Key transmission method and device, related equipment, storage medium and computer program product

By encrypting and/or protecting the integrity of the key during key transmission, the security risks in the key filling process are resolved, and the security of key transmission and user experience are improved.

CN119070977BActive Publication Date: 2026-01-20CHINA MOBILE COMM LTD RES INST +1
View PDF 3 Cites 0 Cited by

Patent Information

Application Number
CN202410979443.3
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2024-07-19
Publication Date
2026-01-20
Estimated Expiration
2044-07-19

AI Technical Summary

Technical Problem

In existing technologies, the key filling process has security risks, as multiple parties possessing the full set of keys and different operators may affect key security.

Method used

During key transmission, the injected key is encrypted and/or protected for integrity based on a shared key of a specific platform, ensuring that third parties cannot obtain the plaintext key and improving transmission security.

Benefits of technology

It improves the security of the key transmission process, protects the security of the key filling process, ensures the secure communication services of the communication network, and enhances the user experience.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN119070977B_ABST
    Figure CN119070977B_ABST
Patent Text Reader

Abstract

The application discloses a key transmission method and device, a terminal, a first device, a storage medium and a computer program product. The method comprises the following steps: a first module on the terminal receives a first key sent by a first device, the first key is encrypted and / or integrity protected based on a second key, and the second key is a shared key between the first device and the first module; the first module generates a third key based on the first key; and the first module receives one or more fourth keys sent by the first device, and the one or more fourth keys are encrypted and / or integrity protected based on the third key.
Need to check novelty before this filing date? Find Prior Art

Description

TECHNICAL FIELD

[0001] The present application relates to the security field, and in particular to a key transmission method and device, related equipment, a storage medium and a computer program product. BACKGROUND

[0002] With the rapid development of Internet technology, the network security risks of information systems continue to increase, and the threat challenges are becoming increasingly severe. Password security is an important foundation of information security, which can effectively protect the data security of network information systems; in other words, password technology is the core technology and important means to protect network information systems.

[0003] However, the key filling process of related password technology may have security risks. SUMMARY

[0004] To solve the problems in the related art, the present application provides a key transmission method and device, related equipment, a storage medium and a computer program product.

[0005] The technical solution of the present application is implemented as follows:

[0006] The present application provides a key transmission method applied to a terminal, comprising:

[0007] A first module on the terminal receives a first key sent by a first device, the first key being encrypted and / or integrity protected based on a second key, the second key being a shared key between the first device and the first module;

[0008] The first module generates a third key based on the first key;

[0009] The first module receives one or more fourth keys sent by the first device, the one or more fourth keys being encrypted and / or integrity protected based on the third key.

[0010] In the above solution, the first key is randomly generated;

[0011] Alternatively,

[0012] The first key is generated based on one or more of the following parameters:

[0013] A fifth key of the first device;

[0014] An identifier of the terminal;

[0015] An identifier of the first module;

[0016] A first random number.

[0017] In the scheme, the method further comprises:

[0018] The first module receives the second key sent by the second device, and the second key is sent by the first device to the second device.

[0019] In the scheme, the second key is encrypted and protected by the first device based on a public key of the second device.

[0020] Or,

[0021] The second key is encrypted and / or integrity-protected by the first device based on a shared key between the second device and the first device.

[0022] In the scheme, the first module on the terminal receives the first key sent by the first device, comprising:

[0023] The first module receives the first information sent by the third device, and the first information is sent by the first device to the third device, and the first information contains a first parameter, and the first parameter is obtained by encrypting the first key based on the second key.

[0024] In the scheme, the method further comprises:

[0025] The first module decrypts the first parameter based on the second key to obtain the first key.

[0026] In the scheme, the first information further contains one or more of the following:

[0027] A second random number;

[0028] An identifier of the terminal;

[0029] An identifier of the first module;

[0030] A second parameter, and the second parameter is obtained by integrity-protecting one or more of the first parameter, a second random number, an identifier of the terminal, and an identifier of the first module based on the second key.

[0031] In the scheme, the method further comprises:

[0032] The first module verifies the correctness of the second parameter based on the second key.

[0033] In the scheme, the first module generates a third key based on the first key, comprising:

[0034] The first module generates the third key based on the first key and a second random number;

[0035] The first module stores the first key and a third key.

[0036] In the above solution, the first module receives one or more fourth keys sent by the first device, and the method comprises:

[0037] The first module receives second information sent by a third device, the second information being sent by the first device to the third device, and the second information comprising a third parameter obtained based on encryption and / or integrity protection of the one or more fourth keys by the third key.

[0038] In the above solution, the method further comprises:

[0039] The first module decrypts the third parameter based on the third key to obtain the one or more fourth keys.

[0040] The first module stores the one or more fourth keys.

[0041] In the above solution, the second information further comprises one or more of:

[0042] An identifier of the terminal;

[0043] An identifier of the first module;

[0044] An identifier of the fourth key;

[0045] A fourth parameter obtained based on integrity protection of one or more of the third parameter, the identifier of the terminal, the identifier of the first module, and one or more identifiers of the one or more fourth keys by the third key.

[0046] In the above solution, the method further comprises:

[0047] The first module verifies correctness of the fourth parameter based on the third key.

[0048] In the above solution, the method further comprises:

[0049] The first module updates the third key based on the first key.

[0050] In the above solution, the method further comprises:

[0051] The first module receives third information sent by a third device, the third information being sent by the first device to the third device, and the third information being used to trigger updating of the third key.

[0052] In the above solution, the third information comprises one or more of:

[0053] an identity of the terminal;

[0054] an identity of the first module;

[0055] an updated second random number;

[0056] a fifth parameter, the fifth parameter being obtained based on an updated third key, integrity protection of one or more of the identity of the terminal, the identity of the first module, and the updated second random number.

[0057] In the foregoing solution, the first module updates the third key based on the first key, including:

[0058] the first module generates an updated third key based on the first key and the updated second random number;

[0059] the first module verifies correctness of the fifth parameter based on the updated third key;

[0060] the first module stores the updated third key.

[0061] Embodiments of the present application further provide a key transmission method, applied to a first device, including:

[0062] sending a first key to a first module on a terminal, the first key being encrypted and / or integrity-protected based on a second key, the second key being a shared key between the first device and the first module;

[0063] generating a third key based on the first key;

[0064] sending one or more fourth keys to the first module, the one or more fourth keys being encrypted and / or integrity-protected based on the third key.

[0065] In the foregoing solution, the method further includes:

[0066] randomly generating the first key;

[0067] or,

[0068] generating the first key based on one or more of the following parameters:

[0069] a fifth key of the first device;

[0070] an identity of the terminal;

[0071] an identity of the first module;

[0072] a first random number.

[0073] In the above aspect, the method further comprises:

[0074] sending the second key to the first module by the second device.

[0075] In the above aspect, the second key is encrypted by the first device based on a public key of the second device;

[0076] or,

[0077] the second key is encrypted and / or integrity protected by the first device based on a shared key between the second device and the first device.

[0078] In the above aspect, the sending the first key to the first module on the terminal comprises:

[0079] sending first information to the first module by a third device, the first information comprising a first parameter, the first parameter being obtained by encrypting the first key based on the second key.

[0080] In the above aspect, the first information further comprises one or more of:

[0081] a second random number;

[0082] an identity of the terminal;

[0083] an identity of the first module;

[0084] a second parameter, the second parameter being obtained by integrity protecting one or more of the first parameter, the second random number, the identity of the terminal, and the identity of the first module based on the second key.

[0085] In the above aspect, the generating a third key based on the first key comprises:

[0086] generating the third key based on the first key and a second random number;

[0087] storing the first key and the third key.

[0088] In the above aspect, the sending one or more fourth keys to the first module comprises:

[0089] sending second information to the first module by a third device, the second information comprising a third parameter, the third parameter being obtained by encrypting and / or integrity protecting the one or more fourth keys based on the third key.

[0090] In the above aspect, the second information further comprises one or more of:

[0091] an identity of the terminal;

[0092] an identity of the first module;

[0093] an identity of the fourth key;

[0094] a fourth parameter, the fourth parameter being obtained based on integrity protection of one or more of the third parameter, the identity of the terminal, the identity of the first module, and one or more identities of the one or more fourth keys.

[0095] In an embodiment, the method further comprises:

[0096] updating the third key based on the first key.

[0097] In an embodiment, the method further comprises:

[0098] sending, by a third device, third information to the first module, the third information being used to trigger updating the third key.

[0099] In an embodiment, the third information comprises one or more of:

[0100] an identity of the terminal;

[0101] an identity of the first module;

[0102] an updated second random number;

[0103] a fifth parameter, the fifth parameter being obtained based on integrity protection of one or more of the identity of the terminal, the identity of the first module, and the updated second random number by the updated third key.

[0104] In an embodiment, the updating the third key based on the first key comprises:

[0105] generating an updated third key based on the first key and the updated second random number;

[0106] storing the updated third key.

[0107] Embodiments of the present application also provide a key transmission apparatus, comprising:

[0108] a first receiving unit configured to receive a first key sent by a first device, the first key being encrypted and / or integrity protected based on a second key, the second key being a shared key between the first device and a first module on a terminal;

[0109] a first processing unit configured to generate a third key based on the first key.

[0110] a second receiving unit, configured to receive one or more fourth keys sent by the first device, the one or more fourth keys being encrypted and / or integrity protected based on the third key.

[0111] Embodiments of the present application further provide a key transmission apparatus, comprising:

[0112] a first sending unit, configured to send a first key to a first module on a terminal, the first key being encrypted and / or integrity protected based on a second key, the second key being a shared key between the first device and the first module;

[0113] a second processing unit, configured to generate a third key based on the first key;

[0114] a second sending unit, configured to send one or more fourth keys to the first module, the one or more fourth keys being encrypted and / or integrity protected based on the third key.

[0115] Embodiments of the present application further provide a terminal, comprising a first module; the first module comprises a first communication interface and a first processor; wherein,

[0116] the first processor is configured to:

[0117] receive a first key sent by a first device through the first communication interface, the first key being encrypted and / or integrity protected based on a second key, the second key being a shared key between the first device and the first module;

[0118] generate a third key based on the first key;

[0119] receive one or more fourth keys sent by the first device through the first communication interface, the one or more fourth keys being encrypted and / or integrity protected based on the third key.

[0120] Embodiments of the present application further provide a first device, comprising a second communication interface and a second processor; wherein,

[0121] the second processor is configured to:

[0122] send a first key to a first module on a terminal through the second communication interface, the first key being encrypted and / or integrity protected based on a second key, the second key being a shared key between the first device and the first module;

[0123] generate a third key based on the first key;

[0124] sending, to the first module, one or more fourth keys via the second communication interface, the one or more fourth keys being encrypted and / or integrity protected based on the third keys.

[0125] The embodiment of the present application further provides a terminal, comprising a first module; the first module comprises a first processor and a first memory for storing a computer program capable of running on the processor,

[0126] The first processor is configured to execute the computer program, and perform the steps of any of the methods on the terminal side.

[0127] The embodiment of the present application further provides a first device, comprising a first processor and a first memory for storing a computer program capable of running on the processor,

[0128] The first processor is configured to execute the computer program, and perform the steps of any of the methods on the first device side.

