Quantum Fusion 5G Encryption Method for Internet of Things Terminals

By integrating quantum true random number chips and 5G communication technology in the Internet of Things terminals, frequency hopping sequences are generated for identity authentication and data encryption, the problem of high power consumption and low processing efficiency of IoT terminals is solved, and efficient and secure data transmission is achieved.

CN118842648BActive Publication Date: 2025-07-11YIXUNTONG TECH CO LTD
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202411206239.4
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2024-08-30
Publication Date
2025-07-11
Estimated Expiration
2044-08-30

AI Technical Summary

Technical Problem

The quantum encryption module of the Internet of Things terminal consumes a large amount of computing resources when resource constraints are limited, resulting in a decline in the overall performance of the device and an increase in data interaction latency, making it difficult to fully utilize the low latency advantages of 5G communication technology.

Method used

The quantum true random number chip is used to generate frequency hopping sequences, combined with 5G communication technology, identity authentication and data encryption are performed through prefabricated keys, and complex quantum components are integrated into small chips, reducing power consumption and improving processing efficiency.

Benefits of technology

在保证安全性的同时,降低了物联网终端的功耗,提高了处理效率,增强了通信的频谱利用能力和抗干扰能力,确保数据传输的完整性和安全性。

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN118842648B_ABST
    Figure CN118842648B_ABST
Patent Text Reader

Abstract

This application relates to the field of Internet of Things technology, and particularly to a quantum fusion 5G encryption method for Internet of Things terminals, which is applied to an Internet of Things terminal quantum fusion 5G encryption system. The system includes an Internet of Things terminal and an Internet of Things terminal management platform; the Internet of Things terminal is provided with a quantum true random number chip for generating quantum true random numbers and random sequences; a communication connection between the Internet of Things terminal and the Internet of Things terminal management platform is established according to a communication request, and the communication connection is established using a frequency hopping sequence; the frequency hopping sequence is obtained based on the quantum true random number generated corresponding to the communication request; the Internet of Things terminal sending the communication request is authenticated using a prefabricated key, and the prefabricated key is a random sequence; the data in the communication request is encrypted using a symmetric session key and then sent to the Internet of Things terminal management platform, and the symmetric session key is the quantum true random number called by the Internet of Things terminal, so as to solve the problems of high power consumption and low processing efficiency in the encryption of Internet of Things terminals while ensuring security.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This application relates to the field of Internet of Things technology, and particularly to a quantum fusion 5G encryption method for Internet of Things terminals. Background Art

[0002] With the rapid development and popularization of Internet of Things technology, more and more devices are connected to the Internet to achieve intelligent control and management. However, the wide application of Internet of Things terminals has also brought challenges in data security and privacy protection. To solve these problems, quantum encryption technology is considered an effective solution because it provides a secure communication method that is almost impossible to crack based on the principles of quantum mechanics.

[0003] Integrating quantum encryption modules into Internet of Things terminals is a trend to improve their security. In related technologies, security modules, such as those using key distribution and encryption modules, require complex computational operations, which consume a large amount of computational resources. For resource-constrained Internet of Things terminals, it will lead to insufficient resources when performing other tasks, thus affecting the overall performance of the device. Moreover, for Internet of Things terminals that need to handle a large amount of data interaction, the integration through module circuits may introduce additional data interaction delays. Although the encryption technology itself has high security, the complexity of its operations may slow down data transmission and processing speeds, making it difficult to fully utilize the low-latency advantage of 5G communication technology. Summary of the Invention

[0004] This application provides a quantum fusion 5G encryption method for Internet of Things terminals to solve the problems of high power consumption and low processing efficiency in Internet of Things terminal encryption while ensuring security.

[0005] This application provides a quantum fusion 5G encryption method for Internet of Things terminals, which is applied to a quantum fusion 5G encryption system for Internet of Things terminals. The system includes an Internet of Things terminal and an Internet of Things terminal management platform; a quantum true random number chip is provided in the Internet of Things terminal for generating quantum true random numbers and random sequences; the method includes:

[0006] Establish a communication connection between the Internet of Things terminal and the Internet of Things terminal management platform according to a communication request, where the communication connection is established using a frequency hopping sequence; the frequency hopping sequence is obtained based on the quantum true random number generated corresponding to the communication request;

[0007] Authenticate the Internet of Things terminal sending the communication request using a prefabricated key, where the prefabricated key is a random sequence stored in the Internet of Things terminal management platform;

[0008] If the identity authentication is successful, encrypt the data in the communication request using the symmetric session key and send it to the Internet of Things (IoT) terminal management platform. The symmetric session key is a quantum true random number called by the IoT terminal after successful identity authentication.

