A cross-domain data transmission method and system based on quantum keys
By introducing a zero-trust control platform and quantum key encryption into the cross-domain data transmission system, the problem that quantum key encryption algorithms cannot provide long-term security guarantees is solved, and high security and communication integrity of cross-domain data transmission are achieved.
Patent Information
- Application Number
- CN202411258429.0
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2024-09-09
- Publication Date
- 2025-11-04
- Estimated Expiration
- 2044-09-09
AI Technical Summary
Existing quantum key encryption algorithms cannot provide long-term security guarantees, which poses a risk to communication security in cross-domain collaborative working modes.
By introducing a zero-trust control platform into the cross-domain data transmission system, quantum key distribution is used to encrypt the session key, and encrypted data is transmitted between different network domains through zero-trust domain nodes. This ensures that the session key is not carried between terminals across domains, and is generated and managed by the zero-trust control platform, thereby enabling terminal authentication and real-time updating of trust tokens.
It improves the security of cross-domain data transmission, ensures the security of session keys and the integrity of communication data, and enhances communication security in cross-domain collaborative working modes.
Smart Images

Figure CN119094123B_ABST
Abstract
Description
TECHNICAL FIELD
[0001] The embodiments of the present application relate to the field of communication security, and in particular to a cross-domain data transmission method and system based on quantum keys. BACKGROUND
[0002] With the rapid development of information technology and the Internet, the collaborative work and data sharing between different organizations and network security domains become increasingly frequent. This cross-domain collaborative work mode greatly improves work efficiency and resource utilization, but at the same time brings huge security challenges. Network attacks and data breaches occur frequently, especially advanced persistent threats and insider attacks, which seriously threaten the security of cross-domain collaborative communication.
[0003] In the prior art, quantum keys can be used to achieve communication security in the cross-domain collaborative work mode. Quantum key distribution technology uses quantum mechanics principles to provide an unconditional secure key distribution mechanism. Quantum key distribution technology transmits keys through quantum states, and any eavesdropping behavior will change the quantum state, which can be detected, ensuring the security of the key distribution process. However, with the development of quantum computing technology, the encryption algorithm of quantum keys will face the risk of being cracked, which cannot provide long-term security, resulting in security risks in the communication security of the cross-domain collaborative work mode. SUMMARY
[0004] The purpose of the embodiments of the present application is to provide a cross-domain data transmission method and system based on quantum keys to improve the communication security in the cross-domain collaborative work mode.
[0005] To solve the above technical problems, the embodiments of the present application provide a cross-domain data transmission method based on quantum keys, applied to a first zero-trust domain node in a first network domain, comprising:
[0006] receiving an application session request sent by a sending terminal in the first network domain;
[0007] sending the application session request to a zero-trust control platform, so that the zero-trust control platform generates a session key according to the application session request, encrypts the session key with a quantum key to obtain session encryption information, and sends the session encryption information to the first zero-trust domain node;
[0008] receiving the session encryption information sent by the zero-trust control platform;
[0009] sending the session encryption information to the sending terminal, so that the sending terminal performs quantum key decryption on the session encryption information to obtain the session key, encrypts communication data by using the session key to obtain encrypted communication data, and sends an encrypted data transmission request carrying the encrypted communication data, a session identifier, and a receiving terminal identifier to the first zero-trust domain node;
[0010] receiving the encrypted data transmission request sent by the sending terminal;
[0011] sending the encrypted data transmission request to a receiving terminal in a second network domain through a second zero-trust domain node in a second network domain corresponding to the receiving terminal identifier.
[0012] Embodiments of the present application also provide a cross-domain data transmission method based on a quantum key, before receiving an application session request sent by a sending terminal in a first network domain, the method further comprises:
[0013] receiving an application access network domain trust token request sent by the sending terminal;
[0014] sending the application access network domain trust token request to a zero-trust control platform, so that the zero-trust control platform determines a trust token of the sending terminal according to the application access network domain trust token request and sends the trust token to the first zero-trust domain node;
[0015] receiving the trust token of the sending terminal sent by the zero-trust control platform;
[0016] sending the trust token to the sending terminal, so that the sending terminal adds the trust token to the encrypted data transmission request;
[0017] The sending of the encrypted data transmission request to a receiving terminal in a second network domain through a second zero-trust domain node in a second network domain corresponding to the receiving terminal identifier comprises:
[0018] verifying an access right of the trust token of the sending terminal to the second network domain;
[0019] if the verification is passed, sending the encrypted data transmission request to the receiving terminal through the second zero-trust domain node.
[0020] Embodiments of the present application also provide a cross-domain data transmission method based on a quantum key, before the verification of an access right of the trust token of the sending terminal to the second network domain, the method further comprises:
[0021] receiving terminal environment information sent by the sending terminal;
[0022] sending the terminal environment information to the zero-trust control platform, so that the zero-trust control platform determines network domain access permission of a trust token of the sending terminal according to the terminal environment information of the sending terminal, and sends the network domain access permission of the trust token of the sending terminal to the first zero-trust domain node;
[0023] receiving the network domain access permission of the trust token of the sending terminal.
[0024] Embodiments of the present application also provide a cross-domain data transmission method based on quantum keys, and before receiving the application session request sent by a sending terminal in a first network domain, the method further comprises:
[0025] receiving an identity authentication request sent by the sending terminal;
[0026] sending the identity authentication request to a zero-trust control platform, so that the zero-trust control platform generates an identity authentication result of the sending terminal according to the identity authentication request, and sends the identity authentication result of the sending terminal to the first zero-trust domain node;
[0027] receiving the identity authentication result of the sending terminal sent by the zero-trust control platform;
[0028] sending the identity authentication result of the sending terminal to the sending terminal, so that the sending terminal sends the application session request to the first zero-trust domain node when the identity authentication result is successful.
[0029] Embodiments of the present application also provide a cross-domain data transmission method based on quantum keys, and a sending terminal in the first network domain comprises a first user terminal and a first terminal agent, and before receiving the application session request sent by the sending terminal in the first network domain, the method further comprises:
[0030] the first user terminal initiates a user session to the first terminal agent, so that the first terminal agent sends an application session request to the first zero-trust domain node according to a first user terminal identifier and a receiving terminal identifier; wherein the user session comprises the first user terminal identifier, the session identifier, the communication data and the receiving terminal identifier;
[0031] after sending the session encryption information to the sending terminal, the method further comprises:
[0032] the first terminal agent performs quantum key decryption on the session encryption information to obtain the session key, encrypts the communication data through the session key to obtain encrypted communication data, and sends an encrypted data transmission request carrying the encrypted communication data, the session identifier and the receiving terminal identifier to the first zero-trust domain node.
