends a query request to the second module to request whether the first key is available.
[0043] The second module sends a second response message to the first module regarding the query request;
[0044] In the case where the second response message indicates that the first key is available, the first module sends the encryption request to the second module.
[0045] Optionally, the data secure transmission method further includes:
[0046] If the second response message indicates that the first key is not available, the first module sends the first message to the first terminal; or, the first module sends a second message to the second device, the second message indicating that the transmission of the first message or the first information failed.
[0047] Optionally, the data secure transmission method further includes:
[0048] If the second response message indicates that the first key is not available, the first module sends a key generation request to the second module to request the generation of a first key that can be shared with the first terminal.
[0049] And / or,
[0050] After generating a first key shared with the first terminal, the second module sends a third response message to the first module.
[0051] Optionally, in the data secure transmission method, after the first module receives the third response message, the method further includes:
[0052] The first module sends the encryption request to the second module.
[0053] Optionally, in the data secure transmission method, the encryption request includes one or more of the following information:
[0054] The data to be encrypted in the first message;
[0055] The length of the data to be encrypted;
[0056] The identification information of the first terminal;
[0057] The address information of the first terminal.
[0058] One embodiment of the present invention also provides a data security transmission method applied to a first terminal, wherein the method includes:
[0059] The first terminal receives a first message sent by the first device; wherein the first message includes first information sent to the first terminal by the second device, and all or part of the content of the first message is encrypted and / or protected for integrity by the first device using a first key;
[0060] The first message is decrypted using the first key.
[0061] Optionally, in the data secure transmission method, the first key includes one or more of the following:
[0062] The key generated by the first device and the first terminal based on wireless physical layer key generation technology or a key derived therefrom;
[0063] A key or a further derived key is generated based on the key generated by the first device and the first terminal using wireless key generation technology and a fifth key; wherein, the fifth key is a key distributed by the key distribution center to the first device and the first terminal, or the fifth key is a key pre-shared between the first device and the first terminal;
[0064] The key generated based on the fifth key and the first parameter, or a key further derived therefrom; the first parameter is a common parameter in the wireless physical layer key generation process between the first device and the first terminal.
[0065] Optionally, in the data secure transmission method, the first information includes a second key for use by the first terminal.
[0066] Optionally, in the data secure transmission method, the received first message is a message whose entire or part of its content has been encrypted and / or protected for integrity by a third key, and then encrypted and / or protected for integrity by the first key.
[0067] The third key is a shared key between the second device and the first terminal.
[0068] Optionally, in the data secure transmission method, the received first message is a message whose entire or part of its content is encrypted and / or protected for integrity by a third key, and then encrypted and / or protected for integrity by a fourth key, and then encrypted and / or protected for integrity by the first key.
[0069] The fourth key is a shared key between the first device and the second device.
[0070] Optionally, the data secure transmission method further includes:
[0071] A first key is used to encrypt and / or protect the integrity of all or part of the third message to be sent to the second device;
[0072] The third message, after being encrypted and / or protected for integrity, is sent to the first device.
[0073] Optionally, in the data secure transmission method, the first terminal includes a third module and a fourth module;
[0074] The first terminal receives a first message sent by the first device, including:
[0075] The third module receives the first message sent by the first device;
[0076] Decrypting the first message using the first key includes:
[0077] The third module sends a decryption request to the fourth module;
[0078] The fourth module decrypts the first message using the first key according to the decryption request;
[0079] The fourth module sends a fourth response message to the third module regarding the decryption request, the fourth response message including the decrypted first message.
[0080] Optionally, in the data secure transmission method, the first terminal includes a third module and a fourth module;
[0081] The first terminal receives a first message sent by the first device, including:
[0082] The fourth module receives the first message sent by the first device;
[0083] The first message is decrypted using the first key to obtain the first information, including:
[0084] The fourth module uses the first key to decrypt the first message;
[0085] The fourth module sends the decrypted first message to the third module.
[0086] Optionally, the data secure transmission method further includes:
[0087] The third module sends a fifth response message to the first device or the fourth module; wherein the fifth response message includes the result of receiving the first message.
[0088] Optionally, the data secure transmission method further includes:
[0089] The third module sends a data request to the first device to request the acquisition of the first information.
[0090] One embodiment of the present invention also provides a network device, wherein the network device is a first device, comprising a transceiver and a processor, wherein:
[0091] The transceiver is used to receive a first message sent by a second device; the first message includes first information sent by the second device to a first terminal.
[0092] The processor is used to encrypt and / or protect the integrity of all or part of the first message using a first key;
[0093] The transceiver is also used to send the first message, after being encrypted and / or protected for integrity, to the first terminal.
[0094] One embodiment of the present invention also provides a terminal, wherein the terminal is a first terminal, comprising a transceiver and a processor; wherein:
[0095] The transceiver is used to receive a first message sent by a first device; wherein the first message includes first information sent by a second device to the first terminal, and all or part of the content of the first message is encrypted and / or protected for integrity by the first device using a first key;
[0096] The processor is used to decrypt the first message using the first key.
[0097] One embodiment of the present invention also provides a data security transmission device, applied to a first device, wherein the device includes:
[0098] The first message receiving module is used to receive a first message sent by the second device; the first message includes first information sent by the second device to the first terminal.
[0099] An encryption module is used to encrypt and / or protect the integrity of all or part of the first message using a first key;
[0100] The message sending module is used to send the first message, after encryption and / or integrity protection, to the first terminal.
[0101] One embodiment of the present invention also provides a data security transmission device applied to a first terminal, wherein the device includes:
[0102] The second message receiving module is used to receive a first message sent by the first device; wherein the first message includes first information sent by the second device to the first terminal, and all or part of the content of the first message is encrypted and / or protected for integrity by the first device using a first key;
[0103] The decryption module is used to decrypt the first message using the first key.
[0104] One embodiment of the present invention also provides a readable storage medium, wherein a program is stored on the readable storage medium, and when the program is executed by a processor, it implements the steps of the data secure transmission method as described in any of the preceding claims.
[0105] At least one of the above technical solutions of the present invention has the following beneficial effects:
[0106] The method described in this embodiment of the invention involves a first device encrypting and / or protecting the integrity of all or part of the first message using a first key after receiving a first message sent by a second device, and then sending the first message to a first terminal. This utilizes the wireless security capabilities between the first device and the terminal, such as wireless key generation and encryption, to achieve secure distribution of sensitive or important data, such as quantum keys, to the terminal over the air interface. This avoids the inconvenience caused by the need for frequent refilling when filling the terminal with sensitive or important data, such as quantum keys, using offline filling methods. Attached Figure Description
[0107] Figure 1 This is a schematic diagram of a system architecture employing the data secure transmission method described in an embodiment of the present invention;
[0108] Figure 2 This is a schematic flowchart of the transmission method according to one embodiment of the present invention;
[0109] Figure 3 This is a flowchart illustrating one embodiment of the method described in this invention.
[0110] Figure 4 This is a schematic diagram of one application scenario of the method described in the embodiments of the present invention;
[0111] Figure 5 This is a second schematic diagram illustrating an application scenario using the method described in this embodiment of the invention;
[0112] Figure 6 This is a flowchart illustrating one embodiment of the method described in this invention.
[0113] Figure 7 This is a flowchart illustrating another embodiment of the method described in the present invention;
[0114] Figure 8 This is a schematic flowchart of the transmission method according to another embodiment of the present invention;
[0115] Figure 9 This is a schematic diagram of the network device described in an embodiment of the present invention;
[0116] Figure 10 This is a schematic diagram of the structure of the terminal described in an embodiment of the present invention;
[0117] Figure 11 This is a schematic diagram of the transmission device according to one embodiment of the present invention;
[0118] Figure 12 This is a schematic diagram of the transmission device according to another embodiment of the present invention. Detailed Implementation
[0119] To make the technical problems, technical solutions and advantages of the present invention clearer, a detailed description will be given below in conjunction with the accompanying drawings and specific embodiments.
[0120] To address the problem that the distribution and deployment of critical data (such as quantum keys) with high confidentiality requirements on terminal devices in existing technologies requires frequent re-addition, causing inconvenience, this invention provides a data security transmission method. This method uses a quantum key distribution (QKD) network to distribute critical data (such as quantum keys) online to terminals, and utilizes a first device to securely protect the critical data transmitted from a second device to the terminal, ensuring the secure transmission of this critical data over the air interface.
[0121] From the perspective of the long-term development and large-scale application of quantum key distribution industry, online distribution of quantum keys to mobile devices based on QKD networks is an effective way to solve the problem of mobile quantum key deployment. Wireless channels have the characteristics of randomness, reciprocity, and decorrelation, and wireless physical layer key generation has the technical feature of "one-time pad". By utilizing these characteristics, keys with information theory security can be generated between wireless devices to securely protect sensitive or important data transmitted over wireless channels.
[0122] Currently, for mobile terminals, the main problem that quantum key distribution needs to solve is how to use wireless security capabilities such as wireless key generation and wireless key encryption to securely distribute sensitive or important data such as quantum keys to mobile terminals and meet the "last mile" secure communication needs of mobile terminals.
