Method for accessing a quantum network and secure capability access gateway

By introducing a secure access gateway into the quantum network, authentication and access to the access network middleware platform is realized, the problem that the quantum network does not support access to other network devices is solved, secure access to the access network and call to quantum services is realized, and the integration of QKD technology and other technologies is promoted.

CN118900185BActive Publication Date: 2025-05-27CAS QUANTUM NETWORK CO LTD
View PDF 3 Cites 0 Cited by

Patent Information

Application Number
CN202311832591.4
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2023-12-27
Publication Date
2025-05-27
Estimated Expiration
2043-12-27

AI Technical Summary

Technical Problem

The existing quantum network does not support access to equipment in other networks, resulting in users on the access network being unable to use the quantum-related services provided by the quantum network.

Method used

Provide a method and security capability access gateway to access the quantum network, and realize authentication and access of the middleware platform by receiving network access requests initiated by the middleware platform of the access network, comparing device information with pre-stored authentication information in the quantum network, and realizing authentication and access of the middleware platform.

Benefits of technology

The access network outside the quantum network is connected to the quantum network, ensuring that the security of the access network meets the security requirements of the quantum network, which is conducive to the integration of QKD technology and other technologies.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN118900185B_ABST
    Figure CN118900185B_ABST
Patent Text Reader

Abstract

Embodiments of the present application relate to the field of quantum information technology, and disclose a method for accessing a quantum network and a security capability access gateway. The method for accessing a quantum network, which is applicable to a security capability access gateway, includes: receiving a first network access request initiated by a middleware platform of an access network, where the first network access request carries device information of the middleware platform that initiates the first network access request; comparing the device information carried in the first network access request with first information, where the first information is information pre-stored in the quantum network for authenticating the middleware platform; if the device information carried in the first network access request passes the comparison with the first information, issuing a token to the middleware platform that initiates the first network access request to access the quantum network. It can connect an access network outside the quantum network to the quantum network.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The embodiments of the present application relate to the field of quantum information technology, and in particular to a method for accessing a quantum network and a security capability access gateway. Background Art

[0002] Quantum information technology is based on the principles of quantum mechanics. It is a new information processing method that realizes information perception, calculation and transmission through the preparation, regulation and observation of physical states in microscopic quantum systems. It includes quantum computing, quantum communication and quantum measurement. It can be combined with other technologies to provide quantum-related services for other technologies, such as the integration of quantum key distribution (QKD) technology and information and communications technology (ICT).

[0003] However, the quantum network (QKD network and Q-HSCS (a service network built by a harmonized security management platform (HSCM) and a security execution module (SEM)), referred to as the "quantum network") currently provided by quantum technology service providers does not support access by devices in other networks (such as peer-to-peer networks, hereinafter referred to as "access networks"), and users on the access network side cannot use the various quantum-related services provided by the quantum network. Summary of the invention

[0004] The embodiments of the present application provide a method for accessing a quantum network and a security capability access gateway, which at least facilitates accessing an access network outside the quantum network to the quantum network.

[0005] According to some embodiments of the present application, on the one hand, embodiments of the present application provide a method for accessing a quantum network, which is applicable to a security capability access gateway, including: receiving a first network access request initiated by a middleware platform of the access network, the first network access request carrying device information of the middleware platform that initiated the first network access request; comparing the device information carried by the first network access request with the first information, wherein the first information is information pre-stored in the quantum network for authenticating the middleware platform; if the device information carried by the first network access request passes the comparison with the first information, issuing a token to the middleware platform that initiated the first network access request to connect the middleware platform that initiated the first network access request to the quantum network.

[0006] According to some embodiments of the present application, on the other hand, the embodiments of the present application further provide a security capability access gateway, comprising: at least one processor; and a memory communicatively connected to the at least one processor; wherein the memory stores instructions executable by the at least one processor, and the instructions are executed by the at least one processor so that the at least one processor can execute the method for accessing a quantum network provided in any embodiment of the present application.

[0007] According to some embodiments of the present application, on the other hand, embodiments of the present application further provide an access system, including: a security capability access gateway provided by any embodiment of the present application.

[0008] According to some embodiments of the present application, on the other hand, the embodiments of the present application further provide a computer-readable non-volatile storage medium that stores computer program instructions. When the computer executes the program instructions, the method for accessing a quantum network provided in any embodiment of the present application is executed.

[0009] The technical solution provided by the embodiment of the present application has at least the following advantages: when the middleware platform on the access network side wants to access the quantum network, it initiates a first network access request to the security capability access gateway, so that the security capability access gateway can compare the device information of the middleware platform carried in the first network access request with the first information pre-stored in the quantum network for authenticating the middleware platform, thereby authenticating the middleware platform. By authenticating the middleware platform, it is ensured that its security meets the security requirements of the quantum network, so that the middleware platform is allowed to access the quantum network as a secure network, thereby realizing the access of access networks outside the quantum network to the quantum network, which is conducive to the integration of QKD technology with other technologies. BRIEF DESCRIPTION OF THE DRAWINGS

[0010] One or more embodiments are exemplarily described by pictures in the corresponding drawings, and these exemplified descriptions do not constitute limitations on the embodiments. Elements with the same reference numerals in the drawings represent similar elements, and unless otherwise stated, the figures in the drawings do not constitute proportional limitations.

[0011] Figure 1 is a schematic diagram of the structure of the quantum network provided in the embodiments of the present application;

[0012] Figure 2 It is a structural diagram of a security capability access gateway provided in an embodiment of the present application;

[0013] Figure 3 It is a schematic diagram of another structure of a security capability access gateway provided in an embodiment of the present application and its application scenario;

[0014] Figure 4Schematic diagram of the OSA architecture of the access sub-gateway in the security capability access gateway provided in the embodiment of the present application;

[0015] Figure 5 is a flow chart of a method for accessing a quantum network provided in an embodiment of the present application;

[0016] Figure 6 is another flow chart of the method for accessing a quantum network provided in an embodiment of the present application;

[0017] Figure 7 is another flow chart of the method for accessing a quantum network provided in an embodiment of the present application;

[0018] Figure 8 is another flow chart of the method for accessing a quantum network provided in an embodiment of the present application;

[0019] Fig. 9 This is another flow chart of the method for accessing a quantum network provided in an embodiment of the present application. DETAILED DESCRIPTION

[0020] To make the purpose, technical scheme and advantages of the embodiments of the present application clearer, the embodiments of the present application will be described in detail below in conjunction with the accompanying drawings. However, it will be appreciated by those skilled in the art that in the present application, many technical details are proposed in order to enable the reader to better understand the present application. However, even without these technical details and various changes and modifications based on the following embodiments, the technical scheme claimed in the present application can also be implemented. The division of the following embodiments is for the convenience of description, and the specific implementation of the present application should not be construed as any limitation, and the various embodiments can be combined and referenced with each other under the premise of no contradiction.

