A white-box key processing method and terminal based on quantum key distribution
Patent Information
- Application Number
- CN202411258428.6
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2024-09-09
- Publication Date
- 2026-08-21
- Estimated Expiration
- 2044-09-09
AI Technical Summary
[0003]尽管量子密钥分发提供了数据通信的安全性,但是在现有技术中,它并没有与数据加密方法紧密结合,通信数据仍依赖于传统加密技术来处理数据的加密和解密
[0030]In this embodiment, the quantum key distribution network converts the distributed quantum key into a first white-box key and a white-box encryption algorithm. The encryption terminal receives the first white-box key and white-box encryption algorithm injected by the quantum key distribution network. Based on the white-box key, white-box encryption algorithm, and plaintext communication data, the encryption terminal determines the ciphertext communication data and transmits the ciphertext communication data to the decryption terminal. The decryption terminal also receives a second white-box key and white-box decryption algorithm injected by the quantum key distribution network. The decryption terminal uses the second white-box key and white-box decryption algorithm to decrypt and recover the plaintext communication data. Since the white-box key is an irreversible sequence of the original quantum key, even if the white-box key is leaked, the corresponding quantum key cannot be directly determined, and therefore the plaintext communication data corresponding to the ciphertext communication data cannot be obtained. This not only improves the security of the quantum key but also improves the security of the communication data, providing a more secure guarantee for data communication. This application is particularly suitable for terminal scenarios that lack security chip support but need to store and use keys or passwords, such as mobile phones and data acquisition devices deployed in suburban areas.
Smart Images

Figure CN119109576B_ABST
Abstract
Description
Technical Field
[0001] This application relates to the field of communication security, and in particular to a white-box key processing method and terminal based on quantum key distribution. Background Technology
[0002] Quantum key distribution utilizes the properties of quantum mechanics to ensure the security of data transmission, avoiding quantum computer attacks that traditional encryption methods may face, and providing security for data communication.
[0003] While quantum key distribution provides security for data communication, it is not tightly integrated with data encryption methods in current technologies. Communication data still relies on traditional encryption techniques for encryption and decryption. This creates a security bottleneck: even with quantum key distribution, the limitations of traditional encryption methods may still exist when using quantum key encryption. Quantum keys may be at risk of leakage during storage, transmission, and even computation, resulting in significant security risks for data communication. Summary of the Invention
[0004] The purpose of this application is to provide a white-box key processing method and terminal based on quantum key distribution to improve the security of data communication.
[0005] To address the aforementioned technical problems, embodiments of this application provide a white-box key processing method based on quantum key distribution, applied to an encrypted terminal. The method includes:
[0006] The system receives a first white-box key and a white-box encryption algorithm injected by a quantum key distribution network; wherein the quantum key distribution network converts the distributed quantum key into the first white-box key and the white-box encryption algorithm.
[0007] The ciphertext communication data is determined based on the first white-box key, the white-box encryption algorithm, and the plaintext communication data;
[0008] The encrypted communication data is transmitted to the decryption terminal, which receives the encrypted communication data and determines the plaintext communication data based on the second white-box key, the white-box decryption algorithm, and the encrypted communication data.
[0009] Embodiments of this application also provide a white-box key processing method based on quantum key distribution, which further includes, before receiving the first white-box key and white-box encryption algorithm injected by the quantum key distribution network:
[0010] Determine the white-box algorithm parameters based on business requirements;
[0011] The white-box algorithm parameters are sent to the quantum key distribution network, so that the quantum key distribution network generates the white-box encryption algorithm based on the white-box algorithm parameters.
[0012] Embodiments of this application also provide a white-box key processing method based on quantum key distribution, which further includes, before receiving the first white-box key and white-box encryption algorithm injected by the quantum key distribution network:
[0013] Receive white-box algorithm parameters input by the user;
[0014] The white-box algorithm parameters are sent to the quantum key distribution network, so that the quantum key distribution network generates the white-box encryption algorithm based on the white-box algorithm parameters.
[0015] Embodiments of this application also provide a white-box key processing method based on quantum key distribution, wherein before transmitting the ciphertext communication data to the decryption terminal, the method further includes:
[0016] The white-box algorithm parameters are synchronized to the decryption terminal.
[0017] Embodiments of this application also provide a white-box key processing method based on quantum key distribution, applied to a decryption terminal, the method comprising:
[0018] The encrypted terminal receives encrypted communication data transmitted by an encrypted terminal. The method for determining the encrypted communication data includes: the encrypted terminal receiving a first white-box key and a white-box encryption algorithm injected by a quantum key distribution network; wherein the quantum key distribution network converts the distributed quantum key into the first white-box key and the white-box encryption algorithm, and the encrypted terminal determines the encrypted communication data based on the first white-box key, the white-box encryption algorithm, and the plaintext communication data.
[0019] The system receives a second white-box key and a white-box decryption algorithm injected by the quantum key distribution network; wherein the quantum key distribution network converts the distributed quantum key into the second white-box key and the white-box decryption algorithm.
[0020] The plaintext communication data is determined based on the second white-box key, the white-box decryption algorithm, and the ciphertext communication data.