[0123] The data security transmission method described in this embodiment of the invention involves a first device and a terminal being matched. After receiving a first message sent by a second device, the first device uses a first key to encrypt and / or protect the integrity of all or part of the first message before sending it to the first terminal. This utilizes the wireless security capabilities between the first device and the terminal, such as wireless key generation and encryption, to achieve secure distribution of sensitive or important data, such as quantum keys, to the terminal over the air interface. This avoids the inconvenience caused by the need for frequent refilling when filling the terminal with sensitive or important data, such as quantum keys, using offline filling methods.
[0124] like Figure 1 The diagram shown is one of the system architecture schematics for the data secure transmission method described in this embodiment of the invention. The system includes a first device 1, a second device 2, and a terminal 3. Using this system, sensitive information transmitted from a server / platform (such as QKDC) to the terminal can be securely protected using a wireless key, ensuring the secure transmission of sensitive or important data over the air interface.
[0125] Optionally, the second device 2 can be a security service center, a security server, or a security service platform. Taking the method described in this embodiment of the invention for the distribution of quantum keys at the terminal as an example, when applied to a quantum key distribution (QKD) network, the second device 2 can be a quantum key security service center, abbreviated as QKDC, which is connected to a quantum random number generator (QRNG) or a QKD network device. It can obtain quantum keys from the QRNG or QKD network device and manage the quantum keys throughout their entire lifecycle, such as key storage, key destruction, and key distribution.
[0126] In addition, the second device 2 supports establishing a secure connection with the first device 1 and the terminal 3, and securely sends / updates quantum keys to the terminal 3 via a wireless channel.
[0127] It should be noted that when the method described in this embodiment of the invention is applied to other sensitive or important data transmissions with high security protection requirements, the second device 2 is not limited to QKDC, but can also be other secure management platforms, systems or devices.
[0128] The first device 1 is a wireless transmission component, such as a wireless gateway. Optionally, the first device can be a WLAN device, a 4G / 5G / 6G mobile communication device, or a Bluetooth or Zigbee system device. Alternatively, the first device 1 can also be a base station.
[0129] When applied to a QKD network, the first device 1 forms a quantum key wireless transmission component. Optionally, the first device supports establishing a secure connection with the QKDC, accepting the management of the QKDC, and receiving important data such as quantum keys sent by the QKDC; and supports securely transmitting data such as quantum keys issued by the QKDC to the terminal via a wireless channel.
[0130] Optionally, the first device 1 may also have functions such as wireless key generation, wireless key management, and wireless key usage. The wireless key generation function generates wireless keys through wireless channel probing, quantization, information coordination, and privacy amplification. The wireless key management function is responsible for managing the wireless key throughout its entire lifecycle, such as triggering wireless key generation, wireless key storage, and wireless key destruction. The wireless key usage function uses the generated wireless key to securely protect the information to be transmitted, including encryption / decryption operations.
[0131] Optionally, the first device 1 can also be responsible for storing the quantum keys pre-installed in the QKDC or sent / updated offline, and for performing cryptographic operations, etc.
[0132] In this embodiment of the invention, terminal 3 is optionally a terminal for wireless distribution of quantum keys. Optionally, terminal 3 supports establishing a secure connection with the QKDC, accepting the management of the QKDC, receiving quantum keys and other data sent by the QKDC, and receiving quantum keys issued by the QKDC and securely storing them in a cryptographic module. Optionally, terminal 3 also has functions such as wireless key generation, wireless key management, and wireless key usage. The wireless key generation function generates wireless keys through wireless channel probing, quantization, information coordination, and privacy amplification. The wireless key management function is responsible for managing the wireless key throughout its entire lifecycle, such as triggering wireless key generation, wireless key storage, and wireless key destruction. The wireless key usage function uses the generated wireless key to securely protect the information to be transmitted, including encryption / decryption operations. Optionally, terminal 3 is also responsible for storing quantum keys pre-installed by the QKDC or issued / updated offline, and implementing cryptographic operations.
[0133] The system uses the distribution and deployment of quantum keys on terminal devices as an example to illustrate the functions of each device in the system using the method described in the embodiments of the present invention. It should be noted that the method described in the embodiments of the present invention is not limited to the distribution and deployment of quantum keys on terminal devices, but can also be applied to the transmission of other sensitive or important data with high security protection requirements. The functions of each device can also be referred to the above description, and will not be described in detail here.
[0134] The data secure transmission method described in one embodiment of the present invention is applied to a first device, such as... Figure 2 As shown, the method includes:
[0135] S210, the first device receives a first message sent by the second device; the first message includes first information sent by the second device to the first terminal;
[0136] S220, the first device uses a first key to encrypt and / or protect the integrity of all or part of the first message;
[0137] S230, the first device sends the first message, after encryption and / or integrity protection, to the first terminal.
[0138] Optionally, using the method described in this embodiment of the invention, the first device is a wireless gateway, and the second device is a security service center that sends / updates first information (such as a quantum key) to the first terminal. After the first device receives the first message containing the first information sent to the first terminal by the second device, it uses wireless security capabilities such as wireless key generation and wireless key encryption between the first device and the first terminal to encrypt and / or protect the integrity of all or part of the first message before transmitting the first message to the first terminal, thereby realizing the secure distribution of sensitive or important data such as quantum keys to the first terminal over the air interface.
[0139] Optionally, the first key includes one or more of the following:
[0140] The key generated by the first device and the first terminal based on wireless physical layer key generation technology or a key derived therefrom;
[0141] A key or a further derived key is generated based on the key generated by the first device and the first terminal using wireless key generation technology and a fifth key; wherein, the fifth key is a key distributed by the key distribution center to the first device and the first terminal, or the fifth key is a key pre-shared between the first device and the first terminal;
[0142] The key generated based on the fifth key and the first parameter, or a key further derived therefrom; the first parameter is a common parameter in the wireless physical layer key generation process between the first device and the first terminal.
[0143] In this embodiment of the invention, optionally, the first parameter can be Received Signal Strength Indication (RSSI), Channel State Information (CSI), or the above information after processing, which can reflect the random characteristics of the wireless channel and has timeliness.
[0144] In this embodiment of the invention, the first device and the first terminal may negotiate and determine a first key for encrypting and / or protecting the integrity of the transmitted messages. The determined first key may be any of the keys mentioned above.
[0145] Optionally, the first information includes a second key for use by the first terminal.
[0146] For example, the second key is a quantum key. This second key can be a key generated by the second device, or a key obtained by the second device from other network devices. For instance, the second key could be a key obtained from a QRNG device, a key generated after obtaining quantum random numbers from a QRNG device, a key obtained from a quantum QKD network, or a key derived from an obtained key.
[0147] Using this implementation method, the first device can encrypt and / or protect the integrity of the quantum key distributed by the second device to the first terminal, so as to realize the distribution and deployment of the quantum key issued / updated by the second device on the terminal.
[0148] Optionally, the first message may also include the terminal identifier and / or address information of the first terminal. This address information includes, but is not limited to, IP addresses and / or MAC addresses.
[0149] Optionally, the first device uses a first key to encrypt and / or protect the integrity of all or part of the first message, including:
[0150] The first device uses the first key to encrypt and / or protect the integrity of the first information.
[0151] In one embodiment, if the first information includes a second key (such as a quantum key), the first device uses the first key to encrypt and / or protect the integrity of the second key.
[0152] Optionally, the first key is a wireless key generated through wireless negotiation between the first device and the first terminal. Optionally, the first device negotiates and generates the first key with the first terminal through steps such as channel detection, quantization, information coordination, and privacy amplification.
[0153] Optionally, the first device uses a first key to encrypt and / or protect the integrity of all or part of the first message, including:
[0154] If the first device has the first key available, the first device uses the first key to encrypt and / or protect the integrity of all or part of the first message.
[0155] In this embodiment, after receiving the first message sent by the second device, the first device determines whether there is a first key that has been negotiated and is available with the first terminal. If it is determined that there is a first key that has been negotiated and is available with the first terminal, the first device uses the first key that has been negotiated and is available with the first terminal to encrypt and / or protect the integrity of all or part of the content of the first message.
[0156] Optionally, the method further includes:
[0157] If the first device does not have a usable first key, after receiving the first message, the first device will send the first message to the first terminal; or, the first device will send a second message to the second device; the second message is used to indicate that the transmission of the first message or the first information failed.
[0158] In another implementation, after receiving the first message sent by the second device, if the first device determines that there is no available first key, it directly sends the first message to the first terminal to ensure that the first terminal can obtain the first information sent by the second device to the first terminal; or, the first device sends a second message to the second device to indicate that the transmission of the first message or the first information has failed, so that the second device can obtain the indication information of transmission failure and can transmit the first information again.
[0159] Optionally, the method further includes:
[0160] If the first device does not have a usable first key, the first device generates a first key that can be shared with the first terminal.
[0161] In this embodiment, after receiving the first message sent by the second device, if the first device determines that there is no available first key, the first device negotiates with the first terminal to generate a corresponding first key through steps such as channel probing, quantization, information coordination and privacy amplification, so as to encrypt and / or protect the integrity of the first message sent by the second device to the first terminal in subsequent steps.