[0021] It should be noted that the terms "first", "second", etc. in the specification and claims of the present application and the above-mentioned drawings are used to distinguish similar objects, and are not necessarily used to describe a specific order or sequence. It should be understood that the data used in this way can be interchangeable where appropriate, so that the embodiments of the present application described herein can be implemented in an order other than those illustrated or described herein. In addition, the terms "including" and "having" and any of their variations are intended to cover non-exclusive inclusions, for example, a process, method, system, product or device comprising a series of steps or units is not necessarily limited to those steps or units clearly listed, but may include other steps or units that are not clearly listed or inherent to these processes, methods, products or devices.

[0022] To better illustrate the embodiments of the present application, a brief description of the quantum network side and the access network side is first given. In some embodiments, the architecture of the quantum network side is as follows: Figure 1As shown, it includes a converged security management platform (HSCM), a security execution module (SEM) and a quantum key distribution network (or QKD network). The converged security management platform is a management device: it is used to manage the security execution module and is the central management platform of the security execution module. It is responsible for, for example, user, device, network management, network management, and billing management, and has an interconnection unit (multiple converged security management platforms can form a converged security management platform network). The security execution module is a cryptographic operation device for data encryption and decryption, such as key generation / storage, digital signature / signature verification, identity authentication, data encryption / decryption, random numbers, and key management capabilities. It can connect to the business system and encrypt and decrypt the business system data. The QKD network distributes quantum key vectors to the security execution module through the key management terminal (Key Management Terminal, KMT). Different QKD local area networks are interconnected through the QKD backbone network, and different key management terminals maintain quantum keys through (Key Management Service, KMS).

[0023] Similar to the architecture of the quantum network side, the access network side includes: a middleware platform with similar functions to the integrated security management platform, a security engine with similar functions to the security execution module, and a quantum key distribution network (or QKD network). The middleware platform is a management device: it is used to manage the security engine and is the central management platform of the security engine. It is responsible for, for example, user, device, network management, network management, billing management, and has an interconnection unit. The security engine is a cryptographic computing device for data encryption and decryption. For example, it has key generation / storage, digital signature / signature verification, identity authentication, data encryption / decryption, random numbers, and key management capabilities. It can connect to the business system and encrypt and decrypt the business system data. The QKD network distributes quantum key vectors to the security engine through the key management terminal.

[0024] Generally speaking, the communication initiator and the communication recipient will complete the negotiation and acquisition of symmetric quantum keys through the QKD network to perform encrypted communication based on the negotiated symmetric quantum keys. When the communication initiator is located on the quantum network side and the communication recipient is located in a network outside the quantum network side, the communication initiator and the communication recipient cannot negotiate symmetric keys or call quantum-related services, resulting in the failure of quantum key service calls.

[0025] To this end, the embodiment of the present application provides a security capability access gateway, which can better connect devices, users, platforms, etc. on the access network side (any network except the current quantum network side) to the quantum network, and connect the access network side and the quantum network, so that the communication initiator on the access network side can use the services provided by the quantum network. Regarding the security capability access gateway provided by the embodiment of the present application, in some embodiments, its structure can be as follows Figure 2As shown, it includes: at least one processor 201; and a memory 202 that is communicatively connected to the at least one processor 201; wherein the memory 202 stores instructions that can be executed by the at least one processor 201, and the instructions are executed by the at least one processor 201 so that the at least one processor 201 can execute the method for accessing a quantum network provided in an embodiment of the present application.

[0026] The memory 202 and the processor 201 are connected in a bus manner, and the bus may include any number of interconnected buses and bridges, and the bus connects various circuits of one or more processors 201 and the memory 202 together. The bus can also connect various other circuits such as peripheral devices, voltage regulators, and power management circuits, which are well known in the art and are therefore not further described herein. The bus interface provides an interface between the bus and the transceiver. The transceiver can be one element or multiple elements, such as multiple receivers and transmitters, providing a unit for communicating with various other devices on a transmission medium. The data processed by the processor 201 is transmitted on a wireless medium via an antenna, and further, the antenna also receives data and transmits the data to the processor 201.

[0027] The processor 201 is responsible for managing the bus and general processing, and can also provide various functions, including timing, peripheral interfaces, voltage regulation, power management and other control functions. The memory 202 can be used to store data used by the processor 201 when performing operations.

[0028] It can be understood that the security capability access gateway provides the ability to connect devices, users, platforms, etc. in the access network side (or simply referred to as the access network) to the quantum network side (or simply referred to as the service network). Therefore, the security capability access gateway involves both docking with the access network and docking with the service network. Furthermore, in some embodiments, such as Figure 3 As shown, the security capability access gateway can also logically include: a security sub-gateway 301 and an access sub-gateway 302. Among them, the security sub-gateway 301 provides the relevant functions of connecting with the access network; the access sub-gateway 302 provides the function of connecting with the service network, and the security sub-gateway 301 and the access sub-gateway 302 are both managed by the service network.

[0029] It should be noted that all modules involved in this embodiment are logical modules. In actual applications, a logical unit can be a physical unit, a part of a physical unit, or a combination of multiple physical units. In addition, in order to highlight the innovative part of this application, this embodiment does not introduce units that are not closely related to solving the technical problems raised by this application, but this does not mean that there are no other units in this embodiment. In some examples, the security sub-gateway 301 acts as a firewall, implements access control and multi-user logical isolation according to its strategy, and can perform bidirectional network address translation (NAT), that is, Figure 4 As shown, the security sub-gateway 301 may include a firewall module 311 and a NAT module 321 .

[0030] It can also be understood that the security capability access gateway provides the ability to access the devices, users, platforms, etc. in the access network to the service network, that is, mainly the access network calls the quantum-related services provided by the service network. Therefore, the access sub-gateway 302 connected to the service network will involve different quantum-related services provided by the service network. Based on this, in some examples, the access sub-gateway 302 adopts an open service access (OSA) architecture so that it can flexibly and easily provide relevant functions to the access network when the service content of the service network is expanded. Among them, the OSA architecture provides a framework, so that the access network can access the service network based on the Framework, and manage the access process at the same time, that is, provide service network service access and management capabilities, for example, discover and register the service capabilities in the service capability server of the service network, and manage the registered service capabilities.