[0033] Embodiments of the present application also provide a cross-domain data transmission method based on quantum keys, applied to a second zero-trust domain node in a second network domain, comprising:
[0034] receiving an encrypted data transmission request sent by a first zero-trust domain node in a first network domain; wherein the first zero-trust domain node is configured to execute any of the cross-domain data transmission methods described above;
[0035] sending the encrypted data transmission request to the receiving terminal, so that the receiving terminal extracts a session identifier from the encrypted data transmission request and sends the session identifier to the second zero-trust domain node;
[0036] receiving the session identifier sent by the receiving terminal, and performing quantum key encryption on the session identifier to obtain session negotiation information;
[0037] sending the session negotiation information to a zero-trust control platform, so that the zero-trust control platform performs quantum key decryption on the session negotiation information to obtain the session identifier, determines a session key according to the session identifier, performs quantum key encryption on the session key to obtain session encryption information, and sends the session encryption information to the second zero-trust domain node;
[0038] receiving the session encryption information sent by the zero-trust control platform;
[0039] sending the session encryption information to the sending terminal, so that the sending terminal performs quantum key decryption on the session encryption information to obtain the session key, and decrypts encrypted communication data in the encrypted data transmission request through the session key to obtain communication data.
[0040] Embodiments of the present application also provide a cross-domain data transmission method based on quantum keys, wherein the encrypted data transmission request comprises a trust token of the sending terminal; and the sending of the encrypted data transmission request to the receiving terminal comprises:
[0041] extracting the trust token of the sending terminal from the encrypted data transmission request;
[0042] sending the trust token of the sending terminal to the zero-trust control platform, so that the zero-trust control platform verifies access rights of the second network domain corresponding to the trust token of the sending terminal and sends a verification result to the second zero-trust domain node;
[0043] receiving the verification result sent by the zero-trust control platform;
[0044] if the verification result indicates that the verification is passed, sending the encrypted data transmission request to the receiving terminal.
[0045] Embodiments of the present application also provide a cross-domain data transmission method based on quantum keys, the receiving terminal in the second network domain comprising: a second user terminal, a second terminal agent;
[0046] After sending the encrypted data transmission request to the receiving terminal, the method further comprises:
[0047] The second terminal agent extracts a session identifier from the encrypted data transmission request and sends the session identifier to the second zero-trust domain node;
[0048] After sending the session encryption information to the sending terminal, the method further comprises:
[0049] The second terminal agent decrypts the session encryption information using quantum keys to obtain the session key, and decrypts the encrypted communication data in the encrypted data transmission request using the session key to obtain communication data;
[0050] The second terminal agent sends the communication data to the second user terminal.
[0051] Embodiments of the present application also provide a cross-domain data transmission system, comprising: a sending terminal in a first network domain, a first zero-trust domain node in the first network domain, a zero-trust control platform, a second zero-trust domain node in a second network domain, and a receiving terminal in the second network domain; the first zero-trust domain node is configured to perform the cross-domain data transmission method performed by the first zero-trust domain node as the subject; and the second zero-trust domain node is configured to perform the cross-domain data transmission method performed by the second zero-trust domain node as the subject;
[0052] The sending terminal is connected to the zero-trust control platform through the first zero-trust domain node, and the receiving terminal is connected to the zero-trust control platform through the second zero-trust domain node.
[0053] Embodiments of the present application also provide a cross-domain data transmission system, the sending terminal in the first network domain comprising: a first user terminal, a first terminal agent; and the receiving terminal in the second network domain comprising: a second user terminal, a second terminal agent;
[0054] The first user terminal is connected to the first zero-trust domain node in the first network domain through the first terminal agent, and the second user terminal is connected to the second zero-trust domain node in the second network domain through the second terminal agent.
[0055] In the present application, the first zero trust domain node exists in the communication between devices in the cross-domain process. The basic quantum key encryption exists in the communication between devices in the cross-domain process. The basic communication security is realized through the quantum key, and the communication data encryption is realized through the session key. The transmission security of the session key is realized, and the session key is not carried in the encryption data transmission request between the two terminals in the cross-domain, and is not generated by the terminal in the cross-domain. The security of the session key is high, and the security of the data transmission in the cross-domain process is further improved, that is, the communication security in the cross-domain collaborative working mode is improved, and a more secure guarantee is provided for the cross-domain data communication. BRIEF DESCRIPTION OF DRAWINGS
[0056] One or more embodiments are illustrated by way of example in the figures that form a part of this patent document. These example are not intended to limit embodiments, but to clarify embodiments for those of ordinary skill in the art.
[0057] Figure 1 is a structural schematic diagram of a first cross-domain data transmission system provided by the present embodiment;
[0058] Figure 2 is a structural schematic diagram of a second cross-domain data transmission system provided by the present embodiment;
[0059] Figure 3 is a flowchart of a first cross-domain data transmission method provided by the present embodiment;
[0060] Figure 4 is a flowchart of a second cross-domain data transmission method provided by the present embodiment
[0061] Figure 5 is a flowchart of a third cross-domain data transmission method provided by the present embodiment;
[0062] Figure 6 is a flowchart of a fourth cross-domain data transmission method provided by the present embodiment
[0063] Figure 7 is a flowchart of a fifth cross-domain data transmission method provided by the present embodiment;
[0064] Figure 8 is a flowchart of a sixth cross-domain data transmission method provided by the present embodiment;
[0065] Figure 9 is a flowchart of a seventh cross-domain data transmission method provided by the present embodiment;
[0066] Figure 10 is a structural schematic diagram of a third cross-domain data transmission system provided by the present embodiment;
[0067] Figure 11is a flowchart of a ninth cross-domain data transmission method provided by an embodiment of the present application;
[0068] Figure 12 is a flowchart of a ninth cross-domain data transmission method provided by an embodiment of the present application;
[0069] Figure 13 is a flowchart of a ninth cross-domain data transmission method provided by an embodiment of the present application;
[0070] Figure 14 is a flowchart of a ninth cross-domain data transmission method provided by an embodiment of the present application;
[0071] Figure 15 is a flowchart of a ninth cross-domain data transmission method provided by an embodiment of the present application;
[0072] Figure 16 is a flowchart of a ninth cross-domain data transmission method provided by an embodiment of the present application;
[0073] Figure 17 is a structural schematic diagram of a fourth cross-domain data transmission system provided by an embodiment of the present application;
[0074] Figure 18 is a structural schematic diagram of a zero-trust domain node provided by an embodiment of the present application. DETAILED DESCRIPTION
[0075] To make the objectives, technical solutions, and advantages of the embodiments of the present application clearer, the embodiments of the present application will be described in detail below with reference to the drawings. However, those skilled in the art can understand that, in the embodiments of the present application, many technical details are presented in order to make the readers better understand the present application. However, the technical solutions claimed by the present application can be implemented even without these technical details and based on various changes and modifications of the following embodiments. The division of the following embodiments is for the convenience of description, and should not constitute any limitation on the specific implementation of the present application, and the embodiments can be combined and referenced with each other on the premise of not contradicting each other.