[0162] It should be noted that if the first device determines that there is no available first key, the first device may send the first message to the first terminal and generate a first key that can be shared with the first terminal simultaneously, or only one of these steps may be performed; and / or, the first device may send a second message to the second device to indicate that the transmission of the first message or first information has failed, and generate a first key that can be shared with the first terminal simultaneously, or only one of these steps may be performed.
[0163] In another embodiment, optionally, after receiving the first message sent by the second device, if the first device determines that there is no available first key, it may not perform the steps of directly sending the first message to the first terminal and sending the second message to the second device. Instead, after generating a first key that can be shared with the first terminal, it may use the generated first key to encrypt and / or protect the integrity of all or part of the currently received first message.
[0164] In this embodiment of the invention, optionally, all or part of the received first message is encrypted with a third key and / or protected for integrity.
[0165] The third key is a shared key between the second device and the first terminal.
[0166] In one implementation, optionally, the third key can be provided to the first terminal by the second device (such as a QKDC). Using this third key, a secure channel is established between the second device and the first terminal, thus achieving end-to-end protection for the transmitted first message between the second device and the first terminal.
[0167] In this implementation, before sending the first message to the first device, the second device encrypts and / or protects the integrity of the first message to be sent using a shared key (third key) between itself and the first terminal, and then sends the first message encrypted and / or protected by the third key to the first device. The first device then encrypts and / or protects the integrity of the received first message using the first key and then transmits it to the first terminal.
[0168] In another embodiment of the present invention, optionally, the received first message, after being encrypted and / or protected for integrity by the third key, is further encrypted and / or protected for integrity by a fourth key.
[0169] The fourth key is a shared key between the first device and the second device.
[0170] In one implementation, optionally, the fourth key can be provided to the first device by the second device (such as a QKDC) through a pre-sharing method. Using this fourth key, a secure channel is established between the second device and the first device, thus achieving end-to-end protection for the transmitted first message between the two devices.
[0171] In this implementation, before sending the first message to the first device, the second device encrypts and / or protects the integrity of the first message using a shared key (a third key) with the first terminal, and then further encrypts and / or protects the integrity of the first message using a fourth key. The first message, encrypted and / or protected by the third and fourth keys, is then sent to the first device. The first device encrypts and / or protects the received first message using the first key before transmitting it to the first terminal. This method effectively protects the security of the first message transmitted to the first terminal.
[0172] Optionally, in this embodiment of the invention, the method further includes:
[0173] The first device receives a data request sent by the first terminal, the data request being used to request the acquisition of first information;
[0174] The first device forwards the data request to the second device.
[0175] In this implementation, the first device forwards the data request from the first terminal to the second device. The second device can send a first message to the first terminal through the first device based on the data request from the first terminal. The first message includes first information sent by the second device to the first terminal.
[0176] In another embodiment, optionally, after the first device sends the encrypted and / or integrity-protected first message to the first terminal, the method further includes:
[0177] The first device receives a fifth response message sent by the first terminal; wherein the fifth response message includes the first terminal's reception result of the first message;
[0178] The first device forwards the fifth response message to the second device.
[0179] Through the above implementation process, the first device can not only forward the first message sent from the second device to the first terminal, but also forward other messages transmitted between the second device and the first terminal (such as request messages sent from the first terminal to the second device, response messages indicating the reception result of the first message, etc.), thereby realizing secure transmission of messages between the second device and the first terminal.
[0180] In another embodiment of the present invention, optionally, the method further includes:
[0181] The first device receives a third message sent by the first terminal, wherein all or part of the content of the third message is encrypted and / or protected for integrity by the first key;
[0182] The third message is sent to the second device.
[0183] Optionally, the first device sends the third message to the second device through a secure channel between the first device and the second device. For example, after encrypting and / or protecting the integrity of the third message using a shared key (fourth key) between the first device and the second device, the first device sends the third message to the second device.
[0184] Optionally, the third message may include, but is not limited to, a data request message that can only include the data request message used by the first terminal to request the acquisition of the first information, and / or, a fifth response message used by the first terminal to include the result of the first terminal receiving the first message after receiving the first message.
[0185] In this implementation, the key (first key) generated by the first device and the first terminal based on the wireless physical layer key generation technology can be used not only to transmit sensitive or important data (such as quantum keys) sent by the second device to the first terminal, but also to provide security protection for other messages transmitted between the first terminal and the second device.
[0186] Combination Figure 3 and Figure 4 As shown, taking quantum key transmission as an example, a secure wireless transmission channel is established between the first terminal and the first device (such as a wireless gateway or wireless network node) through the first key. Quantum key requests sent by the first terminal to the first device, key request confirmation messages sent by the first device to the first terminal, quantum key response messages, and quantum key confirmation messages sent by the first terminal to the first device can all be transmitted through the secure wireless transmission channel. That is, encryption and / or integrity protection are performed through the first key negotiated and determined between the first device and the first terminal.
[0187] In another embodiment of the present invention, the first device (wireless gateway) and the first terminal each include multiple modules. The data security transmission method described in this embodiment of the present invention utilizes data transmission between multiple modules with different functions to further ensure that the quantum key can be securely transmitted from the second device to the first terminal and securely distributed and deployed, so as to effectively guarantee the quantum security communication needs of the terminal.
[0188] like Figure 5 The diagram shows another structural schematic of the system to which the data secure transmission method described in this embodiment of the invention is applied.
[0189] See Figure 5 As shown, the first device (wireless gateway) may include:
[0190] Optionally, the first module, also referred to as a quantum key wireless transmission component, is used to receive quantum key data sent by the second device (QKDC) and to transmit quantum key data issued by the second device (QKDC) to the first terminal. Specifically, the first module is used to establish a secure connection with the second device (QKDC), accept the management of the QKDC, receive quantum key data sent by it, and support the secure transmission of quantum key data issued by the QKDC to the terminal via a wireless channel.
[0191] The second module includes functions such as wireless key generation, wireless key management, and wireless key usage. The wireless key generation function generates wireless keys through wireless channel detection, quantization, information coordination, and privacy amplification. The wireless key management function is responsible for the full lifecycle management of the wireless keys, such as triggering wireless key generation, wireless key storage, and wireless key destruction. The wireless key usage function uses the generated wireless keys to securely protect the information to be transmitted, including encryption / decryption operations; optionally, this second module can also be called the wireless secure communication module.
[0192] The first cryptographic module includes a secure storage medium for storing quantum keys pre-installed in the QKDC or sent / updated offline, and for performing cryptographic operations, etc.
[0193] The first terminal (which can be a quantum-safe terminal) may include:
[0194] The third module, optionally, can be called a quantum key wireless distribution component; it is used to establish a secure connection with the second device (QKDC), accept the management of the QKDC, receive data such as quantum keys sent by it; and receive the quantum keys issued by the QKDC and securely store them in the second cryptographic module, which are forwarded through a wireless gateway (quantum key wireless transmission component).
[0195] The fourth module, optionally referred to as the wireless secure communication module, includes functions such as wireless key generation, wireless key management, and wireless key usage. The wireless key generation function generates wireless keys through wireless channel detection, quantization, information coordination, and privacy amplification. The wireless key management function is responsible for managing the wireless key throughout its entire lifecycle, such as triggering wireless key generation, wireless key storage, and wireless key destruction. The wireless key usage function uses the generated wireless key to securely protect the information to be transmitted, including encryption / decryption operations.
[0196] The second cryptographic module includes a secure storage medium responsible for storing quantum keys pre-installed in the QKDC or sent / updated offline, and for performing cryptographic operations.
[0197] In this embodiment of the invention, combined with Figure 5 As shown, the system also includes the following interface: Q1 interface: This is the offline management interface for the QKDC to the third cryptographic module. The QKDC uses this offline management interface to initialize the third cryptographic module and perform initial key loading. The third cryptographic module is a module connected to the QKDC and is used to store quantum keys.
[0198] Q2 Interface: The interface between QKDC and the first module (quantum key wireless transmission component) of the first device. QKDC establishes a secure channel with the wireless access point (AP) through this interface and performs online management of the AP.
[0199] Q3 Interface: The interface between QKDC and the third module (quantum key wireless distribution component) of the first terminal. QKDC establishes a secure channel with the station (STA) through this interface and performs online management of the STA.
[0200] Q4 Interface: The interface between the first module (quantum key wireless transmission component) of the first device and the first cryptographic module of the first device. The first module (quantum key wireless transmission component) of the first device performs cryptographic operations, securely stores cryptographic resources, and executes the QKDC's management functions for the first cryptographic module through this interface.
[0201] Q5 Interface: This is the interface for interaction between the first module (quantum key wireless transmission component) and the second module (wireless secure communication module) of the first device. The first module (quantum key wireless transmission component) uses this interface to query and manage the wireless key, and uses the wireless key to encrypt and protect the quantum key distributed by the QKDC to the first terminal. This wireless key is also the first key generated by the first device and the first terminal based on wireless physical layer key generation technology.
[0202] Q6 Interface: The interface for interaction between the first module (quantum key wireless transmission component) of the first device and the third module (quantum key wireless distribution component) of the first terminal.
[0203] Q7 Interface: The interface between the third module (quantum key wireless distribution component) of the first terminal and the second cryptographic module of the first terminal. The third module (quantum key wireless distribution component) of the first terminal performs cryptographic operations, securely stores cryptographic resources, and executes the QKDC's management functions for the cryptographic module through this interface.
