A security detection device for a quantum encryption system and its detection method
By designing a security detection device that integrates data acquisition, verification, randomness detection and counting modules, the complex and tedious security detection of quantum encryption systems is solved, and efficient and reliable security detection is achieved.
Patent Information
- Application Number
- CN202411178437.4
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2024-08-27
- Publication Date
- 2025-05-27
- Estimated Expiration
- 2044-08-27
AI Technical Summary
In the prior art, the security detection method of quantum encryption systems is complex and tedious, with low efficiency, which is not conducive to the security detection of quantum encryption.
A security detection device including a data acquisition module, a data verification module, a random detection module, a counting module and a result output module is designed. By conducting legality verification and random detection of the input data and output data of the quantum encryption system, a detection result report is generated.
The security detection of quantum encryption system is realized, and the detection method is simple and efficient, which can effectively save detection time and improve detection reliability.
Smart Images

Figure CN119155023B_ABST
Abstract
Description
Technical Field
[0001] This application relates to the field of communication security technologies, and particularly to a security detection device and method for a quantum encryption system. Background Art
[0002] Currently, to ensure the privacy and security of data during the data flow process, people use encryption methods for data transmission. Based on the encrypted transmission method, users will default that the data flow is secure. However, the security of the encryption algorithm actually determines whether the data flow is truly secure. The patent with the patent number CN117131517B proposes a "security detection method, terminal device, and storage medium for encryption algorithms" to solve the technical problem of inaccurate security detection results of encryption algorithms. This patent is a detection method for the security of traditional encryption algorithms. Given that traditional encryption algorithms are no longer sufficient to ensure the uncrackability of encryption in today's era of rapid development of quantum technology, quantum encryption has emerged. When applying quantum encryption, the system defaults to the security of quantum encryption. However, whether it is truly secure still needs to be further detected. Only a quantum encryption device that has passed the security inspection is a truly secure quantum encryption device. In addition, the existing detection methods are complex and cumbersome, with low efficiency, which is not conducive to the security detection of quantum encryption. In view of this, this application aims to propose a detection method and device for the security of quantum encryption methods. Summary of the Invention
[0003] Object of the Invention: This application provides a security detection device and method for a quantum encryption system to solve the problems existing in the prior art.
[0004] Technical Solution: The present invention provides a security detection device for a quantum encryption system, including a data acquisition module, a data verification module, a randomness detection module, a counting module, and a result output module. Among them, the data acquisition module, the data verification module, the randomness detection module, and the result output module are sequentially communicatively connected. The data verification module, the randomness detection module, and the result output module are also respectively communicatively connected to the counting module. The data acquisition module is also communicatively connected to the data execution module;
[0005] The data acquisition module is used to locate the quantum encryption module in the quantum encryption system, record the positioning result in the quantum encryption module, and obtain the input data and output data of the quantum encryption module according to the positioning result; among them, the input data is the plaintext input to the quantum encryption system, and the output data is the ciphertext output from the quantum encryption system;
[0006] The data verification module is used to perform legality verification on the received input data and output data; among them, the legality verification includes format verification and content verification;
[0007] The randomness detection module is used to perform randomness detection on the received input data after the legality verification is passed, and send the randomness detection result to the result output module;
[0008] The counting module is used to perform a counting operation according to the instructions of the data verification module and / or the randomness detection module, and send the counting result to the result output module;
[0009] The result output module is used to store the received counting result and randomness detection result, and generate a detection result report for output according to the counting result and randomness detection result.
[0010] As an improvement of the present invention, the data acquisition module includes a data positioning unit, an input acquisition unit and an output acquisition unit. The data positioning unit is communicatively connected to the input acquisition unit and the output acquisition unit respectively, and is also communicatively connected to an external quantum encryption system; wherein, the positioning unit is used to locate the quantum encryption module in the quantum encryption system and record the positioning result in the quantum encryption module; the input acquisition unit is used to acquire the input data of the quantum encryption module according to the positioning result and send it to the data verification module and the randomness detection module; the output acquisition unit is used to acquire the output data of the quantum encryption module according to the positioning result and send it to the data verification module and the randomness detection module.
[0011] As an improvement of the present invention, the data verification module includes a format verification unit and a content verification unit that communicate with each other. The format verification unit is communicatively connected to the input acquisition unit and the output acquisition unit respectively, and the content verification unit is communicatively connected to the input acquisition unit and the output module respectively; wherein, the format verification unit is used to perform format verification on the received input data and output data, and send the format verification result as an instruction to the counting module and at the same time send it to the randomness detection module; the content verification unit is used to perform content verification on the received output data, and send the content verification result as an instruction to the counting module and at the same time send it to the randomness detection module.