[0031] Considering that the security capability access gateway is mainly used to connect the access network to the service network to use the quantum-related services provided by the service network. Therefore, the service network is the service capability server (SCS) in the OSA architecture. And the services of the service network mainly involve user query, customer query, device query, user business query, key status query, key usage record query, user traffic information query and other services. Therefore, the service capability feature (SCF, Service Capability Feature) provided by the access sub-gateway 302 may include at least one of the following: user query, customer query, device query, user service query, key status query, key usage record query, user traffic information query, etc.; accordingly, the API interface provided by the access sub-gateway 302 may include at least one of the following: user query API interface, device query API interface, customer query API interface, user service query API interface, key status query API interface, key usage record API interface and user traffic information query API interface, so that the corresponding services can be opened to the access network for calling through these API interfaces; at the same time, the basic capabilities provided by the access sub-gateway 302 for the access network access service network process include at least one of the following: device authentication, user authentication, protocol conversion, routing addressing, heartbeat management, etc.

[0032] That is, the security capability access gateway can be used as follows Figure 4 The OSA architecture is shown in Figure 1. Figure 4 The operation support system (OSS) / business support system (BSS) is also introduced into the access network and service network to more completely reflect the architecture of the access network and service network. Figure 4 The API interface indicated by the double arrows shows that the access network, the security capability access gateway and the service network communicate with each other by calling the API interface. Figure 4 The network information indicated by the double arrows represents the verification based on network information between the access network and the security gateway, providing a security protection function based on network information. In order to facilitate those skilled in the art to better understand the OSA architecture, it will be explained below.

[0033] User query service is a service that provides user-related information of the access network, where the user-related information may include user number, city identification, customer identification, user name, service number, product code, creation time, effective time, expiration time, payment mode, account number, shutdown lock, status and modification time, etc.

[0034] Customer query service is a service that provides customer-related information of the access network, where the customer-related information may include customer identification, city identification, customer name, abbreviation, encrypted password, customer type, nationality, email, creation time, status, etc.

[0035] Device query service is a service that provides device-related information of the access network. The devices in the service network may include a converged security management platform and a security execution module. Device-related information includes: device name, device ID, manufacturer name, device model, node name, node number, software version, operating status, customer, reporting time, device function, etc.

[0036] User service query service is a service that provides service-related information to access network users, where the service-related information may include user name, user number, account number, customer identification, city identification, service name, service code, service package code, service description, service price, service selling price, service effective time, service end time, service status, tariff level, and service location equipment.

[0037] Key status query service is a service that provides quantum key-related information, where the quantum key-related information may include: current key status, current key generation timestamp, current key start timestamp, current key offline timestamp, and the key ID of the current key in each security domain and the sub-ID tree composition of each module, etc.

[0038] The key usage record query service provides information related to the use of quantum keys in the service network, where the information related to the use of quantum keys may include the key generation timestamp, the key start use timestamp, the key offline timestamp, the key status and the corresponding timestamp, the key ID history record in each security domain, and the sub-ID tree composition of each module.

[0039] User traffic information query service, that is, a service that provides users with traffic-related information, where the traffic-related information may include: total traffic using quantum random numbers, total traffic creating keys, total traffic updating keys, total traffic canceling keys, total traffic encryption services, total traffic decryption services, total traffic signing, total traffic signature verification, total traffic hashing, total HMAC traffic, etc.

[0040] Correspondingly, the provided API interfaces include: User query interface, used to initiate a request to the HSCM in the service network to obtain information such as user number, city identification, customer identification, user name, service number, product code, creation time, effective time, expiration time, payment mode, account number, shutdown lock, status and modification time, and return it to the access network. Customer query interface, used to initiate a request to the HSCM in the service network to obtain parameters such as customer identification, city identification, customer name, abbreviation, encrypted password, customer type, nationality, email, creation time, status, etc., and return it to the access network. Device query interface, used to initiate a request to the HSCM in the service network to obtain parameters such as device name, device ID, manufacturer name, device model, node name, node number software version, operating status, customer, reporting time, device function, etc., and return it to the access network. The user service query interface is used to initiate a request to the HSCM in the service network to obtain parameters such as user name, user number, account number, customer identification, city identification, service name, service code, service package code, service description, service price, service price, service effective time, service end time, service status, tariff level, service location equipment, etc. and return them to the access network. The key status query interface is used to initiate a request to the HSCM in the service network to obtain parameters such as the current key status, the current key generation timestamp, the current key start use timestamp, the current key offline timestamp, and the key ID of the current key in each security domain and the sub-ID tree composition of each module and return them to the access network. The key usage record interface is used to initiate a request to the HSCM in the service network to obtain parameters such as the key generation timestamp, the key start use timestamp, the key offline timestamp, the key status and corresponding timestamp, the key ID history record of the key in each security domain and the sub-ID tree composition of each module and return them to the access network. The user traffic information query interface is used to initiate a request to the HSCM in the service network to obtain parameters such as the total traffic using quantum random numbers, the total traffic creating keys, the total traffic updating keys, the total traffic canceling keys, the total traffic of encryption services, the total traffic of decryption services, the total traffic of signatures, the total traffic of signature verification, the total traffic of hashing, and the total traffic of HMAC, and return them to the access network.

[0041] And based on relevant needs, the following basic capabilities are provided: Routing addressing: The platforms and security engines in the access network and service network can discover each other and realize interconnection between the same level, upper and lower levels, and boundaries. Device authentication: Device authentication is performed on the middleware platform, wherein the authenticated device is the device that implements the middleware platform. User authentication: User authentication is performed on the users of the security engine under the middleware platform. Protocol conversion: The middleware platform and the integrated security management platform use different protocols to send information to the access gateway (such as the access sub-gateway 302). The access gateway (such as the access sub-gateway 302) can correspond the information according to the mapping table, and realize the information intercommunication between the two platforms while avoiding information transparent transmission. Heartbeat management: The middleware platform and the integrated security management platform will periodically send heartbeat detection to each other, and the access gateway (such as the access sub-gateway 302) will manage the results of the heartbeat detection to ensure that the status of the other party's device is obtained in real time.

