A group key management method, system, electronic device, and storage medium

By using the Quantum Cryptography Management Service (KMS) system and logical key tree management, the problems of high group key update overhead and insufficient security in multicast communication are solved, achieving secure and efficient group key management and ensuring information confidentiality and security.

CN118842575BActive Publication Date: 2026-04-03CHINA TELECOM QUANTUM TECH CO LTD
View PDF 1 Cites 0 Cited by

Patent Information

Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2024-06-21
Publication Date
2026-04-03

AI Technical Summary

Technical Problem

In existing multicast communication, the group key update process is costly and lacks security, especially when group members change frequently. Although the LKH algorithm can reduce communication overhead, its security is slightly insufficient.

Method used

The Quantum Cryptography Management Service (KMS) system is adopted to encrypt key update information using the quantum keys of group members and manage group keys using a logical key tree. When a new member joins, the first set of key information and update information is generated, and when an old member leaves, the second set of key update information is generated, ensuring the security of information transmission and reducing storage overhead.

Benefits of technology

This reduces network bandwidth and user storage overhead during group key updates when group members change, while also improving the security and confidentiality of information transmission, ensuring that neither new nor old members can access information they should not have.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN118842575B_ABST
    Figure CN118842575B_ABST
Patent Text Reader

Abstract

This invention provides a group key management method, system, electronic device, and storage medium. The method includes: when a new member joins the group, generating a first set of key information for the new member, encrypting the first set of key information using the new member's quantum key, and sending it to the new member; simultaneously generating a first set of key update information for all group members, encrypting the first set of key update information using each member's quantum key, and sending it to each member; when an existing member leaves the group, generating a second set of key update information, encrypting the second set of key update information using the quantum keys of the members other than the departing member, and sending it to the other members. This invention improves the security of group key information transmission by encrypting the group key information with a quantum key before sending it to the corresponding group members when a new member joins or an existing member leaves.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This invention relates to the field of communication technology, and in particular to a group key management method, system, electronic device, and storage medium. Background Technology

[0002] Multicast communication, as an efficient communication method, is now widely used in instant messaging, video conferencing, streaming media, distance learning, and online games. To ensure the security of multicast communication, a shared group key, or group key, is typically introduced within the call group. Group members send and receive messages based on this group key. When a member leaves the call group, the group key is updated to prevent the departing member from accessing group communication content after their departure time. Similarly, when a new member joins the call group, the group key is also updated to prevent the new member from accessing group communication content before their joining time. For call groups with frequent member changes, the key update process incurs significant overhead.

[0003] To reduce the overhead of the key update process, the Logical Key Hierarchy (LKH) algorithm is a good choice. The LKH algorithm can reduce the communication overhead during key updates from O(N) to O(log N), effectively improving the efficiency of group key updates. However, the LKH algorithm has slight shortcomings in terms of security. Summary of the Invention

[0004] In view of the above problems, embodiments of the present invention are proposed to provide a group key management method, system, electronic device and storage medium that overcomes or at least partially solves the above problems.

[0005] In a first aspect, embodiments of the present invention disclose a group key management method applied to a quantum cryptography management service system (KMS), wherein the KMS is communicatively connected to the terminal devices of each member of the group; the KMS stores the quantum keys of each member of the group; each member stores a first logical key tree, the first logical key tree including the group key; the method includes:

[0006] When a new member joins the group, a first set of key information is generated for the new member and a first set of key update information is generated for the group members.

[0007] The quantum key of the new member is obtained, and the first set of key information is encrypted using the quantum key of the new member and then sent to the terminal device of the new member, so that the terminal device of the new member can generate a first logical key tree based on the first set of key information.

[0008] After encrypting the first set of key update information according to the quantum key of each group member, the information is sent to the terminal device of each group member so that the terminal device of each group member updates the first logical key tree according to the first set of key update information.

[0009] When the first group member leaves the group, a second set of key update information is generated. The second set of key update information is then encrypted according to the quantum keys of the remaining group members and sent to the terminal devices of the remaining group members, so that the terminal devices of the remaining group members update the first logical key tree according to the second set of key update information. The remaining group members are the group members other than the first group members.

[0010] Optionally, each member of the group and the new member's terminal device includes a quantum-safe chip; the KMS stores a mapping relationship between the identifier of the quantum-safe chip and the quantum key stored in the quantum-safe chip; the KMS and the new member's terminal device are respectively connected to the business system; the business system stores the new member's user identifier and the quantum-safe chip identifier; the method further includes:

[0011] Before the new member joins the group, the system receives the user identifier and quantum security chip identifier of the new member from the business system.

[0012] The quantum key of the new member is determined based on the identifier of the quantum-safe chip of the new member and the mapping relationship;

[0013] The user identifier of the new member is encrypted using the new member's quantum key to obtain first identity authentication information, and the first identity authentication information is sent to the business system.

[0014] The system receives the authentication result sent by the business system; the authentication result is obtained by the business system receiving second authentication information sent by the new member's terminal device and comparing the second authentication information with the first authentication information; the second authentication information is obtained by the new member's terminal device encrypting the stored user identifier according to the stored quantum key.

[0015] The steps of generating a first set of key information for the new member and generating a first set of key update information for the group members include:

[0016] When the identity authentication result is successful, a first set of key information is generated for the new member and a first set of key update information is generated for the group members.