[0012] As an improvement of the present invention, the randomness detection module includes a data processing unit and a data calling unit that communicate with each other. The data processing unit is communicatively connected to an external quantum encryption system, an output acquisition unit, a content verification unit, and a counting module. The data calling unit is also communicatively connected to an external random number detection tool and a result output module. The data processing unit is configured to process the received input data after obtaining information that both the format verification and the content verification passed from the content verification unit, obtain and store the marked output data, and simultaneously notify the counting module to perform counting. When the counting result is greater than the preset number threshold in the counting module, it notifies the data calling unit to call an external random number detection tool to perform randomness detection. The data calling unit is configured to call an external random number detection tool to perform randomness detection on the marked output data according to the notification of the data processing unit, and send the verification result to the result output module.
[0013] As an improvement of the present invention, the counting module includes a first counting subunit, a second counting subunit, and a third counting subunit. Among them, the first counting subunit is connected and communicates with the format verification unit and the result output module, and is configured to perform a counting operation according to the instruction of the format verification unit, and send the corresponding first counting result to the result output module. The second counting subunit is communicatively connected to the content verification unit and the result output module, and is configured to perform a counting operation according to the instruction of the content verification unit, and send the corresponding second counting result to the result output module. The third counting subunit is communicatively connected to the data processing unit, and is configured to perform a counting operation according to the notification of the data processing unit and feedback the corresponding third counting result.
[0014] As an improvement of the present invention, there is also provided a security detection method for a quantum encryption system, which is applied to the security detection device for a quantum encryption system described above, and includes the following steps:
[0015] Step 1: The security detection device is started, and the data acquisition module acquires input data and output data from the quantum encryption system and sends them to the data verification module.
[0016] Step 2: The data verification module performs a legality verification on the obtained input data and output data. If the verification passes and the number of passes is greater than or equal to the preset number threshold in the counting module, the counting module notifies the result output module to generate a detection result of passing the legality verification for storage. At the same time, the data verification module sends the input data that has passed the verification to the randomness detection module. Otherwise, the counting module notifies the result output module to generate a verification result of failing the legality verification and output it.
[0017] Step 3: The randomness detection module processes the input data that has passed the legality verification in Step 2 to generate marked output data, notifies the counting module to perform a counting operation on the marked output data, and after reaching the preset number threshold in the counting module, feeds back to the randomness detection module. The randomness detection module performs a randomness detection on the marked output data. If the randomness detection passes, it sends the detection result of passing the randomness detection to the result output module; otherwise, it notifies the result output module to generate and output a verification result of failing the randomness detection.
[0018] Step 4: The result output module generates and outputs a detection result report of passing the security detection based on the detection results of passing the legality verification and the randomness detection.
[0019] As an improvement of the present invention, the specific process of Step 1 is as follows: The positioning unit in the data acquisition module locates the quantum encryption module in the quantum encryption system and records the positioning result in the quantum encryption module; the input acquisition unit in the data acquisition module accesses the positioning unit to obtain the positioning result, and acquires the input data of the quantum encryption module according to the positioning result and sends it to the data verification module; the output acquisition unit in the data acquisition module accesses the positioning unit to obtain the positioning result, and acquires the output data of the quantum encryption module according to the positioning result and sends it to the data verification module.
[0020] As an improvement of the present invention, in Step 2, the legality verification includes format verification and content verification, and the format verification is composed of both passing the format verification and passing the content verification;
[0021] The specific process of the format verification is as follows:
[0022] The format verification unit in the data verification module reads the length of the received input data to obtain a first length, reads the length of the output data corresponding to the input data to obtain a second length, compares the first length and the second length. If they are equal, it sends the equal format verification result as an instruction to the first counting subunit in the counting module. The first counting subunit starts counting according to the instruction, monitors the counting result. When the corresponding first counting result is less than the preset first number threshold, it notifies the security detection device to continue to obtain input data and output data from the quantum encryption system; when the corresponding first counting result is greater than or equal to the preset first number threshold, the first counting subunit notifies the result output module to generate and store the first detection result of passing the format verification; otherwise, it sends the format verification result of failing the format verification as an instruction to the first counting subunit in the counting module, and the first counting subunit notifies the result output module to generate and output a detection result of failing the legality detection based on the format verification result of failing the format verification.