[0021] Embodiments of this application also provide a white-box key processing method based on quantum key distribution, which further includes, before receiving ciphertext communication data transmitted by the encrypted terminal:
[0022] Determine the white-box algorithm parameters based on the business requirements of the encrypted terminal;
[0023] The white-box algorithm parameters are sent to the quantum key distribution network, so that the quantum key distribution network generates the white-box decryption algorithm based on the white-box algorithm parameters.
[0024] Embodiments of this application also provide a white-box key processing method based on quantum key distribution, which further includes, before receiving ciphertext communication data transmitted by the encrypted terminal:
[0025] Receive white-box algorithm parameters input by the user;
[0026] The white-box algorithm parameters are sent to the quantum key distribution network, so that the quantum key distribution network generates the white-box decryption algorithm based on the white-box algorithm parameters.
[0027] The embodiments of this application also provide a white-box key processing method based on quantum key distribution, wherein the second white-box key of the decryption terminal corresponds to the first white-box key of the encryption terminal, and the white-box algorithm parameters of the decryption terminal are the same as those of the encryption terminal.
[0028] Embodiments of this application also provide an encrypted terminal, including: at least one first processor; and a first memory communicatively connected to the at least one first processor; wherein the first memory stores instructions executable by the at least one first processor, the instructions being executed by the at least one first processor to enable the at least one first processor to execute the above-described white-box key processing method based on quantum key distribution.
[0029] Embodiments of this application also provide a decryption terminal, comprising: at least one second processor; and a second memory communicatively connected to the at least one second processor; wherein the second memory stores instructions executable by the at least one second processor, the instructions being executed by the at least one second processor to enable the at least one second processor to execute the above-described white-box key processing method based on quantum key distribution.
[0030] In this embodiment, the quantum key distribution network converts the distributed quantum key into a first white-box key and a white-box encryption algorithm. The encryption terminal receives the first white-box key and white-box encryption algorithm injected by the quantum key distribution network. Based on the white-box key, white-box encryption algorithm, and plaintext communication data, the encryption terminal determines the ciphertext communication data and transmits the ciphertext communication data to the decryption terminal. The decryption terminal also receives a second white-box key and white-box decryption algorithm injected by the quantum key distribution network. The decryption terminal uses the second white-box key and white-box decryption algorithm to decrypt and recover the plaintext communication data. Since the white-box key is an irreversible sequence of the original quantum key, even if the white-box key is leaked, the corresponding quantum key cannot be directly determined, and therefore the plaintext communication data corresponding to the ciphertext communication data cannot be obtained. This not only improves the security of the quantum key but also improves the security of the communication data, providing a more secure guarantee for data communication. This application is particularly suitable for terminal scenarios that lack security chip support but need to store and use keys or passwords, such as mobile phones and data acquisition devices deployed in suburban areas. Attached Figure Description
[0031] One or more embodiments are illustrated by way of example with reference to the accompanying drawings, and these illustrative descriptions do not constitute a limitation on the embodiments.
[0032] Figure 1 This is a schematic diagram of the structure of a first communication system provided in an embodiment of this application;
[0033] Figure 2 This is a flowchart of the first white-box key processing method based on quantum key distribution provided in the embodiments of this application;
[0034] Figure 3 A flowchart illustrating a second white-box key processing method based on quantum key distribution, provided in an embodiment of this application;
[0035] Figure 4 A flowchart illustrating a third white-box key processing method based on quantum key distribution provided in this application embodiment;
[0036] Figure 5 This is a schematic diagram of the structure of a second communication system provided in an embodiment of this application;
[0037] Figure 6 This is a flowchart of the fourth white-box key processing method based on quantum key distribution provided in the embodiments of this application;
[0038] Figure 7 This is a flowchart of the fifth white-box key processing method based on quantum key distribution provided in the embodiments of this application;
[0039] Figure 8This is a flowchart of the sixth white-box key processing method based on quantum key distribution provided in the embodiments of this application;
[0040] Figure 9 This is a schematic diagram of the structure of the encrypted terminal provided in the embodiments of this application;
[0041] Figure 10 This is a schematic diagram of the decryption terminal provided in the embodiments of this application. Detailed Implementation
[0042] To make the objectives, technical solutions, and advantages of the embodiments of this application clearer, the various embodiments of this application will be described in detail below with reference to the accompanying drawings. However, those skilled in the art will understand that many technical details have been provided in the various embodiments of this application to help readers better understand this application. However, the technical solutions claimed in this application can be implemented even without these technical details and various changes and modifications based on the following embodiments. The division of the various embodiments below is for the convenience of description and should not constitute any limitation on the specific implementation of this application. The various embodiments can be combined with and referenced by each other without contradiction.
[0043] Embodiments of this application relate to a communication system. Figure 1 This is a schematic diagram of the structure of the first communication system provided in the embodiments of this application, as shown below. Figure 1 As shown, the communication system includes an encryption terminal and a decryption terminal, and the encryption terminal and the decryption terminal are connected in communication.