[0042] Of course, the above is only an example of the security sub-gateway 301 and the access sub-gateway 302. In some examples, the functions and structures of the security sub-gateway 301 and the access sub-gateway 302 may have other situations, which will not be described here one by one. In order to facilitate those skilled in the art to better understand the ability of the security capability access gateway to access the access network to the service network, the following will be combined with the access method of the quantum network applicable to the security capability access gateway provided in the embodiment of the present application. In some embodiments, the method of accessing the quantum network (service network) is as follows Figure 5 As shown, the following steps are included:

[0043] Step 501: receiving a first network access request initiated by a middleware platform of an access network, wherein the first network access request carries device information of the middleware platform that initiates the first network access request.

[0044] Step 502: compare the device information carried in the first network access request with the first information, wherein the first information is information pre-stored in the quantum network for authenticating the middleware platform.

[0045] Step 503: If the device information carried in the first network access request passes the comparison with the first information, a token is issued to the middleware platform that initiates the first network access request to connect the middleware platform that initiates the first network access request to the quantum network.

[0046] In this way, when the middleware platform on the access network side wants to access the quantum network, it initiates the first access request to the security capability access gateway, so that the security capability access gateway can compare the device information of the middleware platform carried in the first access request with the first information pre-stored in the quantum network for authenticating the middleware platform, and authenticate the middleware platform. Thus, by authenticating the middleware platform, its security is guaranteed to meet the security requirements of the quantum network, so that the middleware is allowed to access the quantum network as a secure network, and the access network outside the quantum network is connected to the quantum network, which is conducive to the integration of QKD technology with other technologies. To facilitate technicians in this field to better understand Figure 5 The method for accessing a service network provided by the illustrated embodiment will be explained below.

[0047] In step 501, a first network access request initiated by a middleware platform on the access network side is received. The first network access request is initiated by the middleware platform on the access network side and carries the device information of the middleware platform that initiates the first network access request. It should be noted that this embodiment does not limit the form and content of the first network access request. It can be understood that in the case of different device authentication methods, the first network access request may have different forms, and in particular, the first network access request may carry different forms of device information.

[0048] In some examples, the device authentication method is password authentication. At this time, receiving the first network access request initiated by the middleware platform of the access network can be implemented in the following way: receiving the first network access request of the String type calling the first device authentication API interface sent by the middleware platform, wherein the device information carried by the first network access request includes the device identification and the device authentication password. It should be noted that the device authentication password can be any information that can uniquely authenticate the middleware platform on the access network side, and its length and format are not fixed. And the device authentication password can be given to the administrator of the middleware platform or the equipment vendor, etc., through UKEY and other methods.

[0049] In some examples, the device authentication method is P12 certificate authentication. At this time, the first network access request initiated by the middleware platform of the access network can be implemented as follows: receiving the first network access request of the String type calling the second device authentication API interface sent by the middleware platform, wherein the device information carried by the first network access request includes the device identification, timestamp, and the first encrypted information obtained by encrypting the device identification and timestamp using the P12 certificate by the security engine on the access network side. And the device identification can be any information that can identify the device of the middleware platform, such as the addressing code and / or the device serial number. The subsequent device identification has basically the same meaning, which will not be repeated here.

[0050] It should be noted that the above encryption process can be any encryption algorithm, such as the national encryption SM4 algorithm, etc. The encryption using the P12 certificate is basically the same as the existing encryption using the P12 certificate. The main difference is that the encrypted content here is specified as the encrypted device identification and timestamp. The encryption process will not be repeated here. It should also be noted that in the above example, encrypting the device identification and timestamp is only an example. In some examples, other information related to the middleware platform can also be encrypted, which will not be repeated here.

[0051] In step 502, the device information carried by the first network access request is compared with the first information. The first information is information pre-stored in the quantum network for authenticating the middleware platform. It should be noted that this embodiment does not limit the form and content of the first information. It is understandable that in the case of different device authentication methods, the first information will also be different accordingly.

[0052] In some examples, the device authentication method is password authentication. At this time, the device information carried by the first network access request is compared with the first information, which is achieved by: sending a device query request that calls the device query API interface to the HSCM, which is located in the quantum network and is used to maintain the encrypted device authentication passwords of each middleware platform; receiving the encrypted device authentication passwords of each middleware platform returned by the HSCM, and searching for the encrypted device authentication password of the middleware platform that initiated the first network access request in the encrypted device authentication passwords of each middleware platform received according to the device identifier carried by the first network access request, as the first information and compare. Among them, the comparison process when the encrypted device authentication password is used as the first information is as follows: encrypt the device authentication password carried by the first network access request, and then compare the encryption result with the first information bit by bit.

[0053] It should be noted that the above example is only an exemplary description of the maintenance of the first information by the integrated security management platform, which can ensure the integrity, consistency and security of the first information. In some examples, the first information can also be maintained directly by the security capability access gateway. At this time, there is no need to initiate a request to the integrated security management platform; in some examples, the first information can still be maintained by the integrated security management platform, but the query request initiated can also directly carry the device identification carried by the first network access request, so that the integrated security execution module can directly return the first information required for device authentication by the middleware platform that initiated the first network access request, rather than the first information of each middleware platform, which reduces the processing power and storage capacity required by the security capability access gateway to support related functions, which is conducive to reducing the cost and complexity of the security capability access gateway. It should also be noted that the first information of each middleware platform is obtained by encrypting the device authentication password after generating it. When the first information is maintained by the integrated security management platform, it can be uploaded and stored in the integrated security management platform by the administrator of the integrated security management platform together with the device identification of the corresponding middleware platform.

[0054] In some examples, the device authentication method is P12 certificate authentication. At this time, the device information carried in the first network access request is compared with the first information. This can be achieved in the following way: sending a device query request that calls the device query API interface to the integrated security management platform, which is located in the quantum network and is used to maintain the P12 certificates of each middleware platform; receiving the P12 certificates of each middleware platform returned by the integrated management platform, and searching for the P12 certificate of the middleware platform that initiated the first network access request as the first information in the P12 certificates of each received middleware platform according to the device identifier carried in the first network access request and performing a comparison.

[0055] In step 503, if the device information carried by the first network access request is compared with the first information, a token is issued to the middleware platform that initiated the first network access request to connect the middleware platform that initiated the first network access request to the quantum network. In other words, the middleware platform can communicate with the quantum network through the security capability access gateway by carrying the token in the request, that is, the middleware platform that initiated the first network access request can be connected to the quantum network.