[0023] The specific process of the content verification is as follows:
[0024] The content verification unit in the data verification module retrieves one input data and the corresponding output data from the multiple input data and output data that have passed format verification in the format verification unit, and feeds this input data back to the quantum encryption system for quantum encryption multiple times to obtain multiple output data after quantum encryption. The sort() function is called to arrange the multiple output data after quantum encryption according to specified rules and store them, while preserving the order relationship among the multiple output data after quantum encryption to form an output database. The output data obtained each time is compared with other output data stored in the output database. If no identical output data is found, the content verification result that has not been matched is sent as an instruction to the second counting subunit in the counting module. The second counting subunit starts counting according to the instruction and monitors the counting result. When the corresponding second counting result is less than the preset second count threshold, it notifies the security detection device to continue obtaining the output data after quantum encryption from the quantum encryption system; when the corresponding second counting result is greater than or equal to the preset second count threshold, it notifies the result output module to generate and store the second detection result indicating that the content verification has passed. At the same time, the input data that has passed the content verification is sent to the randomness detection module; otherwise, the content verification result indicating that the content verification has failed is sent as an instruction to the second counting subunit in the counting module, and the second counting subunit notifies the result output module to generate and output a detection result indicating that the legality detection has failed based on the format verification result indicating that the format verification has failed.
[0025] As an improvement of the present invention, the specific process of step 3 is as follows:
[0026] Step 3-1: The data processing module in the randomness detection module performs an exclusive OR operation on the received input data that has passed the verification with itself to obtain a second input data with all bits being 0, adds a processing identifier to this second input data, and feeds it back to the quantum encryption system. The quantum encryption system performs a quantum encryption operation on it to obtain a marked output data with a processing identifier.
[0027] Step 3-2: When the data acquisition module performs the data acquisition operation according to step 1, when it detects the marked output data with a processing identifier, the output acquisition unit directly sends the marked output data to the data processing unit. The data processing unit stores the marked output data when it receives it and notifies the third counting subunit in the counting module to start counting.
[0028] Step 3-3: The third counting subunit monitors the counting result and the preset third number threshold in real time. When the corresponding third counting result is less than the third number threshold, it notifies the security detection device to continue obtaining input data and output data from the quantum encryption system; when the corresponding third counting result is greater than or equal to the third number threshold, it notifies the data processing unit to call the data calling unit to execute the next step.
[0029] Step 3-4: The data calling unit obtains multiple marked output data stored therein from the data processing unit, and retrieves a random number detection tool outside the security detection device to detect the multiple marked output data.
[0030] Step 3-5: In response to passing the detection, the data calling unit sends the information that the randomness detection passes to the result output module, and the result output module generates and stores the third detection result based on the information that the randomness detection passes; in response to failing the detection, the data calling unit sends the information that the randomness detection fails to the result output module, and the result output module generates and outputs the detection result that the randomness detection fails.
[0031] As an improvement of the present invention, in step 4, when the result output module detects that the first detection result, the second detection result, and the third detection result are stored simultaneously, it generates a detection result report indicating that the security detection passes for output.
[0032] Beneficial effects:
[0033] 1. The detection device of the present invention has a high integration degree, and the detection method can detect whether a 1:1 quantum key is used in the quantum encryption process, whether the quantum key is used once, and the randomness of the quantum key. The detection method is simple and efficient, effectively saving the detection time.
[0034] 2. The present invention sets a counting module, which is pre-configured with a number threshold, reducing the number of feedbacks during the detection process, effectively reducing the system operation burden, saving system resources, and greatly improving the reliability of the detection. Description of the drawings
[0035] In order to more clearly illustrate the technical solutions in the embodiments of the present application, the following will briefly introduce the drawings required for the description of the embodiments. Obviously, the following drawings are only some embodiments of the present application. For those of ordinary skill in the art, other drawings can be obtained based on these drawings without creative efforts.
[0036] Figure 1 It is a connection schematic diagram of the quantum encryption system and the security detection device of the present application.
[0037] Figure 2Schematic structural diagram of the security detection device of the present application;
[0038] Figure 3 Schematic flowchart of the security detection method of the present application. Detailed implementation manners
[0039] In order to make the objectives, technical solutions and advantages of the present application clearer, the present application will be further described in detail below with reference to the accompanying drawings. Obviously, the described embodiments are only a part rather than all of the embodiments of the present application. All other embodiments obtained by those of ordinary skill in the art based on the embodiments in the present application without making creative efforts shall fall within the protection scope of the present application.
[0040] As Figure 1 shown, the present application provides a detection device and a corresponding detection method for detecting the security of quantum encryption in a quantum encryption system. The quantum encryption system includes a quantum encryption unit for performing the quantum encryption process. A user inputs plaintext content to be encrypted into the quantum encryption unit, and after being processed by the quantum encryption unit, encrypted ciphertext content is output. The security detection device proposed by the present application is connected to the quantum encryption system and is used to detect the security of the quantum encryption process in the quantum encryption system.