[0044] When the encryption terminal and the decryption terminal communicate, the encryption terminal encrypts the plaintext communication data to obtain the ciphertext communication data, and then transmits the ciphertext communication data to the decryption terminal. The decryption terminal decrypts the ciphertext communication data to obtain the plaintext communication data, thus completing the transmission of communication data.
[0045] Both the encryption and decryption terminals are connected to a quantum key distribution network. Specifically, the quantum key distribution network includes QKD (Quantum Key Distribution) devices. The encryption terminal is connected to QKD device 1, and the decryption terminal is connected to QKD device 2. QKD device 1 can provide the encryption terminal with various keys and other information based on those keys, while QKD device 2 can provide the decryption terminal with various keys and other information based on those keys. This allows the encryption terminal to encrypt data using the keys provided by QKD device 1, and the decryption terminal to decrypt data using the keys provided by QKD device 2.
[0046] QKD device 1 and QKD device 2 are connected, and quantum key distribution can be performed between them, so that the encryption terminal and the decryption terminal obtain the same quantum key. That is, using the distributed quantum key, the ciphertext encrypted by the encryption terminal can be correctly decrypted by the decryption terminal.
[0047] Based on the communication system provided in the above embodiments, the embodiments of this application provide a white-box key processing method based on quantum key distribution. Figure 2 This is a flowchart of the first white-box key processing method based on quantum key distribution provided in the embodiments of this application, as follows: Figure 2 As shown, the white-box key processing method based on quantum key distribution is applied to the encryption terminal in the above communication system, and specifically includes the following steps.
[0048] Step 201: Receive the first white-box key and white-box encryption algorithm injected by the quantum key distribution network.
[0049] In this process, the quantum key distribution network (QKD) converts the distributed quantum key into a first white-box key and a white-box encryption algorithm. Specifically, QKD device 1 and QKD device 2 perform quantum key distribution to obtain the quantum key between the encryption terminal and the decryption terminal. QKD device 1 in the quantum key distribution network then converts the distributed quantum key to obtain the first white-box key and the white-box encryption algorithm.
[0050] In the quantum key distribution network, QKD device 1 injects a first white-box key and a white-box encryption algorithm into the encryption terminal, enabling the encryption terminal to receive the first white-box key and white-box encryption algorithm injected by the quantum key distribution network.
[0051] White-box cryptography is a special implementation of encryption algorithms that protects the quantum key even if an attacker has complete control over the execution environment. White-box cryptography makes it extremely difficult to extract the quantum key directly by embedding it within complex, obfuscated code.
[0052] Optionally, the first white-box key can be determined by performing a white-box algorithm transformation on the quantum key using a white-box encryption algorithm.
[0053] Optionally, a standard encryption algorithm is selected, the quantum key is embedded into the algorithm's implementation, and the entire implementation is obfuscated to generate a white-box encryption algorithm with the embedded quantum key. This implementation is a standalone encryption function that contains the quantum key internally but is difficult to extract from the outside.
[0054] Optionally, the quantum key can be input into a white-box key generator in the encryption terminal for processing to generate a white-box key sequence with a specified white-box algorithm, which is the first white-box key.
[0055] Optionally, the first white-box key can be updated periodically to maintain the security of the communication system. Updates can be achieved by regenerating a new first white-box key.
[0056] Step 202: Determine the ciphertext communication data based on the first white-box key, the white-box encryption algorithm, and the plaintext communication data.
[0057] By inputting the first white-box key and the plaintext communication data into the white-box encryption algorithm, ciphertext communication data can be obtained. Specifically, the encryption terminal uses the white-box encryption algorithm and the generated first white-box key to encrypt the plaintext communication data, generating ciphertext communication data.
[0058] For example, white-box encryption algorithms internally involve complex processing steps such as obfuscation, embedding, and transformation of the white-box key and plaintext communication data. The first white-box key and plaintext communication data are transformed into a form involving lookup table operations and the insertion of irrelevant code, making it impossible for external entities to directly deduce the correspondence between the input and output from the output.
[0059] White-box encryption algorithms ensure the security of the first white-box key and plaintext communication data through a complex internal obfuscation and transformation process, making it impossible for outsiders to obtain the true content of the encrypted communication data or the first white-box key information through simple observation or deduction.
[0060] Step 203: Transmit the encrypted communication data to the decryption terminal.
[0061] After receiving the encrypted communication data, the decryption terminal determines the plaintext communication data based on the second white-box key, the white-box decryption algorithm, and the encrypted communication data.
[0062] Among them, the white-box decryption algorithm corresponds to the white-box encryption algorithm, which enables the white-box decryption algorithm to correctly decrypt encrypted communication data.
[0063] This invention transforms quantum key distribution into a white-box algorithm and white-box key distribution output, aiming to enhance the security of storage, transmission, and use after quantum key distribution. It achieves an effective combination of quantum key distribution and data encryption methods, and the white-box key meets the security requirements of updated environments to adapt to a wider range of application scenarios. This invention aims to improve the security and controllability of quantum key distribution and applications. Traditional quantum key distribution schemes directly output quantum keys, which poses certain security risks because the transmission and storage of quantum keys after distribution may be vulnerable to attacks. To solve this problem, this invention does not directly output the quantum key during quantum key distribution output. Instead, it transforms the quantum key through a specific quantum transformation algorithm to generate a white-box key and a corresponding white-box algorithm output. The white-box key is an irreversible sequence of the original quantum key, and its encryption and decryption effect, combined with the white-box algorithm, is consistent with the conventional encryption and decryption results of the original key. Therefore, the use of white-box keys and white-box algorithms offers higher security. They protect the security of the original key, and the white-box key is more difficult for attackers to steal or crack during transmission and use. These characteristics also allow the white-box key to be used directly in environments without low security or protection. Combining quantum key distribution with white-box technology provides a more reliable solution for secure communication.