[0009] Integrate complex quantum components and functions into a small chip using integrated circuit technology, which can reduce power consumption and volume while ensuring high performance, to meet the interactive requirements of IoT big data based on 5G communication technology. By applying the quantum true random number chip to the IoT 5G frequency hopping communication scheme, using the quantum true random number as the frequency hopping sequence, improving the spectrum utilization ability and anti-interference ability of IoT device communication with 5G frequency hopping technology, and using the quantum true random number chip to solve the forward security risk of the IoT communication frequency modulation channel, so as to solve the problems of high power consumption and low processing efficiency in ensuring the security of IoT terminal encryption.

[0010] Optionally, a 5G communication module and a key management server are also provided in the IoT terminal. The key management server is communicatively connected to the 5G communication module and the quantum true random number chip respectively. The IoT terminal management platform includes a device data management center and a quantum key management center. The 5G communication module is communicatively connected to the device data management center and the quantum key management center through a 5G base station.

[0011] The steps of establishing a communication connection between the IoT terminal and the IoT terminal management platform according to the communication request include:

[0012] The 5G communication module sends a key request to the key management server.

[0013] The key management server obtains a quantum true random number from the quantum true random number chip according to the key request to generate a key.

[0014] Send the key to the 5G communication module for determining the frequency hopping sequence for establishing communication with the 5G base station.

[0015] The 5G communication module transmits a frequency hopping signal to the 5G base station according to the key.

[0016] The 5G base station receives the frequency hopping signal using the synchronized frequency hopping sequence and demodulates the frequency hopping signal to generate IoT terminal data. The IoT terminal data includes IoT terminal registration request data and communication request data.

[0017] Forward the IoT terminal data according to the destination address to establish a communication link. The destination address includes the address of the device data management center and the address of the quantum key management center.

[0018] In the steps of the above-mentioned communication link encryption, by obtaining quantum true random numbers from the quantum true random number chip to generate keys and transmitting frequency hopping signals to the 5G base station according to the keys, the difficulty of communication being cracked can be greatly increased, the anti-jamming ability and anti-predictability of the communication link can be enhanced, helping the system better adapt to environmental changes and maintain the stability and reliability of communication. The 5G base station uses a synchronized frequency hopping sequence to receive the frequency hopping signal and demodulates and processes the frequency hopping signal to generate Internet of Things terminal data, ensuring the integrity and security of the data during transmission and effectively preventing the data from being tampered with or stolen during transmission.

[0019] Optionally, the step of the 5G communication module transmitting a frequency hopping signal to the 5G base station according to the key includes:

[0020] The 5G communication module synchronizes frequencies with the 5G base station so that the clock of the 5G communication module is consistent with the network clock;

[0021] Select a channel according to the current network condition and resource allocation for communication with the 5G base station;

[0022] Modulate and process the Internet of Things terminal data according to the key to generate a frequency hopping signal;

[0023] Transmit the frequency hopping signal to the 5G base station through the antenna.

[0024] The 5G communication module can improve the stability and reliability of communication through frequency synchronization, optimize the performance of the communication link through channel selection, improve the data transmission rate and reduce latency; enhance the security and anti-jamming ability of communication through key modulation processing to achieve long-distance and high-rate data transmission.

[0025] Optionally, the Internet of Things terminal is further provided with an identity authentication module, and the identity authentication module is respectively communicatively connected to the key management server and the Internet of Things terminal management platform;

[0026] The steps of authenticating the identity of the Internet of Things terminal sending the communication request by using a prefabricated key include:

[0027] The quantum key management center registers the Internet of Things terminal according to the Internet of Things terminal registration request to obtain a random sequence and Internet of Things terminal information;

[0028] Store the random sequence as a prefabricated key in the key management module of the quantum key management center;

[0029] The identity authentication module authenticates the identity through the prefabricated key and the Internet of Things terminal information.

[0030] In the above steps of identity authentication protection, by pre-registering the Internet of Things (IoT) terminals in the quantum key management center and allocating prefabricated keys, identity authentication can be performed immediately when the device first accesses the network, reducing the device configuration time. The prefabricated keys are stored in the key management module, effectively preventing the prefabricated keys from being intercepted or tampered with during transmission. The identity authentication module authenticates the identity through the prefabricated keys and the IoT terminal information, significantly reducing the risk of illegal access.

[0031] Optionally, the step in which the identity authentication module authenticates the identity through the prefabricated keys and the IoT terminal information includes:

[0032] The quantum key management center processes the IoT terminal information using a hash function to generate a message authentication code.

[0033] Encrypt the message authentication code according to the prefabricated key to generate an encrypted message authentication code.

[0034] Send the encrypted message authentication code to the identity authentication module.

[0035] The identity authentication module decrypts the encrypted message authentication code according to the prefabricated key to obtain the message authentication code.

[0036] Verify the identity by performing a hash function verification on its own IoT terminal information and the message authentication code.