[0076] The encryption algorithm of the quantum key cannot provide long-term security, resulting in security risks in the communication security of the cross-domain collaborative working mode. In order to solve the above technical problems, an embodiment of the present application provides a cross-domain data transmission system, Figure 1 is a structural schematic diagram of a first cross-domain data transmission system provided by an embodiment of the present application, as Figure 1 shown, the cross-domain data transmission system comprises: a sending terminal 110 in a first network domain, a first zero-trust domain node 120 in the first network domain, a zero-trust control platform 100, a second zero-trust domain node 220 in a second network domain, and a receiving terminal 210 in the second network domain.
[0077] The sending terminal 110 connects the zero-trust control platform 100 through the first zero-trust domain node 120. The sending terminal 110 and the first zero-trust domain node 120 are both in the first network domain, and the sending terminal 110 and the first zero-trust domain node 120 can communicate with each other. For multiple network domains, each network domain needs to have a corresponding zero-trust domain node.
[0078] The receiving terminal 210 connects the zero-trust control platform 100 through the second zero-trust domain node 220. The receiving terminal 210 and the second zero-trust domain node 220 are both in the second network domain, and the receiving terminal 210 and the second zero-trust domain node 220 can communicate with each other.
[0079] The sending terminal 110, the first zero-trust domain node 120, the zero-trust control platform 100, the second zero-trust domain node 220, and the receiving terminal 210 are initialized and configured to connect to the corresponding quantum key output devices. For example, Figure 2 is a structure diagram of a second cross-domain data transmission system provided by the embodiment, as Figure 2 The sending terminal 110, the first zero-trust domain node 120, the zero-trust control platform 100, the second zero-trust domain node 220, and the receiving terminal 210 are all connected to the corresponding quantum key output devices to provide corresponding quantum keys for each node, each terminal, and the platform.
[0080] Specifically, the zero-trust control platform 100, the zero-trust domain node, and the terminal are all connected to the corresponding quantum key output devices in the quantum key distribution network in advance, and obtain quantum keys from the corresponding quantum key output devices to ensure the security of the control plane data link.
[0081] All quantum key output devices form a quantum key distribution network. Through the quantum key distribution network, the symmetric keys of the "zero-trust control platform 100 and each zero-trust domain node", the "zero-trust domain node and the terminal connected thereto", and the "zero-trust domain nodes" are obtained, and the symmetric keys distributed through the quantum key are stored in the security area of the zero-trust control platform 100, each zero-trust domain node, and the terminal. The sending terminal and the first zero-trust domain node, the first zero-trust domain node and the zero-trust control platform, the second zero-trust domain node and the zero-trust control platform, and the receiving terminal and the second zero-trust domain node all realize quantum key encryption communication through the corresponding quantum key.
[0082] The zero-trust architecture requires strict isolation measures to be implemented even between nodes, and therefore, there is a network isolation device between the first zero-trust domain node 120 and the second zero-trust domain node 220, which isolates signals of different network domains. By setting the isolation device, the scope and authority of communication can be limited, only authorized traffic can pass through, security risks can be minimized, and the security and reliability of the network environment can be ensured.
[0083] On the basis of the cross-domain data transmission system shown in the above Figure 1 and Figure 2 The embodiment of the application relates to a cross-domain data transmission method based on a quantum key, Figure 3 is a flowchart of a first cross-domain data transmission method provided by the embodiment of the application, Figure 4 is a flowchart of a second cross-domain data transmission method provided by the embodiment of the application, as shown in Figure 3 and Figure 4 The cross-domain data transmission method based on a quantum key is applied to a first zero-trust domain node in a first network domain in the cross-domain data transmission system, and specifically includes the following steps.
[0084] Step 301, receiving an application session request sent by a sending terminal in the first network domain.
[0085] Before the sending terminal sends communication data to the receiving terminal, the sending terminal sends an application session request to the first zero-trust domain node. The application session request is used to inform the zero-trust control platform that the sending terminal is about to communicate data with the receiving terminal, and therefore, the application session request can include a sending terminal identifier, a receiving terminal identifier, and session request information, wherein the sending terminal identifier is used to uniquely indicate the sending terminal, and the receiving terminal identifier is used to uniquely indicate the receiving terminal.
[0086] Of course, the application session request can also include a first zero-trust domain node identifier, a zero-trust control platform identifier, and other information, which is not specifically limited in the embodiment of the application.
[0087] After the sending terminal sends the application session request to the first zero-trust domain node, the first zero-trust domain node receives the application session request.
[0088] Step 302, sending the application session request to the zero-trust control platform.
[0089] The first zero-trust domain node includes a control plane information forwarding module, which is mainly responsible for forwarding identity authentication information, environment perception information, and session negotiation control plane messages.
[0090] The control plane information forwarding module in the first zero trust domain node can forward the application session request to the zero trust control platform. For example, the first zero trust domain node can determine a unique corresponding zero trust control platform according to the zero trust control platform identifier in the application session request, or the first zero trust domain node can send all application session requests to the zero trust control platform by default, and how to forward is not limited in the embodiments of the present application.
[0091] The zero trust control platform includes an encryption negotiation module for managing session key negotiation between users. After receiving the application session request, the encryption negotiation module in the zero trust control platform generates a session key according to the application session request. The session key is specific to the sending terminal and the receiving terminal, and the zero trust control platform stores the correspondence between the session key, the sending terminal, and the receiving terminal.
[0092] After the zero trust control platform generates the session key, in order to prevent the session key from being leaked, the session key is encrypted by a quantum key to obtain session encryption information, and the session encryption information is sent to the first zero trust domain node.
[0093] Step 303, receiving the session encryption information sent by the zero trust control platform.
[0094] The first zero trust domain node receives the session encryption information sent by the zero trust control platform. The session encryption information includes the encrypted session key.
[0095] Step 304, sending the session encryption information to the sending terminal.
[0096] Optionally, the control plane information forwarding module in the first zero trust domain node can send the session encryption information to the sending terminal.
[0097] The sending terminal decrypts the session encryption information by a quantum key to obtain the session key. The session key is the session key generated by the zero trust control platform.
[0098] The sending terminal encrypts the communication data by the session key to obtain encrypted communication data. The communication data is application data and other data that the sending terminal needs to transmit to the receiving terminal.