[0017] Optionally, the KMS stores a second logical key tree, which includes N layers of nodes interconnected, where N is an integer greater than 2; wherein the first layer is the root node, used to store the group key; the Nth layer is the leaf node, used to store the user key of each member of the group; intermediate nodes are located between the first and Nth layers, used to store node keys; each intermediate node in the (N-1)th layer is connected to at least one leaf node; the group key is calculated from the node key, and the node key is calculated from the user key of the leaf node connected to the intermediate node, or from the node key of the connected intermediate node; the step of generating the first group key information for the new member and generating the first group key update information for the members of the group includes:

[0018] Generate a user key for the new member and store the user key of the new member in the leaf node of the second logical key tree;

[0019] Determine the first intermediate node; the first intermediate node is the intermediate node connected to the leaf node corresponding to the new member;

[0020] The node key of the first intermediate node is updated based on the user key of the new member to obtain the updated node key of the first intermediate node.

[0021] The second logical key tree is updated based on the update node key of the first intermediate node to obtain the updated second logical key tree;

[0022] The first set of key information is generated based on the new member's user key, the group key and node key in the updated second logical key tree;

[0023] The first set of key update information is generated based on the update node key of the first intermediate node.

[0024] Optionally, the first logical key tree includes N layers of nodes, which are interconnected, where N is an integer greater than 2; wherein, the first layer is the root node, used to store the group key; the Nth layer is a leaf node, used to store the user keys of the group members; the nodes between the first and Nth layers are intermediate nodes, used to store node keys; the leaf nodes are connected to one of the intermediate nodes of the (N-1)th layer; the group key is calculated from the node keys.

[0025] Optionally, generating the second set of key update information includes:

[0026] Identify the second group of members and the second intermediate node within the group; the second intermediate node is the intermediate node connected to the leaf node corresponding to the second group member.

[0027] Update the user keys of the second group members, and update the node key of the second intermediate node according to the updated user keys of the second group members;

[0028] A second set of key update information is generated based on the updated node key of the second intermediate node.

[0029] Optionally, the leaf nodes have a preset sorting; the second group of members are the group members corresponding to the leaf node that is sorted last.

[0030] Optionally, the method further includes:

[0031] The target leaf node in the second logical key tree is deleted according to a preset period; the target leaf node is the leaf node corresponding to the first group of members;

[0032] The connections between the leaf nodes and the intermediate nodes of the N-1 layer are rearranged.

[0033] Update the node key and group key of the intermediate node in the second logical key tree, and identify the third intermediate node in the second logical key tree that has changed.

[0034] The third set of key update information is generated according to the third intermediate node, and the third set of key update information is encrypted according to the quantum key of each group member before being sent to the terminal device of each group member.

[0035] Secondly, embodiments of the present invention disclose a quantum cryptography management service system, characterized in that the quantum cryptography management service system (KMS) is communicatively connected to the terminal devices of each member of a group; the KMS stores the quantum keys of each member of the group; each member stores a first logical key tree, the first logical key tree including the group key; the KMS is used for:

[0036] When a new member joins the group, a first set of key information is generated for the new member and a first set of key update information is generated for the group members.

[0037] The quantum key of the new member is obtained, and the first set of key information is encrypted using the quantum key of the new member and then sent to the terminal device of the new member, so that the terminal device of the new member can generate a first logical key tree based on the first set of key information.

[0038] After encrypting the first set of key update information according to the quantum key of each group member, the information is sent to the terminal device of each group member so that the terminal device of each group member updates the first logical key tree according to the first set of key update information.

[0039] When the first group member leaves the group, a second set of key update information is generated. The second set of key update information is then encrypted according to the quantum keys of the remaining group members and sent to the terminal devices of the remaining group members, so that the terminal devices of the remaining group members update the first logical key tree according to the second set of key update information. The remaining group members are the group members other than the first group members.

[0040] Thirdly, embodiments of the present invention disclose an electronic device, including: a processor, a memory, and a computer program stored in the memory and capable of running on the processor, wherein the computer program, when executed by the processor, implements the steps of the group key management method described above.

[0041] Fourthly, embodiments of the present invention disclose a computer-readable storage medium storing a computer program, which, when executed by a processor, implements the steps of the group key management method described above.

[0042] The embodiments of the present invention have the following advantages:

[0043] When a new member joins the group, the group key is updated, preventing the new member from accessing group communication information prior to their joining time, thus ensuring the confidentiality and security of group communication. Furthermore, the group key is stored and computed in the form of a logical key tree. Therefore, when a new member joins the group, an initial key is generated for them, allowing them to create a first logical key tree and obtain the updated group key. Simultaneously, an update is generated for existing members, enabling them to update their first logical key tree and obtain the updated group key. Storing and computed group keys in the form of a logical key tree reduces the overhead of storing group key-related information for users and reduces network bandwidth consumption during key updates. Additionally, the initial key and update are encrypted using the respective quantum keys of the new and existing members, ensuring the security of their transmission.