[0037] During an IoT communication request, by applying a hash function and a prefabricated key for double verification between the quantum key management center and the identity authentication module, not only can the efficiency of identity authentication be improved, but also the accuracy and security of authentication can be enhanced.

[0038] Optionally, the method for obtaining the random sequence and the IoT terminal information is one of offline device injection and remote component injection.

[0039] Offline device injection can set the random sequence and the IoT terminal information in the quantum key management center in advance to ensure that it has the necessary functions and configurations, reducing the subsequent setup work and improving the security and stability of the device. Remote component injection injects the random sequence and the IoT terminal information into the quantum key management center remotely without directly physically accessing the device, which can not only provide the ability for continuous maintenance, update, and function enhancement, but also significantly reduce the operation and maintenance costs.

[0040] Optionally, the IoT terminal further includes a data encryption module, and the data encryption module is communicatively connected to the key management server and the IoT terminal management platform respectively;

[0041] If the identity authentication is successful, the steps of encrypting the data in the communication request with a symmetric session key and then sending it to the Internet of Things terminal management platform include:

[0042] The data encryption module calls quantum true random numbers from the quantum true random chip as the symmetric session key;

[0043] Perform algorithm encryption on the collected data according to the symmetric session key to generate symmetric session key data;

[0044] Send the symmetric session key data to the device data management center;

[0045] Encrypt the symmetric session key according to the prefabricated key to generate an encrypted symmetric session key;

[0046] Send the encrypted symmetric session key to the quantum key management center.

[0047] In the above steps of data transmission encryption, quantum true random numbers are used as the symmetric session key, an Internet of Things one-time pad communication architecture is designed, and the symmetric session key is encrypted according to the prefabricated key, so that even if the data is intercepted during the transmission process, it is difficult to crack without the key, and while ensuring the security of the Internet of Things, it has a low bus load rate.

[0048] Optionally, after sending the encrypted symmetric session key to the quantum key management center, the method further includes:

[0049] The quantum key management center decrypts the encrypted symmetric session key according to the prefabricated key to obtain the symmetric session key;

[0050] Store the symmetric session key in the key management module;

[0051] The device data management center sends a decryption data instruction to the quantum key management center;

[0052] The quantum key management center decrypts the symmetric session key data according to the decryption data instruction and the symmetric session key to obtain the data.

[0053] The above method uses the prefabricated key to decrypt the encrypted symmetric session key, ensuring that only the authorized quantum key management center can access the symmetric session key and preventing unauthorized access; controls the decryption process through the decryption data instruction to ensure the legality and compliance of the decryption operation, and only the verified instruction can trigger the decryption. Centralizing the storage of the symmetric session key in the key management module facilitates key management and improves the efficiency of key use.

[0054] Optionally, after sending the encrypted symmetric session key to the quantum key management center, the method further includes:

[0055] The data encryption module again calls quantum true random numbers from the quantum true random chip as the current symmetric session key;

[0056] Performs algorithm encryption on the collected data according to the current symmetric session key to generate the current symmetric session key data;

[0057] Sends the current symmetric session key data to the device data management center;

[0058] Encrypts the current symmetric session key according to the previous symmetric session key to generate the current encrypted symmetric session key;

[0059] Sends the current encrypted symmetric session key to the quantum key management center.

[0060] In the subsequent identity authentication process, the above method can be used. The data encryption module re - calls quantum true random numbers as the current symmetric session key, and replaces the pre - set key with the previous symmetric session key to encrypt the current symmetric session key, so as to improve the security of encryption.

[0061] Optionally, after sending the current encrypted symmetric session key to the quantum key management center, the method further includes:

[0062] The quantum key management center decrypts the current encrypted symmetric session key according to the previous symmetric session key to generate the current symmetric session key;

[0063] Stores the current symmetric session key in the key management module;

[0064] The device data management center sends a decryption data instruction to the quantum key management center;

[0065] The quantum key management center decrypts the current symmetric session key data according to the decryption data instruction and the current symmetric session key to obtain the data.

[0066] The quantum key management center can update the symmetric session key correspondingly according to the quantum true random numbers called by the data encryption module from the quantum true random chip each time, and save the data through the device data management center to improve the security of encryption.

