A quantum encryption communication method and system adapted to wireless communication system switching

By establishing dual connections in wireless mobile communication and using bidirectional authentication information for key management, the key asynchronous problem caused by rapid movement of communication terminals is solved, and fast key synchronization and communication security during wireless link switching is realized.

CN119155035BActive Publication Date: 2025-05-13JIANGSU WEIZHI QUANTUM TECH CO LTD
View PDF 4 Cites 0 Cited by

Patent Information

Application Number
CN202411641468.9
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2024-11-18
Publication Date
2025-05-13
Estimated Expiration
2044-11-18

AI Technical Summary

Technical Problem

In wireless mobile communication, rapid movement of the communication terminal causes wireless link switching, resulting in an asynchronous state of symmetric quantum keys on the two wireless links, resulting in the inability to switch normally on the wireless links and normal communication cannot be carried out.

Method used

By forming a first wireless connection between the communication terminal and the source edge network element, and when the mobility management network element monitors that the signal power difference is less than the set threshold N, a second wireless connection is established, and a dual connection is used to transmit service data. At the same time, using the bidirectional authentication information between the communication terminal and the network side, identity information authentication and root key encryption service keys are used to support end-to-end and end-to-edge symmetric quantum key wirelessly encrypted communication.

Benefits of technology

When the communication switch between the communication terminal and the edge network element, the synchronization of symmetric quantum keys can be quickly completed, and the communication can be maintained continuously, solving the problem of key synchronization during wireless link switching, and improving the reliability and security of communication.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN119155035B_ABST
    Figure CN119155035B_ABST
Patent Text Reader

Abstract

The present application provides a quantum encryption communication method and system adapted to wireless communication system switching, which relates to the field of wireless communication encryption technology, including respectively injecting root keys at communication terminals and edge network elements; initiating network access authentication to the wireless communication network by using the communication terminal; after command control or dialing, the communication terminal performs encrypted communication between the initiating end and the communication terminal; after command control, the communication terminal performs encrypted communication between the initiating end and the edge network element; when the communication terminal communicates with the edge network element, the signal power of the source edge network element and the surrounding target edge network elements is monitored, and a second wireless connection is established between the communication terminal and the target edge network element. The technical key points are: by utilizing two-way authentication information between the communication terminal and the network side, utilizing identity information authentication and root key encryption of service keys, end-to-end and end-to-edge wireless encryption communications based on symmetric quantum keys can be simultaneously supported.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the field of wireless communication encryption technology, and in particular to a quantum encryption communication method and system adapted to wireless communication system switching. Background Art

[0002] With the advent of 5G-A, wireless communications are gradually shifting from meeting basic data communication needs between people to meeting integrated communication needs for communication, perception, and supervision between objects and networks. This integrated network form of inter-sensing and monitoring is particularly evident in new fields and scenarios such as low-altitude economy, Internet of Vehicles, and Industrial Internet, which has led to many new technical requirements, including computing power sinking to the edge of the network, requiring communication terminals to interact with the edge of the network; communication terminals maintain a considerable speed of movement during communication, and one or even multiple handoffs will occur on the network side, requiring that the wireless link cannot be interrupted during the fast handoff process, and that the communication quality cannot be significantly reduced; physical security strongly relies on the data security of perception, monitoring, and control in the wireless link, requiring wireless data transmission to have extremely high security.

[0003] Quantum encryption (also known as quantum encryption technology) refers to various network security methods that encrypt and transmit secure data based on the natural and unchangeable laws of quantum mechanics. Although quantum encryption is still in its early stages, it has the potential to be much more secure than previous encryption algorithm types and even theoretically unbreakable. Quantum encryption technology uses quantum principles to generate keys, encrypt plaintext obfuscation, restore and decrypt ciphertext, communicate ciphertext, and prevent eavesdropping.

[0004] The patent document with announcement number CN106972922B is based on the mobile confidential communication method of quantum key distribution network. In a communication, by selecting which centralized control station on the link as the business key generation centralized control station for this communication, the quality of service is directly related, especially when the number of concurrent communications in the entire network is large and the pressure of business key generation is large, by fully considering the real-time status and position status of the current business key generation of each centralized control station in this communication link, the most suitable one is selected as the business key generation centralized control station for this communication. This is conducive to reducing the delay caused by the business key generation and transmission process, improving the key relay efficiency in the quantum key distribution network, and improving the service quality.