[0064] This invention converts quantum keys into corresponding white-box keys for distribution, effectively hiding the structure and characteristics of the quantum keys and increasing the difficulty for attackers to crack them. This method avoids the risks that may arise from directly transmitting the key itself, improving the security and confidentiality of key transmission. This invention combines quantum key distribution with white-box algorithms to create a new security scheme. This fusion leverages the advantages of both technologies, providing a more comprehensive protection mechanism. This invention not only utilizes the resistance to quantum computing attacks inherent in quantum key distribution but also combines the security of white-box algorithms, providing a more effective way to deal with the threats posed by future quantum computers.
[0065] This invention combines the advantages of absolutely secure quantum key distribution and reverse engineering resistance of white-box cryptographic algorithms, providing dual security guarantees and making the system more secure and reliable. It possesses a certain degree of resistance to quantum computing attacks; even if quantum computers become a reality in the future, this scheme can still provide a certain level of protection. Employing a white-box key distribution method for indirect quantum key distribution increases the security and confidentiality of key transmission, effectively protecting the confidentiality of communication content.
[0066] In this embodiment, the first white-box key is an irreversible sequence of the original quantum key. Even if the first white-box key is leaked, the corresponding quantum key cannot be directly determined, and thus the plaintext communication data corresponding to the ciphertext communication data cannot be obtained. This not only improves the security of the quantum key but also the security of the communication data, providing a more secure guarantee for data communication.
[0067] In the above Figure 2 Based on the white-box key processing method based on quantum key distribution shown in the previous embodiment, this application also provides another white-box key processing method based on quantum key distribution. Figure 3 A flowchart of the second white-box key processing method based on quantum key distribution provided in the embodiments of this application is shown below. Figure 3 As shown, step 201 above, before receiving the first white-box key and white-box encryption algorithm injected by the quantum key distribution network, specifically includes the following steps.
[0068] Step 301: Determine the white-box algorithm parameters based on business requirements.
[0069] White-box algorithm parameters may include: transformation table, S-box permutation table, number of encryption rounds, changes in the initial vector, etc.
[0070] Transformation tables are used to convert input data, such as plaintext or keys, into an irreversible form used internally by the algorithm, increasing the obfuscation and security of the input data. S-box permutation tables are non-linear permutation tables used to replace specific input values in the algorithm, increasing its complexity and resistance to cryptanalysis. Encryption rounds refer to the number of times the encryption operation is repeated in the algorithm, used to increase the algorithm's obfuscation and security. Initialization vectors are used in certain encryption modes to enhance the randomness and security of encryption, preventing the same plaintext from generating the same ciphertext in different encryption operations. By changing the initialization vector, attackers can be prevented from obtaining the same encryption result using the same plaintext and key pair, thereby increasing the algorithm's security and usability.
[0071] Business requirements may include: security requirements, performance requirements, platform environment requirements, scenario requirements, etc.
[0072] Security requirements aim to select a sufficiently long key length to improve encryption strength based on business needs and security levels. Performance requirements aim to balance the encryption / decryption speed and complexity of the algorithm based on business speed requirements, and to select algorithm parameters suitable for device resources, considering the algorithm's memory footprint on the device. Platform environment requirements aim to select appropriate algorithm parameters based on the algorithm's performance on different devices (such as mobile devices, servers, etc.). Scenario requirements aim to select appropriate algorithm parameters based on the type of digital content to be protected and the transmission method, and to select appropriate algorithm parameters considering payment security and speed requirements.
[0073] White-box algorithm parameters need to comprehensively consider the business's security requirements, performance requirements, platform and environmental factors, specific business scenarios, and industry standards to achieve a secure, reliable encryption solution that meets business needs.
[0074] Different business requirements may correspond to different white-box algorithm parameters, and thus to different white-box encryption algorithms.
[0075] In one embodiment, the encrypted terminal pre-defines the correspondence between business requirements and white-box algorithm parameters. In another embodiment, the business requirements carry white-box algorithm parameters. Of course, there may be other relationships between business requirements and white-box algorithms, which are not specifically limited in this embodiment.
[0076] Step 302: Send the white-box algorithm parameters to the quantum key distribution network so that the quantum key distribution network can generate a white-box encryption algorithm based on the white-box algorithm parameters.
[0077] After the encryption terminal sends the white-box algorithm parameters to the quantum key distribution network (QKDC), the QKDC, in generating the white-box encryption algorithm, determines the algorithm framework, implements the transformation table and S-box permutation table, writes the encryption round function, randomizes the initialization vector, and finally integrates all components to form a complete white-box encryption algorithm. Afterwards, testing and verification can be performed to ensure that the algorithm can correctly encrypt data under various conditions, while meeting both security and performance requirements.