[0056] To facilitate better understanding of those skilled in the art Figure 5The method for accessing the quantum network shown in the figure will be illustrated below in combination with the secure access capability gateway including the secure sub-gateway and the access sub-gateway. In the case where the device authentication is password authentication, the method for accessing the quantum network includes the following steps: Step S11, creating a non-fixed length password for the newly added middleware platform, calculating the password in the password card of the security execution module using the national secret SM3 algorithm, and associating it with the addressing code / device serial number of the corresponding device itself, and reporting it to the database of the fusion security management platform. And offline, the UKEY containing the device addressing code / device serial number and password file is transferred to the middleware platform, and the device addressing code / device serial number and password are all String type parameters. Step S12, when the middleware platform has the need to access the quantum network, the middleware platform calls the first device authentication API interface of the access gateway through the security gateway, and sends the parameters of the String type (including the device identification (including the addressing code and / or the device serial number), the input password) and the network information IP to the security gateway in the form of the first network access request. Step S13, after receiving the first network access request, the security sub-gateway verifies it according to the network information therein, the number analysis routing and black and white list functions, and performs NAT conversion on the IP address. Step S14, after the security sub-gateway determines that the first network access request passes the verification in step S13, the security sub-gateway sends the first network access request processed in step S13 to the access sub-gateway. Step S15, after receiving the first network access request, the access sub-gateway calls the device query API interface of the integrated security management platform to obtain all the encrypted device authentication passwords maintained by it from the database of the integrated security management platform, and searches for the encrypted device authentication password required for the current comparison through the addressing code and / or the device serial number. Step S16, the access sub-gateway performs SM3 operation on the device authentication password carried by the first network access request, and compares the operation result with the encrypted device authentication password found in step S15 bit by bit to achieve authentication. Step S17, if the authentication is successful in step S16, a token (Token) under the String parameter is generated in the access sub-gateway, and the addressing code and / or device serial number, Token and Token timestamp (timestamp is Long type) and their corresponding relationship are saved, and a success response and the Token as a token are returned to the middleware platform through the security sub-gateway; if the authentication fails in step S16, a failure response is returned and the authentication process ends.

[0057] Similarly, when the device authentication is P12 certificate authentication, the method for accessing the quantum network includes the following steps: Step S21, the security execution module uses the quantum key to create a public-private key pair for authentication and authorization, associates it with the device identification (including the device addressing code and / or the device serial number) and generates a P12 certificate, which is reported to the database of the integrated security management platform. The UKEY containing the device addressing code and / or the device serial number and the P12 certificate is transferred to the middleware platform offline, and the device addressing code and / or the device serial number is a parameter of the String type. Step S22, the middleware platform in the access network calls the second device authentication API interface of the access gateway through the security sub-gateway, performs SM3 operation on the addressing code and / or the device serial number + timestamp of the device, and digitally signs its hash value using the private key of the P12 certificate. Then, the parameters of the String type (including the addressing code and / or the device serial number, the hash value after SM3, the digital signature) and the network information IP are sent to the security sub-gateway in the form of the first network access request. Step S23, after receiving the first network access request, the security sub-gateway verifies it according to the network information therein, the number analysis routing and black and white list functions, and performs NAT conversion on the IP address. Step S24, after the security sub-gateway determines that the first network access request passes the verification in step S23, the security sub-gateway sends the first network access request processed in step S23 to the access sub-gateway. Step S25, after receiving the first network access request, the access sub-gateway calls the device query API interface of the integrated security management platform to obtain all the P12 certificates it maintains from the database of the integrated security management platform, and searches for the P12 certificate required for the current comparison through the addressing code and / or the device serial number. Step S26, the access sub-gateway uses the public key in the P12 certificate found in step S25 to decrypt the digital signature in the first network access request, and compares the hash value carried in the first network access request bit by bit to achieve authentication. Step S27, if the authentication is successful in step S16, a token (Token) under the String parameter is generated in the access sub-gateway, and the addressing code and / or device serial number, Token and Token timestamp (timestamp is Long type) and their corresponding relationship are saved, and a success response and the Token as a token are returned to the middleware platform through the security sub-gateway; if the authentication fails in step S16, a failure response is returned and the authentication process ends.

[0058] It is understandable that when the access network accesses the quantum network, there may be a need for not only device authentication but also user authentication. For example, when the security capability access gateway develops different service permissions for different users, it is also necessary to confirm whether the user has the permission to call a certain service. In this case, the user needs to be authenticated. Based on this, in some embodiments, such as Figure 6As shown, the method for accessing a quantum network includes the following steps: Step 601, receiving a first access request initiated by a middleware platform of an access network, the first access request carrying device information of the middleware platform that initiated the first access request. Step 602, comparing the device information carried by the first access request with the first information, wherein the first information is information pre-stored in the quantum network for authenticating the middleware platform. Step 603, if the device information carried by the first access request is compared with the first information, a token is issued to the middleware platform that initiated the first access request to access the middleware platform that initiated the first access request to the quantum network. Step 604, receiving a second access request initiated by a security engine of the access network through the middleware platform, the second access request carrying user information of the security engine that initiated the second access request. Step 605, comparing the user information carried by the second access request with the second information, the second information is information pre-stored in the quantum network for authenticating the security engine of the access network. Step 606: If the user information carried in the second network access request passes the comparison with the second information, a token is issued to the security engine that initiates the second network access request to connect the security engine that initiates the second network access request to the quantum network through the middleware platform.

[0059] That is to say, under the premise of ensuring the security of quantum network, the access network is provided with the service of accessing the quantum network. On this basis, different service permissions are also provided to users to achieve user isolation. Figure 6 The embodiment shown in the figure will be explained below. It should be noted that in step 601-step 603, the implementation is the same as Figure 5 Steps 501 to 503 in the embodiment shown are substantially the same, the difference being that Figure 6 Steps 604 to 606 are also introduced to implement user authentication, and the same parts will not be repeated here.

[0060] In step 604, a second network access request initiated by the security engine of the access network through the middleware platform is received. The second network access request is initiated by the security engine on the access network side through the middleware platform that has been connected to the quantum network when it is necessary to call an application with corresponding permissions in the quantum network, and carries the user information of the security engine that initiated the second network access request. That is, user authentication is performed when the device authentication of the middleware platform is passed. In some examples, receiving the second network access request initiated by the security engine of the access network through the middleware platform can be implemented as follows: receiving a second network access request of a String type that calls the first user authentication API interface sent by the security engine through the middleware platform, wherein the user information carried by the second network access request includes a user identifier and a user authentication password. In some examples, receiving the second network access request initiated by the security engine of the access network through the middleware platform can be implemented as follows: receiving a second network access request of a String type that calls the second user authentication API interface sent by the security engine through the middleware platform, wherein the user information carried by the second network access request includes a user identifier, a timestamp, and a second encrypted information obtained by encrypting the user identifier and the timestamp by the security engine using the P12 certificate. It can be seen that the reception of the second network access request provided by step 604 is substantially the same as the reception of the first network access request provided by step 501, and the main difference lies in the initiator of the request and the information carried for authentication. Therefore, the same parts will not be described in detail here.