[0099] The sending terminal sends an encrypted data transmission request carrying the encrypted communication data, the session identifier, and the receiving terminal identifier to the first zero trust domain node. For example, the message header of the encrypted data transmission request can include the session identifier and the identifier of the receiving terminal, which is used to uniquely indicate the receiving terminal. For example, the identifier of the receiving terminal can be the resource address of the receiving terminal. The session identifier corresponds to the sending terminal and the receiving terminal.
[0100] Step 305, receiving the encrypted data transmission request sent by the sending terminal.
[0101] After the first zero-trust domain node receives the encrypted data transmission request sent by the sending terminal, the encrypted data transmission request is parsed, the second network domain where the receiving terminal is located can be determined, and then the second zero-trust domain node in the second network domain is determined.
[0102] Step 306, sending the encrypted data transmission request to the second zero-trust domain node in the second network domain corresponding to the receiving terminal through the receiving terminal identifier.
[0103] The control plane information forwarding module in the first zero-trust domain node can send the encrypted data transmission request to the second zero-trust domain node in the second network domain corresponding to the receiving terminal identifier. Since the first zero-trust domain node and the second zero-trust domain node are located in two mutually isolated network domains, the sending is encrypted cross-domain forwarding.
[0104] The cross-domain data agent module in the first zero-trust domain node is mainly responsible for forwarding cross-domain data. The cross-domain data agent module sends the encrypted data transmission request to the second zero-trust domain node in the second network domain corresponding to the receiving terminal identifier.
[0105] The second zero-trust domain node forwards the encrypted data transmission request to the receiving terminal in the second network domain. Optionally, the second zero-trust domain node can determine the unique corresponding receiving terminal according to the receiving terminal identifier in the encrypted data transmission request, or the second zero-trust domain node sends all encrypted data transmission requests to the receiving terminal by default. The specific forwarding method is not limited in the embodiment of the present application.
[0106] In the embodiment of the present application, the communication between the sending terminal and the first zero-trust domain node, the communication between the first zero-trust domain node and the zero-trust control platform, the communication between the second zero-trust domain node and the zero-trust control platform, and the communication between the receiving terminal and the second zero-trust domain node are all based on quantum key encryption.
[0107] In the embodiment of the present application, in the cross-domain process, the communication between the devices is based on the basic quantum key encryption. Not only the communication security is realized through the quantum key, but also the communication data transmission security is realized through the session key. Moreover, the session key is not carried in the encrypted data transmission request between the two terminals in the cross-domain, and is not generated by the terminal in the cross-domain. Therefore, the security of the session key is high, which further improves the security of data transmission in the cross-domain process, that is, improves the communication security in the cross-domain collaborative working mode, and provides more secure guarantee for cross-domain data communication.
[0108] In the above Figure 3 andFigure 4 Based on the cross-domain data transmission method shown in the above, the embodiment of the present application further provides another cross-domain data transmission method based on quantum key, Figure 5 is a flow chart of a third cross-domain data transmission method provided by the embodiment of the present application, Figure 6 is a flow chart of a fourth cross-domain data transmission method provided by the embodiment of the present application, as shown in Figure 5 and Figure 6 As shown in the above, before the step 301, receiving the session application request sent by the sending terminal in the first network domain, specifically includes the following steps.
[0109] Step 501, receiving the application access network domain trust token request sent by the sending terminal.
[0110] Each sending terminal has a corresponding trust token, and the token of the sending terminal is stored in the zero trust control platform. The application access network domain trust token request is used to request the trust token corresponding to the sending terminal.
[0111] The first zero trust domain node can receive the application access network domain trust token request sent by the sending terminal.
[0112] Step 502, sending the application access network domain trust token request to the zero trust control platform.
[0113] After the first zero trust domain node sends the application access network domain trust token request to the zero trust control platform, the zero trust control platform determines the trust token of the sending terminal according to the application access network domain trust token request. Wherein, the zero trust control platform stores the corresponding relationship between the sending terminal and the trust token.
[0114] The zero trust control platform sends the trust token to the first zero trust domain node.
[0115] Step 503, receiving the trust token of the sending terminal sent by the zero trust control platform.
[0116] The first zero trust domain node can receive the trust token of the sending terminal sent by the zero trust control platform.
[0117] Step 504, sending the trust token to the sending terminal.
[0118] The trust token and the session application are both control plane data, which are forwarded through the first zero trust domain node, and are encrypted by the quantum key stored in the secure area and distributed by the quantum key.
[0119] After the first zero-trust domain node receives the trust token of the sending terminal sent by the zero-trust control platform, the sending terminal adds the trust token to the encrypted data transmission request, so that the trust token of the sending terminal is also included in the encrypted data transmission request. For example, the trust token can be located in the message header of the encrypted data transmission request.
[0120] At this time, the step 306 of sending the encrypted data transmission request to the receiving terminal in the second network domain through the second zero-trust domain node corresponding to the receiving terminal identifier of the second network domain includes the following steps.
[0121] After the first zero-trust domain node receives the encrypted data transmission request including the trust token of the sending terminal, the first zero-trust domain node parses the encrypted data transmission request to obtain the trust token of the sending terminal, verifies whether the trust token has the access right of the second network domain, and if the trust token has the access right of the second network domain, the first zero-trust domain node sends the encrypted data transmission request to the receiving terminal through the second zero-trust domain node; if the trust token does not have the access right of the second network domain, the first zero-trust domain node does not forward the encrypted data transmission request. For example, if the trust token does not have the access right of the second network domain, the first zero-trust domain node can feed back the information related to the lack of right to the sending terminal.
[0122] The access right of the trust token of the sending terminal is updated in real time according to the terminal environment information of the sending terminal and the like.
[0123] In the embodiments of the present application, the trust token of the sending terminal is set, and the security of data communication is further improved by judging the access right of the trust token.
[0124] Based on the cross-domain data transmission method shown in the above Figure 5 Based on the cross-domain data transmission method shown in the above Figure 7 is a flowchart of the fifth cross-domain data transmission method provided by the embodiments of the present application, as shown in the above Figure 7 Before the above-mentioned step of verifying whether the trust token of the sending terminal has the access right of the second network domain, the following steps are specifically included.
[0125] In step 701, the terminal environment information sent by the sending terminal is received.
[0126] The sending terminal includes an environment perception module for collecting the terminal environment information of the sending terminal through environment perception.
[0127] The terminal environment information can also be referred to as environment perception information, and the terminal environment information is sensitive data related to a user, is encrypted by a quantum key distributed by quantum key distribution, and at least includes device information (device type, software version, connection state, etc.), user behavior information (such as user login time, access resource type, frequency), real-time threat information (vulnerability, malicious IP, etc.), and network environment information (traffic anomaly, topology change, etc.).