[0078] Optionally, the quantum key distribution network can generate a white-box encryption algorithm based on the white-box algorithm parameters and the distributed quantum key.
[0079] In this embodiment of the application, the corresponding white-box encryption algorithm is determined based on business requirements. By using different white-box encryption algorithms, the security of data communication can be further improved.
[0080] In the above Figure 2 Based on the white-box key processing method based on quantum key distribution shown in the previous embodiment, this application also provides another white-box key processing method based on quantum key distribution. Figure 4 A flowchart of the third white-box key processing method based on quantum key distribution provided in the embodiments of this application is shown below. Figure 4 As shown, step 201 above, before receiving the first white-box key and white-box encryption algorithm injected by the quantum key distribution network, specifically includes the following steps.
[0081] Step 401: Receive the white-box algorithm parameters input by the user.
[0082] Users can also specify white-box algorithm parameters. In this case, the encrypted terminal is directly used to receive the white-box algorithm parameters input by the user.
[0083] For example, in security products or applications, it may be necessary to provide customized white-box encryption solutions to meet specific security or performance requirements. In this case, receiving white-box algorithm parameters input by the user can help generate a suitable white-box encryption algorithm based on the user's needs.
[0084] Step 402: Send the white-box algorithm parameters to the quantum key distribution network so that the quantum key distribution network can generate a white-box encryption algorithm based on the white-box algorithm parameters.
[0085] The specific implementation of this step is similar to or the same as that of step 302 above, and will not be elaborated further here.
[0086] This invention allows for the selection of appropriate white-box encryption algorithms based on different application scenarios and security requirements, thus meeting the needs of different users.
[0087] In this embodiment, the corresponding white-box encryption algorithm is obtained through user input, which can realize the personalized customization of the white-box encryption algorithm and improve the applicability of the white-box key processing method based on quantum key distribution.
[0088] In the above Figure 3 and Figure 4 Based on the white-box key processing method based on quantum key distribution shown, the embodiments of this application also provide another white-box key processing method based on quantum key distribution. Before transmitting the ciphertext communication data to the decryption terminal in step 203 above, the method further includes synchronizing the white-box algorithm parameters to the decryption terminal.
[0089] Optionally, the white-box algorithm parameters and the first white-box key can be synchronized to the decryption terminal.
[0090] Specifically, Figure 5 This is a schematic diagram of the structure of a second communication system provided in an embodiment of this application, as shown below. Figure 5 As shown, the data transmission channel between the encryption terminal and the decryption terminal includes two transmission channels: a normal transmission channel and a secure transmission channel. The normal transmission channel is used to transmit encrypted communication data, while the secure transmission channel is used to transmit data that requires secure transmission, such as white-box algorithm parameters, the first white-box key, and quantum keys.
[0091] Synchronous white-box algorithms enable the white-box encryption and decryption algorithms of encryption and decryption terminals to correspond, allowing the white-box decryption algorithm to correctly decrypt communication data encrypted by the white-box encryption algorithm.
[0092] When an encrypted terminal generates a quantum key using a quantum key distribution system, this process ensures that both the encrypted and decrypted terminals obtain the same secure quantum key. In one embodiment, the specific steps are as follows: the encrypted terminal and the decrypted terminal establish a secure transmission channel to ensure the confidentiality and integrity of the communication content; the quantum key distribution device of the encrypted terminal uses a quantum key distribution protocol (such as the BB84 protocol) to generate a random sequence of qubits (quantum key); the encrypted terminal transmits the generated qubit sequence to the decrypted terminal via optical fiber, and the decrypted terminal transmits the qubit sequence to its quantum key distribution device. In another embodiment, such as... Figure 1 As shown, the specific steps are as follows: QKD device 1 of the encryption terminal uses a quantum key distribution protocol (such as the BB84 protocol) to generate a random sequence of qubits (quantum key); QKD device 1 of the encryption terminal transmits the generated qubit sequence to QKD device 2 through the data transmission channel of the quantum key distribution network.
[0093] Before transmitting encrypted communication data to the decryption terminal, the encryption terminal needs to synchronize the white-box algorithm parameters (and the first white-box key) to the decryption terminal through a secure transmission channel. That is, the generated first white-box key and white-box algorithm parameters need to be deployed to the encryption terminal and the corresponding decryption terminal, respectively.
[0094] When synchronizing white-box algorithm parameters and the first white-box key to the decryption terminal, for key update and security considerations, the white-box algorithm parameters and the first white-box key can be deployed in stages. For example, white-box algorithm parameters can be injected during terminal initialization to generate a white-box encryption algorithm, and the first white-box key can be updated periodically when the terminal goes online. The first white-box key and white-box encryption algorithm can be deployed or distributed to terminals using cryptography in stages. For example, a remote terminal can inject the white-box algorithm during initialization, while the first white-box key can be updated periodically when it goes online, thus further enhancing the system's security and flexibility.