[0061] In step 605, the user information carried by the second network access request is compared with the second information. The second information is information pre-stored in the quantum network for authenticating the security engine on the access network side. In some examples, the user information carried by the second network access request is compared with the second information, which can be achieved in the following manner: sending a user query request that calls the user query API interface to the integrated security management platform, the integrated security management platform is located in the quantum network and is used to maintain the encrypted user authentication passwords of each security engine; receiving the encrypted user authentication passwords of each security engine returned by the integrated management platform, and searching the encrypted user authentication passwords of each security engine received according to the user identifier carried by the second network access request for the encrypted user authentication password of the security engine that initiated the second network access request as the second information and performing a comparison. In some examples, the user information carried in the second network access request is compared with the second information, which can also be achieved in the following way: sending a user query request that calls the user query API interface to the integrated security management platform, which is located in the quantum network and is used to maintain the P12 certificates of each security engine; receiving the P12 certificates of each security engine returned by the integrated management platform, and searching the P12 certificates of each security engine received for the P12 certificate of the security engine that initiated the second network access request according to the user identifier carried in the second network access request, as the second information and performing a comparison. It can be seen that the comparison based on the second network access request provided in step 605 is roughly the same as the comparison based on the first network access request provided in step 502, and the main difference is that the objects of the comparison are different, so the same parts will not be repeated here.

[0062] In step 606, a token is issued to the security engine that initiated the second network access request, so that the security engine that initiated the second network access request is connected to the quantum network through the middleware platform that has been connected to the quantum network. It should be noted that the example of the specific implementation process of user authentication provided by steps 604-606 is roughly the same as the scheme provided by the aforementioned steps S11-S17 and steps S21-S27. The difference lies mainly in the different authentication objects. Therefore, the same parts will not be repeated here.

[0063] It is understandable that after accessing the quantum network, the access network can call the quantum-related services provided by the quantum network by initiating corresponding requests. Based on this, in some embodiments, such as Figure 7As shown, the method for accessing a quantum network includes the following steps: Step 701, receiving a first access request initiated by a middleware platform of an access network, the first access request carrying device information of the middleware platform that initiated the first access request. Step 702, comparing the device information carried by the first access request with the first information, wherein the first information is information pre-stored in the quantum network for authenticating the middleware platform. Step 703, if the device information carried by the first access request is compared with the first information, a token is issued to the middleware platform that initiated the first access request to access the middleware platform that initiated the first access request to the quantum network. Step 704, receiving a first service request, the first service request is initiated by the access network. Step 705, according to a preset protocol mapping report, converting the first service request from the communication protocol of the access network to the communication protocol of the quantum network, and performing address conversion on the first service request. Step 706, forwarding the converted first service request to the quantum network to respond to the first service request based on the quantum network.

[0064] That is to say, under the condition of ensuring the security of quantum network, the service of access network access to quantum network is provided. On this basis, corresponding service rights are developed to the access network, so that the access network can provide corresponding services to the access network by initiating the first service request. Figure 7 The embodiment shown in the figure will be explained below. It should be noted that in step 701-step 703, the implementation is the same as Figure 5 Steps 501 to 503 in the embodiment shown are substantially the same, the difference being that Figure 7 Steps 704 to 706 are also introduced to implement the access network's call to the quantum network service, and the same parts will not be repeated here.

[0065] In step 704, a first service request is received. The first service request is initiated by the access network side. This embodiment does not limit the service called by the first service request, which can be any service provided by the quantum network that the access network currently needs to call. This embodiment also does not limit the form of the first service request, which can be any request that can be parsed and received by the security capability access gateway, such as HTTP requests. In some examples, receiving the first service request can be implemented as follows: receiving a first service request of a String type initiated by a security engine or a middleware platform, the first service request carries a token of the middleware platform that initiates the first service request or a token of the security engine that initiates the first service request.

[0066] It should be noted that Figure 7 This is just an example. It is understandable that when the first service request involves the permissions of the user, after step 703 and before step 704, it is also necessary to implement Figure 6 Steps 604-606 are shown to perform user authentication and obtain the token of the security engine issued to the user. That is to say, when it comes to the service permissions available to the user, the first service request needs to carry the token of the security engine. When it does not involve the service permissions available to the user, the first service request can only carry the token of the middleware platform. The subsequent steps performed after the token is issued to the middleware platform that initiates the second network access request are similar. If it is necessary to rely on user authentication in the future, after the token is issued to the middleware platform that initiates the second network access request and before the first step after the token is issued to the middleware platform that initiates the second network access request, you can also add Figure 6 Steps 604 to 606 are shown and will not be described in detail.

[0067] It is also understandable that after accessing the quantum network, in order to ensure normal service provision, the quantum network may also need to synchronize information to the access network or send other information, such as synchronizing the quantum key state from the quantum network to the access network. Based on this, in some embodiments, such as Figure 8 As shown, the method for accessing a quantum network includes the following steps: Step 801, receiving a first access request initiated by a middleware platform of an access network, the first access request carrying device information of the middleware platform that initiated the first access request. Step 802, comparing the device information carried by the first access request with the first information, wherein the first information is information pre-stored in the quantum network for authenticating the middleware platform. Step 803, if the device information carried by the first access request is compared with the first information, a token is issued to the middleware platform that initiated the first access request to access the middleware platform that initiated the first access request to the quantum network. Step 804, receiving a second service request, the second service request is initiated by the quantum network. Step 805, according to a preset protocol mapping report, converting the second service request from the communication protocol of the quantum network to the communication protocol of the access network, and performing address conversion on the second service request. Step 806, forwarding the converted second service request to the middleware platform to respond to the second service request based on the middleware platform.

[0068] That is to say, under the premise of ensuring the security of quantum network, the service of access network access to quantum network is provided. On this basis, corresponding service rights are developed to the access network, so that the quantum network can provide corresponding services to the access network by initiating a second service request. Figure 8 The embodiment shown in the figure will be explained below. It should be noted that in step 801-step 803, the implementation is the same as Figure 5 Steps 501 to 503 in the embodiment shown are substantially the same, the difference being that Figure 8Steps 804 to 806 are also introduced to provide quantum network services to the access network, and the same parts will not be repeated here.