[0005] The patent document with announcement number CN107135072B is based on a quantum encrypted wireless sensor network system, which is improved on the basis of the traditional quantum key distribution technology. The entire sensor network negotiates the key through an infrared quantum channel and transmits the ciphertext stream through a wireless communication channel, ensuring that the wireless sensor network data transmission in free space is safe and reliable, with a simple structure, easy maintenance and convenient management.

[0006] However, in the process of implementing the above technical solution, it is found that the above technical solution has the following technical problems:

[0007] The mobile secure communication method of the above quantum key distribution network (CN106972922B) uses the binding relationship information between the communication terminal and the centralized control station to obtain the service key. However, this method only maintains the identity information of the communication terminal in the quantum key distribution network, and does not obtain and maintain the information on the wireless communication network side. It can neither meet the communication needs of the communication terminal and the network edge side, nor meet the communication requirements of high-speed switching of the communication terminal.

[0008] The process of establishing an encrypted communication channel between the communication terminal node and the network relay node of the above-mentioned quantum encrypted wireless sensor network system (CN107135072B) is complicated, and requires a series of complex processes such as broadcast key distribution application and response, infrared imaging to complete positioning and adjustment of the quantum key distribution module, establishment of quantum channel distribution of quantum keys, establishment of classical channel for encrypted communication, etc. The slow response speed will cause communication interruption during the switching process.

[0009] To summarize, in wireless mobile communications, due to the rapid movement of the communication terminal, the wireless link between the communication terminal and the edge network element of the wireless network will be switched, causing the symmetric quantum key to be asynchronous on the two wireless links, resulting in the failure of normal switching of the wireless link and the inability to carry out normal communication. Summary of the invention

[0010] In order to overcome the problem in existing wireless mobile communications that the wireless link between the communication terminal and the edge network element of the wireless network will be switched due to the rapid movement of the communication terminal, resulting in the lack of synchronization of the symmetric quantum key on the two wireless links, the embodiment of the present application provides a quantum encryption communication method and system that adapts to the switching of wireless communication systems. By utilizing the two-way authentication information between the communication terminal and the network side, and utilizing identity information authentication and root key encryption of business keys, it can simultaneously support end-to-end and end-to-edge wireless encryption communications based on symmetric quantum keys.

[0011] The technical solution adopted by the embodiment of the present application to solve the technical problem is:

[0012] A quantum encryption communication method adapted to wireless communication system switching includes: a communication terminal communicates with a source edge network element to form a first wireless connection, and a mobility management network element detects that the signal power difference between the source edge network element and the surrounding target edge network element is less than a set threshold N for establishing a dual connection, and then notifies the target edge network element to establish a second wireless connection with the communication terminal;

[0013] The second wireless connection does not send service data, and the service data is still transmitted through the first wireless connection. The mobility management network element sends the information that the second wireless connection has been established to the source edge network element;

[0014] The source edge network element sends the end-to-edge service key synchronization information S1 currently in use to the quantum key management device;

[0015] The quantum key management device adds an advance amount D1 to S1 and sends the S1+D1 synchronization position information to the target edge network element. The target edge network element queries the corresponding end-to-edge service key based on the S1+D1 synchronization position information.

[0016] At this time, the communication terminal maintains dual connection and tries to use the end-to-edge service key used by the first wireless connection to decrypt the encrypted transmission information on the second wireless connection. When the decrypted information on the second wireless connection is the same as the decrypted information on the first wireless connection, the symmetric key on the second wireless connection is synchronized, and the communication terminal sends a dual connection line synchronization completion message to the mobility management network element.

[0017] The mobility management network element sends the dual connection line synchronization completion information to the source edge network element, the source edge network element releases the first wireless connection, the mobility management network element sends the dual connection line synchronization completion information to the target edge network element, the target edge network element starts to use the key after the S1+D1 synchronization position information for encrypted transmission and sending, the synchronization key sequence of the communication terminal does not need to be changed, and the target edge network element sends a retrieval request for the adjacent edge network element to the mobility management network element.