[0128] The sending terminal reports the terminal environment information to the zero-trust control platform through the first zero-trust domain node in real time or at a fixed time.
[0129] Step 702, the terminal environment information is sent to the zero-trust control platform.
[0130] The first zero-trust domain node forwards the terminal environment information to the zero-trust control platform in real time. The zero-trust control platform determines the network domain access permission of the trust token of the sending terminal according to the terminal environment information of the sending terminal, and sends the network domain access permission of the trust token of the sending terminal to the first zero-trust domain node.
[0131] Specifically, the zero-trust control platform includes a trust evaluation engine and a dynamic access control engine. The trust evaluation engine is configured to evaluate the environment trust degree of the sending terminal according to the environment perception information of the sending terminal, adjust the trust information according to a rule, and notify the dynamic access control engine of the adjustment. The dynamic access control engine is configured to adjust a resource access strategy according to the trust degree change information (trust policy dynamic adjustment information) sent by the trust evaluation engine. The resource access strategy is the network domain access permission of the trust token of the sending terminal.
[0132] The zero-trust control platform stores a corresponding relationship between the trust token and the network domain access permission.
[0133] Step 703, the network domain access permission of the trust token of the sending terminal is received.
[0134] After the first zero-trust domain node receives the network domain access permission of the trust token of the sending terminal, the network domain access permission of the trust token of the sending terminal is used to verify the access permission of the sending terminal to the second network domain.
[0135] Specifically, the dynamic access control engine in the zero-trust control platform pushes the updated access control strategy to the cross-domain gateway cross-domain data agent of the first zero-trust domain node. The cross-domain gateway serves as an execution point of trust control, and executes the new access strategy.
[0136] In the embodiments of the present application, the network domain access permission of the trust token of the sending terminal is updated in real time to determine the second network domain access permission of the trust token in real time with the latest network domain access permission, so that the verification accuracy of the access permission of the trust token is higher, and the security of data communication is further improved.
[0137] On the basis of the above-mentioned embodiments, the embodiments of the present application further provide another cross-domain data transmission method based on quantum key, Figure 8 is a flowchart of a sixth cross-domain data transmission method provided by the embodiments of the present application, Figure 9 is a flowchart of a seventh cross-domain data transmission method provided by the embodiments of the present application, as Figure 8 and Figure 9 As shown in the above-mentioned step 301, before receiving the application session request sent by the sending terminal in the first network domain, the step specifically includes the following steps.
[0138] Step 801, receiving an identity authentication request sent by the sending terminal.
[0139] The sending terminal includes an authentication module for being responsible for the identity authentication of the user of the sending terminal, and the authentication module sends the identity authentication request to the first zero-trust domain node.
[0140] The identity authentication request includes the user identity of the sending terminal and authentication information.
[0141] Step 802, sending the identity authentication request to the zero-trust control platform.
[0142] The zero-trust control platform generates the identity authentication result of the sending terminal according to the identity authentication request, and sends the identity authentication result of the sending terminal to the first zero-trust domain node.
[0143] Specifically, the zero-trust control platform includes a user identity authentication infrastructure for saving the user identity information and providing the authentication of the user. The user identity authentication infrastructure includes a plurality of identity information. If the identity information corresponding to the user identity of the sending terminal is not in the plurality of identity information, the identity authentication result of the sending terminal is authentication failure. If the identity information corresponding to the user identity of the sending terminal is in the plurality of identity information, the identity authentication result of the sending terminal is authentication success.
[0144] Step 803, receiving the identity authentication result of the sending terminal sent by the zero-trust control platform.
[0145] The first zero-trust domain node receives the identity authentication result of the sending terminal sent by the zero-trust control platform.
[0146] Step 804, sending the identity authentication result of the sending terminal to the sending terminal.
[0147] The sending terminal sends an application session request to the first zero-trust domain node when the identity authentication result is successful.
[0148] For example, if the identity authentication result of the sending terminal fails, the zero-trust control platform can not generate a session key according to the application session request of the sending terminal.
[0149] In the embodiments of the present application, the identity authentication of the sending terminal is performed, so that the security of data communication is further improved.
[0150] On the basis of the cross-domain data transmission system shown in the above Figure 1 On the basis of the cross-domain data transmission system shown in the above Figure 10 is a structural schematic diagram of a third cross-domain data transmission system provided by the embodiments of the present application, as shown in the above Figure 10 The sending terminal 110 in the first network domain of the cross-domain data transmission system includes a first user terminal 111 and a first terminal agent 112, and the receiving terminal 210 in the second network domain includes a second user terminal 211 and a second terminal agent 212.
[0151] The first user terminal 111 and the first terminal agent 112 can share one hardware device, or can be two hardware devices, which are not specifically limited in the embodiments of the present application. The second user terminal 211 and the second terminal agent 212 can share one hardware device, or can be two hardware devices, which are not specifically limited in the embodiments of the present application.
[0152] The first user terminal 111 is connected to the first zero-trust domain node 120 in the first network domain through the first terminal agent 112, and the second user terminal 211 is connected to the second zero-trust domain node 220 in the second network domain through the second terminal agent 212.
[0153] In the embodiments of the present application, the connection between the user terminal and the terminal agent is secure by default, so that the quantum key output device corresponding to the connection of the sending terminal 110 can be connected to the first terminal agent 112, so that the first terminal agent 112 and the first zero-trust domain node 120 are connected through the corresponding quantum key to realize basic encryption; the quantum key output device corresponding to the connection of the receiving terminal 210 can be connected to the second terminal agent 212, so that the second terminal agent 212 and the second zero-trust domain node 220 are connected through the corresponding quantum key to realize basic encryption.
[0154] On the basis of the cross-domain data transmission system shown in the above Figure 10 On the basis of the cross-domain data transmission system shown in the above Figure 11 is a flowchart of an eighth cross-domain data transmission method provided by the embodiments of the present application, as shown in the aboveFigure 11 As shown in the above step 301, before receiving the session application request sent by the sending terminal in the first network domain, the first user terminal initiates a user session to the first terminal agent.
[0155] The user session includes the first user terminal identifier, the session identifier, the communication data, and the receiving terminal identifier. The receiving terminal identifier can be the second user terminal identifier.
[0156] After the first user terminal initiates the user session to the first terminal agent, the first terminal agent sends a session application request to the first zero-trust domain node according to the first user terminal identifier and the receiving terminal identifier.
[0157] At this time, after the above step 304, the first terminal agent performs quantum key decryption on the session encryption information to obtain a session key, encrypts the communication data through the session key to obtain encrypted communication data, and sends an encrypted data transmission request carrying the encrypted communication data, the session identifier, and the receiving terminal identifier to the first zero-trust domain node.