[0069] In step 804, a second service request is received. The second service request is initiated by the quantum network. This embodiment does not limit the service called by the second service request, which can be any service provided to the access network. This embodiment also does not limit the form of the second service request, which can be any request that can be parsed and received by the security capability access gateway, such as an HTTP request. In some examples, receiving the second service request can be implemented as follows: receiving a second service request of a String type initiated by the converged security management platform for calling a service in the middleware platform.

[0070] In addition, the security capability access gateway involves two different networks. Therefore, in some embodiments, in order to ensure the security of the network, the information exchanged between the two networks can be verified to ensure security, such as verifying the network information and token of the first service request, and / or NATing the information exchanged between the two networks to form isolation between the two networks.

[0071] To facilitate better understanding of those skilled in the art Figure 7 , Figure 8The embodiment shown will be illustrated below. The function of the middleware platform sending information to the integrated security management platform is implemented by the following steps: Step S31, the middleware platform calls the API interface of the integrated security management platform through the security capability access gateway, transmits the information to be intercommunication to the security engine, and uses the negotiated quantum key to encrypt it using the national secret SM4 algorithm and then transmits it back to the middleware platform. The middleware platform sends the parameters of String type (encrypted intercommunication information, token Token obtained after the device / user authentication is passed) and network information IP to the security sub-gateway in the form of a first service request. Step S32, after the security sub-gateway receives the first service request, it verifies the first service request according to its number analysis routing and black and white list functions through the network information IP, and performs NAT conversion on the IP address in the first service request. Step S33, after the verification of step S32 is passed, the security sub-gateway sends the first service request to the access sub-gateway. Step S34, after the access sub-gateway receives the first service request, it verifies and compares the token Token carried by the first service request with the token Token stored when the authentication is passed and the token Token is issued. Step S35, after the verification of step S34 is passed, the access sub-gateway performs protocol conversion on the first service request, and converts the communication protocol used by the access network into the communication protocol used by the quantum network through the preset mapping table in the access sub-gateway. If the access network or quantum network uses a private communication protocol, it needs to be adapted in advance. Step S36, the access sub-gateway forwards the first service request after protocol conversion to the fusion security management platform in the quantum network through the corresponding API interface. Among them, since the first service request carries encrypted information, the fusion security management platform will send the encrypted information to the security execution module to decrypt it in the security engine using the negotiated quantum key and the national secret SM4 algorithm, and then store the decryption result returned by the security engine in the database.

[0072] The function of the integrated security management platform sending information to the middleware platform is realized by the following steps: Step S41, the integrated security management platform calls the API interface of the middleware platform through the security capability access gateway, transmits the information to be transmitted to the security engine, and uses the negotiated quantum key for SM4 encryption and then transmits it back to the integrated security management platform. The integrated security management platform sends the parameters of the String type (encrypted intercommunication information) and network information IP and other information to the access sub-gateway in the form of a second service request. Step S42, after receiving the second service request, the access sub-gateway performs protocol conversion on the second service request, and converts the communication protocol used by the quantum network into the communication protocol used by the access network through the preset mapping table in the access sub-gateway, wherein, if the access network or the quantum network uses a private communication protocol, it needs to be adapted in advance. Step S43, the access sub-gateway forwards the converted second service request to the security sub-gateway. Step S44, after receiving the second service request, the security sub-gateway verifies it through the network information IP, according to its number analysis routing and black and white list functions, and performs NAT conversion on the IP address of the second service request. Step S45, after the verification of step S44 is passed, the security sub-gateway sends the second service request to the middleware platform through the API interface. Step S46, the middleware platform receives the second service request. Since the second service request carries encrypted information, the middleware platform sends the encrypted information in the second service request to the security engine to decrypt it using the negotiated quantum key and the national secret SM4 algorithm on the security engine, and stores the decryption result returned by the security engine in the database.

[0073] It should be noted that the first service request can be used to send information to a quantum network (such as a fusion security management platform in a quantum network, etc.), or to query information from a quantum network (such as a fusion security management platform in a quantum network, etc.), and the information sent or queried may include the aforementioned device information, user information, customer information, quantum key information, etc.; the second service request can be used to send information, and the information sent may include the aforementioned device information, user information, customer information, quantum key information. For example, the first service request may be a request initiated by the middleware platform to call a device query API interface, and the request may carry a token Token received by the middleware platform; the second service request may be a request by the fusion security management platform to call a quantum key state synchronization API interface, and the request may carry the quantum key identifier, the state information of the quantum key that needs to be synchronized, etc., which will not be described one by one here.

[0074] It is also understandable that the quantum network and the access network need to know each other's status in a timely manner. For example, when the access network goes offline, the quantum key network needs to sense it in time to avoid continuing to synchronize information with the offline access network. Based on this, in some embodiments, such as Fig. 9As shown, the method for accessing a quantum network includes the following steps: Step 901, receiving a first network access request initiated by a middleware platform of an access network, the first network access request carrying device information of the middleware platform that initiated the first network access request. Step 902, comparing the device information carried by the first network access request with the first information, wherein the first information is information pre-stored in the quantum network for authenticating the middleware platform. Step 903, if the device information carried by the first network access request passes the comparison with the first information, issuing a token to the middleware platform that initiated the first network access request to connect the middleware platform that initiated the first network access request to the quantum network. Step 904, periodically forwarding heartbeat detection packets between the integrated security management platform and the middleware platform. In this way, while ensuring the security of the quantum network, the service of accessing the access network to the quantum network is provided. On this basis, heartbeat detection packets are sent to each other to timely perceive the status of the other party through the heartbeat mechanism so as to make corresponding responses. It should be noted that Fig. 9 In the steps 901 to 903 in the embodiment shown, the implementation is similar to Figure 5 Steps 501 to 503 in the embodiment shown are substantially the same, the difference being that Fig. 9 Step 904 is also introduced to sense the other party's state through the heartbeat mechanism, and the same parts will not be repeated here.

[0075] The step division of the above methods is only for the purpose of clear description. When implemented, they can be combined into one step or some steps can be split and decomposed into multiple steps. As long as they include the same logical relationship, they are all within the scope of protection of this patent; adding insignificant modifications to the algorithm or process or introducing insignificant designs without changing the core design of the algorithm and process are all within the scope of protection of this patent.