[0095] In this embodiment, the white-box algorithm parameters are synchronized to the decryption terminal, so that the white-box algorithm parameters in the decryption terminal and the encryption terminal are the same, and the white-box encryption algorithm of the encryption terminal and the white-box decryption algorithm of the decryption terminal correspond to each other, so as to correctly decrypt the encrypted communication data.
[0096] Based on the communication system provided in the above embodiments, the embodiments of this application provide a white-box key processing method based on quantum key distribution. Figure 6 This is a flowchart of the fourth white-box key processing method based on quantum key distribution provided in the embodiments of this application, as follows: Figure 6 As shown, the white-box key processing method based on quantum key distribution is applied to the decryption terminal in the above communication system, and specifically includes the following steps.
[0097] Step 601: Receive encrypted communication data transmitted by the encrypted terminal.
[0098] The method for determining the encrypted communication data includes: the encrypted terminal receiving a first white-box key and a white-box encryption algorithm injected by the quantum key distribution network; wherein the quantum key distribution network converts the distributed quantum key into a first white-box key and a white-box encryption algorithm, and the encrypted terminal determines the encrypted communication data based on the first white-box key, the white-box encryption algorithm, and the plaintext communication data.
[0099] Step 602: Receive the second white-box key and white-box decryption algorithm injected by the quantum key distribution network.
[0100] The quantum key distribution network converts the distributed quantum key into a second white-box key and a white-box decryption algorithm.
[0101] The quantum key is the quantum key distributed by QKD device 1 of the encryption terminal and QKD device 2 of the decryption terminal. That is, the quantum key in QKD device 1 in the quantum key distribution network is the same as the quantum key in QKD device 2 (and can be used as a symmetric key).
[0102] In a quantum key distribution network (QKD), device 1 converts the distributed quantum key to obtain a first white-box key and a white-box encryption algorithm. Correspondingly, QKD device 2 converts the distributed quantum key to obtain a second white-box key and a white-box decryption algorithm. The first white-box key of the encryption terminal and the second white-box key of the decryption terminal correspond to each other (if the first and second white-box keys are symmetric keys, then the first and second white-box keys are the same).
[0103] In the quantum key distribution network, QKD device 2 injects a second white-box key and a white-box decryption algorithm into the decryption terminal, enabling the decryption terminal to receive the second white-box key and white-box decryption algorithm injected by the quantum key distribution network.
[0104] Step 603: Determine the plaintext communication data based on the second white-box key, the white-box decryption algorithm, and the ciphertext communication data.
[0105] In this system, the decryption terminal injects a second white-box key and a white-box decryption algorithm corresponding to the quantum key during quantum key distribution. The second white-box key and the encrypted communication data are then input into the white-box decryption algorithm to obtain the plaintext communication data. Specifically, the decryption terminal uses the white-box decryption algorithm corresponding to the white-box encryption algorithm, and the second white-box key corresponding to the first white-box key, to decrypt the encrypted communication data and generate plaintext communication data.
[0106] In this embodiment, the encrypted communication data is decrypted according to the second white-box key and the white-box encryption algorithm corresponding to the white-box decryption algorithm to determine the plaintext communication data. Even if the second white-box key is leaked, the correct decryption cannot be performed directly because the white-box decryption algorithm is unknown. Even if the white-box decryption algorithm is leaked, the correct decryption cannot be performed directly because the second white-box key is unknown. Therefore, the plaintext communication data corresponding to the encrypted communication data cannot be obtained. This not only improves the security of the quantum key but also improves the security of the communication data, providing a more secure guarantee for data communication.
[0107] In the above Figure 6 Based on the white-box key processing method based on quantum key distribution shown in the previous embodiment, this application also provides another white-box key processing method based on quantum key distribution. Figure 7 This is a flowchart of the fifth white-box key processing method based on quantum key distribution provided in the embodiments of this application, as follows: Figure 7 As shown, step 601 above, before receiving encrypted communication data transmitted by the encrypted terminal, specifically includes the following steps.
[0108] Step 701: Determine the white-box algorithm parameters based on the business requirements of the encrypted terminal.
[0109] The specific implementation of this step is similar to that of step 301 above, but the executing entity is different, so it will not be elaborated on here.
[0110] Step 702: Send the white-box algorithm parameters to the quantum key distribution network, so that the quantum key distribution network can generate a white-box decryption algorithm based on the white-box algorithm parameters.
[0111] The white-box encryption algorithm and white-box decryption algorithm generated with the same white-box algorithm parameters are corresponding. The white-box decryption algorithm can correctly decrypt data encrypted by the corresponding white-box encryption algorithm.
[0112] In this embodiment of the application, by determining the corresponding white-box decryption algorithm based on the same business requirements as the encryption terminal, the correctness of the decryption terminal in decrypting encrypted communication data can be guaranteed.
[0113] In the above Figure 6 Based on the white-box key processing method based on quantum key distribution shown in the previous embodiment, this application also provides another white-box key processing method based on quantum key distribution. Figure 8 This is a flowchart of the sixth white-box key processing method based on quantum key distribution provided in the embodiments of this application, as follows: Figure 8 As shown, step 601 above, before receiving encrypted communication data transmitted by the encrypted terminal, specifically includes the following steps.