[0129] The embodiment of the present application further provides a storage medium, which stores a computer program, and the computer program is executed by a processor to implement the steps of any of the methods on the terminal side or the steps of any of the methods on the first device side.

[0130] The embodiment of the present application further provides a computer program product, which comprises a computer program, and the computer program is executed by a processor to implement the steps of any of the methods on the terminal side or the steps of any of the methods on the first device side.

[0131] The key transmission method, device, related equipment, storage medium and computer program product provided by the embodiments of the present application, the first module on the terminal receives the first key sent by the first device, the first key is encrypted and / or integrity protected based on the second key, and the second key is a shared key between the first device and the first module; the first module generates a third key based on the first key; and the first module receives one or more fourth keys sent by the first device, and the one or more fourth keys are encrypted and / or integrity protected based on the third key. The scheme provided by the embodiments of the present application, when the specific platform (i.e. the first device) charges the key to the security module (i.e. the first module) of the terminal, the charged key (i.e. the fourth key) is encrypted and / or integrity protected based on a specific key (i.e. the third key), and the specific key is generated based on another specific key (i.e. the first key) sent by the specific platform, and the other specific key is encrypted and / or integrity protected based on the shared key (i.e. the second key) between the specific platform and the security module. In this way, a third party cannot obtain the plaintext key during the key transmission process, thereby improving the security of the key transmission process, i.e. improving the security of the key charging process, and protecting and improving the security of the charged key, thereby effectively protecting the secure communication service of the communication network and improving the user experience. BRIEF DESCRIPTION OF DRAWINGS

[0132] Figure 1 A flowchart of a key transmission method according to an embodiment of the present application is shown;

[0133] Figure 2 A flowchart of another key transmission method according to an embodiment of the present application is shown;

[0134] Figure 3 A flowchart of a third key transmission method according to an embodiment of the present application is shown;

[0135] Figure 4 A flowchart of a fourth key transmission method according to an embodiment of the present application is shown;

[0136] Figure 5 A schematic diagram of an application example key relationship according to an embodiment of the present application is shown;

[0137] Figure 6 A flowchart of a single-interface-merged key charging scheme according to an embodiment of the present application is shown;

[0138] Figure 7 A flowchart of a multi-interface-split key charging scheme according to an embodiment of the present application is shown;

[0139] Figure 8 A structure diagram of a key transmission device according to an embodiment of the present application is shown;

[0140] Figure 9 Another key transmission device structure diagram for an embodiment of the application;

[0141] Figure 10 A third key transmission device structure diagram for an embodiment of the application;

[0142] Figure 11 A fourth key transmission device structure diagram for an embodiment of the application;

[0143] Figure 12 A first module structure diagram on a terminal for an embodiment of the application;

[0144] Figure 13 A first device structure diagram for an embodiment of the application;

[0145] Figure 14 A second device structure diagram for an embodiment of the application;

[0146] Figure 15 A third device structure diagram for an embodiment of the application;

[0147] Figure 16 A key transmission system structure diagram for an embodiment of the application. DETAILED DESCRIPTION

[0148] The application will be described in further detail below with reference to the drawings and embodiments.

[0149] In related technologies, in order to improve the security of a business system, a quantum security key (may also be referred to as a quantum key) and other security solutions can be used. The quantum security key technology can be based on the principles of quantum mechanics, and use the non-cloning and non-measuring properties of quantum states to achieve a new encryption communication method. By using the quantum security key, the business system can achieve unconditional secure communication, thereby greatly improving the security of the system. At the same time, the quantum security key has a fast distribution speed, can achieve real-time encryption communication, and can improve communication efficiency. From the above description, it can be seen that using the quantum security key is an effective means to improve the security of the business system, and can guarantee the security of information and the efficiency of communication.

[0150] For the specific implementation of a security solution such as quantum secure key, a key loading manner can be adopted to load a key such as quantum secure key into a secure area of a terminal offline once to construct a key resource pool; a business application can obtain and use the key from the key resource pool. For example, in the case that the secure area of the terminal includes a universal subscriber identity module (USIM, Universal Subscriber Identity Module) card, a hierarchical management manner can be adopted to guarantee the security of the quantum key; specifically, a quantum cryptography service platform can be responsible for generating a secure quantum key; then, the quantum cryptography service platform can batch send the quantum key to a loading platform, and the loading platform can load the quantum key onto the USIM card of the terminal.

[0151] However, the above scheme can have the following problems:

[0152] Problem 1: multiple parties have full keys; for example, the quantum key is batch sent by the quantum cryptography service platform to the loading platform, and then loaded onto the USIM card, which enables the loading platform to obtain the quantum key of all USIM cards in the network as the quantum cryptography service platform does;

[0153] Problem 2: different operators can affect the security of the key; for example, since the operators of the quantum cryptography service platform and the loading platform can be different, the responsibilities of the quantum cryptography service platform and the loading platform can also be different, which can affect the security of the quantum key.

[0154] In summary, the key loading process of the related cryptography technology can have security risks.

[0155] Based on this, in various embodiments of the present application, when a specific platform loads a key to a secure module of a terminal, the loaded key is encrypted and / or integrity protected based on a specific key, which is generated based on another specific key sent by the specific platform, and the other specific key is encrypted and / or integrity protected based on a shared key between the specific platform and the secure module, in this way, a third party cannot obtain the plaintext key in the key transmission process, thereby improving the security of the key transmission process, i.e., improving the security of the key loading process, i.e., at least solving the above problems 1 and 2, and protecting and improving the security of the loaded key, thereby effectively guaranteeing the secure communication service of the communication network and improving the user experience.

[0156] Specifically, the embodiments of the present application provide a key transmission method applied to a terminal, as shown in the following Figure 1 The method comprises the following steps:

[0157] Step 101: a first module on the terminal receives a first key sent by a first device, the first key being encrypted and / or integrity-protected based on a second key, the second key being a shared key between the first device and the first module;

[0158] Step 102: the first module generates a third key based on the first key;

[0159] Step 103: the first module receives at least one fourth key (i.e., one or more fourth keys) sent by the first device, the one or more fourth keys being encrypted and / or integrity-protected based on the third key.

[0160] In actual application, the terminal can also be referred to as a user equipment (UE) and can also be referred to as a user. In addition, the terminal can specifically include a quantum secure terminal and the like. The specific name and type of the terminal are not limited in the embodiments of the present application, as long as the function thereof is implemented.

[0161] In actual application, the first module can also be referred to as a security module and the like, and can be understood as a security area of the terminal. Specifically, the first module can include a USIM card, a subscriber identity module (SIM) card, a super SIM card, a secure digital (SD) card and the like. The specific name and type of the first module are not limited in the embodiments of the present application, as long as the function thereof is implemented.

[0162] In actual application, the first device can be understood as a specific platform having at least a key and / or password service function, such as a password service platform or a quantum password service platform and the like. The specific name and type of the first device are not limited in the embodiments of the present application, as long as the function thereof is implemented. In addition, the fourth key can be understood as a filled key, a key to be filled or a key needing to be filled, and specifically can include a quantum key and the like. The specific name and type of the fourth key are not limited in the embodiments of the present application, as long as the function thereof is implemented.

[0163] In actual application, the first key being encrypted and / or integrity-protected based on a second key means that the first device does not directly send a plaintext of the first key to the first module, but sends ciphertext information (which can be recorded as first information in subsequent description) corresponding to the first key, the ciphertext information being obtained by encrypting and / or integrity-protecting the first key based on the second key by the first device. In addition, the first device can send the ciphertext information to the first module through other devices (which can be recorded as third devices in subsequent description).

[0164] Based on this, in an embodiment, the first module on the terminal receives the first key sent by the first device, which can include:

[0165] The first module receives the first information sent by the third device, wherein the first information is sent by the first device to the third device, and the first information contains a first parameter obtained by encrypting the first key based on the second key.

[0166] In actual application, the third device can be understood as a specific platform having at least a key distribution and / or refilling function, such as a refilling platform, and the embodiments of the present application do not limit the specific name and type of the third device as long as the function is realized. In addition, after the first module receives the first information sent by the first device through the third device, the first key can be obtained by decrypting the first parameter.

[0167] Based on this, in an embodiment, the method can further include:

[0168] The first module decrypts the first parameter based on the second key to obtain the first key.

[0169] In actual application, the first device can use a symmetric encryption algorithm to encrypt the first key based on the second key to obtain the first parameter; and the first module can use a symmetric decryption algorithm to decrypt the first parameter based on the second key to obtain the first key.

[0170] In actual application, the first device can randomly generate the first key. Alternatively, the first device can generate the first key based on one or more of the following parameters, i.e., generate the first key based on at least one of the following parameters:

[0171] The fifth key of the first device;

[0172] The identifier of the terminal;

[0173] The identifier of the first module;

[0174] The first random number.

[0175] In actual application, the fifth key can include a root key of the first device; the identifier of the terminal can include a UE ID, an APP ID, etc.; the identifier of the first module can include a SEID (Secure Equipment Identifier) or a SIED (Secure Environment Identifier), etc.; and the first random number can be generated in a preset specific manner or can be realized by a timestamp.

[0176] In actual application, the first device can send the second key to the first module through another device (which can be referred to as a second device in subsequent description); the second key can be encrypted by the first device based on a public key of the second device, or the second key can be encrypted and / or integrity-protected by the first device based on a shared key between the second device and the first device. Wherein, the second key being encrypted by the first device based on the public key of the second device means that the first device does not directly send the plaintext of the second key, but sends the ciphertext information corresponding to the second key, which is obtained by the first device based on the public key of the second device; the second key being encrypted and / or integrity-protected by the first device based on the shared key between the second device and the first device means that the first device does not directly send the plaintext of the second key, but sends the ciphertext information corresponding to the second key, which is obtained by the first device based on the shared key between the second device and the first device.

[0177] Based on this, in an embodiment, the method can further include:

[0178] The first module receives the second key sent by the second device, and the second key is sent by the first device to the second device.

[0179] In actual application, the second device can be understood as a specific platform having at least a function of producing, maintaining, managing, etc. the first module, such as a card vendor, etc. The specific name and type of the second device are not limited in the embodiments of the present application, as long as the function is realized.

[0180] In an embodiment, the first information can further include one or more of the following (i.e. can include at least one of the following):

[0181] A second random number;

[0182] An identifier of the terminal;

[0183] an identity of the first module;

[0184] a second parameter, the second parameter being obtained by the first device based on the second key performing integrity protection on one or more of the first parameter, a second random number, an identity of the terminal, and an identity of the first module.

[0185] In actual application, the second random number can be generated in a preset specific manner, or can be implemented by a time stamp. In addition, it can be understood that the first device can perform integrity protection calculation on at least one of the first parameter, the second random number, the identity of the terminal, and the identity of the first module based on the second key, so as to obtain the second parameter; in the case that the first information contains the second parameter, the first module can verify the legality of the second parameter, that is, verify the correctness of the second parameter based on the second key.

[0186] Based on this, in an embodiment, the method can further include:

[0187] the first module verifying the correctness of the second parameter based on the second key.

[0188] In actual application, the first module can generate the third key based on only the first key. Alternatively, in the case that the first information contains the second random number, the first module can generate the third key based on the first key and the second random number.