[0076] Furthermore, it is not difficult to find that the above-mentioned gateway embodiment is an embodiment corresponding to the above-mentioned method embodiment, and the gateway embodiment can be implemented in conjunction with the method embodiment. The relevant technical details mentioned in the method embodiment are still valid in the gateway embodiment. Accordingly, the relevant technical details mentioned in the gateway embodiment can also be applied in the method embodiment.

[0077] Those skilled in the art will appreciate that the above embodiments are specific embodiments for implementing the present application, and in actual applications, various changes may be made thereto in form and detail without departing from the spirit and scope of the present application.

Claims

1. A method for accessing a quantum network, applicable to a security capability access gateway, It is characterized in that include: Receiving a first network access request initiated by a middleware platform of an access network, wherein the first network access request carries device information and network information of the middleware platform; Verify the middleware platform according to the network information, obtain the device information in the first network access request converted by NAT if the middleware platform passes the verification, and compare the device information with the first information, wherein the first information is the information pre-stored in the quantum network for authenticating the middleware platform; If the device information carried in the first network access request is compared with the first information, a token is issued to the middleware platform that initiated the first network access request to connect the middleware platform that initiated the first network access request to the quantum network; Receiving a second network access request initiated by a security engine of the access network through the middleware platform; After the second network access request passes the comparison, a token is issued to the security engine that initiated the second network access request to connect the security engine that initiated the second network access request to the quantum network through the middleware platform.

2. The method for accessing a quantum network according to claim 1, It is characterized in that Receiving a first network access request initiated by a middleware platform of the access network includes: Receiving the first network access request of the String type for calling the first device authentication API interface sent by the middleware platform, wherein the device information carried by the first network access request includes a device identifier and a device authentication password; or, Receive the first network access request of String type calling the second device authentication API interface sent by the middleware platform, wherein the device information carried by the first network access request includes the device identification, timestamp, and the first encrypted information obtained by encrypting the device identification and timestamp by using the P12 certificate through the security engine of the access network.

3. The method for accessing a quantum network according to claim 2, It is characterized in that Comparing the device information with the first information includes: Sending a device query request for calling a device query API interface to a converged security management platform, wherein the converged security management platform is located in a quantum network and is used to maintain the encrypted device authentication passwords of each middleware platform; receiving the encrypted device authentication passwords of each middleware platform returned by the converged security management platform; searching for the encrypted device authentication password of the middleware platform that initiated the first network access request in the received encrypted device authentication passwords of each middleware platform according to the device identifier carried in the first network access request, as the first information and performing a comparison; or, Send a device query request that calls the device query API interface to the integrated security management platform, wherein the integrated security management platform is located in the quantum network and is used to maintain the P12 certificates of each middleware platform; receive the P12 certificates of each middleware platform returned by the integrated security management platform; and search for the P12 certificate of the middleware platform that initiated the first network access request in the P12 certificates of each received middleware platform according to the device identifier carried by the first network access request, as the first information and perform a comparison.

4. The method for accessing a quantum network according to claim 1, It is characterized in that The second network access request carries user information of a security engine that initiates the second network access request; The comparison of the second network access request is implemented in the following manner: The user information carried by the second network access request is compared with the second information, wherein the second information is the information of the security engine pre-stored in the quantum network for authenticating the access network.

5. The method for accessing a quantum network according to claim 4, It is characterized in that Receiving a second network access request initiated by the security engine of the access network through the middleware platform includes: Receiving the second network access request of the String type for calling the first user authentication API interface sent by the security engine through the middleware platform, wherein the user information carried by the second network access request includes a user identifier and a user authentication password; or, Receive the second network access request of String type calling the second user authentication API interface sent by the security engine through the middleware platform, wherein the user information carried by the second network access request includes the user identifier, timestamp, and the second encrypted information obtained by encrypting the user identifier and timestamp using the P12 certificate.

6. The method for accessing a quantum network according to claim 5, It is characterized in that Comparing the user information carried in the second network access request with the second information includes: Sending a user query request for calling a user query API interface to a converged security management platform, wherein the converged security management platform is located in a quantum network and is used to maintain the encrypted user authentication passwords of each security engine; receiving the encrypted user authentication passwords of each security engine returned by the converged security management platform; searching for the encrypted user authentication password of the security engine that initiated the second network access request in the received encrypted user authentication passwords of each security engine according to the user identifier carried in the second network access request, as the second information and performing a comparison; or, Send a user query request that calls a user query API interface to the integrated security management platform, wherein the integrated security management platform is located in the quantum network and is used to maintain the P12 certificate of each security engine; receive the P12 certificate of each security engine returned by the integrated security management platform; and search the P12 certificate of the security engine that initiated the second network access request in the P12 certificates of each received security engine according to the user identifier carried by the second network access request, as the second information and perform a comparison.

7. The method for accessing a quantum network according to any one of claims 1 to 6, It is characterized in that After issuing the token to the middleware platform that initiated the first network access request, the method further includes: receiving a first service request, wherein the first service request is initiated by an access network; According to a preset protocol mapping report, convert the first service request from the communication protocol of the access network to the communication protocol of the quantum network, and perform address conversion on the first service request; The converted first service request is forwarded to the quantum network to respond to the first service request based on the quantum network.

8. The method for accessing a quantum network according to claim 7, It is characterized in that Receiving a first service request includes: The first service request of String type initiated by a security engine or a middleware platform is received, wherein the first service request carries a token of the middleware platform that initiates the first service request or a token of the security engine that initiates the first service request.

9. The method for accessing a quantum network according to any one of claims 1 to 6, It is characterized in that After issuing the token to the middleware platform that initiated the first network access request, the method further includes: Receiving a second service request, wherein the second service request is initiated by the quantum network; According to a preset protocol mapping report, convert the second service request from the communication protocol of the quantum network to the communication protocol of the access network, and perform address conversion on the second service request; The converted second service request is forwarded to the middleware platform, so as to respond to the second service request based on the middleware platform.

10. A security capability access gateway, It is characterized in that include: at least one processor; as well as, a memory communicatively connected to the at least one processor; wherein, The memory stores instructions executable by the at least one processor, and the instructions are executed by the at least one processor to enable the at least one processor to perform the method for accessing a quantum network as described in any one of claims 1 to 9.

Citation Information

Patent Citations

  • Authentication system and authentication method of network access device in quantum network

    CN105812367A

  • User access cloud platform security access authentication system and application method thereof

    CN111917543A

  • Identity authentication method and device and electronic equipment

    CN116248290A