[0204] Q8 Interface: The interface between the third module (quantum key wireless distribution component) of the first terminal and the fourth module (wireless secure communication module) of the first terminal. The fourth module (wireless secure communication module) of the first terminal queries and manages the wireless key (first key) through this interface, and uses the wireless key to decrypt the quantum key distributed to the terminal by QKDC.
[0205] Based on the above system, using the data secure transmission method described in this embodiment of the invention, a secure channel (secure channel 1) is established between the second device (QKDC) and the first module (quantum key wireless transmission component) of the first device, thus achieving end-to-end protection between the QKDC and the first module (quantum key wireless transmission component); a secure channel (secure channel 2) is established between the QKDC and the third module (quantum key wireless distribution component) of the first terminal, thus achieving end-to-end protection between the QKDC and the third module (quantum key wireless distribution component) of the first terminal.
[0206] Optionally, a secure channel 1 is established between the second device (QKDC) and the first module (quantum key wireless transmission component) of the first device by establishing a shared key (fourth key); a secure channel is established between the QKDC and the third module (quantum key wireless distribution component) of the first terminal by establishing a shared key (third key).
[0207] Optionally, the second module (wireless secure communication module) of the first device and the fourth module (wireless secure communication module) of the first terminal negotiate and generate a wireless key (first key) through steps such as channel detection, quantization, information coordination and privacy amplification, which is used to transmit the quantum key.
[0208] Combination Figure 2 and Figure 5 As shown, the first device receives a first message sent by the second device, including:
[0209] The first module receives the first message sent by the second device;
[0210] The first message includes first information sent by the second device to the first terminal, such as a quantum key; optionally, the first message also includes the terminal identifier and / or address information of the first terminal. This address information includes, but is not limited to, IP addresses and / or MAC addresses.
[0211] Wherein, the first device uses a first key to encrypt and / or protect the integrity of all or part of the first message, including:
[0212] The first module sends an encryption request to the second module to request encryption and / or integrity protection of all or part of the first message;
[0213] The second module uses the first key to encrypt and / or protect the integrity of all or part of the first message.
[0214] Optionally, the encryption request may include one or more of the following information:
[0215] 1) The data to be encrypted in the first message, such as quantum keys, quantum key ciphertext, or other sensitive data that needs to be encrypted and protected;
[0216] 2) The length of the data to be encrypted;
[0217] 3) Identification information of the first terminal;
[0218] 4) The address information of the first terminal; the address information includes, but is not limited to, terminal IP address and / or terminal MAC address information.
[0219] The first device sends the encrypted and / or integrity-protected first message to the first terminal, including:
[0220] The first module or the second module sends the first message, after encryption and / or integrity protection, to the first terminal.
[0221] It should be noted that the "first message after encryption and / or integrity protection" mentioned in the embodiments of the present invention actually refers to "the first message after being partially or fully encrypted and / or integrity protected". The following will not explain each of the contents described separately.
[0222] In one implementation, after the second module encrypts and / or protects the integrity of all or part of the first message using the first key, the second module sends the encrypted and / or integrity-protected first message to the fourth module of the first terminal, and the fourth module decrypts the first message.
[0223] In another implementation, after the second module encrypts and / or protects the integrity of all or part of the first message using the first key, the second module sends a first response message to the first module, the first response message including the first message after encryption and / or integrity protection; wherein, after receiving the first response message, the first module sends the first message after encryption and / or integrity protection to the first terminal.
[0224] Based on the above, in one embodiment, optionally, after the second module uses the first key to encrypt and / or protect the integrity of all or part of the first message, the method further includes:
[0225] The second module sends a first response message to the first module regarding the encryption request; wherein the first response message includes the first message after encryption and / or integrity protection;
[0226] Wherein, after receiving the first response message, the first module sends the first message, which has been encrypted and / or protected for integrity, to the first terminal.
[0227] Optionally, the first response message includes one or more of the following information:
[0228] 1) The first message after being encrypted and / or protected for integrity;
[0229] 2) Encryption result information, used to indicate whether encryption was successful; wherein, if the encryption result information indicates that encryption was successful, the first response message includes the first message after encryption and / or integrity protection;
[0230] 3) The data length of the first message after encryption and / or integrity protection.
[0231] In one embodiment, optionally, the method further includes:
[0232] After receiving the first message sent by the second device, the first module sends a query request to the second module to request whether the first key is available.
[0233] The second module sends a second response message to the first module regarding the query request;
[0234] In the case where the second response message indicates that the first key is available, the first module sends the encryption request to the second module.
[0235] Optionally, the query request includes the terminal identifier and / or terminal address information of the first terminal, used to request whether there is a usable first key corresponding to the first terminal.
[0236] Optionally, the method further includes:
[0237] If the second response message indicates that the first key is not available, the first module sends the first message to the first terminal; or, the first module sends a second message to the second device, the second message indicating that the transmission of the first message or the first information failed.
[0238] In this implementation, when the second response message indicates that the first key is not available, in one processing method, the first device refuses to transmit the first message to the first terminal and returns a second message to the second device, indicating that the transmission of the first message or first information has failed. Optionally, the second message includes the reason for the transmission failure: the first key is not available. In another processing method, the first module of the first device sends the first message to the first terminal, wherein the first message sent to the first terminal is encrypted and protected by a shared key (third key) between the second device and the first terminal to ensure the secure transmission of the first message.
[0239] Alternatively, in another embodiment, the method may further include:
[0240] If the second response message indicates that the first key is not available, the first module sends a key generation request to the second module to request the generation of a first key that can be shared with the first terminal; and / or,
[0241] After generating a first key shared with the first terminal, the second module sends a third response message to the first module.
[0242] It should be noted that sending the third response message by the second module is an optional step.
[0243] Optionally, the key generation request may include one or more of the following information:
[0244] 1) The terminal identifier corresponding to the requested first terminal;
[0245] 2) The terminal address information corresponding to the requested first terminal, such as including IP address and / or MAC address;
[0246] 3) The number of first keys requested to be generated.
[0247] In one embodiment, optionally, the method further includes:
[0248] After receiving the third response message, the first module sends the encryption request to the second module.
[0249] In this implementation, after receiving the first message sent by the second device, if the first module of the first device determines that there is no available first key, it may not perform the steps of directly sending the first message to the first terminal and sending the second message to the second device. Instead, after the second module generates a first key that can be shared with the first terminal, the first module receives a third response message after generating the first key shared with the first terminal and sends an encryption request to the second module. The second module then uses the generated first key to encrypt and / or protect the integrity of all or part of the currently received first message. After that, the first module transmits the encrypted and / or integrity-protected first message to the first terminal.
[0250] The following will take the data secure transmission method described in the embodiments of the present invention and its application to quantum key distribution as an example to explain the specific implementation process of the method in detail.
[0251] Figure 6 This is a flowchart illustrating one embodiment of the method described in this invention. In this embodiment, after encrypting and / or protecting the integrity of the first message, the first module of the first device sends the encrypted and / or integrity-protected first message to the first terminal.
[0252] S601, a secure channel 1 is established between the second device (QKDC) and the first module (quantum key wireless transmission component) of the first device by establishing a shared key (fourth key); end-to-end protection is achieved between the QKDC and the quantum key wireless transmission component;
[0253] S602, a secure channel 2 is established between the QKDC and the third module (quantum key wireless distribution component) of the first terminal by establishing a shared key (third key), thereby achieving end-to-end protection between the QKDC and the quantum key wireless distribution component;
[0254] S603, the second module (wireless secure communication module) of the first device and the fourth module (wireless secure communication module) of the first terminal negotiate and generate a wireless key through steps such as channel detection, quantization, information coordination and privacy amplification, that is, generate the first key;
[0255] S604, the third module (quantum key wireless distribution component) of the first terminal sends a data request to the first module (quantum key wireless transmission component) of the first device through the secure channel 2 to request first information, such as requesting to obtain a quantum key;
[0256] S605, the first module (quantum key wireless transmission component) of the first device forwards the data request to the second device (QKDC) through secure channel 2;
[0257] S606, the QKDC sends the quantum key requested by the first terminal to the first module (quantum key wireless transmission component) of the first device through secure channel 1, that is, sends a first message to the first module (quantum key wireless transmission component) of the first device. The first message includes the quantum key ciphertext requested by the first terminal; optionally, the first message also includes the terminal identifier and / or address information of the first terminal. The address information includes, but is not limited to, only IP address and / or MAC address;
[0258] S607, after receiving the first message, the first module (quantum key wireless transmission component) of the first device sends a query request to the second module (wireless secure communication module) of the first device to request whether the first key is available; optionally, the query request includes the terminal identifier and / or terminal address information of the first terminal;
[0259] S608, the second module (wireless secure communication module) of the first device determines whether a usable first key has been generated with the first terminal according to the query request, and sends a second response message of the query request to the first module (quantum key wireless transmission component) of the first device, the second response message including the query result;
[0260] S609, the first module (quantum key wireless transmission component) of the first device determines whether there is an available first key based on the query result in the second response message; wherein, if it is determined that there is no available first key, the following steps S610 to S616 are executed; if it is determined that there is an available first key, the following steps S617 to S623 are executed.