[0189] Based on this, in an embodiment, the method can further include:

[0190] the first module generating the third key based on the first key and the second random number;

[0191] the first module storing the first key and the third key.

[0192] In actual application, the one or more fourth keys being encrypted and / or integrity-protected based on the third key means that the first device does not directly send the plaintext of the one or more fourth keys to the first module, but sends the ciphertext information (which can be recorded as second information in the subsequent description) corresponding to the one or more fourth keys, the ciphertext information being obtained by the first device based on the third key encrypting and / or integrity-protecting the one or more fourth keys. In addition, the first device can send the ciphertext information to the first module through the third device.

[0193] Based on this, in an embodiment, the first module receiving the one or more fourth keys sent by the first device can include:

[0194] The first module receives second information sent by a third device, the second information being sent by the first device to the third device, and the second information comprising a third parameter obtained by encrypting and / or integrity protecting the one or more fourth keys based on the third key.

[0195] In actual application, after the first module receives the second information sent by the first device through the third device, the first key can be obtained by decrypting the third parameter.

[0196] Based on this, in an embodiment, the method can further comprise:

[0197] The first module decrypts the third parameter based on the third key to obtain the one or more fourth keys.

[0198] The first module stores the one or more fourth keys.

[0199] In actual application, the first device can encrypt the one or more fourth keys based on the third key to obtain the third parameter using a symmetric encryption algorithm, and the first module can decrypt the third parameter based on the third key to obtain the one or more fourth keys using a symmetric decryption algorithm.

[0200] In an embodiment, the second information can further comprise one or more of (i.e., can comprise at least one of) the following:

[0201] An identifier of the terminal;

[0202] An identifier of the first module;

[0203] An identifier of the fourth key;

[0204] A fourth parameter obtained by integrity protecting one or more of the third parameter, the identifier of the terminal, the identifier of the first module, and one or more identifiers of the one or more fourth keys based on the third key.

[0205] Here, since the fourth key can be one or more, the identifier of the fourth key can also be one or more, i.e., each fourth key can have a corresponding identifier for indexing.

[0206] In practice, the first device can employ a specific integrity calculation function to perform integrity protection calculation on at least one of the third parameter, the identity of the terminal, the identity of the first module, and one or more identities of the one or more fourth keys based on the third key, thereby obtaining the fourth parameter; correspondingly, in the case where the second information contains the fourth parameter, the first module can verify the legitimacy of the fourth parameter, i.e., can verify the correctness of the fourth parameter based on the third key.

[0207] Based on this, in an embodiment, the method can further include:

[0208] The first module verifies the correctness of the fourth parameter based on the third key.

[0209] In an embodiment, the method can further include:

[0210] The first module updates the third key based on the first key.

[0211] In practice, the first device can trigger the first module to update the third key through the third device.

[0212] Based on this, in an embodiment, the method can further include:

[0213] The first module receives third information sent by a third device, the third information being sent by the first device to the third device, and the third information being used to trigger updating of the third key.

[0214] The third information can contain one or more of the following (i.e., can contain at least one of the following):

[0215] The identity of the terminal;

[0216] The identity of the first module;

[0217] The updated second random number;

[0218] A fifth parameter, the fifth parameter being obtained based on the updated third key performing integrity protection on one or more of the identity of the terminal, the identity of the first module, and the updated second random number.

[0219] In actual application, the first module can update the third key based on the first key. Alternatively, in the case that the third information contains an updated second random number, the first module can generate an updated third key based on the first key and the updated second random number. In addition, the first device can perform integrity protection calculation on at least one of the identity of the terminal, the identity of the first module and the updated second random number based on the updated third key by using a specific integrity calculation function, so as to obtain the fifth parameter; the first module can verify the legitimacy of the fifth parameter, i.e., can verify the correctness of the fifth parameter based on the updated third key.

[0220] Based on this, in an embodiment, the first module updates the third key based on the first key can include:

[0221] The first module generates an updated third key based on the first key and the updated second random number;

[0222] The first module verifies the correctness of the fifth parameter based on the updated third key;

[0223] The first module stores the updated third key.

[0224] Correspondingly, the embodiments of the present application further provide a key transmission method applied to a first device, as shown in the following table: Figure 2 The method includes:

[0225] Step 201: sending a first key to a first module on a terminal, the first key being encrypted and / or integrity protected based on a second key, the second key being a shared key between the first device and the first module;

[0226] Step 202: generating a third key based on the first key;

[0227] Step 203: sending one or more fourth keys to the first module, the one or more fourth keys being encrypted and / or integrity protected based on the third key.

[0228] In an embodiment, the method can further include:

[0229] randomly generating the first key;

[0230] Alternatively,

[0231] generating the first key based on one or more of the following parameters:

[0232] a fifth key of the first device;

[0233] an identity of the terminal;

[0234] an identity of the first module;

[0235] a first random number.

[0236] In an embodiment, the method can further comprise:

[0237] sending, by the second device, the second key to the first module.

[0238] The second key can be encrypted by the first device based on a public key of the second device, or the second key can be encrypted and / or integrity protected by the first device based on a shared key between the second device and the first device.

[0239] In an embodiment, the sending of the first key to the first module on the terminal can comprise:

[0240] sending, by the third device, first information to the first module, the first information comprising a first parameter, the first parameter being obtained by encrypting the first key based on the second key.

[0241] The first information can further comprise one or more of:

[0242] a second random number;

[0243] an identity of the terminal;

[0244] an identity of the first module;

[0245] a second parameter, the second parameter being obtained by integrity protecting one or more of the first parameter, the second random number, the identity of the terminal, and the identity of the first module based on the second key.

[0246] In an embodiment, the generating of the third key based on the first key can comprise:

[0247] generating the third key based on the first key and a second random number;

[0248] storing the first key and the third key.

[0249] In an embodiment, the sending of one or more fourth keys to the first module can comprise:

[0250] sending, by the third device, second information to the first module, the second information comprising a third parameter, the third parameter being obtained by encrypting and / or integrity protecting the one or more fourth keys based on the third key.

[0251] The second information can further include one or more of the following:

[0252] An identifier of the terminal;

[0253] An identifier of the first module;

[0254] An identifier of the fourth key;

[0255] A fourth parameter, the fourth parameter being obtained based on integrity protection of one or more of the third parameter, the identifier of the terminal, the identifier of the first module, and one or more identifiers of the one or more fourth keys by the third key.

[0256] In an embodiment, the method can further include:

[0257] Updating the third key based on the first key.

[0258] In an embodiment, the method can further include:

[0259] Sending, by a third device, third information to the first module, the third information being used to trigger updating the third key.

[0260] The third information can include one or more of the following:

[0261] An identifier of the terminal;

[0262] An identifier of the first module;

[0263] An updated second random number;

[0264] A fifth parameter, the fifth parameter being obtained based on integrity protection of one or more of the identifier of the terminal, the identifier of the first module, and the updated second random number by the updated third key.

[0265] In an embodiment, the updating the third key based on the first key can include:

[0266] Generating the updated third key based on the first key and the updated second random number;

[0267] Storing the updated third key.

[0268] Correspondingly, an embodiment of the present application further provides a key transmission method applied to a second device, as shown in the following Figure 3 The method includes:

[0269] Step 301: receiving a second key sent by a first device, the second key being a shared key between the first device and a first module on a terminal;

[0270] Step 302: sending the second key to the first module.

[0271] Correspondingly, the embodiments of the present application further provide a key transmission method, applied to a third device, as shown in the following table: Figure 4 The method comprises the following steps:

[0272] Step 401: receiving first information sent by a first device, and sending the first information to a first module on a terminal, wherein the first information comprises a first parameter, the first parameter is obtained by encrypting a first key based on a second key, the first key is encrypted and / or integrity protected based on the second key, and the second key is a shared key between the first device and the first module.

[0273] In an embodiment, as shown in the following table, the method can further comprise the following steps: Figure 4

[0274] Step 402: receiving second information sent by the first device, and sending the second information to the first module, wherein the second information comprises a third parameter, the third parameter is obtained by encrypting and / or integrity protecting one or more fourth keys based on a third key, the third key is generated based on the first key, and the one or more fourth keys are encrypted and / or integrity protected based on the third key.

[0275] In an embodiment, as shown in the following table, the method can further comprise the following steps: Figure 4

[0276] Step 403: receiving third information sent by the first device, and sending the third information to the first module, wherein the third information is used to trigger updating the third key.

[0277] ​​The key transmission method provided in the embodiments of the present application comprises the following steps: a first module on a terminal receives a first key sent by a first device, the first key being encrypted and / or integrity protected based on a second key, the second key being a shared key between the first device and the first module; the first module generates a third key based on the first key; and the first module receives one or more fourth keys sent by the first device, the one or more fourth keys being encrypted and / or integrity protected based on the third key. According to the scheme provided in the embodiments of the present application, when a specific platform (i.e., the first device) charges a security module (i.e., the first module) of a terminal with a key, the charged key (i.e., the fourth key) is encrypted and / or integrity protected based on a specific key (i.e., the third key), the specific key being generated based on another specific key (i.e., the first key) sent by the specific platform, and the another specific key being encrypted and / or integrity protected based on a shared key (i.e., the second key) between the specific platform and the security module. In this way, a third party cannot obtain a plaintext key in the key transmission process, thereby improving the security of the key transmission process, i.e., improving the security of the key charging process, i.e., at least solving the above problems 1 and 2, and protecting and improving the security of the charged key, thereby effectively guaranteeing the secure communication service of the communication network and improving the user experience.

[0278] In addition, it should be noted that the specific names of the keys (i.e., the first key, the second key, the third key, the fourth key, and the fifth key) are not limited in the embodiments of the present application, as long as the functions thereof are achieved.

[0279] The present application will be further described in detail in combination with application examples.

[0280] In the application example, the first device is referred to as a quantum cryptography service platform, the second device is referred to as a card vendor, and the third device is referred to as a refilling platform. The first key is referred to as a key encapsulation root key, denoted as RKEK; the second key is referred to as an initial key encapsulation key, denoted as KEK_i; the third key is referred to as a key encapsulation key, denoted as KEK; the fourth key is referred to as a quantum key, denoted as QK, and the identity of the fourth key is denoted as QKID; and the fifth key is referred to as a root key of the quantum cryptography service platform, denoted as RK. The first module includes a USIM card, the identity of the first module includes SEID, and the first module is written with a quantum key service card application (which can be referred to as a quantum key service card application for short), which can be used to implement the method on the terminal side of the above-described embodiments. The first random number is denoted as R_RKEK, and the second random number is denoted as R_KEK. The first parameter is denoted as ERKEK, the second parameter is denoted as RKEK_MAC, the third parameter is denoted as EQKs, the fourth parameter is denoted as QKs_MAC, and the fifth parameter is denoted as KEK_MAC.

[0281] Other related definitions of the application example are explained below.

[0282] H = HASH(m1, m2,...) represents a digest function, that is, a digest value of m1, m2,... can be calculated using a quantum-secure digest algorithm, where the combination of m1, m2,... can include but is not limited to m1||m2||.... E(key, data) represents a symmetric encryption algorithm, key represents a key, and data represents data to be encrypted. D(key, data) represents a symmetric decryption algorithm, key represents a key, and data represents data to be decrypted. Epub(PK, data) represents a public key encryption algorithm, PK represents a public key or a digital certificate, and data represents data to be encrypted. Dpub(SK, data) represents a private key decryption algorithm, SK represents a private key, and data represents data to be decrypted. KDF(key, data_1, data_2,...) represents a key derivation function, key represents a key, and data_x represents derived data, which can be implemented based on HASH or HMAC. HMAC(key, data_1, data_2,...) represents an integrity calculation function, key represents a key, and data_x represents data to be integrity protected.