[0067] As can be seen from the above technical solutions, the present application provides an Internet of Things (IoT) terminal quantum fusion 5G encryption method, which is applied to an IoT terminal quantum fusion 5G encryption system. The system includes an IoT terminal and an IoT terminal management platform. A quantum true random number chip is provided in the IoT terminal for generating quantum true random numbers and random sequences. The method includes: establishing a communication connection between the IoT terminal and the IoT terminal management platform according to a communication request, wherein the communication connection is established using a frequency hopping sequence, and the frequency hopping sequence is obtained based on the quantum true random number generated corresponding to the communication request; authenticating the identity of the IoT terminal sending the communication request using a prefabricated key, wherein the prefabricated key is a random sequence stored in the IoT terminal management platform; if the identity authentication is successful, encrypting the data in the communication request using a symmetric session key and then sending it to the IoT terminal management platform, wherein the symmetric session key is the quantum true random number called by the IoT terminal after successful identity authentication, so as to solve the problems of high power consumption and low processing efficiency in IoT terminal encryption while ensuring security. BRIEF DESCRIPTION OF THE DRAWINGS

[0068] In order to more clearly illustrate the technical solutions of the present application, the accompanying drawings required for the embodiments will be briefly introduced below. Obviously, for those of ordinary skill in the art, other drawings can also be obtained based on these drawings without creative efforts.

[0069] Figure 1 It is a flowchart of the IoT terminal quantum fusion 5G encryption method described in the embodiments of the present application;

[0070] Figure 2 It is a flowchart of communication link encryption in the IoT terminal quantum fusion 5G encryption method described in the embodiments of the present application;

[0071] Figure 3 It is a flowchart of identity authentication protection in the IoT terminal quantum fusion 5G encryption method described in the embodiments of the present application;

[0072] Figure 4 It is a flowchart of authenticating identity through a prefabricated key and IoT terminal information in the IoT terminal quantum fusion 5G encryption method described in the embodiments of the present application;

[0073] Figure 5 It is a flowchart of data transmission encryption in the IoT terminal quantum fusion 5G encryption method described in the embodiments of the present application. DETAILED DESCRIPTION OF THE EMBODIMENTS

[0074] Embodiments will be described in detail below, and examples thereof are shown in the accompanying drawings. When the following description refers to the accompanying drawings, unless otherwise indicated, the same numbers in different drawings represent the same or similar elements. The embodiments described in the following examples do not represent all embodiments consistent with the present application. They are only examples of systems and methods consistent with some aspects of the present application.

[0075] To solve the problem that the encryption of Internet of Things (IoT) terminals has high power consumption and low processing efficiency while ensuring security, refer to Figure 1 , an embodiment of the present application provides an IoT terminal quantum fusion 5G encryption method, which is applied to an IoT terminal quantum fusion 5G encryption system. The system includes an IoT terminal and an IoT terminal management platform; a quantum true random number chip is provided in the IoT terminal for generating quantum true random numbers and random sequences.

[0076] It should be understood that the quantum true random number chip is provided in the IoT terminal, which can improve the security of the key and prevent the situation where the information security of all relevant IoT terminals fails due to the attack on the IoT terminal management platform.

[0077] The method includes:

[0078] S100: Establish a communication connection between the IoT terminal and the IoT terminal management platform according to a communication request.

[0079] Among them, the communication connection is established using a frequency hopping sequence; the frequency hopping sequence is obtained based on the quantum true random number generated corresponding to the communication request.

[0080] S200: Authenticate the IoT terminal that sends the communication request using a prefabricated key.

[0081] Among them, the prefabricated key is a random sequence stored in the IoT terminal management platform.

[0082] S300: If the authentication is successful, encrypt the data in the communication request using a symmetric session key and send it to the IoT terminal management platform.

[0083] Among them, the symmetric session key is the quantum true random number called by the IoT terminal after the authentication is successful.

[0084] It should be understood that a quantum true random number chip is a miniature electronic device that generates true random numbers based on the principles of quantum mechanics. It uses integrated circuit technology to integrate complex quantum components and functions into a small chip, which can reduce power consumption and size while ensuring high performance, so as to realize the interaction needs of IoT big data based on 5G communication technology. By applying quantum true random number chips to the 5G frequency hopping communication solution of the IoT, using quantum true random numbers as frequency hopping sequences, and using 5G frequency hopping technology to improve the spectrum utilization and anti-interference capabilities of IoT device communications, and using quantum true random number chips to solve the forward security risks of IoT communication frequency modulation channels, the problem of high power consumption and low processing efficiency in IoT terminal encryption while ensuring security can be solved.

[0085] In some embodiments, the IoT terminal is further provided with a 5G communication module and a key management server, and the key management server is respectively connected to the 5G communication module and the quantum true random number chip; the IoT terminal management platform includes a device data management center and a quantum key management center, and the 5G communication module is connected to the device data management center and the quantum key management center through a 5G base station;

[0086] See also Figure 2 The steps of establishing a communication connection between the IoT terminal and the IoT terminal management platform according to the communication request include:

[0087] S110: The 5G communication module sends a key request to the key management server.

[0088] It should be understood that before the 5G communication module sends a key request to the key management server, it is necessary to determine whether the 5G communication module initiates communication with the 5G base station. If no communication is initiated to the 5G base station, the 5G communication module needs to initiate a communication request to the 5G base station.