[0044] When the first member leaves the group, the group key is updated, ensuring that the first member cannot access group communication after their departure time, thus guaranteeing the confidentiality and security of group communication. Furthermore, when the first member leaves the group, a second key update is generated for the remaining members. Upon receiving this update, the remaining members can update their first logical key tree and obtain the updated group key. Storing and calculating the group key using a logical key tree reduces the overhead of storing group key information and network bandwidth consumption during key updates. Additionally, the second key update is encrypted using the individual quantum keys of the remaining members, ensuring the security of its transmission. Attached Figure Description

[0045] Figure 1 This is a flowchart of the steps of a group key management method provided in an embodiment of the present invention;

[0046] Figure 2 This is a group key management system provided in an embodiment of the present invention;

[0047] Figure 3 This is a flowchart of an identity authentication process provided by an embodiment of the present invention;

[0048] Figure 4 This is an example of an initialized LKH tree provided in this embodiment of the invention;

[0049] Figure 5 This is an LKH tree provided in an embodiment of the present invention when a new member is added;

[0050] Figure 6 This is another LKH tree provided in this embodiment of the invention when a new member is added;

[0051] Figure 7 This is an LKH tree provided in an embodiment of the present invention when the first group of members exits;

[0052] Figure 8 This is an LKH tree updated after the first group of members leaves, as provided in an embodiment of the present invention. Detailed Implementation

[0053] To make the above-mentioned objects, features and advantages of the present invention more apparent and understandable, the present invention will be further described in detail below with reference to the accompanying drawings and specific embodiments.

[0054] In related technologies, the LKH algorithm can be used to manage group keys, which can reduce the communication overhead during key updates from O(N) to O(log N), effectively improving the efficiency of group key updates. However, the LKH algorithm has some shortcomings in terms of security.

[0055] In view of this, one of the core concepts of the present invention is that when it is necessary to update and distribute the group key, the key update information is encrypted with the quantum key of each group member and then sent to each group member, so that each group member updates their own first logical key tree according to the key update information. Managing the group key through the LKH tree can reduce the key storage overhead, and encrypting the key update information with the quantum key before sending can improve the security of key update information transmission.

[0056] Reference Figure 1 This diagram illustrates a flowchart of a group key management method provided by an embodiment of the present invention. The method is applied to a quantum cryptography management service system (KMS), where the KMS is communicatively connected to the terminal devices of each member of the group. The KMS stores the quantum keys of each member of the group. Each member stores a first logical key tree, which includes the group key. The method may specifically include the following steps:

[0057] Step 101: When a new member joins the group, generate the first set of key information for the new member and generate the first set of key update information for the group members.

[0058] Step 102: Obtain the quantum key of the new member, encrypt the first set of key information using the quantum key of the new member, and send it to the terminal device of the new member so that the terminal device of the new member can generate the first logical key tree based on the first set of key information.

[0059] The new member's terminal device may include a quantum-safe chip. Before the new member joins the group, a quantum key can be injected into the quantum-safe chip of both the KMS and the new member's terminal device using a quantum key injector. When the new member joins the group, the KMS can determine the new member's quantum key, encrypt the first set of key information using the new member's quantum key, and then send it to the new member's terminal device.

[0060] Step 103: After encrypting the first set of key update information according to the quantum key of each group member, the information is sent to the terminal devices of each group member so that the terminal devices of each group member can update the first logical key tree according to the first set of key update information.

[0061] KMS can store the quantum keys of each member of the group. When a new member joins the group, the first key update information is encrypted using the quantum keys of each member and then sent to the terminal devices of each member. After receiving the first key update information, each member's terminal device can decrypt the encrypted first key update information using its own quantum key, update the first logical key tree based on the decrypted first key update information, and obtain the group key in the updated first logical key tree, i.e., the updated group key.

[0062] Step 104: When the first group member leaves the group, a second set of key update information is generated. The second set of key update information is encrypted according to the quantum key of the remaining group member and then sent to the terminal device of each remaining group member so that the terminal device of each remaining group member can update the first logical key tree according to the second set of key update information. The remaining group members are the group members other than the first group member.

[0063] The first group of members consists of any one or more members within the group. When a member of the first group leaves the group, KMS generates a second set of key update information. This second set of key update information is then encrypted using the quantum keys of the remaining members in the group, and sent to the terminal devices of each remaining member. Upon receiving the second set of key update information, the terminal devices of the remaining members can decrypt the encrypted information using their own quantum keys. They then update the first logical key tree based on the decrypted information, obtaining the group key in the updated first logical key tree, which is the updated group key.

[0064] In this embodiment of the invention, when it is necessary to update and distribute the group key, the key update information is encrypted with the quantum key of each group member and then sent to each group member, so that each group member updates their own first logical key tree according to the key update information. Managing the group key through the LKH tree can reduce key storage overhead, and encrypting the key update information with the quantum key before sending can improve the security of key update information transmission.

[0065] Reference Figure 2This diagram illustrates a group key management system. The group key management system includes a quantum random number generator, a quantum exchange cryptography machine, a quantum key injection machine, a KMS (Key Management System), and a quantum-safe chip. The quantum random number generator generates quantum keys. The quantum exchange cryptography machine receives the quantum keys sent by the quantum random number generator. The quantum key injection machine connects to the output of the quantum exchange cryptography machine and injects quantum keys into the KMS and the quantum-safe chip. The KMS interacts with the quantum-safe chip and a business system (such as an instant messaging system) via a network. The quantum-safe chip stores the quantum-safe keys; the keys stored in each quantum-safe chip and the keys pre-stored in the quantum exchange cryptography machine are symmetric keys; the quantum-safe chip is embedded in the user terminal device.