[0261] S610, when it is determined that there is no available first key, in one of the processing methods of the first module (quantum key wireless transmission component) of the first device, a second message is returned to the QKDC, indicating that the first message or the first information transmission failed, and informing that the reason for the failure is "the first key does not exist";
[0262] S611, when it is determined that there is no available first key, another processing method of the first module (quantum key wireless transmission component) of the first device is to send the first message to the third module (quantum key wireless distribution component) of the first terminal. Specifically, the first message is encrypted and / or its integrity is protected through the secure channel 2, and then the first message is sent to the third module (quantum key wireless distribution component) of the first terminal.
[0263] It should be noted that steps S610 and S611 are steps that can be performed by selecting one of them.
[0264] S612, after receiving the first message, the third module (quantum key wireless distribution component) of the first terminal sends a fifth response message to the first module (quantum key wireless transmission component) of the first device, including the reception result of the first message; optionally, the third module of the first terminal may encrypt and / or protect the integrity of all or part of the fifth response message using the first key before sending it to the first module (quantum key wireless transmission component) of the first device, so as to send the fifth response message to the first module (quantum key wireless transmission component) of the first device through a secure channel;
[0265] S613, the first module (quantum key wireless transmission component) of the first device sends the fifth response message to the QKDC, completing the entire distribution process;
[0266] Optionally, if it is determined that no available first key exists, the following steps S614 to S616 may also be performed;
[0267] S614, the first module (quantum key wireless transmission component) of the first device sends a key generation request to the second module (wireless secure communication module) to request the generation of a first key that can be shared with the first terminal;
[0268] Alternatively, the key generation request can be implemented by calling the interaction interface with the second module (wireless secure communication module).
[0269] Optionally, the key generation request may include one or more of the following information:
[0270] 1) The terminal identifier corresponding to the requested first terminal;
[0271] 2) The terminal address information corresponding to the requested first terminal, such as including IP address and / or MAC address;
[0272] 3) The number of first keys requested to be generated.
[0273] S615, the second module (wireless secure communication module) of the first device negotiates with the fourth module (wireless secure communication module) of the corresponding first terminal to generate a first key through steps such as channel detection, quantization, information coordination and privacy amplification;
[0274] S616, the second module (wireless secure communication module) of the first device sends a third response message to the first module (quantum key wireless transmission component) of the first device to provide feedback on the result of the first key generation;
[0275] S617, when it is determined that a usable first key exists, the first module of the first device sends a first encryption request to the second module (wireless secure communication module) of the first device. Specifically, by calling the wireless key encryption function of the second module, the second module (wireless secure communication module) encrypts and / or protects the integrity of part or all of the first message.
[0276] Optionally, the first encryption request may include one or more of the following information:
[0277] 1) The data to be encrypted in the first message, such as quantum keys, quantum key ciphertext, or other sensitive data that needs to be encrypted and protected;
[0278] 2) The length of the data to be encrypted;
[0279] 3) Identification information of the first terminal;
[0280] 4) The address information of the first terminal; the address information includes, but is not limited to, terminal IP address and / or terminal MAC address information.
[0281] It should be noted that step S617, by sending a first encryption request to request the second module to perform encryption and / or integrity protection operations on the first message, can include multiple implementations. One implementation is that the first encryption request sent by the first module instructs the second module to perform encryption and / or integrity protection operations on the first message. The second module is configured to, upon receiving the instruction, directly send the encrypted and / or integrity-protected first message to the first terminal after completing the encryption and / or integrity protection operations. Another implementation is that the first module sends the first encryption request instructing the second module to send the first message to the first terminal. Upon receiving the instruction, the second module first performs encryption and / or integrity protection on the first message, and then sends the encrypted and / or integrity-protected first message to the first terminal. Yet another implementation is that the first encryption request sent by the first module instructs the second module to perform encryption and / or integrity protection and sending operations. Upon receiving the instruction, the second module first performs encryption and / or integrity protection on the first message, and then sends the encrypted and / or integrity-protected first message to the first terminal.
[0282] S618, the second module (wireless secure communication module) calls the wireless key encryption function, uses the first key negotiated with the first terminal to encrypt the data of the first message, and sends the first response message to the first module (quantum key wireless transmission component);
[0283] Optionally, the first response message includes one or more of the following information:
[0284] The encryption result information of the first message is used to indicate whether the encryption was successful;
[0285] The first message after encryption;
[0286] The length of the encrypted first message.
[0287] S619, the first module (quantum key wireless transmission component) sends the encrypted and / or integrity-protected first message to the third module (quantum key wireless distribution component) of the first terminal through the secure channel 2; with this implementation, the first message is protected by the first key on the basis of end-to-end protection of the secure channel 2, thus ensuring the secure transmission of the transmitted quantum key.
[0288] S620, the third module (quantum key wireless distribution component) of the first terminal sends a decryption request to the fourth module (wireless secure communication module) of the first terminal; that is, the first message is decrypted by calling the wireless key decryption interface of the fourth module (wireless secure communication module) of the first terminal.
[0289] Optionally, the decryption request may include one or more of the following information:
[0290] The data of the first message to be decrypted; such as quantum keys, quantum key ciphertext, or other sensitive data that needs to be encrypted and protected;
[0291] The length of the data to be decrypted.
[0292] S621, the fourth module (wireless secure communication module) of the first terminal sends a fourth response message to the third module (quantum key wireless distribution component) of the first terminal;
[0293] Optionally, the fourth response message includes one or more of the following information:
[0294] The first message after decryption;
[0295] Decryption result indication information, used to indicate whether decryption was successful;
[0296] The data length of the first message after decryption.
[0297] S622, the third module (quantum key wireless distribution component) of the first terminal sends a fifth response message to the first module (quantum key wireless transmission component) of the first device, the fifth response message including the reception result of the first message; optionally, the third module (quantum key wireless distribution component) of the first terminal encrypts and / or protects the integrity of the fifth response message with the first key, and then sends the fifth response message to the first module (quantum key wireless transmission component).
[0298] S623, the first module (quantum key wireless transmission component) of the first device sends the fifth response message to the QKDC to send the response of the first key received to the QKDC, thus completing the entire quantum key distribution process.
[0299] Figure 7 This is a flowchart illustrating a second embodiment of the method described in this invention. In this second embodiment, after the first device encrypts and / or protects the integrity of the first message, the second module of the first device sends the encrypted and / or integrity-protected first message to the first terminal.
[0300] Combination Figure 6 and Figure 7 As shown, in this second embodiment, the execution steps of steps S701 to S716 are the same as those of steps S601 to S616 in the first embodiment, and will not be repeated here.
[0301] In the second embodiment, the method further includes the following implementation steps:
[0302] S717, when the first module of the first device determines that there is a usable first key, the first module of the first device sends a second encryption request to the second module (wireless secure communication module) of the first device. Specifically, by calling the wireless key encryption function of the second module, the second module (wireless secure communication module) encrypts and / or protects the integrity of part or all of the content of the first message.
[0303] Optionally, the second encryption request may include one or more of the following information:
[0304] 1) The data to be encrypted in the first message, such as quantum keys, quantum key ciphertext, or other sensitive data that needs to be encrypted and protected;
[0305] 2) The length of the data to be encrypted;
[0306] 3) Identification information of the first terminal;
[0307] 4) The address information of the first terminal; the address information includes, but is not limited to, terminal IP address and / or terminal MAC address information.
[0308] It should be noted that step S717, by sending a second encryption request to request the second module to perform encryption and / or integrity protection operations on the first message, can include multiple implementations. One implementation is that the second encryption request sent by the first module instructs the second module to perform encryption and / or integrity protection operations on the first message. The second module is configured to, upon receiving the instruction, directly send the encrypted and / or integrity-protected first message to the first terminal after completing the encryption and / or integrity protection operations. Another implementation is that the second encryption request sent by the first module instructs the second module to send the first message to the first terminal. Upon receiving the instruction, the second module first performs encryption and / or integrity protection on the first message, and then sends the encrypted and / or integrity-protected first message to the first terminal. Yet another implementation is that the second encryption request sent by the first module instructs the second module to perform encryption and / or integrity protection and sending operations. Upon receiving the instruction, the second module first performs encryption and / or integrity protection on the first message, and then sends the encrypted and / or integrity-protected first message to the first terminal.
[0309] S718, the second module (wireless secure communication module) calls the wireless key encryption function to encrypt the data of the first message using the first key negotiated with the first terminal;
[0310] S719, the second module (wireless secure communication module) sends the encrypted first message to the fourth module (wireless secure communication module) of the first terminal via the air interface;
[0311] S720, after receiving the encrypted first message, the fourth module (wireless secure communication module) of the first terminal decrypts the first message using the first key negotiated with the first device;
[0312] S721, the fourth module (wireless secure communication module) of the first terminal sends the decrypted first message to the third module (quantum key wireless distribution component) of the first terminal;
[0313] S722, the third module (quantum key wireless distribution component) of the first terminal returns a fifth response message to the fourth module of the first terminal, the fifth response message including the reception result of the first message;
[0314] S723, the fourth module of the first terminal sends the fifth response message to the second module of the first device;
[0315] S724, the second module of the first device sends the fifth response message to the first module of the first device;
[0316] S725, the first module of the first device then forwards the fifth response message to the QKDC.