[0283] The quantum secure terminal (i.e., the terminal described above) refers to a secure terminal device that provides quantum security services for various service applications in the upper layer based on quantum keys. The management of the quantum keys can be specifically responsible for the quantum key service card application on the USIM card (i.e., the first module described above), and provides quantum key services for various APPs in the upper layer. In addition, the quantum key service card application can be responsible for receiving instructions and data from the charging platform (i.e., the third device described above), storing the quantum key to the secure storage area of the quantum key service card application, and completing the charging of the quantum key.

[0284] The quantum cryptography service platform (i.e., the first device described above) can be responsible for interfacing with a quantum random number generator, a quantum key distribution (QKD) node, and the like, thereby generating, managing, and distributing quantum keys. RK can represent a root key of the quantum cryptography service platform (i.e., the fifth key described above), and the quantum cryptography service platform can generate and secretly save RK. RK can be used to derive the key packaging root key RKEK (i.e., the first key described above) of each USIM card. KEK_i represents an initial key packaging key (i.e., the second key described above), and the quantum cryptography service platform can generate and secretly save KEK_i. KEK_i of each USIM card can be the same, and KEK_i can be mainly used to protect the key packaging root key RKEK of each USIM card. PKm represents a public key (such as a digital certificate, etc.) of a card vendor obtained from a secure channel.

[0285] The charging platform (i.e., the third device described above) can receive a charging task from the quantum cryptography service platform (i.e., the first device described above) at a time or in batches, charge the quantum key into the quantum key service card application of the USIM card (i.e., the first module described above), and complete the charging of the quantum key. The card vendor (i.e., the second device described above) refers to the manufacturer of the USIM card, and is mainly responsible for manufacturing blank USIM cards, and can support writing the quantum key service card application and personalized data into the USIM card. (SKm, PKm) represents a public-private key pair (which can include a digital certificate, etc.) that each card vendor owns, and is used to protect the initial packaging key KEK_i (i.e., the second key described above).

[0286] In the application example, the quantum cryptography service platform (i.e., the first device) can use the public key encapsulation encryption technology to securely synchronize the initial key encapsulation key KEK_i (i.e., the second key) with the card vendor (i.e., the second device). In addition, the quantum cryptography service platform and the USIM card (i.e., the first module) can generate and update the key encapsulation key KEK (i.e., the third key) based on the initial key encapsulation key KEK_i. Furthermore, the quantum cryptography service platform and the USIM card can securely inject the key QK (i.e., the fourth key) based on the key encapsulation key KEK, thereby improving the security of the key injection process and achieving the dual separation management of the USIM card access permission (i.e., the permission of the injection platform) and the key management permission (i.e., the permission of the quantum cryptography service platform).

[0287] In the application example, the quantum cryptography service platform (i.e., the first device) can use the public key encapsulation encryption technology to securely synchronize the initial key encapsulation key KEK_i (i.e., the second key) with the card vendor (i.e., the second device). In addition, the quantum cryptography service platform and the USIM card (i.e., the first module) can generate and update the key encapsulation key KEK (i.e., the third key) based on the initial key encapsulation key KEK_i. Furthermore, the quantum cryptography service platform and the USIM card can securely inject the key QK (i.e., the fourth key) based on the key encapsulation key KEK, thereby improving the security of the key injection process and achieving the dual separation management of the USIM card access permission (i.e., the permission of the injection platform) and the key management permission (i.e., the permission of the quantum cryptography service platform).

[0288] Alternatively, the quantum cryptography service platform can use the public key encapsulation encryption technology to securely synchronize the initial key encapsulation key KEK_i (i.e., the second key) with the card vendor (i.e., the second device) through the key injection process based on the key encapsulation key KEK_i, thereby completing the personalization of the key of each quantum key service card application (i.e., generating an independent RKEK for each USIM card (i.e., the first module)); at the same time, completing the generation and update of the key encapsulation key of each quantum key service card application (i.e., generating a new KEK); and completing the quantum key injection of each USIM card.

[0289] The relationship between the keys in the application example is described below. Figure 5 The relationship between the keys in the application example is described below.

[0290] As Figure 5As shown, RK represents the root key (i.e., the fifth key mentioned above), which can be generated and secretly stored by the quantum cryptography service platform (i.e., the first device mentioned above). It can be used to derive the key encapsulation root key RKEK (i.e., the first key mentioned above) for each USIM card. RKEK represents the key encapsulation root key, which can be derived by the quantum cryptography service platform for each USIM card. The RKEK of each USIM card can be different. RKEK can be used to derive the key encapsulation key KEK (i.e., the third key mentioned above) for each USIM card. KEK represents the key encapsulation key, which can be derived by the quantum cryptography service platform and each USIM card based on RKEK. KEK can be used to protect the charging key QK (i.e., the fourth key mentioned above). QK represents the key to be charged (such as a quantum key), which can be generated by the quantum cryptography service platform and charged onto the USIM card through the charging platform (i.e., the third device mentioned above). KEK_i represents the initial key encapsulation key (i.e., the second key mentioned above), which can be generated and secretly stored by the quantum cryptography service platform. The KEK_i of each USIM card can be the same. KEK_i can be used to protect the key encapsulation root key RKEK of each USIM card. (SKm, PKm) represent the unique public-private key pair (which may include digital certificates, etc.) possessed by each card vendor (i.e., the second device mentioned above), used to protect the initial encapsulation key KEK_i. The quantum cryptography service platform can obtain the card vendor's public key PKm (such as digital certificates, etc.) from secure channels.

[0291] The following is combined Figure 6 Describe the key injection scheme for single-interface merging in this application example.

[0292] like Figure 6 As shown, during the preparation phase, the charging platform (i.e., the third device mentioned above) can send the developed quantum key service card application to the card vendor (i.e., the second device mentioned above) through a secure channel. The quantum cryptography service platform (i.e., the first device mentioned above) can encrypt card data in batches and perform the following processing on each card data: protect the initialization encapsulation key KEK_i (i.e., the second key mentioned above) to obtain EKEK_i, that is, calculate EKEK_i = Epub(PKm, KEK_i); set the RKEK (i.e., the first key mentioned above) of the USIM card to empty. Afterwards, the quantum cryptography service platform can send the EKEK_i of each USIM card in batches to the card vendor through a secure channel. The card vendor can decrypt each initialization encapsulation key KEK_i based on EKEK_i, that is, calculate KEK_i = Dpub(SKm, EKEK_i), and can write the quantum key service card application to the USIM card in batches, while writing KEK_i to the secure area of ​​each USIM card. Finally, the card vendor can securely synchronize the list of USIM card identifiers (SEIDs, i.e., the identifiers from the first module mentioned above) to the filling platform and the quantum cryptography service platform.

[0293] In the charging phase, when the charging platform (i.e., the third device described above) receives a quantum key charging task, it can prepare a QK (i.e., the fourth key described above) requirement list {SEID, QKN}_i (where i = 1, …, n; n is an integer greater than 1) according to the task requirements, where QKN represents the number of quantum keys that need to be generated. Then, the charging platform can send a charging key acquisition request to the quantum cryptography service platform (i.e., the first device described above), which can contain {SEID, QKN}_i.

[0294] The quantum cryptography service platform can perform the following processing for each pair (SEID, QKN)_i:

[0295] 1) If there is no RKEK (i.e., the first key described above) or the RKEK needs to be updated, then generate the RKEK and the KEK (i.e., the third key described above). Specifically, generate R_RKEK (i.e., the first random number), i.e., generate a random number or a timestamp; derive the RKEK based on the RK (i.e., the fifth key described above) and the random number, i.e., calculate RKEK = KDF(RK, SEID, R_RKEK); encrypt the RKEK based on the KEK_i (i.e., the second key described above), i.e., calculate ERKEK = E(KEK_i, RKEK); also generate R_KEK (i.e., the second random number), i.e., generate a random number or a timestamp; derive the KEK based on the RKEK and the random number, i.e., calculate KEK = KDF(RKEK, R_KEK); and finally perform integrity protection calculation, i.e., calculate RKEK_MAC = HMAC(KEK_i, SEID, ERKEK, R_KEK, …).

[0296] 2) If the KEK needs to be updated (at this time there is already an RKEK), then generate a new KEK. Specifically, generate R_KEK, i.e., generate a random number or a timestamp; derive the KEK based on the RKEK and the random number, i.e., calculate KEK = KDF(RKEK, R_KEK); and finally perform integrity protection calculation, i.e., calculate KEK_MAC = HMAC(KEK, SEID, R_KEK, …).

[0297] 3) If there are RKEK and KEK, and the RKEK and KEK do not need to be updated, then package the quantum keys QKs. Specifically, generate a quantum key set QKs = {QK1, QK2, …, QKm} and the corresponding QKIDs = {QKID1, QKID2, …, QKIDm}, where m is an integer greater than 1; also encrypt the QKs based on the KEK, i.e., calculate EQKs = E(KEK, QKs); and finally perform integrity protection calculation, i.e., calculate QKs_MAC = HMAC(KEK, SEID, QKIDs, EQKs, …).

[0298] After that, the quantum cryptography service platform can return the recharging key acquisition response to the recharging platform, and the response can include {SEID, [ERKEK, R_KEK, RKEK_MAC], [R_KEK, KEK_MAC], QKIDs, EQKs, QKs_MAC}_i, i = 1, …, n; n is an integer greater than 1. Wherein, [xxx] can represent that there can be no such parameter, that is, [ERKEK, R_KEK, RKEK_MAC] and [R_KEK, KEK_MAC] can be optional parameters. Here, {SEID, QKIDs, EQKs, QKs_MAC}_i can represent the first information described above, [ERKEK, R_KEK, RKEK_MAC] can represent the second information described above, and [R_KEK, KEK_MAC] can represent the third information described above. After that, the recharging platform can assemble the data according to the instructions of the USIM card and send a key recharging request to the quantum key service card application, and the request can include {SEID, [ERKEK, R_KEK, RKEK_MAC], [R_KEK, KEK_MAC], QKIDs, EQKs, QKs_MAC}_i; that is, the quantum cryptography service platform can send one or more of the first information, the second information and the third information described above to the quantum key service card application through the recharging platform.

[0299] The quantum key service card application can perform the following processing for each SEIDi:

[0300] 1) If [ERKEK, R_KEK, RKEK_MAC] is received, that is, the first information described above is received, it is necessary to save the new RKEK and KEK. Specifically, the RKEK_MAC can be verified for legality, and the RKEK can be decrypted based on KEK_i, that is, RKEK = D(KEK_i, ERKEK) is calculated; the KEK can also be derived based on the RKEK and the random number, that is, KEK = KDF(RKEK, R_KEK) is calculated; finally, the RKEK can be safely saved, and the KEK can be saved.