[0066] Reference Figure 3 This diagram illustrates a flowchart of an identity authentication process provided by an embodiment of the present invention. The KMS and the terminal device of the new member can respectively communicate with the business system. The business system can store the user identifier and the identifier of the new member's quantum-safe chip; the KMS can store the mapping relationship between the identifier of the quantum-safe chip and the quantum key stored in the quantum-safe chip. Before a new member joins, their identity can be authenticated. After successful authentication, a first set of key information and a first set of key update information are generated and distributed. The specific steps of identity authentication may include:

[0067] Step 201: Before a new member joins the group, receive the user identifier and quantum security chip identifier of the new member sent by the business system.

[0068] Step 202: Determine the quantum key of the new member based on the identifier and mapping relationship of the new member's quantum secure chip.

[0069] Step 203: Encrypt the user identifier of the new member according to the quantum key of the new member to obtain the first identity authentication information, and send the first identity authentication information to the business system.

[0070] Step 204: Receive the identity authentication result sent by the business system; the identity authentication result is obtained by the business system receiving the second identity authentication information sent by the new member's terminal device and comparing the second identity authentication information with the first identity authentication information; the second identity authentication information is obtained by the new member's terminal device encrypting the stored user identifier according to the stored quantum key.

[0071] Step 205: When the identity authentication result is successful, generate the first set of key information for the new member and generate the first set of key update information for the group members.

[0072] Before joining the group, new members can register or activate their accounts. New members can send an account registration or activation request to the business system; the request can include the identifier of the new member's quantum-safe chip. Upon receiving the request, the business system can generate a user identifier for the new member and send the user identifier, along with the identifier of the new member's quantum-safe chip, to KMS.

[0073] Subsequently, the new member can encrypt their user identifier using the SM3_HMAC algorithm based on the quantum key stored in the quantum-safe chip to obtain first authentication information, which is then sent to the business system. KMS determines the new member's quantum key based on the quantum-safe chip's identifier and the aforementioned mapping relationship, and encrypts the user identifier using the SM3_HMAC algorithm based on the new member's quantum key to obtain second authentication information, which is then sent to the business system.

[0074] The business system compares the first and second identity authentication information. If the comparison results match, the identity authentication is successful.

[0075] When joining a group, members also need to verify their identity. The verification process is similar to that of new members, so it will not be elaborated on here.

[0076] In one embodiment, the KMS may store a second logical key tree, which includes N layers of nodes interconnected, where N is an integer greater than 2. The first layer is the root node, used to store the group key; the Nth layer is the leaf node, used to store the user key of each group member; the nodes between the first and Nth layers are intermediate nodes, used to store the node key; each intermediate node in the (N-1)th layer is connected to at least one leaf node; the group key is calculated from the node key, and the node key is calculated from the user key of the leaf node connected to the intermediate node, or from the node key of the connected intermediate node.

[0077] The structure of the second logical key tree can be referred to Figure 4 . Figure 4 This is an initialized LKH tree, where boxes represent user nodes and circles represent key nodes. Where K... G It is the group key stored in the root node, K n1 ~K n3K1 to K8 are the node keys stored in the intermediate nodes, and K1 to K8 are the user keys stored in the leaf nodes corresponding to users u1 to u8. The node key generation method is as follows: Encryption is performed using the SM4 (Simplified Message Block Cipher for 128-bit Data) algorithm in CBC (Cipher Block Chaining) mode. The user key on the right is encrypted using the user key on the right and the initialization vector, and this encryption continues until the right node is empty, as shown below, with K... n1 The calculation process is as follows:

[0078] K n1 =SM4_CBC_ENC(SM4_CBC_ENC(K1, K2, IV2), K3, IV3), where,

[0079] IV2 and IV3 are the initialization vectors of K2 and K3, respectively, and SM4_CBC_ENC is the CBC mode encryption of the SM4 algorithm.

[0080] When the node tree is not full, use K n3 For example:

[0081] K n3 =SM4_CBC_ENC(K7, K8, IV8), where IV8 is the initialization vector of K8.

[0082] When there is only one user under a node, the node key and the user key are the same.

[0083] The group key is calculated as follows:

[0084] K G =SM4_CBC_ENC(SM4_CBC_ENC(K n1 K n2 IV n2 ), K n3 IV n3 ),That

[0085] In the middle, IV n3 =IV7⊕IV8, IV n2 =IV4⊕IV5⊕IV6.

[0086] In this embodiment of the invention, step 101 may specifically include: generating a user key for the new member and storing the user key of the new member in the leaf node of the second logical key tree; determining a first intermediate node; the first intermediate node is the intermediate node connected to the leaf node corresponding to the new member; updating the node key of the first intermediate node according to the user key of the new member to obtain the updated node key of the first intermediate node; updating the second logical key tree according to the updated node key of the first intermediate node to obtain the updated second logical key tree; generating a first set of key information according to the user key of the new member, the group key and the node key in the updated second logical key tree; and generating a first set of key update information according to the updated node key of the first intermediate node.

[0087] When a new member joins, KMS can generate a user key for the new member, store the new member's user key in a leaf node of the second logical key tree, and calculate the node key of the first intermediate node to which the new member is connected, according to the calculation method described above. Then, the calculated node key of the first intermediate node is encrypted and sent to each member of the group, and the node keys and group keys of each intermediate node in the second logical key tree are encrypted and sent to the new member.