[0089] S120: The key management server obtains a quantum true random number from the quantum true random number chip according to the key request to generate a key.

[0090] S130: Sending a key to the 5G communication module for determining a frequency hopping sequence for establishing communication with the 5G base station.

[0091] It should be understood that due to the high unpredictability and randomness of quantum true random numbers, the use of key-determined frequency hopping sequences can greatly increase the difficulty of communication cracking, more effectively avoid interference, help the system better adapt to environmental changes, and maintain the stability and reliability of communications.

[0092] S140: The 5G communication module transmits a frequency hopping signal to the 5G base station according to the key.

[0093] It should be understood that the frequency-hopping signal is a signal that uses frequency-hopping technology for communication, and the frequency-hopping signal in the embodiments of the present application is provided with Internet of Things terminal data.

[0094] S150: The 5G base station receives the frequency-hopping signal by using a synchronized frequency-hopping sequence, and demodulates and processes the frequency-hopping signal to generate Internet of Things terminal data.

[0095] It should be understood that the Internet of Things terminal data includes Internet of Things terminal registration request data and communication request data. Specifically, it can be connection requests, identity authentication information, protocols and configuration information, keys, destination addresses, etc., to ensure the effective establishment of a communication link.

[0096] S160: Forward the Internet of Things terminal data according to the destination address to establish a communication link.

[0097] It should be understood that the destination address includes the address of the device data management center and the address of the quantum key management center. When this communication ends, the role of the frequency-hopping sequence also ends accordingly.

[0098] In the above steps of encrypting the communication link, by obtaining quantum true random numbers from the quantum true random number chip to generate keys, and transmitting frequency-hopping signals to the 5G base station according to the keys, the difficulty of communication being cracked can be greatly increased, the anti-interference ability and anti-predictability of the communication link can be enhanced, helping the system to better adapt to environmental changes, and maintaining the stability and reliability of communication. The 5G base station receives the frequency-hopping signal by using a synchronized frequency-hopping sequence, and demodulates and processes the frequency-hopping signal to generate Internet of Things terminal data, ensuring the integrity and security of the data during transmission, and effectively preventing the data from being tampered with or stolen during transmission.

[0099] In some embodiments, the step of the 5G communication module transmitting a frequency-hopping signal to the 5G base station according to the key includes:

[0100] The 5G communication module synchronizes the frequency with the 5G base station so that the clock of the 5G communication module is consistent with the network clock.

[0101] Select a channel according to the current network conditions and resource allocation for communication with the 5G base station.

[0102] Modulate and process the Internet of Things terminal data according to the key to generate a frequency-hopping signal.

[0103] Transmit the frequency-hopping signal to the 5G base station through the antenna.

[0104] The 5G communication module can improve the stability and reliability of communication through frequency synchronization, optimize the performance of the communication link through channel selection, increase the data transmission rate and reduce latency; enhance the security and anti-interference ability of communication through key modulation processing to achieve long-distance and high-rate data transmission.

[0105] In some embodiments, the Internet of Things terminal is further provided with an identity authentication module, and the identity authentication module is communicatively connected to the key management server and the Internet of Things terminal management platform respectively;

[0106] See Figure 3 , the steps of using the pre-shared key to authenticate the identity of the Internet of Things terminal sending the communication request include:

[0107] S210: The quantum key management center registers the Internet of Things terminal according to the Internet of Things terminal registration request to obtain a random sequence and Internet of Things terminal information.

[0108] It should be understood that a device registration module is provided in the quantum key management center for registering the Internet of Things terminal according to the Internet of Things terminal registration request.

[0109] S220: Store the random sequence as a pre-shared key in the key management module of the quantum key management center.

[0110] It should be understood that the key management module is used to strictly control and manage each link of the key from generation to destruction. By adopting security measures and technical means such as auditing and monitoring, the security and reliability of the key can be effectively guaranteed, thereby maintaining the overall security of the system.

[0111] S230: The identity authentication module authenticates the identity through the pre-shared key and the Internet of Things terminal information.

[0112] It should be understood that the random sequence can be obtained from the quantum true random number chip in advance to generate quantum true random numbers, so that the pre-shared key has extremely high randomness and unpredictability, thereby enhancing the security and reliability of the system.

[0113] In the above steps of identity authentication protection, by registering the Internet of Things terminal in the quantum key management center in advance and allocating a pre-shared key, identity authentication can be performed immediately when the device first accesses the network, reducing the device configuration time; the pre-shared key is stored in the key management module, effectively preventing the pre-shared key from being intercepted or tampered with during transmission; the identity authentication module authenticates the identity through the pre-shared key and the Internet of Things terminal information, greatly reducing the risk of illegal access.