[0041] As Figure 2 shown, the security detection device of the present invention includes a data acquisition module, a data verification module, a randomness detection module, a counting module and a result output module. The data acquisition module, the data verification module, the randomness detection module and the result output module are sequentially communicatively connected. The data verification module, the randomness detection module and the result output module are also respectively communicatively connected to the counting module. The data acquisition module is also communicatively connected to a data execution module.
[0042] In an embodiment of the present invention, the data acquisition module is used to locate the quantum encryption module in the quantum encryption system, record the positioning result in the quantum encryption module, and acquire the input data and output data of the quantum encryption module according to the positioning result; the input data is the plaintext input into the quantum encryption system, and the output data is the ciphertext output from the quantum encryption system. Specifically, the data acquisition module includes a data positioning unit, an input acquisition unit and an output acquisition unit. The data positioning unit is respectively communicatively connected to the input acquisition unit and the output acquisition unit, and is also communicatively connected to an external quantum encryption system; the positioning unit is used to locate the quantum encryption module in the quantum encryption system and record the positioning result in the quantum encryption module; the input acquisition unit is used to acquire the input data of the quantum encryption module according to the positioning result and send it to the data verification module and the randomness detection module; the output acquisition unit is used to acquire the output data of the quantum encryption module according to the positioning result and send it to the data verification module and the randomness detection module.
[0043] In an embodiment of the present invention, the data verification module is used to perform legality verification on the received input data and output data; the legality verification includes format verification and content verification. The data verification module includes a format verification unit and a content verification unit that communicate with each other. The format verification unit is respectively communicatively connected to the input acquisition unit and the output acquisition unit, and the content verification unit is respectively communicatively connected to the input acquisition unit and the output acquisition module; the format verification unit is used to perform format verification on the received input data and output data, and send the format verification result as an instruction to the counting module and at the same time send it to the randomness detection module; the content verification unit is used to perform content verification on the received output data, and send the content verification result as an instruction to the counting module and at the same time send it to the randomness detection module.
[0044] In an embodiment of the present invention, the randomness detection module is used to perform randomness detection on the received input data after the legality verification is passed, and send the randomness detection result to the result output module. Specifically, the randomness detection module includes a data processing unit and a data calling unit that communicate with each other. The data processing unit is communicatively connected to an external quantum encryption system, an output acquisition unit, a content verification unit, and a counting module, and the data calling unit is also communicatively connected to an external random number detection tool and a result output module. In an embodiment of the present invention, the random number detection tool uses a tool that can be used to detect random numbers, and meets the test requirements of national standards such as GMT 0005-2012 "Randomness Detection Specification", GMT 0062-2018 "Random Number Detection Requirements for Cryptographic Products", GMT 0078-2020 "Design Guide for Cryptographic Random Number Generation Modules", GMT0103-2021 "General Framework of Random Number Generators", and GMT 0105-2021 "Design Guide for Software Random Number Generators", etc. For example, GM / T 0005-2021 detection tools, NIST random number test software, etc. The core content of the national cryptographic random number detection standard is that the quality of random numbers directly affects the actual security of key generation, digital signatures, and other cryptographic algorithms and protocols.
[0045] The data processing unit is used to process the received input data after obtaining the information that both the format verification and the content verification are passed from the content verification unit, obtain the marked output data and store it, and at the same time notify the counting module to perform counting. When the counting result is greater than the preset number threshold in the counting module, it notifies the data calling unit to call an external random number detection tool to perform randomness detection; the data calling unit is used to call an external random number detection tool to perform randomness detection on the marked output data according to the notification of the data processing unit, and send the verification result to the result output module.
[0046] In an embodiment of the present invention, the counting module is configured to perform a counting operation according to instructions from the data verification module and / or the randomness detection module, and send the counting result to the result output module. The performing of the counting operation includes starting counting, comparing the counting result with a preset number threshold, and stopping counting. Specifically, the counting module includes a first counting subunit, a second counting subunit, and a third counting subunit. The corresponding counting results respectively generated by the first counting subunit, the second counting subunit, and the third counting subunit are referred to as the first counting result, the second counting result, and the third counting result. The first counting subunit is connected and communicates with the format verification unit and the result output module, and is configured to perform a counting operation according to instructions from the format verification unit and send the corresponding first counting result to the result output module. The second counting subunit is communicatively connected with the content verification unit and the result output module, and is configured to perform a counting operation according to instructions from the content verification unit and send the corresponding second counting result to the result output module. The third counting subunit is communicatively connected with the data processing unit, and is configured to perform a counting operation according to a notification from the data processing unit and feedback the corresponding third counting result.