[0158] In the embodiment of the application, the structure of the first terminal agent includes four modules: an authentication module (responsible for managing terminal user identity information authentication), an encryption and decryption module (responsible for encrypting and decrypting user terminal information), an isolated storage module (storing pre-key and session key), and an environment perception module (collecting device information, user behavior information, real-time threat information, network environment information, etc., and reporting these information to the zero-trust control platform regularly).
[0159] In the embodiment of the application, the terminal agent can improve the adaptability of the cross-domain data transmission system and the applicability of the cross-domain data transmission method based on quantum key.
[0160] Based on the above Figure 1 and Figure 2 The embodiment of the application relates to a cross-domain data transmission method based on quantum key, Figure 12 is a flowchart of the ninth cross-domain data transmission method provided by the embodiment of the application, Figure 13 is a flowchart of the tenth cross-domain data transmission method provided by the embodiment of the application, as Figure 12 and Figure 13 The cross-domain data transmission method based on quantum key is applied to the second zero-trust domain node in the second network domain of the above cross-domain data transmission system, and specifically includes the following steps.
[0161] Step 1201, receiving an encrypted data transmission request sent by the first zero-trust domain node in the first network domain.
[0162] The second zero-trust domain node receives the encrypted data transmission request sent by the first zero-trust domain node in the first network domain.
[0163] In step 1202, the encrypted data transmission request is sent to the receiving terminal.
[0164] The second zero-trust domain node sends the encrypted data transmission request to the receiving terminal, and the receiving terminal extracts the session identifier from the encrypted data transmission request. The session identifier can be in the message header of the encrypted data transmission request.
[0165] After the receiving terminal extracts the session identifier from the encrypted data transmission request, the session identifier is sent to the second zero-trust domain node.
[0166] In step 1203, the session identifier sent by the receiving terminal is received, and the session identifier is quantum key encrypted to obtain session negotiation information.
[0167] After the second zero-trust domain node receives the session identifier sent by the receiving terminal, the session identifier is quantum key encrypted to obtain session negotiation information. The session negotiation information contains the encrypted session identifier.
[0168] In step 1204, the session negotiation information is sent to the zero-trust control platform.
[0169] The second zero-trust domain node sends the session negotiation information to the zero-trust control platform, and the zero-trust control platform quantum key decrypts the session negotiation information to obtain the session identifier.
[0170] Since the zero-trust control platform contains the correspondence between the session identifier and the sending terminal and the receiving terminal, and the correspondence between the session key, the sending terminal and the receiving terminal, the zero-trust control platform can determine the corresponding sending terminal and receiving terminal according to the session identifier and the correspondence between the session identifier and the sending terminal and the receiving terminal, and determine the corresponding session key according to the determined sending terminal, receiving terminal and the correspondence between the session key, the sending terminal and the receiving terminal. That is, the zero-trust control platform can determine the session key according to the session identifier. The session key is the same as the session key obtained by the sending terminal.
[0171] After the zero-trust control platform determines the session key, the session key is quantum key encrypted to obtain session encryption information, and the session encryption information is sent to the second zero-trust domain node.
[0172] In step 1205, the session encryption information sent by the zero-trust control platform is received.
[0173] The second zero-trust domain node receives the session encryption information sent by the zero-trust control platform.
[0174] Step 1206, the session encryption information is sent to the sending terminal.
[0175] The second zero-trust domain node sends the session encryption information to the sending terminal, the sending terminal performs quantum key decryption on the session encryption information to obtain a session key, and the encrypted communication data in the encrypted data transmission request is decrypted by the session key to obtain the communication data.
[0176] In the embodiment of the application, the second zero-trust domain node obtains the session key from the zero-trust control platform through quantum key encryption communication, so that the receiving terminal obtains the communication data by decryption through the session key. The session key is not generated by the receiving terminal across the domain, so that the security of the session key is higher, and the communication between devices is all based on quantum key encryption, which further improves the security of data transmission in the cross-domain process, that is, improves the communication security in the cross-domain collaborative working mode, and provides more secure protection for cross-domain data communication.
[0177] On the basis of the cross-domain data transmission method shown in the above Figure 13 The embodiment of the application further provides another cross-domain data transmission method based on a quantum key, Figure 14 is a flowchart of the eleventh cross-domain data transmission method provided by the embodiment of the application, as shown in Figure 14 The step 1202 sends the encrypted data transmission request to the receiving terminal, and specifically includes the following steps.
[0178] Step 1401, the trust token of the sending terminal is extracted from the encrypted data transmission request.
[0179] The first zero-trust domain node receives the application access network domain trust token request sent by the sending terminal, sends the application access network domain trust token request to the zero-trust control platform, determines the trust token of the sending terminal according to the application access network domain trust token request, sends the trust token to the first zero-trust domain node, and the first zero-trust domain node receives the trust token of the sending terminal sent by the zero-trust control platform, and sends the trust token to the sending terminal. At this time, the encrypted data transmission request contains the trust token of the sending terminal.
[0180] The second zero-trust domain node can extract the trust token of the sending terminal from the encrypted data transmission request. The trust token of the sending terminal can be in the message header of the encrypted data transmission request.
[0181] Step 1402, the trust token of the sending terminal is sent to the zero-trust control platform.
[0182] The second zero-trust domain node can send the trust token of the sending terminal to the zero-trust control platform, and the zero-trust control platform checks the access right of the second network domain corresponding to the trust token of the sending terminal and sends the checking result to the second zero-trust domain node.
[0183] The zero-trust control platform verifies whether the trust token has the access right of the second network domain, and if the trust token has the access right of the second network domain, the checking result is a check pass; if the trust token does not have the access right of the second network domain, the checking result is a check failure.
[0184] In step 1403, the checking result sent by the zero-trust control platform is received.
[0185] The second zero-trust domain node receives the checking result sent by the zero-trust control platform, and the checking result is a check pass or a check failure.
[0186] In step 1404, if the checking result indicates a check pass, the encrypted data transmission request is sent to the receiving terminal.
[0187] Only in the case of a check pass, the sending terminal can communicate with the receiving terminal, and therefore, when the check pass, the second zero-trust domain node sends the encrypted data transmission request to the receiving terminal.
[0188] When the check fails, the second zero-trust domain node cannot send the encrypted data transmission request to the receiving terminal, and in the example, the first zero-trust domain node can feed back information related to the lack of right to the sending terminal.
[0189] In the embodiments of the present application, the trust token of the sending terminal is set, and by judging the access right of the trust token, the security of data communication is further improved.