[0018] In a possible implementation, the communication terminal includes a wireless sending module on the communication terminal side, a wireless receiving module on the communication terminal side, a key storage medium, and a key calling control module; the wireless sending module on the communication terminal side encodes the data block into information bits according to the processing requirements of the communication terminal, modulates to form coding symbols, and finally sends them into the wireless channel; the wireless receiving module on the communication terminal side receives the coding symbols from the wireless channel according to the processing requirements of the communication terminal, performs channel equalization and demodulation processing, and then decodes the information bits, and finally recovers the data block sent by the network side; the key storage medium on the communication terminal side obtains the key from the quantum network under the control of the quantum key management device, and stores the key partitions securely according to the classification of the root key, the end-to-end service key, and the end-to-edge service key; the key calling control module on the communication terminal side calls the key from the corresponding partition of the key storage medium according to different service classifications and communication opportunities to encrypt the data, and maintains the order and continuity of the key in the corresponding partition.

[0019] In a possible implementation, the edge network element includes a network-side wireless sending module, a network-side wireless receiving module, a key storage medium and a key calling control module; wherein the network-side wireless sending module encodes the data block into information bits according to the processing requirements of the network side of the wireless communication protocol, modulates to form a coding symbol, and finally sends it into the wireless channel; the network-side wireless receiving module receives the coding symbol from the wireless channel according to the processing requirements of the network side of the wireless communication protocol, performs channel equalization and demodulation processing, and then decodes the information bits, and finally restores the module for sending the data block on the communication terminal side; the key storage medium of the edge network element obtains the key from the quantum network under the control of the quantum key management device, and securely stores the key partition according to the classification of the root key and the end-to-edge service key; the key calling control module of the edge network element calls the key from the corresponding partition of the key storage medium according to different communication opportunities to encrypt the data, and maintains the order and continuity of the key in the corresponding partition.

[0020] The beneficial effects of this application are:

[0021] First, in this solution, when the communication terminal communicates with the source edge network element, a first wireless connection is formed, and after the mobility management network element detects that the signal power difference between the source edge network element and the surrounding target edge network element is less than the set threshold N for establishing a dual connection, the target edge network element is notified to establish a second wireless connection with the communication terminal, and finally the service data is transmitted by the dual connection. When the communication between the communication terminal and the edge network element is switched, the dual connection can be used to quickly complete the synchronization of the symmetric quantum key while maintaining continuous communication;

[0022] Second, in this solution, by utilizing the two-way authentication information between the communication terminal and the network side, using identity information authentication and root key encryption of business keys, it can simultaneously support end-to-end and end-to-edge wireless encrypted communications based on symmetric quantum keys. BRIEF DESCRIPTION OF THE DRAWINGS

[0023] Figure 1 A schematic diagram of the process of charging the root key of a communication terminal according to the present invention;

[0024] Figure 2 A schematic diagram of the process of filling the root key of the edge network element of the present invention;

[0025] Figure 3 A schematic diagram of a process of a communication terminal initiating network access authentication to a wireless communication network according to the present invention;

[0026] Figure 4 A schematic diagram of the process of encrypted communication from a communication terminal initiator to a communication terminal of the present invention;

[0027] Figure 5A schematic diagram of the encrypted communication process from the communication terminal initiator to the edge network element of the present invention;

[0028] Figure 6 A schematic diagram of a dual connection for a communication terminal of the present invention to enter switching;

[0029] Figure 7 It is a schematic diagram of the system structure of the present invention. DETAILED DESCRIPTION

[0030] The technical solution in the embodiment of the present application is to solve the problems of the above-mentioned background technology, and the overall idea is as follows: Example

[0031] This embodiment introduces a specific structure of a quantum encryption communication system that is suitable for switching wireless communication systems. Figure 1 , Figure 2 and Figure 7 As shown, it includes a quantum network and a wireless communication network, the quantum network includes a quantum key source and a quantum key management device, the wireless communication network includes a mobility management network element and an authentication management network element; the communication terminal includes a communication terminal side wireless transmission module, a communication terminal side wireless receiving module, a key storage medium, and a key call control module; the edge network element includes a network side wireless transmission module, a network side wireless receiving module, a key storage medium, and a key call control module;

[0032] Among them, the communication terminal and the edge network element are built inside the wireless communication network. When the quantum key source generates the quantum key, the quantum key management device can support the quantum key application management and secure transmission between the quantum key source and the communication terminal and the edge network element.

[0033] The mobility management network element maintains a list of adjacent edge network elements for the edge network element. When the communication terminal establishes a wireless connection with the edge network element, it triggers the quantum key synchronization of the adjacent edge network element. When the wireless connection between the communication terminal and the edge network element is switched, it triggers the establishment of a dual connection. After the dual connection completes the synchronization of the symmetric key, the dual connection is released.