[0114] In some embodiments, see Figure 4, the steps for the identity authentication module to authenticate the identity through the pre - configured key and the Internet of Things terminal information include:

[0115] S231: The quantum key management center processes the Internet of Things terminal information using a hash function to generate a message authentication code.

[0116] It should be understood that a hash function is a function that maps input data of any length to output data of a fixed length and is suitable for verifying data integrity.

[0117] S232: Encrypt the message authentication code according to the pre - configured key to generate an encrypted message authentication code. S233: Send the encrypted message authentication code to the identity authentication module.

[0118] It should be understood that when the Internet of Things terminal makes a communication request, the legitimacy of the identity is authenticated based on whether the encrypted message authentication code sent by the Internet of Things terminal management platform has the correct pre - configured key.

[0119] S234: The identity authentication module decrypts the encrypted message authentication code according to the pre - configured key to obtain the message authentication code.

[0120] S235: Verify the Internet of Things terminal information of itself and the message authentication code using a hash function to authenticate the identity.

[0121] It should be understood that if the hash function verification is successful, it indicates that the identity authentication is successful and data communication can be carried out; if the hash function verification fails, it indicates that the identity authentication fails and the pre - set key and the Internet of Things terminal information do not match the registered ones.

[0122] During an Internet of Things communication request, by applying a hash function and a pre - configured key for double - verification between the quantum key management center and the identity authentication module, not only can the efficiency of identity authentication be improved, but also the accuracy and security of authentication can be enhanced.

[0123] In some embodiments, the way to obtain the random sequence and the Internet of Things terminal information is one of offline device injection and remote component injection.

[0124] It should be understood that offline device injection refers to a technology of pre-implanting necessary data, firmware or configuration information into the device. Random sequences and Internet of Things (IoT) terminal information can be set in the quantum key management center in advance to ensure that it has the necessary functions and configurations, reduce subsequent setup work, and improve the security and stability of the device. Remote component injection is a technology for remotely updating and injecting data in IoT devices. Injecting random sequences and IoT terminal information into the quantum key management center remotely, without directly physically accessing the device, can not only provide the ability for continuous maintenance, update and function enhancement, but also significantly reduce the operation and maintenance costs.

[0125] In some embodiments, the IoT terminal further includes a data encryption module, and the data encryption module is communicatively connected to the key management server and the IoT terminal management platform respectively;

[0126] See Figure 5 , if the identity authentication is successful, the steps of encrypting the data in the communication request with the symmetric session key and then sending it to the IoT terminal management platform include:

[0127] S310: The data encryption module calls a quantum true random number from the quantum true random chip as the symmetric session key.

[0128] It should be understood that the data encryption module can send a call request to the key management server, and the key management server calls a quantum true random number from the quantum true random chip as the symmetric session key.

[0129] S320: Algorithmically encrypt the collected data according to the symmetric session key to generate symmetric session key data.

[0130] S330: Send the symmetric session key data to the device data management center.

[0131] It should be understood that a secure storage module is provided in the device data management center, which can save the data collected by the IoT terminal.

[0132] S340: Encrypt the symmetric session key according to the prefabricated key to generate an encrypted symmetric session key.

[0133] S350: Send the encrypted symmetric session key to the quantum key management center.

[0134] In the above steps of data transmission encryption, quantum true random numbers are used as the symmetric session key, an Internet of Things one-time pad communication architecture is designed, and the symmetric session key is encrypted according to the prefabricated key, so that even if the data is intercepted during the transmission process, it is difficult to crack without the key, and while ensuring the security of the Internet of Things, it has a low bus load rate.

[0135] In some embodiments, referring to Figure 5 , after sending the encrypted symmetric session key to the quantum key management center, the method further includes:

[0136] S360: The quantum key management center decrypts the encrypted symmetric session key according to the prefabricated key to obtain the symmetric session key.

[0137] S370: Store the symmetric session key in the key management module.

[0138] S380: The device data management center sends a decryption data instruction to the quantum key management center.

[0139] It should be understood that an instruction control module is provided in the device data management center, which can generate a decryption data instruction to control the quantum key management center.

[0140] S390: The quantum key management center decrypts the symmetric session key data according to the decryption data instruction and the symmetric session key to obtain the data.

[0141] The above method uses the prefabricated key to decrypt the encrypted symmetric session key, ensuring that only the authorized quantum key management center can access the symmetric session key and preventing unauthorized access; the decryption process is controlled by the decryption data instruction to ensure the legality and compliance of the decryption operation, and only the verified instruction can trigger the decryption. The symmetric session keys are centrally stored in the key management module, which is convenient for key management and improves the efficiency of key use.

[0142] In some embodiments, after sending the encrypted symmetric session key to the quantum key management center, the method further includes:

[0143] The data encryption module again calls quantum true random numbers from the quantum true random chip as the current symmetric session key.