[0088] Reference Figure 5 This illustrates an LKH tree for a new member joining according to an embodiment of the present invention. u9 is the new member's username and k9 is the new member's username. After a new member joins, the node key of the intermediate node to which the new member is connected, i.e., the first intermediate node, needs to be updated. The update process is as follows:

[0089] K' n3 =SM4_CBC_ENC(K n3 (K9, IV9), where K' n3 The node key is updated by the first intermediate node, IV9 is the initialization vector for K9, and K... n3 This is the node key before the first intermediate node was updated.

[0090] The new group key is calculated as follows:

[0091] K' G =SM4_CBC_ENC(K G K' n3 IV' n3 ), where IV' n3 =IV7⊕IV8⊕IV9.

[0092] Therefore, the group members receive the updated node key K' from the first intermediate node. n3 Then, it can be based on the SM4 algorithm and K' n3 The new group key K' is calculated. GWhen updating the group key, KMS only needs to send the affected node key to the user terminal, which can reduce the network bandwidth overhead during the group key update process.

[0093] Reference Figure 6 This illustrates another LKH tree provided by an embodiment of the present invention when a new member is added. 10 For new members, K 10 This is the user key for the new member. After the new member joins, a new node key K is added to the logical key tree. n4 K m2 The original group key K G Become the node key K m1 The new K G The calculation process is as follows:

[0094] K G =SM4_CBC_ENC(K m1 K m2 IV m2 ), where K m2 =K n4 =K 10 IV m2 =IV 10 .

[0095] In one embodiment, the first logical key tree includes N layers of interconnected nodes, where N is an integer greater than 2. The first layer is the root node, used to store the group key; the Nth layer is a leaf node, used to store the user keys of group members; intermediate nodes exist between the first and Nth layers, used to store node keys; each leaf node is connected to one of the intermediate nodes in the (N-1)th layer; the group key is calculated from the node keys. The difference between the first and second logical key trees is that each group member has their own corresponding first logical key tree, and the leaf nodes of each group member's first logical key tree only store their own user key, not the user keys of other group members. The second logical key tree needs to store the user keys of all group members.

[0096] In one embodiment, the step of generating the second set of key update information may include: determining the second group members and the second intermediate node within the group; the second intermediate node is the intermediate node connected to the leaf node corresponding to the group member; updating the user key of the second group member, and updating the node key of the second intermediate node according to the updated user key of the second group member; generating the second set of key update information according to the updated node key of the second intermediate node.

[0097] Leaf nodes can have a preset order; the second group of members can be the group members corresponding to the last leaf node in the order. The user key of the second group of members can be updated, thereby updating the node key of the second intermediate node, and further updating the group key.

[0098] Reference Figure 7 This illustration shows an LKH tree provided by an embodiment of the present invention when a member of the first group leaves the group. When a member of the first group leaves the group, the structure of the LKH tree is not updated temporarily, that is, no initialization is performed. Instead, the key of the rightmost node is updated, which is to update the key of the second intermediate node connected to the leaf node of the second group member, thereby updating the group key. KMS distributes the updated key of the second intermediate node to other group members except the first group member. The distributed second key update information is encrypted using the quantum key corresponding to the other member, ensuring that only that member can decrypt it.

[0099] In this example, the second member is u9, and the updated user key for u9 is K'9. The node key calculation method for the second intermediate node is as follows: first, the original value is symmetrically decrypted using the SM4 algorithm in CBC mode, and then the new key is used for symmetric encryption using the SM4 algorithm in CBC mode, as shown below:

[0100] K” n3 =SM4_CBC_ENC(SM4_CBC_DEC(K' n3 ,K9,IV9),K'9,IV'9), where,K” n3 For K' n3 The updated node key, IV'9 is the initialization vector for K'9, and SM4_CBC_DEC is the CBC mode decryption for the SM4 algorithm.

[0101] The new group key is calculated as follows:

[0102] K” G =SM4_CBC_ENC(SM4_CBC_DEC(K' G K' n3 IV' n3 ), K” n3 IV n3 ),That

[0103] In the middle, K” G For the new group key, K' G For the old group key,

[0104] In this embodiment of the invention, when a group member joins or leaves the group, the tree structure is updated less. Calculating the new group key only requires calculating the change of the node key of the rightmost middle node, resulting in low computational complexity.

[0105] In one embodiment, the group key management method may further include: deleting a target leaf node in the second logical key tree according to a preset period; the target leaf node is the leaf node corresponding to the first group member; rearranging the connections between the leaf node and the intermediate nodes of layer N-1; updating the node key and group key of the intermediate nodes in the second logical key tree, and determining the third intermediate node that has changed in the second logical key tree; generating a third set of key update information based on the third intermediate node, and encrypting the third set of key update information according to the quantum key of each group member, and sending it to the terminal device of each group member.

[0106] Reference Figure 8 This illustration shows an LKH tree updated after a first group member leaves the group, according to an embodiment of the present invention. When a first group member leaves the group, the structure of the LKH tree is not updated temporarily; instead, the key of the rightmost node is updated to achieve the effect of updating the group key. Then, the structure of the LKH tree is updated periodically or in batches, which can reduce the frequency of LKH tree structure updates.