[0047] In an embodiment of the present invention, the result output module is configured to store the received counting result and randomness detection result, and generate and output a detection result report according to the counting result and randomness detection result.
[0048] As Figure 3 shown, the present invention also provides a security detection method for a quantum encryption system, which is applied to the security detection device for a quantum encryption system described above. The security detection method includes the following steps:
[0049] Step 1: The security detection device is started, and the data acquisition module acquires input data and output data from the quantum encryption system and sends them to the data verification module.
[0050] Specifically, the positioning unit in the data acquisition module locates the quantum encryption module in the quantum encryption system and records the positioning result in the quantum encryption module. The input acquisition unit in the data acquisition module accesses the positioning unit to obtain the positioning result, acquires the input data of the quantum encryption module according to the positioning result, and sends it to the data verification module. The output acquisition unit in the data acquisition module accesses the positioning unit to obtain the positioning result, acquires the output data of the quantum encryption module according to the positioning result, and sends it to the data verification module. Separately acquiring and storing the input data and output data helps to clarify the flow of the method.
[0051] Step 2: The data verification module performs legality verification on the obtained input data and output data. If the verification passes and the number of passes is greater than or equal to the preset number threshold in the counting module, the counting module notifies the result output module to generate a detection result indicating that the legality verification has passed for storage. At the same time, the data verification module sends the verified input data to the randomness detection module; otherwise, the counting module notifies the result output module to generate a verification result indicating that the legality verification has failed and output it.
[0052] Specifically, the legality verification includes format verification and content verification, and the format verification consists of both format verification passing and content verification passing;
[0053] More specifically, the specific process of the format verification is as follows:
[0054] The format verification unit in the data verification module reads the length of the received input data to obtain a first length, reads the length of the output data corresponding to the input data to obtain a second length, and compares the first length and the second length. If they are equal, it indicates that the length of the plaintext input in the quantum security system is equal to the length of the ciphertext output, and further indicates that the encryption key of the quantum security system and the length of the input plaintext are in a 1:1 ratio. Then, the equal format verification result is sent as an instruction to the first counting subunit in the counting module. The first counting subunit starts counting according to the instruction and monitors the counting result. When the corresponding first counting result is less than the preset first number threshold, it notifies the security detection device to continue obtaining input data and output data from the quantum encryption system; when the corresponding first counting result is greater than or equal to the preset first number threshold, the first counting subunit notifies the result output module to generate a first detection result indicating that the format verification has passed for storage; otherwise, the format verification result indicating that the format verification has failed is sent as an instruction to the first counting subunit in the counting module, and the first counting subunit notifies the result output module to generate a detection result indicating that the legality detection has failed based on the format verification result indicating that the format verification has failed and output it. It should be noted that the purpose of setting the number threshold here is to reduce the frequency of feedback information of the security detection device of the present invention and reduce the system operation burden. At the same time, the passing of individual data verifications is not highly persuasive for system detection. By setting a threshold, the reliability of the detection can be effectively demonstrated when the passing rate reaches a certain value. The passing of the format verification indicates that the quantum encryption key used by the quantum encryption system for which the security detection device performs detection is encrypted in a 1:1 ratio, and the length of the key is the same as that of the plaintext, which is theoretically indecipherable and ensures the security of the communication process.
[0055] Specifically, the specific process of the content verification is as follows:
[0056] The content verification unit in the data verification module retrieves an input data and the corresponding output data from the multiple input and output data that have passed the format verification in the format verification unit, and feeds this input data back to the quantum encryption system for quantum encryption multiple times to obtain multiple output data after quantum encryption. The sort() function is called to arrange the multiple output data after quantum encryption according to the specified rules and store them, while preserving the order relationship between the multiple output data after quantum encryption, forming an output database. More specifically, the stable sort algorithm is used to rearrange the elements within the specified range according to the specified rules and preserve the order relationship between equal elements. The output data obtained each time is compared with the other output data stored in the output database. If no identical output data is found, the content verification result that has not been matched is sent as an instruction to the second counting subunit in the counting module. The second counting subunit starts counting according to the instruction, monitors the counting result, and when the corresponding second counting result is less than the preset second count threshold, it notifies the security detection device to continue obtaining the output data after quantum encryption from the quantum encryption system; when the corresponding second counting result is greater than or equal to the preset second count threshold, it notifies the result output module to generate a second detection result indicating that the content verification has passed for storage. At the same time, the input data that has passed the content verification is sent to the randomness detection module. It should be noted that the purpose of setting the count threshold here is the same as above and will not be elaborated further. Otherwise, the content verification result indicating that the content verification has failed is sent as an instruction to the second counting subunit in the counting module, and the second counting subunit notifies the result output module to generate and output a detection result indicating that the legality detection has failed based on the format verification result indicating that the format verification has failed. The quantum encryption key used by the quantum encryption system for which the content verification passes to indicate the security detection device for detection is a one-time pad. Utilizing the non-clonability of quantum states and the uncertainty principle, the security of the encryption process is ensured by the irreproducibility of the key.