[0034] In addition, the authentication management network element registers and manages the identity of the edge network elements of the wireless communication network; when the communication terminal initially accesses, it controls the communication terminal and the edge network element to complete a two-way authentication process;

[0035] Secondly, when the wireless transmission module on the communication terminal side encodes the data block into information bits according to the processing requirements of the communication terminal, modulates it to form a coded symbol, and finally sends it into the wireless channel. At this time, the wireless receiving module on the communication terminal side receives the coded symbol from the wireless channel according to the processing requirements of the communication terminal, and after channel equalization and demodulation, decodes the information bit, and can restore the data block sent by the network side;

[0036] The key storage medium on the communication terminal side obtains the key from the quantum network under the control of the quantum key management device, and stores the key partitions securely according to the classification of root key, end-to-end service key, and end-to-edge service key. When the key call control module on the communication terminal side calls the key from the corresponding partition of the key storage medium to encrypt the data according to different service classifications and communication opportunities, it maintains the order and continuity of the keys in the corresponding partitions.

[0037] Furthermore, when the wireless transmission module on the network side encodes the data block into information bits according to the processing requirements of the wireless communication protocol network side, it can be modulated to form a coded symbol and then sent into the wireless channel. When the wireless reception module on the network side receives the coded symbol from the wireless channel according to the processing requirements of the wireless communication protocol network side, it undergoes channel equalization and demodulation processing, and then decodes the information bits, and finally restores the module that sends the data block on the communication terminal side;

[0038] At the same time, under the control of the quantum key management device, the key storage medium of the edge network element obtains keys from the quantum network, and safely stores the key partitions according to the classification of root keys and end-to-edge business keys; when the key call control module of the edge network element calls the key from the corresponding partition of the key storage medium to encrypt data according to different communication opportunities, the order and continuity of the keys in the corresponding partition can be maintained. Example

[0039] Based on Example 1, this example introduces a quantum encryption communication method adapted to wireless communication system switching, such as Figures 1 to 7 As shown, the root key is injected into the communication terminal and the edge network element respectively;

[0040] Among them, the root key charging of the communication terminal: the key charging work on the communication terminal and the edge network element first initiates the charging application, then verifies the security of the key storage medium, then verifies the identity information, stores relevant records, and charges the root key. The process is as follows:

[0041] (1) The communication terminal uses the key call control module to initiate a registration and root key injection application for the quantum key network to the quantum key management device;

[0042] (2) The quantum key management device verifies the security of the key storage medium of the communication terminal (including confirmation of identity authentication information, verification of the quantum key storage space, and clearing of the keys of each partition);

[0043] (3) After the security verification is passed, the quantum key management device applies for the root key from the quantum key source, and then the quantum key source responds to the root key application of the quantum key management device, generates a quantum random number and sends it to the quantum key management device;

[0044] At the same time, the quantum key management device binds the root key to the identity authentication information of the communication terminal and stores the record;

[0045] The quantum key management device injects the root key into the root key storage area (located on the key storage medium of the communication terminal);

[0046] Secondly, the root key injection process of the edge network element is as follows:

[0047] (1) The edge network element uses the key call control module to initiate a registration and root key injection application for the quantum key network to the quantum key management device;

[0048] (2) The quantum key management device verifies the security of the key storage medium of the edge network element (including confirmation of identity authentication information, verification of the quantum key storage space, and clearing of the keys of each partition);

[0049] (3) After the security verification is passed, the quantum key management device applies for the root key from the quantum key source, and then the quantum key source responds to the root key application of the quantum key management device, generates a quantum random number and sends it to the quantum key management device;

[0050] At the same time, the quantum key management device binds the root key to the identity authentication information of the edge network element and stores the record;

[0051] (4) The quantum key management device injects the root key into the root key storage area (located on the key storage medium of the edge network element);

[0052] like Figure 3 As shown, a communication terminal is used to initiate network access authentication to a wireless communication network. The network access authentication of the communication terminal is first initiated by an edge network element to apply for network access authentication, and then both the edge network element and the communication terminal are authenticated. After completing the two-way authentication, it is verified that both the communication terminal and the edge network element have completed registration and formed a service key. Then, on the basis of completing the identity authentication, the service keys on the edge network element and the communication terminal are encrypted using the root key;

[0053] The specific process of network authentication is as follows:

[0054] First, the communication terminal is turned on, and the wireless receiving module on it receives the wireless signals sent by multiple edge network elements through the wireless transmitting module. At this time, the communication terminal initiates a network access authentication application for the wireless communication network to the edge network element with the largest power according to the receiving power;

[0055] (2) After receiving the network access authentication application from the communication terminal, the edge network element forwards it to the authentication management network element device, which calls the corresponding authentication algorithm to generate an authentication vector according to the authentication protocol defined in the wireless communication specification, extracts the authentication result and feeds it back to the edge network element, completing the edge network element's authentication of the communication terminal;

[0056] (3) The authentication management network element device extracts the corresponding authentication key and authentication result according to the authentication method of the communication terminal, and feeds back the authentication result to the communication terminal. The communication terminal verifies the authenticity of the authentication result sent by the network side, and completes the authentication of the edge network element by the communication terminal;

[0057] (4) The authentication management network element sends the result of the two-way authentication to the mobility management network element. The mobility management network element binds the identity information of the communication terminal with the access information of the edge network element and stores them.

[0058] (5) After completing the two-way authentication, the key call control module of the edge network element sends the edge service key application to the quantum key management device initiator;

[0059] (6) After receiving the end-to-edge service key application, the quantum key management device extracts the result of the two-way authentication, obtains the identity information of the edge network element and the communication terminal device, and verifies it with the stored edge network element identity authentication information and communication terminal identity authentication information to confirm that both have completed registration. Then, it applies for the quantum key from the quantum key source;

[0060] (7) The quantum key source generates a quantum random number to form an end-to-edge service key and sends it to the quantum key management device. The quantum key management device extracts the root key of the edge network element from the binding of the root key and the identity authentication information of the edge network element based on the identity authentication information of the edge network element, encrypts the end-to-edge network element service key with the root key, and then fills the end-to-edge service key into the end-to-edge service key storage area of ​​the key storage medium of the edge network element;

[0061] (8) The quantum key management device extracts the root key of the communication terminal device from the binding of the root key and the identity authentication information of the communication terminal device based on the identity authentication information of the communication terminal device, encrypts the end-to-edge service key with the root key, and then fills the end-to-edge service key into the end-to-edge service key storage area of ​​the key storage medium of the communication terminal device;

[0062] like Figure 4As shown, after the communication terminal issues a command control or dials, encrypted communication is performed between the initiator and the communication terminal: the network access authentication of the communication terminal is first initiated by the edge network element to apply for network access authentication, and then both the edge network element and the communication terminal are authenticated. After completing the two-way authentication, it is verified that the communication terminal and the edge network element have completed the registration and formed a business key. Then, on the basis of completing the identity authentication, the root key is used to encrypt the business keys on the edge network element and the communication terminal. The specific process is as follows:

[0063] (1) Communication terminal 1 initiates a call request (including the service level requirement for this call) to the wireless communication network through edge network element 1 to which it is connected, for communication terminal 2. At the same time, communication terminal 1 prepares processing resources that meet the service level requirement.

[0064] (2) Edge network element 1 routes the call request to edge network element 2 where communication terminal 2 accesses the wireless communication network through the wireless communication network and the core network. Subsequently, edge network element 2 sends the call request to communication terminal 2.

[0065] (3) Communication terminal 2 establishes processing resources to respond to the service level requirement according to the service level requirement in the call request, and then sends a call response to edge network element 2;

[0066] (4) Edge network element 2 sends the call response to edge network element 1 through the core network of the wireless communication network, and edge network element 1 sends the call response to communication terminal 1;

[0067] (5) Communication terminal 1 receives the call response, extracts the call confirmation information, and confirms that a connection corresponding to the call service level requirement can be established with communication terminal 2. Then, communication terminal 1 initiates an end-to-end service key application to the quantum key management device. The application includes the identity information of communication terminal 1 and communication terminal 2.