[0301] 2) If [R_KEK, KEK_MAC] is received, that is, the third information described above is received, it is necessary to save the new KEK, that is, to update the KEK. Specifically, the KEK can be derived based on the RKEK and the random number, that is, KEK = KDF(RKEK, R_KEK) is calculated, and the KEK_MAC can be verified for legality; finally, the KEK can be safely saved.

[0302] 3) If EQKs and QKs_MAC are received, i.e., the first information mentioned above is received, the quantum key QKs can be decrypted (at this point, RKEK and KEK are already available). Specifically, the validity of QKs_MAC can be verified, and QK can be decrypted based on KEK, i.e., QKs = D(KEK, EQKs) can be calculated; finally, QK can be written locally, i.e., QKs = {QK1, QK2, ..., QKn} and the corresponding QKIDs = {QKID1, QKID2, ..., QKIDn} can be written.

[0303] Subsequently, the quantum key distribution card application can return a key filling result response to the filling platform; the filling platform can then return a key filling result response to the quantum cryptography service platform. The quantum cryptography service platform can perform the following processing:

[0304] If a new RKEK and KEK are created, the RKEK and KEK corresponding to the SEID are safely overwritten and saved.

[0305] If the KEK is updated, the KEK corresponding to the SEID is securely overwritten and saved.

[0306] Configure the charging status of each QKs key.

[0307] The following is combined Figure 7 This describes the key injection scheme for multi-interface splitting in this application example.

[0308] like Figure 7 As shown, during the preparation phase, the charging platform (i.e., the third device mentioned above) can send the developed quantum key service card application to the card vendor (i.e., the second device mentioned above) through a secure channel. The quantum cryptography service platform (i.e., the first device mentioned above) can encrypt card data in batches and perform the following processing on each card data: protect the initialization encapsulation key KEK_i (i.e., the second key mentioned above) to obtain EKEK_i, that is, calculate EKEK_i = Epub(PKm, KEK_i); set the RKEK (i.e., the first key mentioned above) of the USIM card to empty. Afterwards, the quantum cryptography service platform can send the EKEK_i of each USIM card in batches to the card vendor through a secure channel. The card vendor can decrypt each initialization encapsulation key KEK_i based on EKEK_i, that is, calculate KEK_i = Dpub(SKm, EKEK_i), and can write the quantum key service card application to the USIM card in batches, while writing KEK_i to the secure area of ​​each USIM card. Finally, the card vendor can securely synchronize the list of USIM card identifiers (SEIDs, i.e., the identifiers from the first module mentioned above) to the filling platform and the quantum cryptography service platform.

[0309] The filling phase may include the following three sub-processes:

[0310] Flow 1, RKEK and KEK initialization flow;

[0311] Flow 2, KEK update flow;

[0312] Flow 3, Key refill flow.

[0313] Wherein, for the above flow 1, if the USIM card is not initialized (i.e. the first time using the USIM card), i.e. the USIM card has no RKEK, the RKEK and KEK initialization flow can be run. First, the refill platform can send an RKEK initialization request to the quantum cryptography service platform, which can contain one or more SEIDs.

[0314] Then, the quantum cryptography service platform can perform the following processing for each SEID:

[0315] 1) If there is no corresponding RKEK or the RKEK needs to be updated, generate the RKEK and KEK. Specifically, R_RKEK can be generated, i.e. a random number or a timestamp; RKEK can be derived based on RK and the random number, i.e. RKEK = KDF(RK, SEID, R_RKEK) is calculated; RKEK can be encrypted based on KEK_i, i.e. ERKEK = E(KEK_i, RKEK) is calculated; R_KEK (random number or timestamp) can also be generated; KEK can be derived based on RKEK and the random number, i.e. KEK = KDF(RKEK, R_KEK) is calculated; and integrity protection calculation can be performed, i.e. RKEK_MAC = HMAC(KEK_i, SEID, ERKEK, R_KEK,...) is calculated;

[0316] 2) If there is a corresponding RKEK and the RKEK does not need to be updated, return an RKEK no update message to the refill platform.

[0317] Then, the quantum cryptography service platform can return an RKEK and KEK initialization response to the refill platform, which can contain SEID, ERKEK, R_KEK, RKEK_MAC, i.e. the response can contain the above first information; the refill platform can send an RKEK and KEK initialization request to the quantum key service card application, which can contain SEID, ERKEK, R_KEK, RKEK_MAC, i.e. the request can contain the above first information.

[0318] Then, the quantum key service card application can perform the following processing: verify the legality of RKEK_MAC; decrypt RKEK based on KEK_i, i.e. RKEK = D(KEK_i, ERKEK) is calculated; derive KEK based on RKEK and the random number, i.e. KEK = KDF(RKEK, R_KEK) is calculated; and finally, RKEK can be safely saved, and KEK can be saved.

[0319] Afterwards, the quantum key service card application can return the RKEK and KEK initialization response to the refilling platform; the refilling platform can return the RKEK and KEK initialization response to the quantum cryptography service platform; and the quantum cryptography service platform can securely save the RKEK and KEK corresponding to the SEID.

[0320] For the above flow 2, if the USIM card does not exist the corresponding KEK or the KEK needs to be updated, the KEK update flow is run. First, the refilling platform can send a KEK update request to the quantum cryptography service platform, which can contain one or more SEIDs.

[0321] Afterwards, the quantum cryptography service platform can perform the following processing for each SEID:

[0322] 1) If the corresponding RKEK exists and the KEK needs to be updated, a new KEK is generated; specifically, R_KEK, i.e., a random number or a timestamp, is generated; the KEK is derived based on the RKEK and the random number, i.e., KEK = KDF(RKEK, R_KEK) is calculated; and the integrity protection calculation is performed, i.e., KEK_MAC = HMAC(KEK, SEID, R_KEK,...) is calculated.

[0323] 2) If the corresponding RKEK exists and the RKEK does not need to be updated, a KEK does not need to be updated message is returned.

[0324] 3) If the corresponding RKEK does not exist, a no RKEK message is returned.

[0325] Afterwards, the quantum cryptography service platform can return a KEK update response to the refilling platform, which can contain the SEID, R_KEK, and KEK_MAC, i.e., the response can contain the third information described above; the refilling platform can send a KEK update request to the quantum key service card application, which can contain the SEID, R_KEK, and KEK_MAC, i.e., the request can contain the third information described above.

[0326] Afterwards, the quantum key service card application can perform the following processing: the KEK is derived based on the RKEK and the random number, i.e., KEK = KDF(RKEK, R_KEK) is calculated; the KEK_MAC is verified for legality; and finally, the KEK is securely overwritten and saved.

[0327] Afterwards, the quantum key service card application can return a KEK update response to the refilling platform; the refilling platform can return a KEK update response to the quantum cryptography service platform; and the quantum cryptography service platform can securely save the KEK corresponding to the SEID.

[0328] For the above flow 3, if the USIM card does not need to be initialized and / or the KEK does not need to be updated, the key top-up flow is run. First, the top-up platform can perform the following processing for each USIM card: when the top-up platform (i.e., the third device described above) receives a quantum key top-up task, it can prepare a QK (i.e., the fourth key described above) demand list {SEID, QKN}_i according to the task requirements, where i = 1, …, n; n is an integer greater than 1, and QKN represents the number of quantum keys that need to be generated. Then, the top-up platform can send a top-up key acquisition request to the quantum cryptography service platform, which can include {SEID, QKN}_i.

[0329] Then, the quantum cryptography service platform can perform the following processing for each pair (SEID, QKN)_i:

[0330] 1) When there is an RKEK and a KEK, and the RKEK and the KEK do not need to be updated, the quantum key QKs can be packaged; specifically, a quantum key set QKs = {QK1, QK2, …, QKm} and corresponding QKIDs = {QKID1, QKID2, …, QKIDm} can be generated; QKs is encrypted based on KEK, i.e., EQKs = E(KEK, QKs) is calculated; and an integrity protection calculation can be performed, i.e., QKs_MAC = HMAC(KEK, SEID, QKIDs, EQKs, …) is calculated.

[0331] 2) If there is no corresponding RKEK and / or KEK, an error message response is returned.

[0332] Then, the quantum cryptography service platform can return a top-up key acquisition response to the top-up platform, which can include {SEID, QKIDs, EQKs, QKs_MAC}_i, (where i = 1, …, n; n is an integer greater than 1), i.e., the response can include the first information described above; the top-up platform can assemble the data according to the instructions of the USIM card, and send a key top-up request to the quantum key service card application, which can include {SEID, QKIDs, EQKs, QKs_MAC}_i, i.e., the request can include the first information described above.

[0333] Then, the quantum key service card application can perform the following processing for each SEID_i: decrypt the quantum key QKs (at this time, there is a corresponding RKEK and KEK); verify the QKs_MAC legitimacy; decrypt the QK based on the KEK, i.e., QKs = D(KEK, EQKs) is calculated; and finally, the QK can be written locally, i.e., QKs = {QK1, QK2, …, QKn} and corresponding QKIDs = {QKID1, QKID2, …, QKIDn} are written.

[0334] Afterwards, the quantum key service card application can return a key recharge result response to the recharge platform; the recharge platform can return the key recharge result response to the quantum cryptography service platform; and the quantum cryptography service platform can set the recharge state of each key of the QKs.

[0335] The scheme provided by the application example has the following advantages:

[0336] 1) The quantum cryptography service platform is the only entity that owns all the keys, and neither the card vendor nor the recharge platform can obtain the recharged quantum keys, thereby enabling double separation management of the USIM card access authority (i.e., the authority of the recharge platform) and the key management authority (i.e., the authority of the quantum cryptography service platform), and improving the security of the key recharge process;

[0337] 2) In the recharge process, the recharge keys are generated and securely packaged by the quantum cryptography service platform, and are written into the USIM card by the recharge platform, so that a third party cannot obtain the plaintext keys in the process, thereby facilitating the protection and improvement of the security of the quantum keys;

[0338] 3) The quantum cryptography service platform can update the key packaging key at any time according to the security policy requirements, thereby preventing the security risks that may be caused by long-term use of the key packaging key, and facilitating the protection and improvement of the security of the quantum keys.

[0339] In order to implement the method of the terminal side of the application embodiment, the application embodiment further provides a key transmission device, which is arranged on a first module on the terminal, as shown in Figure 8 The device comprises:

[0340] A first receiving unit 801 is configured to receive a first key sent by a first device, wherein the first key is encrypted and / or integrity-protected based on a second key, and the second key is a shared key between the first device and the first module;

[0341] A first processing unit 802 is configured to generate a third key based on the first key;

[0342] A second receiving unit 803 is configured to receive one or more fourth keys sent by the first device, wherein the one or more fourth keys are encrypted and / or integrity-protected based on the third key.

[0343] In an embodiment, as shown in Figure 8 The device can further comprise:

[0344] A third receiving unit 804 is configured to receive the second key sent by a second device, wherein the second key is sent by the first device to the second device.

[0345] In an embodiment, the first receiving unit 801 is specifically configured to receive first information sent by a third device, the first information being sent by the first device to the third device, and the first information comprising a first parameter, the first parameter being obtained by encrypting the first key based on the second key.

[0346] In an embodiment, the first processing unit 802 is further configured to decrypt the first parameter based on the second key to obtain the first key.

[0347] In an embodiment, the first processing unit 802 is further configured to verify the correctness of the second parameter based on the second key.