[0057] Step 3: The randomness detection module processes the input data that has passed the legality verification in Step 2 to generate marked output data, notifies the counting module to perform a counting operation on the marked output data, and after reaching the preset count threshold in the counting module, feeds it back to the randomness detection module. The randomness detection module performs a randomness detection on the marked output data. If the randomness detection passes, the detection result indicating that the randomness detection has passed is sent to the result output module; otherwise, it notifies the result output module to generate and output a verification result indicating that the randomness detection has failed.
[0058] Specifically, Step 3 includes the following:
[0059] Step 3-1: The data processing module in the randomness detection module performs an exclusive OR operation on the received verified input data with itself to obtain a second input data with all bits being 0. A processing identifier is added to this second input data and fed back to the quantum encryption system. After the quantum encryption system performs quantum encryption operations on it, marked output data with the processing identifier is obtained. It should be noted that performing an exclusive OR operation on the input data with itself is to ensure that the input data to be detected is still transmitted in ciphertext during communication, improving data security.
[0060] Step 3-2: When the data acquisition module performs data acquisition operations according to Step 1, when it detects the marked output data with the processing identifier, the output acquisition unit directly sends the marked output data to the data processing unit. When the data processing unit receives the marked output data, it stores the marked output data and notifies the third counting subunit in the counting module to start counting.
[0061] Step 3-3: The third counting subunit monitors the counting result and the preset third number threshold in real time. When the corresponding third counting result is less than the third number threshold, it notifies the security detection device to continue obtaining input data and output data from the quantum encryption system. When the corresponding third counting result is greater than or equal to the third number threshold, it notifies the data processing unit to call the data calling unit to execute the next step. It should be noted that the purpose of setting the number threshold here is the same as above and will not be elaborated here. The first number threshold, the second number threshold, and the third number threshold mentioned above are pre-configured in the first counting subunit, the second counting subunit, and the third counting subunit respectively. The values of the first number threshold, the second number threshold, and the third number threshold can be equal or unequal.
[0062] Step 3-4: The data calling unit obtains multiple marked output data stored therein from the data processing unit and retrieves a random number detection tool outside the security detection device to detect the multiple marked output data.
[0063] Step 3-5: In response to passing the detection, the data calling unit sends the information that the randomness detection has passed to the result output module. The result output module generates and stores a third detection result based on the information that the randomness detection has passed. In response to failing the detection, the data calling unit sends the information that the randomness detection has failed to the result output module. The result output module generates and outputs a detection result indicating that the randomness detection has failed based on the information that the randomness detection has failed. The random number detection tool adopted in the present invention is a national cryptographic random number detection tool that complies with national standards and is suitable for high-frequency testing.
[0064] Step 4: The result output module generates and outputs a detection result report indicating that the security detection has passed based on the detection results of passing the legality verification and passing the randomness detection.
[0065] Specifically, when the result output module detects that the first detection result, the second detection result, and the third detection result are stored simultaneously, it generates a detection result report indicating that the security detection has passed and outputs it, for example, outputs it to a client outside the detection device of the present invention.
Claims
1. A security detection method for a quantum encryption system, performed by a security detection device, characterized in that: The following steps are involved: Step 1: The security detection device is started, and the data acquisition module obtains input data and output data from the quantum encryption system and sends them to the data verification module; Step 2: The data verification module verifies the legitimacy of the input data and output data obtained. If the verification passes, and the number of passes is greater than or equal to the number threshold preset in the counting module, the counting module notifies the result output module to generate a test result of passing the legitimacy verification for storage. At the same time, the data verification module sends the input data that passes the verification to the randomness detection module; otherwise, the counting module notifies the result output module to generate and output a verification result of failing the legitimacy verification; Step 3: The randomness detection module generates marked output data after processing the input data that has passed the legality verification in step 2, notifies the counting module to perform a counting operation on the marked output data, and feeds back to the randomness detection module after reaching a preset number threshold in the counting module. The randomness detection module performs a randomness test on the marked output data. If the randomness test passes, the test result of passing the randomness test is sent to the result output module; otherwise, the result output module is notified to generate and output a verification result of failing the randomness test; wherein, the randomness detection module generates marked output data after processing the input data that has passed the legality verification in step 2 means that the data processing module in the randomness detection module performs an XOR operation on the received input data that has passed the verification with itself to obtain a second input data in which each bit is 0, and adds a processing mark to the second input data and feeds it back to the quantum encryption system, and the quantum encryption system performs a quantum encryption operation on it to obtain the marked output data with the processing mark; Step 4: The result output module generates a test result report of security test passing based on the test results of legality verification passing and randomness test passing for output; The input data is the plaintext input to the quantum encryption system, and the output data is the ciphertext output from the quantum encryption system.