[0107] It should be noted that, for the sake of simplicity, the method embodiments are all described as a series of actions. However, those skilled in the art should understand that the embodiments of the present invention are not limited to the described order of actions, because according to the embodiments of the present invention, some steps can be performed in other orders or simultaneously. Furthermore, those skilled in the art should also understand that the embodiments described in the specification are preferred embodiments, and the actions involved are not necessarily essential to the embodiments of the present invention.

[0108] This invention also provides a quantum cryptography management service system (KMS), which is communicatively connected to the terminal devices of each member of a group; the KMS stores the quantum keys of each member of the group; each member stores a first logical key tree, which includes the group's group key; the KMS is used for:

[0109] When a new member joins the group, a first set of key information is generated for the new member and a first set of key update information is generated for the group members.

[0110] The quantum key of the new member is obtained, and the first set of key information is encrypted using the quantum key of the new member and then sent to the terminal device of the new member, so that the terminal device of the new member can generate a first logical key tree based on the first set of key information.

[0111] After encrypting the first set of key update information according to the quantum key of each group member, the information is sent to the terminal device of each group member so that the terminal device of each group member updates the first logical key tree according to the first set of key update information.

[0112] When the first group member leaves the group, a second set of key update information is generated. The second set of key update information is then encrypted according to the quantum keys of the remaining group members and sent to the terminal devices of the remaining group members, so that the terminal devices of the remaining group members update the first logical key tree according to the second set of key update information. The remaining group members are the group members other than the first group members.

[0113] Optionally, each member of the group and the new member's terminal device includes a quantum-safe chip; the KMS stores a mapping relationship between the identifier of the quantum-safe chip and the quantum key stored in the quantum-safe chip; the KMS and the new member's terminal device are respectively connected to the business system; the KMS is used to: receive the user identifier and quantum-safe chip identifier of the new member sent by the business system before the new member joins the group; determine the quantum key of the new member according to the identifier of the quantum-safe chip and the mapping relationship; and encrypt the user identifier of the new member according to the quantum key. The system obtains first identity authentication information and sends it to the business system; it receives the identity authentication result sent by the business system; the identity authentication result is obtained by the business system receiving second identity authentication information sent by the new member's terminal device and comparing the second identity authentication information with the first identity authentication information; the second identity authentication information is obtained by the new member's terminal device encrypting the stored user identifier according to the stored quantum key; when the identity authentication result is successful, the system generates a first set of key information for the new member and a first set of key update information for the group members.

[0114] Optionally, the KMS stores a second logical key tree, which includes N layers of interconnected nodes, where N is an integer greater than 2. The first layer is the root node, used to store the group key; the Nth layer is the leaf nodes, used to store the user keys of each group member; intermediate nodes exist between the first and Nth layers, used to store node keys; each intermediate node in the (N-1)th layer is connected to at least one leaf node; the group key is calculated from the node keys, and the node keys are calculated from the user keys of the leaf nodes connected to the intermediate nodes, or from the node keys of the connected intermediate nodes; the KMS is used to: generate user keys for the new members. The process involves: storing the new member's user key in a leaf node of the second logical key tree; determining a first intermediate node, which is the intermediate node connected to the leaf node corresponding to the new member; updating the node key of the first intermediate node based on the new member's user key to obtain an updated node key for the first intermediate node; updating the second logical key tree based on the updated node key of the first intermediate node to obtain an updated second logical key tree; generating a first set of key information based on the new member's user key, the group key, and the node key in the updated second logical key tree; and generating a first set of key update information based on the updated node key of the first intermediate node.

[0115] Optionally, the first logical key tree includes N layers of nodes, which are interconnected, where N is an integer greater than 2; wherein, the first layer is the root node, used to store the group key; the Nth layer is a leaf node, used to store the user keys of the group members; the nodes between the first and Nth layers are intermediate nodes, used to store node keys; the leaf nodes are connected to one of the intermediate nodes of the (N-1)th layer; the group key is calculated from the node keys.

[0116] Optionally, the KMS is used to: determine a second group of members and a second intermediate node within the group; the second intermediate node is the intermediate node connected to the leaf node corresponding to the second member; update the user key of the second group member, and update the node key of the second intermediate node according to the updated user key of the second group member; generate a second set of key update information according to the updated node key of the second intermediate node.

[0117] Optionally, the leaf nodes have a preset sorting; the second group of members are the group members corresponding to the leaf node that is sorted last.

[0118] Optionally, the KMS is used to: delete target leaf nodes in the second logical key tree according to a preset period; the target leaf node is the leaf node corresponding to the first group member; rearrange the connections between the leaf node and the intermediate nodes of the N-1 layer; update the node key and group key of the intermediate nodes in the second logical key tree, and determine the third intermediate node that has changed in the second logical key tree; generate a third set of key update information according to the third intermediate node, and encrypt the third set of key update information according to the quantum key of the group member, and send it to the terminal device of each group member.

[0119] As the system implementation is basically similar to the method implementation, it is described in a relatively simple way. For relevant details, please refer to the description of the method implementation.

[0120] This invention also provides an electronic device, comprising:

[0121] It includes a processor, a memory, and a computer program stored in the memory and capable of running on the processor. When the computer program is executed by the processor, it implements the various processes of the above-described group key management method embodiments and achieves the same technical effect. To avoid repetition, it will not be described again here.

[0122] This invention also provides a computer-readable storage medium storing a computer program. When the computer program is executed by a processor, it implements the various processes of the above-described group key management method embodiments and achieves the same technical effect. To avoid repetition, it will not be described again here.