[0190] Based on the cross-domain data transmission method shown in the above Figure 13 Based on the cross-domain data transmission method shown in the above Figure 15 is a flowchart of the twelfth cross-domain data transmission method provided by the embodiments of the present application, as shown in Figure 15 After the step 1202 of sending the encrypted data transmission request to the receiving terminal, the step 1202 specifically includes: when the receiving terminal in the second network domain includes a second user terminal and a second terminal agent, the second terminal agent extracts the session identifier from the encrypted data transmission request and sends the session identifier to the second zero-trust domain node.
[0191] The second zero-trust domain node performs quantum key encryption on the session identifier to obtain session negotiation information, and sends the session negotiation information to the zero-trust control platform, so that the zero-trust control platform performs quantum key decryption on the session negotiation information to obtain the session identifier, the zero-trust control platform determines a session key according to the session identifier, performs quantum key encryption on the session key to obtain session encryption information, and sends the session encryption information to the second zero-trust domain node, and the second zero-trust domain node receives the session encryption information sent by the zero-trust control platform and sends the session encryption information to the sending terminal.
[0192] After the step 1206 of sending the session encryption information to the sending terminal, the second terminal agent performs quantum key decryption on the session encryption information to obtain the session key, decrypts the encrypted communication data in the encrypted data transmission request through the session key to obtain communication data, and the second terminal agent sends the communication data to the second user terminal, and the second user terminal receives the communication data.
[0193] In the embodiment of the application, the adaptability of the cross-domain data transmission system and the applicability of the cross-domain data transmission method based on quantum keys can be improved through the terminal agent.
[0194] On the basis of the above Figures 1-15 The embodiment of the application further provides a complete cross-domain data transmission method based on quantum keys, Figure 16 is a flowchart of the thirteenth cross-domain data transmission method provided by the embodiment of the application, as shown in the figure, the sending result of the first zero-trust domain node sending the encrypted data transmission request is sending success or sending failure, and the first zero-trust domain node sends the sending result to the first user terminal through the first terminal agent. Figure 16
[0195] Figure 17 is a structural schematic diagram of the fourth cross-domain data transmission system provided by the embodiment of the application, as shown in the figure, the terminal agent in the terminal is the first terminal agent or the second terminal agent, and the user terminal in the terminal is the first user terminal or the second user terminal, and the use of the first terminal agent, the first user terminal, the second terminal agent and the second user terminal has been described in the above embodiment. Figure 17
[0196] The control plane forwarding module is a control plane information forwarding module, and the cross-domain data processing module is a cross-domain data agent module, and the use of the control plane information forwarding module and the cross-domain data agent module has been described in the above embodiment.
[0197] The zero-trust control platform comprises an identity authentication infrastructure, a session security negotiation module, a trust evaluation engine and a dynamic access control engine, wherein the identity authentication infrastructure is a user identity authentication infrastructure, and the session security negotiation module is an encryption negotiation module.
[0198] The embodiments of the present application provide a secure key distribution mechanism by using quantum key distribution technology, and strictly verify the identity and dynamically authorize each access request by combining the zero-trust architecture, to realize secure collaborative communication between cross-domain. This method not only improves the security and reliability of cross-domain communication, but also has significant advantages in dealing with future quantum computing threats.
[0199] The embodiments of the present application significantly improve the overall security of cross-domain collaborative communication by combining quantum key distribution technology and zero-trust architecture. The quantum key distribution technology uses quantum mechanics to ensure the unconditional security of the key distribution process, avoiding the vulnerability of traditional key distribution mechanisms. The zero-trust architecture further enhances the security of access control through strict identity verification and dynamic authorization mechanisms, preventing unauthorized access and internal threats. The security of the zero-trust environment perception is improved, and the trust perception reporting and data transmission process are combined to use the key encrypted by the quantum key distribution network to ensure the security of the trust environment data reporting, and improve the reliability of dynamic trust management and access control.
[0200] The step division of the above methods is only for clear description, and can be combined into one step or some steps can be split or decomposed into multiple steps, as long as the same logical relationship is included, and all are within the protection scope of the patent; adding irrelevant modifications or introducing irrelevant designs in the algorithm or process, but not changing the core design of the algorithm and process are within the protection scope of the patent.
[0201] The embodiments of the present application relate to a zero-trust domain node, Figure 18 is a structural schematic diagram of the zero-trust domain node provided by the embodiments of the present application, like Figure 18As shown, the device includes at least one processor 1801, and a memory 1802 connected with the at least one processor 1801; the memory 1802 stores instructions executable by the at least one processor 1801, and the instructions are executed by the at least one processor 1801 to enable the at least one processor 1801 to perform the quantum key-based cross-domain data transmission method in the above embodiments. When the device is the first zero-trust domain node, the device is configured to perform the quantum key-based cross-domain data transmission method performed by the first zero-trust domain node in the above embodiments. When the device is the second zero-trust domain node, the device is configured to perform the quantum key-based cross-domain data transmission method performed by the second zero-trust domain node in the above embodiments.
[0202] The memory 1802 and the processor 1801 are connected in a bus manner, and the bus can include any number of interconnected buses and bridges, which connect various circuits of one or more processors and memories together.
[0203] The embodiments of the present application relate to a computer readable storage medium storing a computer program. The computer program is executed by a processor to implement the above method embodiments.
[0204] That is, those skilled in the art can understand that all or part of the steps of the above-mentioned method embodiments can be completed by a program instructing related hardware, the program is stored in a storage medium, and includes a plurality of instructions for enabling a device (which can be a single-chip microcomputer, a chip, etc.) or a processor to execute all or part of the steps of the method described in each embodiment of the present application. The foregoing storage medium includes a U disk, a mobile hard disk, a read-only memory (ROM, Read-Only Memory), a random access memory (RAM, Random Access Memory), a magnetic disk or an optical disk, and various program code storage media.
[0205] Those skilled in the art can understand that the above embodiments are specific embodiments for implementing the present application, and in actual applications, various changes can be made in form and details without departing from the spirit and scope of the present application.
Claims
1. A cross-domain data transmission method based on quantum key distribution, characterized in that, The method, applied to a first zero-trust domain node in a first network domain, includes: Receive a session request sent by a sending terminal in the first network domain; The request for a session is sent to the zero-trust control platform, which generates a session key based on the request, performs quantum key encryption on the session key to obtain session encryption information, and sends the session encryption information to the first zero-trust domain node. Receive the session encryption information sent by the zero-trust control platform; The session encryption information is sent to the sending terminal, which then performs quantum key decryption on the session encryption information to obtain the session key. The communication data is then encrypted using the session key to obtain encrypted communication data. Finally, an encrypted data transmission request carrying the encrypted communication data, session identifier, and receiving terminal identifier is sent to the first zero-trust domain node. Receive the encrypted data transmission request sent by the sending terminal; The encrypted data transmission request is sent to the receiving terminal in the second network domain through the second zero-trust domain node in the second network domain corresponding to the receiving terminal identifier.