[0068] (6) After receiving the application for the end-to-end service key, the quantum key management device extracts the identity information of communication terminal 1 and communication terminal 2 respectively, and searches with the stored communication terminal identity authentication information. If the identity information of communication terminal 1 and communication terminal 2 already exists, the quantum key source is requested to apply for the end-to-end service key;

[0069] (7) The quantum key source generates quantum random numbers to form end-to-end business keys and sends them to the quantum key management device;

[0070] (8) The quantum key management device obtains the root key of communication terminal 1 based on the binding relationship between the root key of communication terminal 1 and the identity authentication information of the communication terminal, uses the root key to encrypt the end-to-end service key, and injects the key into the end-to-end service key storage area of ​​the key storage medium of communication terminal 1;

[0071] (9) The quantum key management device obtains the root key of communication terminal 2 based on the binding relationship between the root key of communication terminal 2 and the identity authentication information of the communication terminal, uses the root key to encrypt the end-to-end service key, and injects the key into the end-to-end service key storage area of ​​the key storage medium of communication terminal 2;

[0072] (10) After communication terminal 1 and communication terminal 2 obtain the symmetric end-to-end service key, the key call control module performs symmetric encryption and decryption when sending and receiving service data;

[0073] like Figure 5 As shown, after the communication terminal is controlled by the command control or dialing, encrypted communication is performed between the initiator and the edge network element. The specific process is as follows:

[0074] (1) The communication terminal sends an end-to-edge call request to the access edge network element (the request carries the identity information of the communication terminal and the service level requirement of this call, and prepares the processing resources required by the service level). The access edge network element receives the end-to-edge call request, extracts the identity information of the communication terminal from it, compares it with the two-way authentication result when the communication terminal accesses, and then sends an end-to-edge call response to the communication terminal and prepares the processing resources required by the service level.

[0075] (2) When the communication terminal and the access edge network element use the communication terminal to access, the generated end-to-edge service key is used by the key call control module to perform symmetric encryption and decryption when sending and receiving service data;

[0076] (3) The access edge network element sends a search request for adjacent edge network elements to the mobility management network element. This request contains the identity information of the communication terminal and the access edge network element.

[0077] (4) After receiving the search request from the adjacent edge network element, the mobility management management network element extracts the identity information of the communication terminal and the access edge network element, searches and confirms the binding pair of the identity information of the communication terminal and the access information of the edge network element that has been stored, and then extracts the identity information of the adjacent network element of the access edge network element from the adjacent edge network element list, and sends it to the access edge network element through the search response of the edge network element;

[0078] (5) After receiving the retrieval response from the edge network element, the access edge network element sends a diffusion request to the quantum key management device for the service key of the edge network element. The request includes the identity information of the communication terminal and the access edge network element, and the identity information of the adjacent network elements of the access edge network element.

[0079] (6) The quantum key management device extracts the identity information of the communication terminal and the access edge network element in the diffusion request of the end-to-edge network element service key, and verifies it with the stored identity authentication information of the edge network element and the identity authentication information of the communication terminal, confirms the legitimacy of the device, and extracts the service key from the corresponding end to the edge network element;

[0080] (7) The quantum key management device extracts the identity information of the adjacent network element in the diffusion request of the end-to-edge network element service key, binds it with the stored root key and the identity authentication information set by the edge network element to confirm the legitimacy of the device, extracts the root key of each adjacent network element, and then uses the root key to encrypt the end-to-edge network element service key, and fills the service key into the end-to-edge service key storage area of ​​the key storage medium set by the adjacent edge network element, completing the synchronization of the end-to-edge service key in the adjacent edge network element, and preparing for rapid switching.

[0081] like Figure 6 As shown, when the communication terminal communicates with a certain edge network element, the signal power sent by the source edge network element and its surrounding target edge network elements through the wireless communication sending module is received by the wireless communication receiving module on the communication terminal side, and is sent to the mobility management network element through the wireless connection between the communication terminal and the source edge network element;

[0082] A second wireless connection is established between the communication terminal and the target edge network element, which is determined by the signal power difference between the source edge network element and the target edge network element. In this process, a threshold N is set for the signal power difference between the source edge network element and the target edge network element. When the actual difference is less than the threshold N, it is determined to establish the second wireless connection;

[0083] Among them, when the communication terminal communicates with the source edge network element, the signal power of the source edge network element and the surrounding target edge network elements is monitored, and a second wireless connection is established between the communication terminal and the target edge network element to provide switchable conditions for line use, as shown in the following figure:

[0084] (1) The communication terminal communicates with the source edge network element to form the first wireless connection;

[0085] (2) After the mobility management network element detects that the signal power difference between the source edge network element and the surrounding target edge network element is less than the set threshold N for establishing dual connections, it notifies the target edge network element to establish a second wireless connection with the communication terminal;

[0086] (3) The mobility management network element notifies the communication terminal to establish a second wireless connection with the target edge network element;

[0087] (4) After the second wireless connection is established (the symmetric keys of the communication terminal and the target edge network element are not synchronized), the second wireless connection does not send service data, and service data is still transmitted through the first wireless connection;