[0348] In an embodiment, the first processing unit 802 is further configured to:

[0349] generate the third key based on the first key and a second random number;

[0350] store the first key and the third key.

[0351] In an embodiment, the second receiving unit 803 is specifically configured to receive second information sent by a third device, the second information being sent by the first device to the third device, and the second information comprising a third parameter, the third parameter being obtained by encrypting and / or integrity protecting the one or more fourth keys based on the third key.

[0352] In an embodiment, the first processing unit 802 is further configured to:

[0353] decrypt the third parameter based on the third key to obtain the one or more fourth keys;

[0354] store the one or more fourth keys.

[0355] In an embodiment, the first processing unit 802 is further configured to verify the correctness of the fourth parameter based on the third key.

[0356] In an embodiment, the first processing unit 802 is further configured to update the third key based on the first key.

[0357] In an embodiment, as shown in FIG. 8, Figure 8 the apparatus can further include:

[0358] a fourth receiving unit 805, configured to receive third information sent by a third device, the third information being sent by the first device to the third device, and the third information being used to trigger updating of the third key.

[0359] In an embodiment, the first processing unit 802 is further configured to:

[0360] generate an updated third key based on the first key and the updated second random number;

[0361] verify the correctness of the fifth parameter based on the updated third key;

[0362] store the updated third key.

[0363] In actual application, the first receiving unit 801, the second receiving unit 803, the third receiving unit 804 and the fourth receiving unit 805 can be implemented by a communication interface in a key transmission device; and the first processing unit 802 can be implemented by a processor in the key transmission device.

[0364] To implement the method of the first device side in the embodiments of the present application, the embodiments of the present application further provide a key transmission device arranged on a first device, as shown in Figure 9 The device comprises:

[0365] A first sending unit 901 is configured to send a first key to a first module on a terminal, the first key being encrypted and / or integrity protected based on a second key, the second key being a shared key between the first device and the first module;

[0366] A second processing unit 902 is configured to generate a third key based on the first key;

[0367] A second sending unit 903 is configured to send one or more fourth keys to the first module, the one or more fourth keys being encrypted and / or integrity protected based on the third key.

[0368] In an embodiment, the second processing unit 902 is further configured to:

[0369] randomly generate the first key;

[0370] Alternatively,

[0371] generate the first key based on one or more of the following parameters:

[0372] a fifth key of the first device;

[0373] an identity of the terminal;

[0374] an identity of the first module;

[0375] a first random number.

[0376] In an embodiment, as shown in Figure 9 The device can further comprise:

[0377] The third sending unit 904 is configured to send the second key to the first module by the second device.

[0378] In an embodiment, the first sending unit 901 is specifically configured to send first information to the first module by the third device, and the first information comprises a first parameter, which is obtained by encrypting the first key based on the second key.

[0379] In an embodiment, the second processing unit 902 is further configured to:

[0380] generate the third key based on the first key and the second random number;

[0381] store the first key and the third key.

[0382] In an embodiment, the second sending unit 903 is specifically configured to send second information to the first module by the third device, and the second information comprises a third parameter, which is obtained by encrypting and / or integrity protecting the one or more fourth keys based on the third key.

[0383] In an embodiment, the second processing unit 902 is further configured to update the third key based on the first key.

[0384] In an embodiment, as shown in Figure 9 the apparatus can further include:

[0385] The fourth sending unit 905 is configured to send third information to the first module by the third device, and the third information is used to trigger updating the third key.

[0386] In an embodiment, the second processing unit 902 is further configured to:

[0387] generate an updated third key based on the first key and an updated second random number;

[0388] store the updated third key.

[0389] In actual application, the first sending unit 901, the second sending unit 903, the third sending unit 904 and the fourth sending unit 905 can be implemented by a communication interface in a key transmission apparatus; and the second processing unit 902 can be implemented by a processor in the key transmission apparatus.

[0390] In order to implement the method on the second device side in the embodiments of the present application, the embodiments of the present application further provide a key transmission apparatus arranged on a second device, as shown in Figure 10 the apparatus includes:

[0391] a fifth receiving unit 1001, configured to receive a second key sent by the first device, the second key being a shared key between the first device and the first module on the terminal;

[0392] a fifth sending unit 1002, configured to send the second key to the first module.

[0393] In actual application, the fifth receiving unit 1001 and the fifth sending unit 1002 can be implemented by a communication interface in the key transmission apparatus.

[0394] In order to implement the method on the third device side in the embodiments of the present application, the embodiments of the present application further provide a key transmission apparatus arranged on a third device, as shown in the following Figure 11 The apparatus comprises:

[0395] a first transmission unit 1101, configured to receive first information sent by the first device and send the first information to the first module on the terminal, the first information containing a first parameter, the first parameter being obtained by encrypting a first key based on a second key, the first key being encrypted and / or integrity-protected based on the second key, the second key being a shared key between the first device and the first module.

[0396] In an embodiment, as shown in the following Figure 11 The apparatus can further comprise:

[0397] a second transmission unit 1102, configured to receive second information sent by the first device and send the second information to the first module, the second information containing a third parameter, the third parameter being obtained by encrypting and / or integrity-protecting one or more fourth keys based on a third key, the third key being generated based on the first key, the one or more fourth keys being encrypted and / or integrity-protected based on the third key.

[0398] In an embodiment, as shown in the following Figure 11 The apparatus can further comprise:

[0399] a third transmission unit 1103, configured to receive third information sent by the first device and send the third information to the first module, the third information being used to trigger updating the third key.

[0400] In actual application, the first transmission unit 1101, the second transmission unit 1102 and the third transmission unit 1103 can be implemented by a communication interface in the key transmission apparatus.

[0401] It should be noted that the key transmission device provided by the above-mentioned embodiments only takes the division of the above-mentioned program modules as an example when transmitting the key. In actual application, the above-mentioned processing can be completed by different program modules according to needs, that is, the internal structure of the device is divided into different program modules to complete all or part of the above-mentioned processing. In addition, the key transmission device and the key transmission method provided by the above-mentioned embodiments belong to the same concept, and the specific implementation process is detailed in the method embodiments, which will not be repeated here.

[0402] Based on the hardware implementation of the above-mentioned program modules, and in order to realize the method of the terminal side of the embodiment of the application, the embodiment of the application further provides a terminal, which comprises a first module, as shown in the figure, the first module 1200 comprises: Figure 12

[0403] The first communication interface 1201 can interact with other devices (such as the first device, the second device, the third device, etc.) to exchange information;

[0404] The first processor 1202 is connected with the first communication interface 1201 to realize information interaction with other devices, and is used to run a computer program to execute the method provided by one or more technical solutions of the terminal side described above;

[0405] The first memory 1203 stores the computer program.

[0406] Specifically, the first processor 1202 is configured to:

[0407] Receive the first key sent by the first device through the first communication interface 1201, the first key is encrypted and / or integrity protected based on the second key, and the second key is a shared key between the first device and the first module 1200;

[0408] Generate a third key based on the first key;

[0409] Receive one or more fourth keys sent by the first device through the first communication interface 1201, the one or more fourth keys are encrypted and / or integrity protected based on the third key.

[0410] In an embodiment, the first processor 1202 is further configured to receive the second key sent by the second device through the first communication interface 1201, and the second key is sent by the first device to the second device.

[0411] ​In an embodiment, the first processor 1202 is further configured to receive, by the first communication interface 1201, first information sent by a third device, the first information being sent by the first device to the third device, the first information comprising a first parameter, the first parameter being obtained by encrypting the first key based on the second key.

[0412] In an embodiment, the first processor 1202 is further configured to decrypt the first parameter based on the second key to obtain the first key.

[0413] In an embodiment, the first processor 1202 is further configured to verify correctness of the second parameter based on the second key.

[0414] In an embodiment, the first processor 1202 is further configured to:

[0415] generate the third key based on the first key and a second random number;

[0416] store the first key and the third key.

[0417] In an embodiment, the first processor 1202 is further configured to receive, by the first communication interface 1201, second information sent by a third device, the second information being sent by the first device to the third device, the second information comprising a third parameter, the third parameter being obtained by encrypting and / or integrity protecting the one or more fourth keys based on the third key.

[0418] In an embodiment, the first processor 1202 is further configured to:

[0419] decrypt the third parameter based on the third key to obtain the one or more fourth keys;

[0420] store the one or more fourth keys.

[0421] In an embodiment, the first processor 1202 is further configured to verify correctness of the fourth parameter based on the third key.

[0422] In an embodiment, the first processor 1202 is further configured to update the third key based on the first key.

[0423] In an embodiment, the first processor 1202 is further configured to receive, by the first communication interface 1201, third information sent by a third device, the third information being sent by the first device to the third device, the third information being used to trigger updating the third key.

[0424] In an embodiment, the first processor 1202 is further configured to:

[0425] generate an updated third key based on the first key and the updated second random number;

[0426] verify the correctness of the fifth parameter based on the updated third key;

[0427] store the updated third key.

[0428] It should be noted that the specific processing process of the first processor 1202 can be understood with reference to the above method, which will not be repeated here.

[0429] Of course, in actual application, various components in the first module 1200 are coupled together through the bus system 1204. It can be understood that the bus system 1204 is used to realize the connection and communication between the components. The bus system 1204 includes not only a data bus, but also a power bus, a control bus and a status signal bus. However, for the purpose of clear illustration, all kinds of buses are marked as the bus system 1204 in the figure. Figure 12

[0430] The first memory 1203 in the embodiment of the present application is used to store various types of data to support the operation of the first module 1200. Examples of these data include: any computer program used for operation on the first module 1200.

[0431] The method disclosed in the above embodiment of the present application can be applied to or implemented by the first processor 1202. The first processor 1202 can be an integrated circuit chip with signal processing capability. In the implementation process, each step of the above method can be completed by integrated logic circuits of hardware or instructions in the form of software in the first processor 1202. The above first processor 1202 can be a general-purpose processor, a digital signal processor (DSP), or other programmable logic devices, discrete gates or transistor logic devices, discrete hardware components, etc. The first processor 1202 can implement or execute the disclosed methods, steps and logic block diagrams in the embodiments of the present application. The general-purpose processor can be a microprocessor or any conventional processor. In combination with the steps of the method disclosed in the embodiments of the present application, the hardware decoding processor can be directly embodied to execute the above method, or the combination of hardware and software modules in the decoding processor can be executed. The software module can be located in a storage medium, which is located in the first memory 1203, and the first processor 1202 reads the information in the first memory 1203 and combines the hardware to complete the steps of the above method.

[0432] ​In an exemplary embodiment, the first module 1200 can be implemented by one or more Application Specific Integrated Circuits (ASICs), DSPs, Programmable Logic Devices (PLDs), Complex Programmable Logic Devices (CPLDs), Field-Programmable Gate Arrays (FPGAs), general-purpose processors, controllers, microcontrollers (MCUs), microprocessors (Microprocessors), or other electronic elements, for executing the foregoing methods.