[0114] Step 801: Receive white-box algorithm parameters input by the user or white-box algorithm parameters transmitted by the encrypted terminal.
[0115] Users can also specify white-box algorithm parameters. In this case, the decryption terminal is used to directly receive the white-box algorithm parameters input by the user.
[0116] The encryption terminal can also transmit the generated white-box algorithm parameters to the decryption terminal through a secure transmission channel. The decryption terminal receives the white-box algorithm parameters transmitted by the encryption terminal and sends them to the QKD device 2 of the decryption terminal in the quantum key distribution network.
[0117] Step 802: Send the white-box algorithm parameters to the quantum key distribution network, so that the quantum key distribution network can generate a white-box decryption algorithm based on the white-box algorithm parameters.
[0118] The specific implementation of this step is similar to or the same as that of step 702 above, and will not be elaborated further here.
[0119] In this embodiment, the white-box algorithm parameters transmitted by the encryption terminal ensure that the white-box encryption algorithm of the encryption terminal corresponds to the white-box decryption algorithm of the decryption terminal, thus guaranteeing the correctness of the decryption of encrypted communication data. Furthermore, user input not only allows the white-box encryption algorithm and white-box decryption algorithm to correspond, but also enables both the white-box encryption algorithm and white-box decryption algorithm to be customized, thereby improving the applicability of the white-box key processing method based on quantum key distribution.
[0120] In the above Figure 7 and Figure 8 Based on the white-box key processing method based on quantum key distribution shown, the embodiments of this application also provide another white-box key processing method based on quantum key distribution, wherein the second white-box key of the decryption terminal corresponds to the first white-box key of the encryption terminal, and the white-box algorithm parameters of the decryption terminal are the same as those of the encryption terminal.
[0121] When the encryption is symmetric, the second white-box key of the decryption terminal is the same as the first white-box key of the encryption terminal. When the encryption is asymmetric, the second white-box key of the decryption terminal corresponds to the first white-box key of the encryption terminal. These two white-box keys exist in pairs and have a specific mathematical relationship.
[0122] When the white-box algorithm parameters of the decryption terminal are the same as those of the encryption terminal, the white-box encryption algorithm generated by the encryption terminal corresponds to the white-box decryption algorithm generated by the decryption terminal, enabling the decryption terminal to correctly decrypt and obtain plaintext communication data.
[0123] In this embodiment, the white-box algorithm parameters in the decryption terminal and the encryption terminal are the same, and the white-box keys are corresponding, so as to correctly decrypt the encrypted communication data.
[0124] Based on the above embodiments, the embodiments of this application also provide another white-box key processing method based on quantum key distribution.
[0125] Specifically, this application contains three combinations of encryption and decryption schemes.
[0126] The first encryption / decryption scheme is as follows: the encryption side (encryption terminal) uses a white-box encryption algorithm and a white-box key for encryption, and the decryption side (decryption terminal) uses a white-box decryption algorithm and a white-box key for decryption.
[0127] The second encryption / decryption scheme is as follows: the encryption side (encryption terminal) uses a white-box encryption algorithm and a white-box key for encryption, and the decryption side (decryption terminal) directly uses a quantum key for decryption.
[0128] The third encryption / decryption scheme is as follows: the encryption side (encryption terminal) directly uses quantum key encryption, and the decryption side (decryption terminal) uses white-box encryption algorithm and white-box key decryption.
[0129] In environments with cryptographic security, quantum key encryption and decryption can be performed directly, while in insecure environments, white-box encryption and decryption algorithms and white-box keys can be used for encryption and decryption to adapt to different environments.
[0130] The steps of the various methods described above are only for clarity. In practice, they can be combined into one step or some steps can be split into multiple steps. As long as they include the same logical relationship, they are all within the scope of protection of this patent. Adding insignificant modifications or introducing insignificant designs to the algorithm or process, but without changing the core design of the algorithm and process, are also within the scope of protection of this patent.
[0131] This application relates to an encrypted terminal. Figure 9 This is a schematic diagram of the structure of the encrypted terminal provided in the embodiments of this application, as shown below. Figure 9 As shown, it includes: at least one first processor 901; and a first memory 902 communicatively connected to at least one first processor 901; wherein the first memory 902 stores instructions that can be executed by at least one first processor 901, and the instructions are executed by at least one first processor 901 to enable at least one first processor 901 to execute the above-mentioned white-box key processing method based on quantum key distribution with the encryption terminal as the execution subject.
[0132] The first memory 902 and the first processor 901 are connected by a bus. The bus can include any number of interconnected buses and bridges, and the bus connects various circuits of one or more processors and memories together.
[0133] This application relates to a decryption terminal. Figure 10 This is a schematic diagram of the decryption terminal provided in the embodiments of this application, as shown below. Figure 10 As shown, it includes: at least one second processor 1001; and a second memory 1002 communicatively connected to at least one second processor 1001; wherein the second memory 1002 stores instructions that can be executed by at least one second processor 1001, and the instructions are executed by at least one second processor 1001 to enable at least one second processor 1001 to execute the white-box key processing method based on quantum key distribution with the decryption terminal as the execution subject.