[0123] The various embodiments in this specification are described in a progressive manner, with each embodiment focusing on the differences from other embodiments. The same or similar parts between the various embodiments can be referred to each other.

[0124] Those skilled in the art will understand that embodiments of the present invention can be provided as methods, apparatus, or computer program products. Therefore, embodiments of the present invention can take the form of entirely hardware embodiments, entirely software embodiments, or embodiments combining software and hardware aspects. Furthermore, embodiments of the present invention can take the form of computer program products implemented on one or more computer-usable storage media (including but not limited to disk storage, CD-ROM, optical storage, etc.) containing computer-usable program code.

[0125] This invention is described with reference to flowchart illustrations and / or block diagrams of methods, terminal devices (systems), and computer program products according to embodiments of the invention. It will be understood that each block of the flowchart illustrations and / or block diagrams, and combinations of blocks in the flowchart illustrations and / or block diagrams, can be implemented by computer program instructions. These computer program instructions can be provided to a processor of a general-purpose computer, special-purpose computer, embedded processor, or other programmable data processing terminal device to produce a machine, such that the instructions, which execute via the processor of the computer or other programmable data processing terminal device, generate instructions for implementing the flowchart illustrations and / or block diagrams. Figure 1 One or more processes and / or boxes Figure 1 A device that provides the functions specified in one or more boxes.

[0126] These computer program instructions may also be stored in a computer-readable storage medium that can direct a computer or other programmable data processing terminal device to operate in a particular manner, such that the instructions stored in the computer-readable storage medium produce an article of manufacture including instruction means, which are implemented in a process Figure 1 One or more processes and / or boxes Figure 1 The function specified in one or more boxes.

[0127] These computer program instructions can also be loaded onto a computer or other programmable data processing terminal equipment, causing a series of operational steps to be performed on the computer or other programmable terminal equipment to produce a computer-implemented process, thereby providing instructions that execute on the computer or other programmable terminal equipment for implementing the process. Figure 1 One or more processes and / or boxes Figure 1 The steps of the function specified in one or more boxes.

[0128] Although preferred embodiments of the present invention have been described, those skilled in the art, upon learning the basic inventive concept, can make other changes and modifications to these embodiments. Therefore, the appended claims are intended to be interpreted as including the preferred embodiments as well as all changes and modifications falling within the scope of the embodiments of the present invention.

[0129] Finally, it should be noted that in this document, relational terms such as "first" and "second" are used only to distinguish one entity or operation from another, and do not necessarily require or imply any such actual relationship or order between these entities or operations. Furthermore, the terms "comprising," "including," or any other variations thereof are intended to cover non-exclusive inclusion, such that a process, method, article, or terminal device that comprises a list of elements includes not only those elements but also other elements not expressly listed, or elements inherent to such a process, method, article, or terminal device. Without further limitations, an element defined by the phrase "comprising one..." does not exclude the presence of other identical elements in the process, method, article, or terminal device that includes said element.

[0130] The above provides a detailed description of the group key management method, system, electronic device, and storage medium provided by the present invention. Specific examples have been used to illustrate the principles and implementation methods of the present invention. The descriptions of the above embodiments are only for the purpose of helping to understand the method and core ideas of the present invention. At the same time, for those skilled in the art, there will be changes in the specific implementation methods and application scope based on the ideas of the present invention. Therefore, the content of this specification should not be construed as a limitation of the present invention.

Claims

1. A group key management method, characterized in that, A quantum cryptography management service system (KMS) is applied, wherein the KMS is communicatively connected to the terminal devices of each member of the group; the KMS stores the quantum keys of each member of the group. Each of the group members stores a first logical key tree, the first logical key tree including the group key of the group, the method comprising: When a new member joins the group, a first set of key information is generated for the new member and a first set of key update information is generated for the group members. The quantum key of the new member is obtained, and the first set of key information is encrypted using the quantum key of the new member and then sent to the terminal device of the new member, so that the terminal device of the new member can generate a first logical key tree based on the first set of key information. After encrypting the first set of key update information according to the quantum key of each group member, the information is sent to the terminal device of each group member so that the terminal device of each group member updates the first logical key tree according to the first set of key update information. When the first group member leaves the group, a second set of key update information is generated. The second set of key update information is then encrypted according to the quantum keys of the remaining group members and sent to the terminal devices of the remaining group members, so that the terminal devices of the remaining group members update the first logical key tree according to the second set of key update information; wherein, the remaining group members are the group members other than the first group members. Each member of the group and the new member's terminal device includes a quantum-safe chip; the KMS stores a mapping relationship between the identifier of the quantum-safe chip and the quantum key stored in the quantum-safe chip; the KMS and the new member's terminal device are respectively connected to the business system; the business system stores the new member's user identifier and the quantum-safe chip identifier; the method further includes: Before the new member joins the group, the system receives the user identifier and quantum security chip identifier of the new member from the business system. The quantum key of the new member is determined based on the identifier of the quantum-safe chip of the new member and the mapping relationship; The user identifier of the new member is encrypted using the new member's quantum key to obtain first identity authentication information, and the first identity authentication information is sent to the business system. The system receives the authentication result sent by the business system; the authentication result is obtained by the business system receiving second authentication information sent by the new member's terminal device and comparing the second authentication information with the first authentication information; the second authentication information is obtained by the new member's terminal device encrypting the stored user identifier according to the stored quantum key. The steps of generating a first set of key information for the new member and generating a first set of key update information for the group members include: When the identity authentication result is successful, a first set of key information is generated for the new member and a first set of key update information is generated for the group members.