[0433] Based on the hardware implementation of the foregoing program modules, and in order to implement the method of the first device side of the embodiments of the present application, the embodiments of the present application further provide a first device, as shown in the figure, the first device 1300 comprises: Figure 13

[0434] a second communication interface 1301 capable of information interaction with other devices (such as a second device, a third device, a terminal, etc.);

[0435] a second processor 1302 connected with the second communication interface 1301 to realize information interaction with other devices, for running a computer program, executing the method provided by one or more technical solutions of the first device side described above;

[0436] a second memory 1303, wherein the computer program is stored on the second memory 1303.

[0437] Specifically, the second processor 1302 is configured to:

[0438] send a first key to the first module on the terminal through the second communication interface 1301, wherein the first key is encrypted and / or integrity protected based on a second key, and the second key is a shared key between the first device 1300 and the first module;

[0439] generate a third key based on the first key;

[0440] send one or more fourth keys to the first module through the second communication interface 1301, wherein the one or more fourth keys are encrypted and / or integrity protected based on the third key.

[0441] In an embodiment, the second processor 1302 is further configured to: ​

[0442] generating the first key randomly;

[0443] or,

[0444] generating the first key based on one or more of the following parameters:

[0445] a fifth key of the first device 1300;

[0446] an identity of the terminal;

[0447] an identity of the first module;

[0448] a first random number.

[0449] In an embodiment, the second communication interface 1301 is further configured to send, by a second device, the second key to the first module.

[0450] In an embodiment, the second communication interface 1301 is further configured to send, by a third device, first information to the first module, the first information comprising a first parameter, the first parameter being obtained by encrypting the first key based on the second key.

[0451] In an embodiment, the second processor 1302 is further configured to:

[0452] generate the third key based on the first key and a second random number;

[0453] store the first key and the third key.

[0454] In an embodiment, the second communication interface 1301 is further configured to send, by a third device, second information to the first module, the second information comprising a third parameter, the third parameter being obtained by encrypting and / or integrity protecting the one or more fourth keys based on the third key.

[0455] In an embodiment, the second processor 1302 is further configured to update the third key based on the first key.

[0456] In an embodiment, the second communication interface 1301 is further configured to send, by a third device, third information to the first module, the third information being used to trigger updating the third key.

[0457] In an embodiment, the second processor 1302 is further configured to:

[0458] generate an updated third key based on the first key and an updated second random number;

[0459] store the updated third key.

[0460] It should be noted that the specific process of the second communication interface 1301 and the second processor 1302 can be understood with reference to the above method, which will not be described here.

[0461] Of course, in actual application, various components in the first device 1300 are coupled together through the bus system 1304. It can be understood that the bus system 1304 is used to realize the connection communication between the components. The bus system 1304 includes not only a data bus, but also a power bus, a control bus and a status signal bus. However, for the purpose of clear illustration, all kinds of buses are marked as the bus system 1304 in the Figure 13

[0462] The second memory 1303 in the embodiment of the present application is used to store various types of data to support the operation of the first device 1300. Examples of these data include: any computer program used for operation on the first device 1300.

[0463] The method disclosed in the above embodiment of the present application can be applied to the second processor 1302 or implemented by the second processor 1302. The second processor 1302 can be an integrated circuit chip with signal processing capability. In the implementation process, each step of the above method can be completed by the integrated logic circuit of hardware or the instruction in the form of software in the second processor 1302. The above second processor 1302 can be a general-purpose processor, DSP, or other programmable logic device, discrete gate or transistor logic device, discrete hardware component, etc. The second processor 1302 can implement or execute the disclosed methods, steps and logic block diagrams in the embodiments of the present application. The general-purpose processor can be a microprocessor or any conventional processor, etc. In combination with the steps of the method disclosed in the embodiments of the present application, the hardware decoding processor can be directly embodied to execute the completion, or the combination of hardware and software modules in the decoding processor can be executed to complete. The software module can be located in the storage medium, which is located in the second memory 1303, and the second processor 1302 reads the information in the second memory 1303, and combines the hardware to complete the steps of the above method.

[0464] In the exemplary embodiment, the first device 1300 can be implemented by one or more ASICs, DSPs, PLDs, CPLDs, FPGAs, general-purpose processors, controllers, MCUs, Microprocessors, or other electronic elements, for executing the above method.

[0465] Based on the hardware implementation of the above program module, and in order to implement the method of the second device side in the embodiments of the present application, the embodiments of the present application also provide a second device, as shown in the figure, which includes: Figure 14 as shown in the figure, the second device 1400 includes: ​

[0466] The third communication interface 1401 is capable of information interaction with other devices (such as the first device, terminal, etc.);

[0467] The third processor 1402 is connected with the third communication interface 1401 to realize information interaction with other devices, and is used to run a computer program to execute the method provided by one or more technical solutions of the second device side;

[0468] The third memory 1403 stores the computer program.

[0469] Specifically, the third communication interface 1401 is configured to:

[0470] receive the second key sent by the first device, the second key being a shared key between the first device and the first module on the terminal;

[0471] send the second key to the first module.

[0472] It should be noted that the specific processing process of the third communication interface 1401 can be understood with reference to the above method, which will not be described here.

[0473] Of course, in actual application, various components in the second device 1400 are coupled together through the bus system 1404. It can be understood that the bus system 1404 is used to realize the connection communication between the components. The bus system 1404 includes not only a data bus, but also a power bus, a control bus and a status signal bus. However, in order to clearly illustrate, various buses are marked as the bus system 1404 in the Figure 14 .

[0474] The third memory 1403 in the embodiment of the application is used to store various types of data to support the operation of the second device 1400. Examples of these data include: any computer program used to operate on the second device 1400.

[0475] The method disclosed by the embodiments of the present application can be applied to the third processor 1402 or implemented by the third processor 1402. The third processor 1402 can be an integrated circuit chip with signal processing capability. In the implementation process, each step of the above method can be completed by the integrated logic circuit of hardware in the third processor 1402 or the instruction in the form of software. The third processor 1402 described above can be a general processor, a DSP, or other programmable logic devices, discrete gate or transistor logic devices, discrete hardware components, etc. The third processor 1402 can implement or execute the methods, steps and logic block diagrams disclosed in the embodiments of the present application. The general processor can be a microprocessor or any conventional processor, etc. In combination with the steps of the method disclosed in the embodiments of the present application, the hardware decoding processor can be directly embodied to execute the steps of the method, or the combination of hardware and software modules in the decoding processor can be executed. The software module can be located in the storage medium, which is located in the third memory 1403, and the third processor 1402 reads the information in the third memory 1403, and combines the hardware to complete the steps of the method.

[0476] In the exemplary embodiments, the second device 1400 can be implemented by one or more ASICs, DSPs, PLDs, CPLDs, FPGAs, general-purpose processors, controllers, MCUs, microprocessors, or other electronic elements for executing the foregoing method.

[0477] Based on the hardware implementation of the above program module, and in order to implement the method of the third device side in the embodiments of the present application, the embodiments of the present application further provide a third device, as shown in the following Figure 15 The third device 1500 includes:

[0478] The fourth communication interface 1501 can interact with other devices (such as the first device, the terminal, etc.) to exchange information;

[0479] The fourth processor 1502 is connected with the fourth communication interface 1501 to realize information interaction with other devices, and is used to run the computer program to execute the method provided by one or more technical solutions of the third device side;

[0480] The fourth memory 1503 stores the computer program.

[0481] Specifically, the fourth communication interface 1501 is configured to receive first information sent by the first device, and send the first information to a first module on the terminal, the first information comprising a first parameter, the first parameter being obtained by encrypting a first key based on a second key, the first key being encrypted and / or integrity-protected based on the second key, and the second key being a shared key between the first device and the first module.

[0482] In an embodiment, the fourth communication interface 1501 is further configured to receive second information sent by the first device, and send the second information to the first module, the second information comprising a third parameter, the third parameter being obtained by encrypting and / or integrity-protecting one or more fourth keys based on a third key, the third key being generated based on the first key, and the one or more fourth keys being encrypted and / or integrity-protected based on the third key.

[0483] In an embodiment, the fourth communication interface 1501 is further configured to receive third information sent by the first device, and send the third information to the first module, the third information being used to trigger updating of the third key.

[0484] It should be noted that the specific processing process of the fourth communication interface 1501 can be understood with reference to the above method, which will not be described here.

[0485] Of course, in actual application, various components in the third device 1500 are coupled together through the bus system 1504. It can be understood that the bus system 1504 is used to realize the connection and communication between the components. In addition to including a data bus, the bus system 1504 also includes a power bus, a control bus and a status signal bus. However, in order to clearly illustrate the application, various buses are marked as the bus system 1504 in the Figure 15 .

[0486] The fourth memory 1503 in the embodiment of the application is used to store various types of data to support the operation of the third device 1500. Examples of these data include: any computer programs used to operate on the third device 1500.

[0487] The method disclosed by the embodiments of the present application can be applied to the fourth processor 1502 or implemented by the fourth processor 1502. The fourth processor 1502 can be an integrated circuit chip with signal processing capability. In the implementation process, each step of the above method can be completed by the integrated logic circuit of hardware in the fourth processor 1502 or the instruction in the form of software. The fourth processor 1502 can be a general processor, a DSP, or other programmable logic devices, discrete gate or transistor logic devices, discrete hardware components, etc. The fourth processor 1502 can implement or execute the methods, steps and logic block diagrams disclosed in the embodiments of the present application. The general processor can be a microprocessor or any conventional processor, etc. In combination with the steps of the method disclosed in the embodiments of the present application, the hardware decoding processor can be directly embodied to execute the steps of the foregoing method, or the hardware and software modules in the decoding processor can be combined to execute the steps of the foregoing method. The software module can be located in the storage medium, and the fourth processor 1502 reads the information in the fourth storage 1503 to complete the steps of the foregoing method in combination with the hardware.

[0488] In the exemplary embodiments, the third device 1500 can be implemented by one or more ASICs, DSPs, PLDs, CPLDs, FPGAs, general processors, controllers, MCUs, microprocessors, or other electronic elements for executing the foregoing method.

[0489] It can be understood that the memory (the first memory 1203, the second memory 1303, the third memory 1403, and the fourth memory 1503) of the embodiments of the present application can be a volatile memory or a non-volatile memory, and can also include both volatile and non-volatile memories. The non-volatile memory can be a read-only memory (ROM), a programmable read-only memory (PROM), an erasable programmable read-only memory (EPROM), an electrically erasable programmable read-only memory (EEPROM), a ferromagnetic random access memory (FRAM), a flash memory, a magnetic surface memory, an optical disc, or a compact disc read-only memory (CD-ROM). The magnetic surface memory can be a disk memory or a tape memory. The volatile memory can be a random access memory (RAM) used as an external cache.By way of example and not limitation, many forms of RAM can be used, such as Static Random Access Memory (SRAM), Synchronous Static Random Access Memory (SSRAM), Dynamic Random Access Memory (DRAM), Synchronous Dynamic Random Access Memory (SDRAM), Double Data Rate Synchronous Dynamic Random Access Memory (DDR SDRAM), Enhanced Synchronous Dynamic Random Access Memory (ESDRAM), SyncLink Dynamic Random Access Memory (SLDRAM), Direct Rambus Random Access Memory (DRRAM). The memory described in embodiments of the application is intended to include, but not be limited to, these and any other suitable types of memory.

[0490] To implement the method provided by the embodiments of the present application, the embodiments of the present application further provide a key transmission system, as shown in the following Figure 16 The system comprises a terminal 1601, a first device 1602, a second device 1603 and a third device 1604, which contain first modules.