[0088] (5) The mobility management network element sends the information that the second wireless connection has been established to the source edge network element;

[0089] (6) The key call control module of the source edge network element sends the end-to-edge service key synchronization information S1 currently in use to the quantum key management device;

[0090] (7) The quantum key management device adds the advance amount D1 to S1 and sends the S1+D1 synchronization position information to the target edge network element;

[0091] (8) The key call control module of the target edge network element queries the corresponding end-to-edge service key from the key storage module based on the S1+D1 synchronization location information (and continues to use this key to send the same information as the first wireless connection on the second wireless connection);

[0092] At this time, the communication terminal maintains dual connection and tries to use the end-to-edge service key used by the first wireless connection to decrypt the encrypted transmission information on the second wireless connection. When the decrypted information on the second wireless connection is the same as the decrypted information on the first wireless connection, the symmetric key on the second wireless connection is synchronized, and the communication terminal sends a dual connection line synchronization completion message to the mobility management network element.

[0093] (9) The mobility management network element sends the dual connection line synchronization completion information to the source edge network element, and the source edge network element releases the first wireless connection;

[0094] (10) The mobility management network element sends the dual connection line synchronization completion information to the target edge network element, and the target edge network element starts to use the key after the S1+D1 synchronization position information for encrypted transmission and sending. The synchronization key sequence of the communication terminal does not need to be changed;

[0095] (11) The target edge network element sends a search request for adjacent edge network elements to the mobility management network element. The subsequent process is as follows Figure 5 The process (5) to (7) is continued.

[0096] Finally, it should be noted that: Obviously, the above embodiments are only examples for clearly explaining the present invention, and are not intended to limit the implementation methods. For ordinary technicians in the relevant field, other different forms of changes or modifications can be made based on the above description. It is not necessary and impossible to list all the implementation methods here. The obvious changes or modifications derived from this are still within the scope of protection of the present invention.

Claims

1. A quantum encryption communication method adapted to wireless communication system switching, characterized in that: include: Perform root key injection at communication terminals and edge network elements respectively; Using the communication terminal to initiate network access authentication to the wireless communication network; After the communication terminal is commanded or dialed, encrypted communication is performed between the initiator and the communication terminal; After the command control, the communication terminal performs encrypted communication between the initiator and the edge network element; Among them, the communication terminal communicates with the source edge network element to form a first wireless connection, and after the mobility management network element monitors that the signal power difference between the source edge network element and the surrounding target edge network element is less than the set threshold N for establishing dual connections, the target edge network element is notified to establish a second wireless connection with the communication terminal; The second wireless connection does not send service data, and the service data is still transmitted through the first wireless connection. The mobility management network element sends the information that the second wireless connection has been established to the source edge network element; The source edge network element sends the end-to-edge service key synchronization information S1 currently in use to the quantum key management device; The quantum key management device adds an advance amount D1 to S1 and sends the S1+D1 synchronization position information to the target edge network element. The target edge network element queries the corresponding end-to-edge service key based on the S1+D1 synchronization position information, and continues to use this key to send the same information as the first wireless connection on the second wireless connection; At this time, the communication terminal maintains dual connection and tries to use the end-to-edge service key used by the first wireless connection to decrypt the encrypted transmission information on the second wireless connection. When the decrypted information on the second wireless connection is the same as the decrypted information on the first wireless connection, the symmetric key on the second wireless connection is synchronized, and the communication terminal sends a dual connection line synchronization completion message to the mobility management network element. The mobility management network element sends the dual connection line synchronization completion information to the source edge network element, the source edge network element releases the first wireless connection, the mobility management network element sends the dual connection line synchronization completion information to the target edge network element, the target edge network element starts to use the key after the S1+D1 synchronization position information for encrypted transmission and sending, the synchronization key sequence of the communication terminal does not need to be changed, and the target edge network element sends a retrieval request for the adjacent edge network element to the mobility management network element.

2. A quantum encryption communication method adapted to wireless communication system switching as claimed in claim 1, characterized in that: The key injection work on communication terminals and edge network elements includes: first initiating an injection application, then verifying the security of the key storage medium, then verifying the identity information, storing relevant records, and injecting the root key.