2. The method according to claim 1, characterized in that, The KMS stores a second logical key tree, which includes N layers of interconnected nodes, where N is an integer greater than 2. The first layer is the root node, used to store the group key; the Nth layer is the leaf nodes, used to store the user keys of each group member; intermediate nodes exist between the first and Nth layers, used to store node keys; each intermediate node in the (N-1)th layer is connected to at least one leaf node. The group key is calculated from the node keys, and the node keys are calculated from the user keys of the leaf nodes connected to the intermediate nodes, or from the node keys of the connected intermediate nodes. The process of generating first group key information for the new member and generating first group key update information for the group members includes: Generate a user key for the new member and store the user key of the new member in the leaf node of the second logical key tree; Determine the first intermediate node; the first intermediate node is the intermediate node connected to the leaf node corresponding to the new member; The node key of the first intermediate node is updated based on the user key of the new member to obtain the updated node key of the first intermediate node. The second logical key tree is updated based on the update node key of the first intermediate node to obtain the updated second logical key tree; The first set of key information is generated based on the new member's user key, the group key and node key in the updated second logical key tree; The first set of key update information is generated based on the update node key of the first intermediate node.

3. The method according to claim 2, characterized in that, The first logical key tree includes N layers of nodes, which are interconnected, where N is an integer greater than 2. The first layer is the root node, which stores the group key. The Nth layer is a leaf node, which stores the user keys of the group members. The nodes between the first and Nth layers are intermediate nodes, which store the node keys. The leaf nodes are connected to one of the intermediate nodes in the (N-1)th layer. The group key is calculated from the node keys.

4. The method according to claim 2, characterized in that, The generation of the second set of key update information includes: Identify the second group of members and the second intermediate node within the group; the second intermediate node is the intermediate node connected to the leaf node corresponding to the second group member. Update the user keys of the second group members, and update the node key of the second intermediate node according to the updated user keys of the second group members; The second set of key update information is generated based on the updated node key of the second intermediate node.

5. The method according to claim 4, characterized in that, The leaf nodes have a preset sorting; the second group of members are the group members corresponding to the leaf node that is sorted last.

6. The method according to claim 2, characterized in that, The method further includes: The target leaf node in the second logical key tree is deleted according to a preset period; the target leaf node is the leaf node corresponding to the first group of members; The connections between the leaf nodes and the intermediate nodes of the N-1 layer are rearranged. Update the node key and group key of the intermediate node in the second logical key tree, and identify the third intermediate node in the second logical key tree that has changed. The third set of key update information is generated according to the third intermediate node, and the third set of key update information is encrypted according to the quantum key of each group member before being sent to the terminal device of each group member.

7. A quantum cryptography management service system, characterized in that, The quantum cryptography management service system (KMS) communicates with the terminal devices of each member of the group; the KMS stores the quantum keys of each member of the group; each member stores a first logical key tree, which includes the group key; the KMS is used for: When a new member joins the group, a first set of key information is generated for the new member and a first set of key update information is generated for the group members. The quantum key of the new member is obtained, and the first set of key information is encrypted using the quantum key of the new member and then sent to the terminal device of the new member, so that the terminal device of the new member can generate a first logical key tree based on the first set of key information. After encrypting the first set of key update information according to the quantum key of each group member, the information is sent to the terminal device of each group member so that the terminal device of each group member updates the first logical key tree according to the first set of key update information. When the first group member leaves the group, a second set of key update information is generated. The second set of key update information is then encrypted according to the quantum keys of the remaining group members and sent to the terminal devices of the remaining group members, so that the terminal devices of the remaining group members update the first logical key tree according to the second set of key update information; wherein, the remaining group members are the group members other than the first group members. Each member of the group and the new member's terminal device includes a quantum-safe chip; the KMS stores a mapping relationship between the identifier of the quantum-safe chip and the quantum key stored in the quantum-safe chip; the KMS and the new member's terminal device are respectively connected to the business system; the KMS is used to: receive the user identifier and quantum-safe chip identifier of the new member sent by the business system before the new member joins the group; determine the new member's quantum key based on the quantum-safe chip identifier and the mapping relationship; and encrypt the new member's user identifier based on the new member's quantum key. The system receives first identity authentication information and sends it to the business system; it receives the identity authentication result sent by the business system; the identity authentication result is obtained by the business system receiving second identity authentication information sent by the new member's terminal device and comparing the second identity authentication information with the first identity authentication information; the second identity authentication information is obtained by the new member's terminal device encrypting the stored user identifier according to the stored quantum key; when the identity authentication result is successful, the system generates a first set of key information for the new member and a first set of key update information for the group members.

8. An electronic device, characterized in that, include: A processor, a memory, and a computer program stored in the memory and capable of running on the processor, wherein the computer program, when executed by the processor, implements the steps of the group key management method as described in any one of claims 1-6.

9. A computer-readable storage medium, characterized in that, A computer program is stored on the computer-readable storage medium, which, when executed by a processor, implements the steps of the group key management method as described in any one of claims 1-6.

Citation Information

Patent Citations

  • Quantum key management

    US20130083926A1