2. The security detection method for a quantum encryption system according to claim 1, characterized in that: The specific process of step 1 is as follows: the positioning unit in the data acquisition module locates the quantum encryption module in the quantum encryption system and records the positioning result in the quantum encryption module; the input acquisition unit in the data acquisition module accesses the positioning unit to obtain the positioning result, obtains the input data of the quantum encryption module according to the positioning result and sends it to the data verification module; The output acquisition unit in the data acquisition module accesses the positioning unit to obtain the positioning result, obtains the output data of the quantum encryption module according to the positioning result, and sends it to the data verification module.
3. The security detection method for a quantum encryption system according to claim 2, characterized in that: In the step 2, the legality verification includes format verification and content verification, and the format verification passing is composed of both the format verification passing and the content verification passing; The specific process of format verification is as follows: The format verification unit in the data verification module reads the length of the received input data to obtain a first length, reads the length of the output data corresponding to the input data to obtain a second length, compares the first length and the second length, and if they are equal, sends the equal format verification results as instructions to the first counting subunit in the counting module, and the first counting subunit starts counting according to the instructions, monitors the counting results, and notifies the security detection device to continue to obtain input data and output data from the quantum encryption system when the corresponding first counting result is less than the first number threshold preset therein; when the corresponding first counting result is greater than or equal to the first number threshold preset therein, the first counting subunit notifies the result output module to generate a first detection result of format verification passing for storage; otherwise, the format verification result of format verification failing is sent as an instruction to the first counting subunit in the counting module, and the first counting subunit notifies the result output module to generate and output a detection result of legality failure based on the format verification result of format verification failing; The specific process of content verification is as follows: The content verification unit in the data verification module extracts one input data and corresponding output data from the multiple input data and output data that have passed the format verification in the format verification unit, feeds back the input data to the quantum encryption system for quantum encryption multiple times, obtains multiple quantum encrypted output data, calls the sort() function to arrange the multiple quantum encrypted output data according to the specified rule and stores them, and retains the order relationship between the multiple quantum encrypted output data to form an output database; compares the output data obtained each time with other output data stored in the output database, and if the same output data is not compared, sends the unmatched content verification result as an instruction to the second counting subunit in the counting module, and the second counting subunit starts counting according to the instruction, monitors the counting result, and notifies the security detection device to continue to obtain the quantum encrypted output data from the quantum encryption system when the corresponding second counting result is less than the second number threshold preset therein; when the corresponding second counting result is greater than or equal to the second number threshold preset therein, notifies the result output module to generate a second detection result that passes the content verification for storage, and at the same time, sends the input data that passes the content verification to the randomness detection module; Otherwise, the content verification result that fails the content verification is sent as an instruction to the second counting subunit in the counting module, and the second counting subunit notifies the result output module to generate and output a detection result that fails the legality detection based on the format verification result that fails the format verification.
4. The security detection method for a quantum encryption system according to claim 3, characterized in that: The specific process of step 3 is as follows: Step 3-1: The data processing module in the randomness detection module performs an XOR operation on the received verified input data and itself to obtain a second input data in which each bit is 0, and adds a processing mark to the second input data and feeds it back to the quantum encryption system. The quantum encryption system performs a quantum encryption operation on the second input data to obtain the marked output data with the processing mark; Step 3-2: When the data acquisition module performs the data acquisition operation according to step 1, when the marked output data with the processing identifier is detected, the output acquisition unit directly sends the marked output data to the data processing unit, and the data processing unit stores the marked output data while receiving the marked output data and notifies the third counting subunit in the counting module to start counting; Step 3-3: The third counting subunit monitors the counting result and the preset third number threshold in real time. When the corresponding third counting result is less than the third number threshold, the security detection device is notified to continue to obtain input data and output data from the quantum encryption system; when the corresponding third counting result is greater than or equal to the third number threshold, the data processing unit is notified to call the data calling unit to execute the next step; Step 3-4: the data calling unit obtains the multiple labeled output data stored in the data processing unit, and calls the random number detection tool outside the security detection device to detect the multiple labeled output data; Step 3-5: In response to the detection passing, the data calling unit sends the information that the randomness detection passed to the result output module, and the result output module generates and stores the third detection result based on the information that the randomness detection passed; In response to the detection failure, the data calling unit sends the information that the randomness detection failed to the result output module, and the result output module generates and outputs the detection result of the randomness detection failure based on the information that the randomness detection failed.