2. The cross-domain data transmission method based on quantum key distribution according to claim 1, characterized in that, Before receiving the request for a session sent by the sending terminal in the first network domain, the method further includes: Receive the request from the sending terminal to access the network domain trust token; The request to access the network domain trust token is sent to the zero trust control platform, so that the zero trust control platform determines the trust token of the sending terminal based on the request to access the network domain trust token, and sends the trust token to the first zero trust domain node. Receive the trust token of the sending terminal sent by the zero-trust control platform; The trust token is sent to the sending terminal, causing the sending terminal to add the trust token to the encrypted data transmission request; Sending the encrypted data transmission request to the receiving terminal in the second network domain through the second zero-trust domain node in the second network domain corresponding to the receiving terminal identifier includes: Verify the access rights of the sending terminal's trust token to the second network domain; If the verification passes, the encrypted data transmission request will be sent to the receiving terminal through the second zero-trust domain node.
3. The cross-domain data transmission method based on quantum key distribution according to claim 2, characterized in that, Before verifying the access rights of the sending terminal's trust token to the second network domain, the method further includes: Receive terminal environment information sent by the sending terminal; The terminal environment information is sent to the zero trust control platform, so that the zero trust control platform determines the network domain access permission of the trust token of the sending terminal based on the terminal environment information of the sending terminal, and sends the network domain access permission of the trust token of the sending terminal to the first zero trust domain node. Network domain access permissions to receive the trust token of the sending terminal.
4. The cross-domain data transmission method based on quantum key distribution according to claim 1, characterized in that, Before receiving the request for a session sent by the sending terminal in the first network domain, the method further includes: Receive the authentication request sent by the sending terminal; The authentication request is sent to the zero trust control platform, which generates the authentication result of the sending terminal based on the authentication request, and sends the authentication result of the sending terminal to the first zero trust domain node. Receive the authentication result of the sending terminal sent by the zero-trust control platform; The authentication result of the sending terminal is sent to the sending terminal, so that the sending terminal sends the request for session to the first zero-trust domain node when the authentication result is successful.
5. The cross-domain data transmission method based on quantum key distribution according to claim 1, characterized in that, The sending terminal in the first network domain includes: a first user terminal and a first terminal agent; before receiving the request for a session sent by the sending terminal in the first network domain, it further includes: The first user terminal initiates a user session to the first terminal agent, causing the first terminal agent to send a session request to the first zero-trust domain node based on the first user terminal identifier and the receiving terminal identifier; wherein, the user session includes: the first user terminal identifier, the session identifier, the communication data, and the receiving terminal identifier; After sending the session encryption information to the sending terminal, the method further includes: The first terminal agent decrypts the session encryption information using quantum key decryption to obtain the session key, encrypts the communication data using the session key to obtain encrypted communication data, and sends an encrypted data transmission request carrying the encrypted communication data, session identifier, and receiving terminal identifier to the first zero-trust domain node.
6. A cross-domain data transmission method based on quantum key distribution, characterized in that, The method, applied to a second zero-trust domain node in a second network domain, includes: The method receives an encrypted data transmission request sent by a first zero-trust domain node in a first network domain; wherein the first zero-trust domain node is used to execute the cross-domain data transmission method based on quantum key as described in any one of claims 1-5. The encrypted data transmission request is sent to the receiving terminal, so that the receiving terminal extracts the session identifier from the encrypted data transmission request and sends the session identifier to the second zero-trust domain node; The receiver receives the session identifier sent by the receiving terminal and performs quantum key encryption on the session identifier to obtain session negotiation information. The session negotiation information is sent to the zero-trust control platform, which then performs quantum key decryption on the session negotiation information to obtain the session identifier. Based on the session identifier, a session key is determined, and the session key is encrypted using quantum key encryption to obtain session encrypted information. The session encrypted information is then sent to the second zero-trust domain node. Receive the session encryption information sent by the zero-trust control platform; The session encryption information is sent to the sending terminal, which then performs quantum key decryption on the session encryption information to obtain the session key. The session key is then used to decrypt the encrypted communication data in the encrypted data transmission request to obtain the communication data.
7. The cross-domain data transmission method based on quantum key distribution according to claim 6, characterized in that, The encrypted data transmission request includes the trust token of the sending terminal; Sending the encrypted data transmission request to the receiving terminal includes: Extract the trust token of the sending terminal from the encrypted data transmission request; The trust token of the sending terminal is sent to the zero trust control platform, so that the zero trust control platform verifies the access permissions of the second network domain corresponding to the trust token of the sending terminal and sends the verification result to the second zero trust domain node. Receive the verification result sent by the zero-trust control platform; If the verification result indicates that the verification is successful, the encrypted data transmission request is sent to the receiving terminal.
8. The cross-domain data transmission method based on quantum key distribution according to claim 6, characterized in that, The receiving terminals in the second network domain include: a second user terminal and a second terminal agent; After sending the encrypted data transmission request to the receiving terminal, the method further includes: The second terminal agent extracts the session identifier from the encrypted data transmission request and sends the session identifier to the second zero-trust domain node; After sending the session encryption information to the sending terminal, the method further includes: The second terminal agent decrypts the session encryption information using quantum key decryption to obtain the session key, and then uses the session key to decrypt the encrypted communication data in the encrypted data transmission request to obtain the communication data. The second terminal agent sends the communication data to the second user terminal.
9. A cross-domain data transmission system, characterized in that, include: The network consists of a transmitting terminal in a first network domain, a first zero-trust domain node in the first network domain, a zero-trust control platform, a second zero-trust domain node in a second network domain, and a receiving terminal in the second network domain; the first zero-trust domain node is used to execute the quantum key-based cross-domain data transmission method as described in any one of claims 1-5; the second zero-trust domain node is used to execute the quantum key-based cross-domain data transmission method as described in any one of claims 6-8. The sending terminal connects to the zero-trust control platform through the first zero-trust domain node, and the receiving terminal connects to the zero-trust control platform through the second zero-trust domain node.
10. The cross-domain data transmission system according to claim 9, characterized in that, The sending terminals in the first network domain include: a first user terminal and a first terminal agent; the receiving terminals in the second network domain include: a second user terminal and a second terminal agent. The first user terminal connects to the first zero-trust domain node in the first network domain through the first terminal proxy, and the second user terminal connects to the second zero-trust domain node in the second network domain through the second terminal proxy.
Citation Information
Patent Citations
Cross-domain identity authentication method and system based on quantum key distribution network
CN116527259A
Cross-domain collaboration method and system based on zero trust
CN117544346A