[0317] In this implementation, the quantum key distribution response message is returned to the QKDC by sending the fifth response message to the QKDC step by step, thus completing the entire distribution process.
[0318] One embodiment of the present invention also provides a data security transmission method, applied to a first terminal, such as... Figure 8 As shown, the method includes:
[0319] S810, the first terminal receives a first message sent by the first device; wherein, the first message includes first information sent by the second device to the first terminal, and all or part of the content of the first message is encrypted and / or protected for integrity by the first device using a first key;
[0320] S820, the first message is decrypted using the first key. Using the method described in this embodiment of the invention, after receiving the first message sent by the second device, the first device encrypts and / or protects the integrity of all or part of the first message using the first key, and then sends the first message to the first terminal. This utilizes the wireless security capabilities between the first device and the terminal, such as wireless key generation and encryption, to achieve secure distribution of sensitive or important data such as quantum keys to the terminal over the air interface. This avoids the inconvenience caused by frequent refilling when adding sensitive or important data such as quantum keys to the terminal offline.
[0321] Optionally, in the data secure transmission method, the first key includes one or more of the following:
[0322] The key generated by the first device and the first terminal based on wireless physical layer key generation technology or a key derived therefrom;
[0323] A key or a further derived key is generated based on the key generated by the first device and the first terminal using wireless key generation technology and a fifth key; wherein, the fifth key is a key distributed by the key distribution center to the first device and the first terminal, or the fifth key is a key pre-shared between the first device and the first terminal;
[0324] The key generated based on the fifth key and the first parameter, or a key further derived therefrom; the first parameter is a common parameter in the wireless physical layer key generation process between the first device and the first terminal.
[0325] Optionally, in the data secure transmission method, the first information includes a second key for use by the first terminal.
[0326] Optionally, in the data secure transmission method, the received first message is a message whose entire or part of its content has been encrypted and / or protected for integrity by a third key, and then encrypted and / or protected for integrity by the first key.
[0327] The third key is a shared key between the second device and the first terminal.
[0328] Optionally, in the data secure transmission method, the received first message is a message whose entire or part of its content is encrypted and / or protected for integrity by a third key, and then encrypted and / or protected for integrity by a fourth key, and then encrypted and / or protected for integrity by the first key.
[0329] The fourth key is a shared key between the first device and the second device.
[0330] Optionally, the data secure transmission method further includes:
[0331] A first key is used to encrypt and / or protect the integrity of all or part of the third message to be sent to the second device;
[0332] The third message, after being encrypted and / or protected for integrity, is sent to the first device.
[0333] Optionally, in the data secure transmission method, the first terminal includes a third module and a fourth module;
[0334] The first terminal receives a first message sent by the first device, including:
[0335] The third module receives the first message sent by the first device;
[0336] Decrypting the first message using the first key includes:
[0337] The third module sends a decryption request to the fourth module;
[0338] The fourth module decrypts the first message using the first key according to the decryption request;
[0339] The fourth module sends a fourth response message to the third module regarding the decryption request, the fourth response message including the decrypted first message.
[0340] Optionally, in the data secure transmission method, the first terminal includes a third module and a fourth module;
[0341] The first terminal receives a first message sent by the first device, including:
[0342] The fourth module receives the first message sent by the first device;
[0343] The first message is decrypted using the first key to obtain the first information, including:
[0344] The fourth module uses the first key to decrypt the first message;
[0345] The fourth module sends the decrypted first message to the third module.
[0346] Optionally, the data secure transmission method further includes:
[0347] The third module sends a fifth response message to the first device or the fourth module; wherein the fifth response message includes the result of receiving the first message.
[0348] Optionally, the data secure transmission method further includes:
[0349] The third module sends a data request to the first device to request the acquisition of the first information.
[0350] The specific implementation process of the method described in this embodiment of the invention when applied to the first terminal can be described in conjunction with the detailed description of the specific implementation process when applied to the first device, and will not be repeated here.
[0351] This invention also provides a transmission system, wherein the transmission system includes a first device and a first terminal, wherein:
[0352] The first device includes a first module and a second module; the first module is configured to: receive a first message sent by the second device; the first message includes first information sent by the second device to a first terminal; the second module is configured to: encrypt and / or protect the integrity of all or part of the first message using a first key; the first key is a key generated by the first device and the first terminal based on wireless physical layer key generation technology; the first module is further configured to: send the encrypted and / or integrity-protected first message to the first terminal; or, the second module is configured to: send the encrypted and / or integrity-protected first message to the first terminal;
[0353] The second device includes a third module and a fourth module; the third module or the fourth module receives the first message sent by the first device; the fourth module is used to decrypt the first message using the first key.
[0354] In this embodiment of the invention, the specific implementation functions of the first module, the second module, the third module and the fourth module can be found in the detailed description of the method section above, and will not be repeated here.
[0355] One embodiment of the present invention also provides a network device, wherein the network device is a first device, such as... Figure 9 As shown, the first device 900 includes a transceiver 910 and a processor 920, wherein:
[0356] The transceiver 910 is used to receive a first message sent by the second device; the first message includes first information sent by the second device to the first terminal.
[0357] The processor 920 is used to encrypt and / or protect the integrity of all or part of the first message using a first key.
[0358] The transceiver 910 is further configured to send the first message, after encryption and / or integrity protection, to the first terminal.
[0359] Optionally, in the network device, the first key includes one or more of the following:
[0360] The key generated by the first device and the first terminal based on wireless physical layer key generation technology or a key derived therefrom;
[0361] A key or a further derived key is generated based on the key generated by the first device and the first terminal using wireless key generation technology and a fifth key; wherein, the fifth key is a key distributed by the key distribution center to the first device and the first terminal, or the fifth key is a key pre-shared between the first device and the first terminal;
[0362] The key generated based on the fifth key and the first parameter, or a key further derived therefrom; the first parameter is a common parameter in the wireless physical layer key generation process between the first device and the first terminal.
[0363] Optionally, in the network device, the first information includes a second key for use by the first terminal.
[0364] Optionally, in the network device, the processor 920 uses a first key to encrypt and / or protect the integrity of all or part of the first message, including:
[0365] The first key is used to encrypt and / or protect the integrity of the first information.
[0366] Optionally, in the network device, the processor 920 uses a first key to encrypt and / or protect the integrity of all or part of the first message, including:
[0367] If the first device has the first key available, it uses the first key to encrypt and / or protect the integrity of all or part of the first message.
[0368] Optionally, in the network device, the transceiver 910 is further configured to:
[0369] If the first device does not have a usable first key, after receiving the first message, the first device will send the first message to the first terminal; or, send a second message to the second device; the second message is used to indicate that the transmission of the first message or the first information failed.
[0370] Optionally, in the network device, the processor 920 is further configured to:
[0371] If the first device does not have a usable first key, the first device generates a first key that can be shared with the first terminal.
[0372] Optionally, in the network device, all or part of the received first message is encrypted and / or protected for integrity using a third key;
[0373] The third key is a shared key between the second device and the first terminal.
[0374] Optionally, in the network device, the first message received, after being encrypted and / or protected for integrity by the third key in whole or in part, is further encrypted and / or protected for integrity by the fourth key.
[0375] The fourth key is a shared key between the first device and the second device.
[0376] Optionally, in the network device, the transceiver 910 is further configured to:
[0377] Receive a third message sent by the first terminal, wherein all or part of the content of the third message is encrypted and / or protected for integrity by the first key;
[0378] The third message is sent to the second device.
[0379] One embodiment of the present invention also provides a terminal, wherein the terminal is a first terminal, such as... Figure 10As shown, the first terminal 1000 includes a transceiver 1010 and a processor 1020; wherein:
[0380] The transceiver 1010 is used to receive a first message sent by a first device; wherein the first message includes first information sent by a second device to the first terminal, and all or part of the content of the first message is encrypted and / or protected for integrity by the first device using a first key;
[0381] The processor 1020 is used to decrypt the first message using the first key.
[0382] Optionally, in the terminal, the first key includes one or more of the following:
[0383] The key generated by the first device and the first terminal based on wireless physical layer key generation technology or a key derived therefrom;
[0384] A key or a further derived key is generated based on the key generated by the first device and the first terminal using wireless key generation technology and a fifth key; wherein, the fifth key is a key distributed by the key distribution center to the first device and the first terminal, or the fifth key is a key pre-shared between the first device and the first terminal;
[0385] The key generated based on the fifth key and the first parameter, or a key further derived therefrom; the first parameter is a common parameter in the wireless physical layer key generation process between the first device and the first terminal.
[0386] Optionally, in the terminal, the first information includes a second key for use by the first terminal.
[0387] Optionally, in the terminal, the first message received is a message whose entire or part of its content is encrypted and / or protected for integrity by a third key, and then encrypted and / or protected for integrity by the first key.
[0388] The third key is a shared key between the second device and the first terminal.
[0389] Optionally, in the terminal, the first message received is a message whose entire or part of its content is encrypted and / or protected for integrity by a third key, and then encrypted and / or protected for integrity by a fourth key, and then encrypted and / or protected for integrity by the first key.
[0390] The fourth key is a shared key between the first device and the second device.