5. The security detection method for a quantum encryption system according to claim 4, characterized in that: In step 4, when the result output module detects that the first test result, the second test result and the third test result are stored at the same time, a test result report indicating that the safety test has passed is generated and outputted.
6. A security detection device for a quantum encryption system, used to execute the security detection method for a quantum encryption system according to any one of claims 1 to 5, characterized in that: It comprises a data acquisition module, a data verification module, a randomness detection module, a counting module and a result output module, wherein the data acquisition module, the data verification module, the randomness detection module and the result output module are sequentially connected in communication, the data verification module, the randomness detection module and the result output module are also respectively connected in communication with the counting module, and the data acquisition module is also connected in communication with the data execution module; The data acquisition module is used to locate the quantum encryption module in the quantum encryption system, record the positioning result in the quantum encryption module, and obtain the input data and output data of the quantum encryption module according to the positioning result; wherein the input data is the plaintext input to the quantum encryption system, and the output data is the ciphertext output from the quantum encryption system; The data verification module is used to verify the legitimacy of the received input data and output data; wherein the legitimacy verification includes format verification and content verification; The randomness detection module is used to perform randomness detection on the received input data after the legality verification is passed, and send the randomness detection result to the result output module; The counting module is used to perform counting operations according to instructions of the data verification module and / or the randomness detection module, and send the counting results to the result output module; The result output module is used to store the received counting results and randomness detection results, and generate a detection result report according to the counting results and randomness detection results for output.
7. The security detection device for a quantum encryption system according to claim 6, characterized in that: The data acquisition module includes a data positioning unit, an input acquisition unit and an output acquisition unit. The data positioning unit is respectively connected to the input acquisition unit and the output acquisition unit in communication, and is also connected to an external quantum encryption system in communication. The positioning unit is used to locate the quantum encryption module in the quantum encryption system and record the positioning result in the quantum encryption module. The input acquisition unit is used to obtain the input data of the quantum encryption module according to the positioning result and send it to the data verification module and the randomness detection module. The output acquisition unit is used to obtain the output data of the quantum encryption module according to the positioning result and send it to the data verification module and the randomness detection module.
8. The security detection device for a quantum encryption system according to claim 7, characterized in that: The data verification module includes a format verification unit and a content verification unit that communicate with each other, the format verification unit is respectively connected to the input acquisition unit and the output acquisition unit, and the content verification unit is respectively connected to the input acquisition unit and the output acquisition module; wherein the format verification unit is used to perform format verification according to the received input data and output data, and send the format verification result as an instruction to the counting module, and send it to the randomness detection module at the same time; the content verification unit is used to perform content verification according to the received output data, and send the content verification result as an instruction to the counting module, and send it to the randomness detection module at the same time.
9. The security detection device for a quantum encryption system according to claim 8, characterized in that: The randomness detection module includes a data processing unit and a data calling unit that communicate with each other. The data processing unit is connected to the external quantum encryption system, output acquisition unit, content verification unit and counting module, and the data calling unit is also connected to the external random number detection tool and result output module; the data processing unit is used to process the received input data after obtaining information that both format verification and content verification have passed from the content verification unit, obtain the marked output data and store it, and notify the counting module to count at the same time, and notify the data calling unit to call the external random number detection tool to perform randomness detection when the counting result is greater than the number threshold preset in the counting module; the data calling unit is used to call the external random number detection tool to perform randomness detection on the marked output data according to the notification of the data processing unit, and send the verification result to the result output module.
10. The security detection device for a quantum encryption system according to claim 9, characterized in that: The counting module includes a first counting subunit, a second counting subunit and a third counting subunit; wherein the first counting subunit is connected and communicated with the format verification unit and the result output module, and is used to perform a counting operation according to the instruction of the format verification unit, and send the corresponding first counting result to the result output module; the second counting subunit is connected and communicated with the content verification unit and the result output module, and is used to perform a counting operation according to the instruction of the content verification unit, and send the corresponding second counting result to the result output module; the third counting subunit is connected and communicated with the data processing unit, and is used to perform a counting operation according to the notification of the data processing unit and feed back the corresponding third counting result.
Citation Information
Patent Citations
Security detection method of encryption algorithm, terminal device and storage medium
CN117131517B
Data encryption compliance detection method and device
CN115017519A
Universal password detection method
CN116305080A