[0144] Encrypt the collected data according to the current symmetric session key to generate the current symmetric session key data.

[0145] Send the current symmetric session key data to the device data management center.

[0146] Encrypt the current symmetric session key according to the previous symmetric session key to generate the current encrypted symmetric session key.

[0147] Send the current encrypted symmetric session key to the quantum key management center.

[0148] In the subsequent identity authentication process, the data encryption module can re - call the quantum true random number as the current symmetric session key, and replace the pre - configured key with the previous symmetric session key to encrypt the current symmetric session key, so as to enhance the security of encryption.

[0149] In some embodiments, after sending the current encrypted symmetric session key to the quantum key management center, the method further includes:

[0150] The quantum key management center decrypts the current encrypted symmetric session key according to the previous symmetric session key to generate the current symmetric session key.

[0151] Store the current symmetric session key in the key management module.

[0152] The device data management center sends a decryption data instruction to the quantum key management center.

[0153] The quantum key management center decrypts the current symmetric session key data according to the decryption data instruction and the current symmetric session key to obtain the data.

[0154] The quantum key management center can update the symmetric session key correspondingly according to the quantum true random number called by the data encryption module from the quantum true random chip each time, and save the data through the device data management center to enhance the security of encryption.

[0155] In some embodiments, the method for the device data management center to communicate with the Internet of Things terminal is the same as the communication steps described in the above embodiments, and will not be repeated here. Therefore, each time the Internet of Things terminal performs fusion data transmission communication, 3 quantum true random numbers will be used, which are respectively applied to the establishment of the Internet of Things terminal communication link, identity authentication protection, and data transmission encryption.

[0156] As can be seen from the above technical solutions, the embodiments of the present application provide an Internet of Things (IoT) terminal quantum fusion 5G encryption method, which is applied to an IoT terminal quantum fusion 5G encryption system. The system includes an IoT terminal and an IoT terminal management platform; a quantum true random number chip is provided in the IoT terminal for generating quantum true random numbers and random sequences; the method includes: establishing a communication connection between the IoT terminal and the IoT terminal management platform according to a communication request, wherein the communication connection is established using a frequency hopping sequence; the frequency hopping sequence is obtained based on the quantum true random number corresponding to the communication request; authenticating the identity of the IoT terminal sending the communication request using a prefabricated key, wherein the prefabricated key is a random sequence stored in the IoT terminal management platform; if the identity authentication is successful, encrypting the data in the communication request using a symmetric session key and sending it to the IoT terminal management platform, wherein the symmetric session key is the quantum true random number called by the IoT terminal after the identity authentication is successful, so as to solve the problems of high power consumption and low processing efficiency in IoT terminal encryption while ensuring security.

[0157] For the similarities between the embodiments provided in the present application, reference can be made to each other. The specific embodiments provided above are only several examples under the general concept of the present application and do not constitute a limitation on the protection scope of the present application. For those skilled in the art, any other embodiments extended based on the solution of the present application without creative efforts belong to the protection scope of the present application.

Claims

1. An Internet of Things terminal quantum fusion 5G encryption method, characterized in that Quantum Fusion 5G Encryption System Applied to Internet of Things Terminals, the system includes Internet of Things terminals and an Internet of Things terminal management platform; A quantum true random number chip is provided in the Internet of Things terminal for generating quantum true random numbers and random sequences; the method includes: Establish a communication connection between the Internet of Things terminal and the Internet of Things terminal management platform according to a communication request, wherein the communication connection is established using a frequency hopping sequence; the frequency hopping sequence is obtained based on the quantum true random number generated corresponding to the communication request; Authenticate the Internet of Things terminal that sends the communication request using a prefabricated key, wherein the prefabricated key is a random sequence stored in the Internet of Things terminal management platform; If the identity authentication is successful, encrypt the data in the communication request using a symmetric session key and send it to the Internet of Things terminal management platform, wherein the symmetric session key is the quantum true random number called by the Internet of Things terminal after the identity authentication is successful; A 5G communication module and a key management server are further provided in the Internet of Things terminal, and the key management server is communicatively connected to the 5G communication module and the quantum true random number chip respectively; the Internet of Things terminal management platform includes a device data management center and a quantum key management center, and the 5G communication module is communicatively connected to the device data management center and the quantum key management center through a 5G base station; The steps of establishing a communication connection between the Internet of Things terminal and the Internet of Things terminal management platform according to a communication request include: The 5G communication module sends a key request to the key management server; The key management server obtains quantum true random numbers from the quantum true random number chip according to the key request to generate keys; Send the key to the 5G communication module for determining a frequency hopping sequence for establishing communication with the 5G base station; The 5G communication module transmits a frequency hopping signal to the 5G base station according to the key; The 5G base station receives the frequency hopping signal using the synchronized frequency hopping sequence and demodulates the frequency hopping signal to generate Internet of Things terminal data; the Internet of Things terminal data includes Internet of Things terminal registration request data and communication request data; Forward the Internet of Things terminal data according to the destination address to establish a communication link; the destination address includes the address of the device data management center and the address of the quantum key management center.