[0391] Optionally, in the terminal, the processor 1020 is further configured to:
[0392] A first key is used to encrypt and / or protect the integrity of all or part of the third message to be sent to the second device;
[0393] The third message, after being encrypted and / or protected for integrity, is sent to the first device.
[0394] One embodiment of the present invention also provides a data security transmission device, applied to a first device, wherein, as Figure 11 As shown, the device includes:
[0395] The first message receiving module 1101 is used to receive a first message sent by the second device; the first message includes first information sent by the second device to the first terminal.
[0396] Encryption module 1102 is used to encrypt and / or protect the integrity of all or part of the first message using a first key;
[0397] The message sending module 1103 is used to send the first message, after encryption and / or integrity protection, to the first terminal.
[0398] Optionally, in the data secure transmission device, the first key includes one or more of the following:
[0399] The key generated by the first device and the first terminal based on wireless physical layer key generation technology or a key derived therefrom;
[0400] A key or a further derived key is generated based on the key generated by the first device and the first terminal using wireless key generation technology and a fifth key; wherein, the fifth key is a key distributed by the key distribution center to the first device and the first terminal, or the fifth key is a key pre-shared between the first device and the first terminal;
[0401] The key generated based on the fifth key and the first parameter, or a key further derived therefrom; the first parameter is a common parameter in the wireless physical layer key generation process between the first device and the first terminal.
[0402] Optionally, in the data secure transmission device, the first information includes a second key for use by the first terminal.
[0403] Optionally, in the aforementioned data secure transmission device, the encryption module 1102 uses a first key to encrypt and / or protect the integrity of all or part of the first message, including:
[0404] The first key is used to encrypt and / or protect the integrity of the first information.
[0405] Optionally, in the aforementioned data secure transmission device, the encryption module 1102 uses a first key to encrypt and / or protect the integrity of all or part of the first message, including:
[0406] If the first device has the first key available, it uses the first key to encrypt and / or protect the integrity of all or part of the first message.
[0407] Optionally, in the aforementioned data security transmission device, the encryption module 1102 is further used for:
[0408] If the first device does not have a usable first key, after receiving the first message, the first device will send the first message to the first terminal; or, the first device will send a second message to the second device; the second message is used to indicate that the transmission of the first message or the first information failed.
[0409] Optionally, in the aforementioned data security transmission device, the encryption module 1102 is further used for:
[0410] If the first device does not have a usable first key, it generates a first key that can be shared with the first terminal.
[0411] Optionally, in the data security transmission device, all or part of the received first message is encrypted and / or protected for integrity using a third key.
[0412] The third key is a shared key between the second device and the first terminal.
[0413] Optionally, in the data security transmission device, the first message received, after being encrypted and / or protected for integrity by the third key in whole or in part, is further encrypted and / or protected for integrity by the fourth key.
[0414] The fourth key is a shared key between the first device and the second device.
[0415] Optionally, in the aforementioned data secure transmission device:
[0416] The first message receiving module 1101 is further configured to receive a third message sent by the first terminal, wherein all or part of the content of the third message is encrypted and / or protected by the first key;
[0417] The message sending module 1103 is also used to send the third message to the second device.
[0418] One embodiment of the present invention also provides a data security transmission device, applied to a first terminal, such as... Figure 12 As shown, the device includes:
[0419] The second message receiving module 1201 is used to receive a first message sent by the first device; wherein the first message includes first information sent by the second device to the first terminal, and all or part of the content of the first message is encrypted and / or protected for integrity by the first device using a first key;
[0420] The decryption module 1202 is used to decrypt the first message using the first key.
[0421] Optionally, in the data secure transmission device, the first key includes one or more of the following:
[0422] The key generated by the first device and the first terminal based on wireless physical layer key generation technology or a key derived therefrom;
[0423] A key or a further derived key is generated based on the key generated by the first device and the first terminal using wireless key generation technology and a fifth key; wherein, the fifth key is a key distributed by the key distribution center to the first device and the first terminal, or the fifth key is a key pre-shared between the first device and the first terminal;
[0424] The key generated based on the fifth key and the first parameter, or a key further derived therefrom; the first parameter is a common parameter in the wireless physical layer key generation process between the first device and the first terminal.
[0425] Optionally, in the data secure transmission device, the first information includes a second key for use by the first terminal.
[0426] Optionally, in the data security transmission device, the first message received is a message whose entire or part of its content has been encrypted and / or protected for integrity by a third key, and then encrypted and / or protected for integrity by the first key.
[0427] The third key is a shared key between the second device and the first terminal.
[0428] Optionally, in the data security transmission device, the first message received is a message whose entire or part of its content is encrypted and / or protected for integrity by a third key, and further encrypted and / or protected for integrity by a fourth key, and then encrypted and / or protected for integrity by the first key.
[0429] The fourth key is a shared key between the first device and the second device.
[0430] Optionally, in the aforementioned data security transmission device, the decryption module 1202 is further configured to:
[0431] A first key is used to encrypt and / or protect the integrity of all or part of the third message to be sent to the second device;
[0432] The third message, after being encrypted and / or protected for integrity, is sent to the first device.
[0433] In addition, specific embodiments of the present invention also provide a readable storage medium having a computer program stored thereon, wherein the program, when executed by a processor, implements the steps of the data secure transmission method as described in any of the above.
[0434] Specifically, the readable storage medium is applied to the first terminal or the first device described above. When applied to the first terminal or the first device, the execution steps of the corresponding data secure transmission method are as described in the detailed description above, and will not be repeated here.
[0435] In the several embodiments provided in this application, it should be understood that the disclosed methods and apparatus can be implemented in other ways. For example, the apparatus embodiments described above are merely illustrative; for instance, the division of units is only a logical functional division, and in actual implementation, there may be other division methods. For example, multiple units or components may be combined or integrated into another system, or some features may be ignored or not executed. Furthermore, the coupling or direct coupling or communication connection shown or discussed may be through some interfaces; the indirect coupling or communication connection between devices or units may be electrical, mechanical, or other forms.
[0436] Furthermore, the functional units in the various embodiments of the present invention can be integrated into one processing unit, or each unit can be physically comprised separately, or two or more units can be integrated into one unit. The integrated unit described above can be implemented in hardware or in the form of hardware plus software functional units.
[0437] The integrated units implemented as software functional units described above can be stored in a computer-readable storage medium. These software functional units, stored in a storage medium, include several instructions that cause a computer device (which may be a personal computer, server, or network device, etc.) to execute some steps of the transmission and reception methods described in the various embodiments of this invention. The aforementioned storage medium includes various media capable of storing program code, such as USB flash drives, portable hard drives, read-only memory (ROM), random access memory (RAM), magnetic disks, or optical disks.
[0438] The above describes the preferred embodiments of the present invention. It should be noted that those skilled in the art can make various improvements and modifications without departing from the principles of the present invention, and these improvements and modifications should also be considered within the scope of protection of the present invention.
Claims
1. A data security transmission method, applied to a first device, characterized in that, The method comprises: The first device receives a first message sent by a second device; the first message comprises first information sent by the second device to a first terminal; wherein the first information comprises a second key for use by the first terminal; the received first message is encrypted and / or integrity protected in whole or in part by a third key and further encrypted and / or integrity protected by a fourth key; wherein the third key is a shared key between the second device and the first terminal; and the fourth key is a shared key between the first device and the second device; The first device encrypts and / or integrity protects, in whole or in part, the first message using a first key; The first device sends the first message that has been encrypted and / or integrity protected to the first terminal; The first key comprises one or more of: A key generated by the first device and the first terminal based on a wireless physical layer key generation technique or a further derived key; A key generated based on a key generated by the first device and the first terminal based on a wireless key generation technique and a fifth key, or a further derived key; wherein the fifth key is a key distributed to the first device and the first terminal by a key distribution center, or the fifth key is a pre-shared key between the first device and the first terminal; A key generated based on the fifth key and a first parameter, or a further derived key; wherein the first parameter is a common parameter in a wireless physical layer key generation process between the first device and the first terminal.
2. The method of claim 1, wherein, The first device encrypts and / or integrity protects, in whole or in part, the first message using a first key, comprising: The first device encrypts and / or integrity protects the first information using the first key.
3. The method of claim 1, wherein, The first device encrypts and / or integrity protects, in whole or in part, the first message using a first key, comprising: In the case that the first device has available the first key, the first device encrypts and / or integrity protects, in whole or in part, the first message using the first key.
4. The method of claim 1, wherein, The method further comprises: In the case that the first device does not have available the first key, the first device sends the first message to the first terminal after receiving the first message; or the first device sends a second message to the second device; the second message is used to indicate that the transmission of the first message or the first information fails.
5. The data secure transmission method of claim 1 or 4, wherein, The method further comprises: In the case that the first device does not have available the first key, the first device generates the first key that can be shared with the first terminal.
6. The method of claim 1, wherein, The method further comprises: The first device receives a third message sent by the first terminal; the third message is encrypted and / or integrity protected in whole or in part by the first key; The first device sends the third message to the second device.