[0134] The second memory 1002 and the second processor 1001 are connected by a bus. The bus can include any number of interconnected buses and bridges, and the bus connects various circuits of one or more processors and memories together.
[0135] This application relates to a computer-readable storage medium storing a computer program. When the computer program is executed by a processor, it implements the method embodiments described above.
[0136] That is, those skilled in the art will understand that all or part of the steps in the methods of the above embodiments can be implemented by a program instructing related hardware. This program is stored in a storage medium and includes several instructions to cause a device (which may be a microcontroller, chip, etc.) or processor to execute all or part of the steps of the methods described in the various embodiments of this application. The aforementioned storage medium includes various media capable of storing program code, such as a USB flash drive, a portable hard drive, a read-only memory (ROM), a random access memory (RAM), a magnetic disk, or an optical disk.
[0137] Those skilled in the art will understand that the above embodiments are specific embodiments for implementing this application, and in practical applications, various changes can be made to them in form and detail without departing from the spirit and scope of this application.
Claims
1. A white-box key processing method based on quantum key distribution, characterized in that, Applied to encrypted terminals, the method includes: The system receives a first white-box key and a white-box encryption algorithm injected by a quantum key distribution network; wherein the quantum key distribution network converts the distributed quantum key into the first white-box key and the white-box encryption algorithm. The ciphertext communication data is determined based on the first white-box key, the white-box encryption algorithm, and the plaintext communication data; The encrypted communication data is transmitted to the decryption terminal, so that the decryption terminal receives the encrypted communication data and determines the plaintext communication data based on the second white-box key, the white-box decryption algorithm and the encrypted communication data. Specifically, before receiving the first white-box key and white-box encryption algorithm injected by the quantum key distribution network, the white-box algorithm parameters are sent to the quantum key distribution network, so that the quantum key distribution network generates the white-box encryption algorithm according to the white-box algorithm parameters; In this process, the decryption terminal has already injected the second white-box key corresponding to the quantum key and the white-box decryption algorithm during quantum key distribution.
2. The white-box key processing method according to claim 1, characterized in that, The parameters of the white-box algorithm are determined according to business requirements.
3. The white-box key processing method according to claim 1, characterized in that, Before receiving the first white-box key and white-box encryption algorithm injected by the quantum key distribution network, the method further includes: Receive the white-box algorithm parameters input by the user.
4. The white-box key processing method according to any one of claims 2-3, characterized in that, Before transmitting the encrypted communication data to the decryption terminal, the method further includes: The white-box algorithm parameters are synchronized to the decryption terminal.
5. A white-box key processing method based on quantum key distribution, characterized in that, Applied to a decryption terminal, the method includes: The encrypted terminal receives encrypted communication data transmitted by an encrypted terminal. The method for determining the encrypted communication data includes: the encrypted terminal receiving a first white-box key and a white-box encryption algorithm injected by a quantum key distribution network; wherein the quantum key distribution network converts the distributed quantum key into the first white-box key and the white-box encryption algorithm, and the encrypted terminal determines the encrypted communication data based on the first white-box key, the white-box encryption algorithm, and the plaintext communication data. The system receives a second white-box key and a white-box decryption algorithm injected by the quantum key distribution network; wherein the quantum key distribution network converts the distributed quantum key into the second white-box key and the white-box decryption algorithm. The plaintext communication data is determined based on the second white-box key, the white-box decryption algorithm, and the ciphertext communication data. Specifically, before receiving encrypted communication data transmitted by the encrypted terminal, white-box algorithm parameters are sent to the quantum key distribution network, so that the quantum key distribution network generates the white-box decryption algorithm based on the white-box algorithm parameters. In this process, the decryption terminal has already injected the second white-box key corresponding to the quantum key and the white-box decryption algorithm during quantum key distribution.
6. The white-box key processing method according to claim 5, characterized in that, The white-box algorithm parameters are determined based on the business requirements of the encryption terminal.
7. The white-box key processing method according to claim 5, characterized in that, Before receiving the encrypted communication data transmitted by the encrypted terminal, the method further includes: Receive the white-box algorithm parameters input by the user or transmitted by the encrypted terminal.
8. The white-box key processing method according to any one of claims 6-7, characterized in that, The second white-box key of the decryption terminal corresponds to the first white-box key of the encryption terminal, and the white-box algorithm parameters of the decryption terminal are the same as those of the encryption terminal.
9. An encrypted terminal, characterized in that, include: At least one first processor; as well as, A first memory communicatively connected to the at least one first processor; wherein, The first memory stores instructions that can be executed by the at least one first processor, which, when executed by the at least one first processor, enables the at least one first processor to perform the white-box key processing method based on quantum key distribution as described in any one of claims 1 to 4.
10. A decryption terminal, characterized in that, include: At least one second processor; as well as, A second memory communicatively connected to the at least one second processor; wherein, The second memory stores instructions that can be executed by the at least one second processor, which, when executed by the at least one second processor, enables the at least one second processor to perform the white-box key processing method based on quantum key distribution as described in any one of claims 5 to 8.
Citation Information
Patent Citations
Method, device and system for generating and encrypting white box key
CN108123794A