2. The quantum fusion 5G encryption method for the Internet of Things terminal according to claim 1, characterized in that, The steps of the 5G communication module transmitting a frequency hopping signal to the 5G base station according to the key include: The 5G communication module synchronizes the frequency with the 5G base station so that the clock of the 5G communication module is consistent with the network clock; Select a channel according to the current network condition and resource allocation for communicating with the 5G base station; Modulate and process the Internet of Things terminal data according to the key to generate a frequency hopping signal; Transmit the frequency hopping signal to the 5G base station through an antenna.

3. The quantum fusion 5G encryption method for the Internet of Things terminal according to claim 1, characterized in that The Internet of Things terminal is further provided with an identity authentication module, and the identity authentication module is communicatively connected to the key management server and the Internet of Things terminal management platform respectively; The steps of authenticating the Internet of Things terminal that sends the communication request using a prefabricated key include: The quantum key management center registers the Internet of Things (IoT) terminal according to the IoT terminal registration request to obtain a random sequence and IoT terminal information; The random sequence is stored as a prefabricated key in the key management module of the quantum key management center; The identity authentication module authenticates the identity through the prefabricated key and the IoT terminal information.

4. The quantum fusion 5G encryption method for the Internet of Things terminal according to claim 3, characterized in that, The steps for the identity authentication module to authenticate the identity through the prefabricated key and the IoT terminal information include: The quantum key management center processes the IoT terminal information using a hash function to generate a message authentication code; Encrypt the message authentication code according to the prefabricated key to generate an encrypted message authentication code; Send the encrypted message authentication code to the identity authentication module; The identity authentication module decrypts the encrypted message authentication code according to the prefabricated key to obtain the message authentication code; Verify the identity by performing a hash function verification on its own IoT terminal information and the message authentication code.

5. The quantum fusion 5G encryption method for the Internet of Things terminal according to claim 3, wherein The method for obtaining the random sequence and IoT terminal information is one of offline device injection and remote component injection.

6. The quantum fusion 5G encryption method for the Internet of Things terminal according to claim 3, wherein The IoT terminal further includes a data encryption module, which is communicatively connected to the key management server and the IoT terminal management platform respectively; If the identity authentication is successful, the step of encrypting the data in the communication request using a symmetric session key and then sending it to the IoT terminal management platform includes: The data encryption module calls a quantum true random number from the quantum true random chip as the symmetric session key; Encrypt the collected data according to the symmetric session key using an algorithm to generate symmetric session key data; Send the symmetric session key data to the device data management center; Encrypt the symmetric session key according to the prefabricated key to generate an encrypted symmetric session key; Send the encrypted symmetric session key to the quantum key management center.

7. The quantum fusion 5G encryption method for the Internet of Things terminal according to claim 6, wherein, After sending the encrypted symmetric session key to the quantum key management center, the method further includes: The quantum key management center decrypts the encrypted symmetric session key according to the prefabricated key to obtain the symmetric session key; Store the symmetric session key in the key management module; The device data management center sends a decryption data instruction to the quantum key management center; The quantum key management center decrypts the symmetric session key data according to the decryption data instruction and the symmetric session key to obtain the data.

8. The quantum fusion 5G encryption method for the Internet of Things terminal according to claim 7, wherein, After sending the encrypted symmetric session key to the quantum key management center, the method further includes: The data encryption module calls a quantum true random number from the quantum true random chip again as the current symmetric session key; Encrypt the collected data according to the current symmetric session key using an algorithm to generate the current symmetric session key data; Send the current symmetric session key data to the device data management center; Encrypt the current symmetric session key according to the previous symmetric session key to generate the current encrypted symmetric session key; Send the current encrypted symmetric session key to the quantum key management center.

9. The quantum fusion 5G encryption method for the Internet of Things terminal according to claim 8, characterized in that, After sending the current encrypted symmetric session key to the quantum key management center, the method further includes: The quantum key management center decrypts the current encrypted symmetric session key according to the previous symmetric session key to generate the current symmetric session key; Store the current symmetric session key in the key management module; The device data management center sends a decryption data instruction to the quantum key management center; The quantum key management center decrypts the current symmetric session key data according to the decryption data instruction and the current symmetric session key to obtain the data.

Citation Information

Patent Citations

  • Security verification method and device under cloud architecture, and electronic equipment

    CN112989388A

  • Method, system and equipment for enhancing MQTT protocol identity authentication by using symmetric cryptographic technology

    CN113612605A