3. A quantum encryption communication method adapted to wireless communication system switching as claimed in claim 1, characterized in that: The network access authentication of the communication terminal first initiates a network access authentication application through the edge network element, and then authenticates both the edge network element and the communication terminal. After completing the two-way authentication, it is verified that the communication terminal and the edge network element have completed the registration and formed the business key. Then, based on the completion of the identity authentication, the business keys on the edge network element and the communication terminal are encrypted using the root key.

4. A quantum encryption communication method adapted to wireless communication system switching as claimed in claim 1, characterized in that: A second wireless connection is established between the communication terminal and the edge network element, which is determined by the signal power difference between the source edge network element and the target edge network elements around it. In this process, a threshold N is set for the signal power difference between the source edge network element and the target edge network element. When the actual difference is less than the threshold N, it is determined to establish the second wireless connection.

5. A quantum encryption communication method adapted to wireless communication system switching as claimed in claim 2, characterized in that: The security verification of the key storage medium includes the confirmation of identity authentication information, the verification of the quantum key storage space and the clearing operation of each partition key.

6. A quantum encryption communication system adapted to wireless communication system switching, adopting the quantum encryption communication method adapted to wireless communication system switching according to any one of claims 1 to 5, characterized in that: include: Quantum networks; A wireless communication network, a communication terminal and an edge network element are constructed inside the wireless communication network; The quantum network includes a quantum key source and a quantum key management device, the mobility management network element is constructed inside the wireless communication network, and the wireless communication network also includes an authentication management network element; Wherein, the quantum key source is used to generate a quantum key; The quantum key management device supports quantum key application management and secure transmission between the quantum key source and the communication terminal and edge network element; The mobility management network element is used to maintain a list of adjacent edge network elements for the edge network element; when a communication terminal establishes a wireless connection with an edge network element, trigger the quantum key synchronization of the adjacent edge network element; when the wireless connection between the communication terminal and the edge network element is switched, trigger the establishment of a dual connection; after the dual connection completes the synchronization of the symmetric key, release the dual connection; The authentication management network element is used to register and manage the identity of the edge network element of the wireless communication network; when the communication terminal initially accesses, the communication terminal and the edge network element are controlled to complete a two-way authentication process.

7. A quantum encryption communication system adapted to wireless communication system switching as claimed in claim 6, characterized in that: The communication terminal includes a communication terminal side wireless transmission module, a communication terminal side wireless reception module, a key storage medium, and a key calling control module; Among them, the wireless transmission module on the communication terminal side encodes the data block into information bits according to the processing requirements of the communication terminal, modulates it to form a coded symbol, and finally sends it into the wireless channel; The wireless receiving module on the communication terminal side receives the coded symbols from the wireless channel according to the processing requirements of the communication terminal, performs channel equalization and demodulation processing, then decodes the information bits, and finally recovers the data blocks sent by the network side; The key storage medium on the communication terminal side obtains the key from the quantum network under the control of the quantum key management device, and stores the key partitions securely according to the classification of root key, end-to-end service key, and end-to-edge service key; The key calling control module on the communication terminal side calls the key from the corresponding partition of the key storage medium to encrypt the data according to different service classifications and communication opportunities, and maintains the order and continuity of the key in the corresponding partition.

8. A quantum encryption communication system adapted to wireless communication system switching as claimed in claim 7, characterized in that: The edge network element includes a network-side wireless transmission module, a network-side wireless reception module, a key storage medium and a key calling control module; The network-side wireless transmission module encodes the data block into information bits according to the network-side processing requirements of the wireless communication protocol, modulates the information bits to form coded symbols, and finally transmits the information bits into the wireless channel. The network-side wireless receiving module receives coded symbols from the wireless channel according to the processing requirements of the wireless communication protocol network side, undergoes channel equalization and demodulation processing, then decodes the information bits, and finally recovers the module for sending data blocks on the communication terminal side; The key storage medium of the edge network element obtains the key from the quantum network under the control of the quantum key management device, and stores the key partitions securely according to the classification of the root key and the end-to-edge service key; The key calling control module of the edge network element calls the key from the corresponding partition of the key storage medium according to different communication opportunities to encrypt data, and maintains the order and continuity of the key in the corresponding partition.

Citation Information

Patent Citations

  • A mobile secure communication method based on quantum key distribution networks

    CN106972922B

  • A quantum-encrypted wireless sensor network system

    CN107135072B

  • Method for updating key in dual connection communication environment and device thereof

    CN104936175A

  • Methods, systems, and apparatus for enabling and managing quantum networks

    CN114128211A