7. The method of claim 1, wherein, The first device comprises a first module and a second module; The first device receives a first message sent by a second device, comprising: The first module receives a first message sent by the second device; The first device uses a first key to encrypt and / or integrity protect all or part of the content of the first message, including: The first module sends an encryption request to the second module, for requesting to encrypt and / or integrity protect all or part of the content of the first message; The second module uses the first key to encrypt and / or integrity protect all or part of the content of the first message; The first device sends the first message after encryption and / or integrity protection to the first terminal, including: The first module or the second module sends the first message after encryption and / or integrity protection to the first terminal.
8. The method of claim 7, wherein, After the second module uses the first key to encrypt and / or integrity protect all or part of the content of the first message, the method further includes: The second module sends a first response message of the encryption request to the first module; wherein the first response message includes the first message after encryption and / or integrity protection; wherein the first module receives the first response message, and the first module sends the first message after encryption and / or integrity protection to the first terminal; Or, the second module sends the first message after encryption and / or integrity protection to the first terminal.
9. The method of claim 7, wherein, The method further includes: After the first module receives the first message sent by the second device, the first module sends a query request to the second module, for querying whether there is an available first key; The second module sends a second response message of the query request to the first module; Wherein, in the case that the second response message indicates that there is an available first key, the first module sends the encryption request to the second module.
10. The method of claim 9, wherein, The method further includes: In the case that the second response message indicates that there is no available first key, the first module sends the first message to the first terminal; or, the first module sends a second message to the second device, and the second message is used to indicate that the first message or the first information transmission fails.
11. The method of claim 9 or 10, wherein, The method further includes: In the case that the second response message indicates that there is no available first key, the first module sends a key generation request to the second module, for requesting to generate a first key that can be shared with the first terminal; And / or, After the second module generates the first key that can be shared with the first terminal, the second module sends a third response message to the first module.
12. The method of claim 11, wherein, After the first module receives the third response message, the method further includes: The first module sends the encryption request to the second module.
13. The method of claim 7, wherein, The encryption request includes one or more of the following information: Data to be encrypted in the first message; Data length of the data to be encrypted; Identity information of the first terminal; Address information of the first terminal.
14. A data security transmission method, applied to a first terminal, characterized in that, The method includes: The first terminal receives a first message sent by a first device; wherein the first message comprises first information sent by a second device to the first terminal, and all or part of the content of the first message is encrypted and / or integrity protected by the first device using a first key; the first information comprises a second key for the first terminal to use; the received first message is a message whose all or part of the content is encrypted and / or integrity protected by a third key, and then encrypted and / or integrity protected by a fourth key, and then encrypted and / or integrity protected by the first key; wherein the fourth key is a shared key between the first device and the second device; The first message is decrypted using the first key; The first key comprises one or more of the following: The first device and the first terminal generate a key or a further derived key based on a wireless physical layer key generation technique; A key or a further derived key generated based on a key generated by the first device and the first terminal based on a wireless key generation technique and a fifth key; wherein the fifth key is a key distributed to the first device and the first terminal by a key distribution center, or the fifth key is a pre-shared key between the first device and the first terminal; A key or a further derived key generated based on the fifth key and a first parameter; the first parameter is a common parameter in a wireless physical layer key generation process between the first device and the first terminal.
15. The method of claim 14, wherein, The method further comprises: The first key is used to encrypt and / or integrity protect all or part of the content of a third message to be sent to the second device; The third message encrypted and / or integrity protected is sent to the first device.
16. The method of claim 14, wherein, The first terminal comprises a third module and a fourth module; The first terminal receives a first message sent by a first device, comprising: The third module receives the first message sent by the first device; The first message is decrypted using the first key, comprising: The third module sends a decryption request to the fourth module; The fourth module decrypts the first message using the first key according to the decryption request; The fourth module sends a fourth response message of the decryption request to the third module, wherein the fourth response message comprises the decrypted first message.
17. The method of claim 14, wherein, The first terminal comprises a third module and a fourth module; The first terminal receives a first message sent by a first device, comprising: The fourth module receives the first message sent by the first device; The first message is decrypted using the first key to obtain the first information, comprising: The fourth module decrypts the first message using the first key; The fourth module sends the decrypted first message to the third module.
18. The method of claim 16 or 17, wherein, The method further comprises: The third module sends a fifth response message to the first device or the fourth module; wherein the fifth response message comprises a reception result of the first message.
19. The method of claim 16 or 17, wherein, The method further comprises: The third module sends a data request to the first device, for requesting the first information.
20. A network device, wherein, The network device is a first device, and the network device comprises a transceiver and a processor, wherein: The transceiver is configured to receive a first message sent by a second device, wherein the first message comprises first information sent by the second device to a first terminal, and the first information comprises a second key used by the first terminal; and the received first message is a message after all or part of the content of the first message is encrypted and / or integrity protected by a third key and further encrypted and / or integrity protected by a fourth key; the third key is a shared key between the second device and the first terminal; and the fourth key is a shared key between the first device and the second device. The processor is configured to encrypt and / or integrity protect all or part of the content of the first message by using a first key. The transceiver is further configured to send the first message after encryption and / or integrity protection to the first terminal. The first key comprises one or more of the following: A key generated by the first device and the first terminal based on a wireless physical layer key generation technology or a further derived key; A key generated based on a key generated by the first device and the first terminal based on a wireless key generation technology and a fifth key or a further derived key, wherein the fifth key is a key distributed by a key distribution center for the first device and the first terminal, or the fifth key is a pre-shared key between the first device and the first terminal; A key generated based on the fifth key and a first parameter or a further derived key, wherein the first parameter is a common parameter in a wireless physical layer key generation process between the first device and the first terminal.
21. A terminal, wherein, The terminal is a first terminal, and the terminal comprises a transceiver and a processor, wherein: The transceiver is configured to receive a first message sent by a first device, wherein the first message comprises first information sent by a second device to the first terminal, and all or part of the content of the first message is encrypted and / or integrity protected by the first device by using a first key; the first information comprises a second key used by the first terminal; and the received first message is a message after all or part of the content of the first message is encrypted and / or integrity protected by a third key, further encrypted and / or integrity protected by a fourth key, and then encrypted and / or integrity protected by the first key; the fourth key is a shared key between the first device and the second device. The processor is configured to decrypt the first message by using the first key. The first key comprises one or more of the following: A key generated by the first device and the first terminal based on a wireless physical layer key generation technology or a further derived key. generate a resultant key or a further derived key according to a key generated by the first device and the first terminal based on a wireless key generation technique and a fifth key; the fifth key is a key distributed by a key distribution center for the first device and the first terminal, or the fifth key is a pre-shared key between the first device and the first terminal; generate a resultant key or a further derived key based on the fifth key and a first parameter; the first parameter is a common parameter in a wireless physical layer key generation process between the first device and the first terminal.
22. A data secure transmission apparatus, applied to a first device, characterized in that, The apparatus comprises: a first message receiving module configured to receive a first message sent by a second device; the first message comprises first information sent by the second device to a first terminal; the first information comprises a second key for use by the first terminal; all or part of the received first message is encrypted and / or integrity protected by a third key and further encrypted and / or integrity protected by a fourth key; the third key is a shared key between the second device and the first terminal; the fourth key is a shared key between the first device and the second device; an encryption module configured to encrypt and / or integrity protect all or part of the first message by using a first key; a message sending module configured to send the first message encrypted and / or integrity protected to the first terminal; the first key comprises one or more of the following: a key or a further derived key generated by the first device and the first terminal based on a wireless physical layer key generation technique; generate a resultant key or a further derived key according to a key generated by the first device and the first terminal based on a wireless key generation technique and a fifth key; the fifth key is a key distributed by a key distribution center for the first device and the first terminal, or the fifth key is a pre-shared key between the first device and the first terminal; generate a resultant key or a further derived key based on the fifth key and a first parameter; the first parameter is a common parameter in a wireless physical layer key generation process between the first device and the first terminal.
23. A data secure transmission apparatus, applied to a first terminal, characterized in that, The apparatus comprises: a second message receiving module configured to receive a first message sent by a first device; the first message comprises first information sent by a second device to the first terminal, and all or part of the first message is encrypted and / or integrity protected by the first device by using a first key; the first information comprises a second key for use by the first terminal; the received first message is a message whose all or part of the content is encrypted and / or integrity protected by a third key and further encrypted and / or integrity protected by a fourth key, and then encrypted and / or integrity protected by the first key; the fourth key is a shared key between the first device and the second device; a decryption module configured to decrypt the first message by using the first key; The first key comprises one or more of the following: The first device and the first terminal generate a key based on a wireless physical layer key generation technique or further derive a key; The first device and the first terminal generate a key based on a wireless key generation technique, a key derived therefrom or further derived therefrom; wherein the fifth key is a key distributed by a key distribution center to the first device and the first terminal, or the fifth key is a pre-shared key between the first device and the first terminal; The first device and the first terminal generate a key based on the fifth key and a first parameter or further derive a key therefrom; the first parameter is a common parameter in a wireless physical layer key generation process between the first device and the first terminal.
24. A readable storage medium characterized by, The readable storage medium stores a program, and the program is executed by the processor to implement the steps in the data security transmission method according to any one of claims 1 to 13, or to implement the steps in the data security transmission method according to any one of claims 14 to 19.
Citation Information
Patent Citations
Quantum security key distribution method and system
CN115442040A
Quantum key distribution and negotiation method for internet-of-things wireless terminal
WO2022213564A1