[0491] Here, it should be noted that the specific processing procedures of the terminal 1601, the first device 1602, the second device 1603 and the third device 1604 have been described in the foregoing, and will not be described here.

[0492] In an example embodiment, the embodiments of the present application further provide a storage medium, i.e., a computer storage medium, specifically a computer readable storage medium, such as a first memory 1203 storing a computer program, which can be executed by a first processor 1202 of the first module 1200 to complete the steps of any method described above on the terminal side. For example, a second memory 1303 storing a computer program, which can be executed by a second processor 1302 of the first device 1300 to complete the steps of any method described above on the first device side. For example, a third memory 1403 storing a computer program, which can be executed by a third processor 1402 of the second device 1400 to complete the steps of any method described above on the second device side. For example, a fourth memory 1503 storing a computer program, which can be executed by a fourth processor 1502 of the third device 1500 to complete the steps of any method described above on the third device side. In addition, the computer readable storage medium can be a memory such as FRAM, ROM, PROM, EPROM, EEPROM, Flash Memory, magnetic surface memory, optical disc, or CD-ROM.

[0493] The embodiments of the present application further provide a computer program product, which includes a computer program, which can be executed by the first processor 1202 of the first module 1200 to complete the steps of any method described above on the terminal side; or the computer program can be executed by the second processor 1302 of the first device 1300 to complete the steps of any method described above on the first device side; or the computer program can be executed by the third processor 1402 of the second device 1400 to complete the steps of any method described above on the second device side; or the computer program can be executed by the fourth processor 1502 of the third device 1500 to complete the steps of any method described above on the third device side.

[0494] It should be noted that "first", "second", and the like are used to distinguish similar objects, and do not necessarily have to describe a specific order or sequence.

[0495] In addition, the technical solutions described in the embodiments of the present application can be combined arbitrarily without conflict.

[0496] The above is only a preferred embodiment of the present application, and is not intended to limit the protection scope of the present application.

Claims

1. A method of key transport, characterized by, The application is applied to a terminal, comprising: A first module on the terminal receives a first key sent by a first device, the first key is encrypted and / or integrity protected based on a second key, the second key is a shared key between the first device and the first module; the first key is randomly generated, or the first key is generated based on one or more of a fifth key of the first device, an identity of the terminal, an identity of the first module and a first random number; The first module generates a third key based on the first key; The first module receives one or more fourth keys sent by the first device, the one or more fourth keys are encrypted and / or integrity protected based on the third key.

2. The method of claim 1, wherein, The method further comprises: The first module receives the second key sent by a second device, the second key is sent by the first device to the second device.

3. The method of claim 2, wherein, The second key is encrypted and protected by the first device based on a public key of the second device; Or, The second key is encrypted and / or integrity protected by the first device based on a shared key between the second device and the first device.

4. The method of claim 1, wherein, The first module on the terminal receives a first key sent by a first device, comprising: The first module receives first information sent by a third device, the first information is sent by the first device to the third device, and the first information contains a first parameter, the first parameter is obtained by encrypting the first key based on the second key.

5. The method of claim 4, wherein, The method further comprises: The first module decrypts the first parameter based on the second key to obtain the first key.

6. The method of claim 4, wherein, The first information further contains one or more of: A second random number; An identity of the terminal; An identity of the first module; A second parameter, the second parameter is obtained by integrity protecting one or more of the first parameter, a second random number, an identity of the terminal and an identity of the first module based on the second key.

7. The method of claim 6, wherein, The method further comprises: The first module verifies the correctness of the second parameter based on the second key.

8. The method of claim 6, wherein, The first module generates a third key based on the first key, comprising: The first module generates the third key based on the first key and a second random number; The first module stores the first key and the third key.

9. The method of claim 1, wherein, The first module receives one or more fourth keys sent by the first device, comprising: The first module receives second information sent by a third device, the second information is sent by the first device to the third device, and the second information contains a third parameter, the third parameter is obtained by encrypting and / or integrity protecting the one or more fourth keys based on the third key.

10. The method of claim 9, wherein, The method further comprises: The first module decrypts the third parameter based on the third key to obtain the one or more fourth keys; The first module stores the one or more fourth keys.

11. The method of claim 9, wherein, The second information further contains one or more of: An identity of the terminal; An identity of the first module; an identity of the fourth key; a fourth parameter, the fourth parameter being obtained based on integrity protection of one or more of the third parameter, an identity of the terminal, an identity of the first module, and one or more identities of the one or more fourth keys, by the third key.

12. The method of claim 11, wherein, The method further includes: verifying, by the first module, correctness of the fourth parameter based on the third key.

13. The method according to any one of claims 1 to 12, characterized in that, The method further includes: updating, by the first module, the third key based on the first key.

14. The method of claim 13, wherein, The method further includes: receiving, by the first module, third information sent by a third device, the third information being sent by the first device to the third device, the third information being used to trigger updating the third key.

15. The method of claim 14, wherein, The third information includes one or more of: an identity of the terminal; an identity of the first module; an updated second random number; a fifth parameter, the fifth parameter being obtained based on integrity protection of one or more of the identity of the terminal, the identity of the first module, and the updated second random number, by an updated third key.

16. The method of claim 15, wherein, The updating, by the first module, the third key based on the first key includes: generating, by the first module, the updated third key based on the first key and the updated second random number; verifying, by the first module, correctness of the fifth parameter based on the updated third key; storing, by the first module, the updated third key.

17. A method of key transport, the method comprising: The method is applied to a first device, and includes: sending, to a first module on a terminal, a first key, the first key being encrypted and / or integrity-protected based on a second key, the second key being a shared key between the first device and the first module; the first key being randomly generated, or the first key being generated based on one or more of a fifth key of the first device, an identity of the terminal, an identity of the first module, and a first random number; generating, based on the first key, a third key; sending, to the first module, one or more fourth keys, the one or more fourth keys being encrypted and / or integrity-protected based on the third key.

18. The method of claim 17, wherein, The method further includes: sending, by a second device, the second key to the first module.

19. The method of claim 18, wherein, The second key is encrypted and protected by the first device based on a public key of the second device; or The second key is encrypted and / or integrity-protected by the first device based on a shared key between the second device and the first device. The sending, to a first module on a terminal, a first key includes:

20. The method of claim 17, wherein, sending, by a third device, first information to the first module, the first information including a first parameter, the first parameter being obtained based on encryption of the first key by the second key. The first information further includes one or more of:

21. The method of claim 20, wherein, a second random number; an identity of the terminal; an identity of the first module; a second parameter, the second parameter being obtained based on integrity protection of one or more of the first parameter, the second random number, the identity of the terminal, and the identity of the first module, by the second key. ​ 22. The method of claim 21, wherein, The generating the third key based on the first key comprises: generating the third key based on the first key and a second random number; storing the first key and the third key.

23. The method of claim 17, wherein, The sending the one or more fourth keys to the first module comprises: sending, by the third device, second information to the first module, the second information containing a third parameter, the third parameter being obtained by encrypting and / or integrity protecting the one or more fourth keys based on the third key.

24. The method of claim 23, wherein, The second information further contains one or more of: an identity of the terminal; an identity of the first module; an identity of the fourth key; a fourth parameter, the fourth parameter being obtained by integrity protecting one or more of the third parameter, the identity of the terminal, the identity of the first module, and one or more identities of the one or more fourth keys based on the third key.

25. The method according to any one of claims 17 to 24, characterized in that, The method further comprises: updating the third key based on the first key.

26. The method of claim 25, wherein, The method further comprises: sending, by the third device, third information to the first module, the third information being used to trigger updating the third key.

27. The method of claim 26, wherein, The third information contains one or more of: an identity of the terminal; an identity of the first module; an updated second random number; a fifth parameter, the fifth parameter being obtained by integrity protecting one or more of the identity of the terminal, the identity of the first module, and the updated second random number based on the updated third key.

28. The method of claim 27, wherein, The updating the third key based on the first key comprises: generating the updated third key based on the first key and the updated second random number; storing the updated third key.

29. A key transport apparatus, characterized by comprises: a first receiving unit, configured to receive a first key sent by a first device, the first key being encrypted and / or integrity protected based on a second key, the second key being a shared key between the first device and a first module on a terminal; the first key being randomly generated, or the first key being generated based on one or more of a fifth key of the first device, an identity of the terminal, an identity of the first module, and a first random number; a first processing unit, configured to generate a third key based on the first key; a second receiving unit, configured to receive one or more fourth keys sent by the first device, the one or more fourth keys being encrypted and / or integrity protected based on the third key.

30. A key transport apparatus, comprising: comprises: a first sending unit, configured to send a first key to a first module on a terminal, the first key being encrypted and / or integrity protected based on a second key, the second key being a shared key between a first device and the first module; the first key being randomly generated, or the first key being generated based on one or more of a fifth key of the first device, an identity of the terminal, an identity of the first module, and a first random number; a second processing unit, configured to generate a third key based on the first key; a second sending unit, configured to send one or more fourth keys to the first module, the one or more fourth keys being encrypted and / or integrity protected based on the third key.

31. A terminal, characterized by comprising a first module; the first module comprising a first communication interface and a first processor; wherein the first processor is configured to: receive, through the first communication interface, a first key sent by a first device, the first key being encrypted and / or integrity protected based on a second key, the second key being a shared key between the first device and the first module; the first key being randomly generated, or the first key being generated based on one or more of a fifth key of the first device, an identity of the terminal, an identity of the first module, and a first random number; generate a third key based on the first key; receive, through the first communication interface, one or more fourth keys sent by the first device, the one or more fourth keys being encrypted and / or integrity protected based on the third key.

32. A first device, comprising: comprising: a second communication interface and a second processor; wherein the second processor is configured to: send, through the second communication interface, a first key to a first module on a terminal, the first key being encrypted and / or integrity protected based on a second key, the second key being a shared key between the first device and the first module; the first key being randomly generated, or the first key being generated based on one or more of a fifth key of the first device, an identity of the terminal, an identity of the first module, and a first random number; generate a third key based on the first key; send, through the second communication interface, one or more fourth keys to the first module, the one or more fourth keys being encrypted and / or integrity protected based on the third key.

33. A terminal, characterized by comprising a first module; the first module comprising a first processor and a first memory for storing a computer program capable of running on the processor, wherein the first processor is configured to execute the steps of the method according to any one of claims 1 to 16 when running the computer program.

34. A first device, comprising: comprising: a first processor and a first memory for storing a computer program capable of running on the processor, wherein the first processor is configured to execute the steps of the method according to any one of claims 17 to 28 when running the computer program.

35. A storage medium having stored thereon a computer program, characterized in that The computer program is executed by the processor to implement the steps of the method according to any one of claims 1 to 16, or to implement the steps of the method according to any one of claims 17 to 28.

36. A computer program product comprising a computer program, characterised in that, The computer program is executed by the processor to implement the steps of the method according to any one of claims 1 to 16, or to implement the steps of the method according to any one of claims 17 to 28.

Citation Information

Patent Citations

  • Data transmission method and device in network conference and storage medium

    CN112737774A

  • Key management method and device, equipment and storage medium

    CN117439734A

  • Key transmission method and device

    CN117957861A