A connection method for an SDP gateway
By generating and storing truly random quantum keys on the SDP client and using the quantum security service platform for authorization and authentication, the problems of insufficient randomness in key generation and dependence of storage security on the system environment in SDP gateway connections are solved, thus achieving higher connection security and key storage security.
Patent Information
- Application Number
- CN202411340750.3
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2024-09-25
- Publication Date
- 2025-12-16
- Estimated Expiration
- 2044-09-25
AI Technical Summary
In existing SDP gateways, the randomness of authentication key generation is insufficient and the storage security depends on the system environment, which affects connection security.
A quantum key based on truly random parameters is used, which is stored in a SIM card and used to generate quantum key ciphertext. The quantum security service platform is used for authorization and authentication to improve connection security.
It improves the security of the connection between the SDP client and the SDP gateway, enhances the difficulty of cracking authentication keys and the security of storage, and reduces the risk of key leakage.
Smart Images

Figure CN119276480B_ABST
Abstract
Description
Technical Field
[0001] This application relates to the field of communication technology, and in particular to a connection method for an SDP gateway, related hardware and software products. Background Technology
[0002] With the development of network technology, the boundaries of network security have become increasingly blurred, and internal and external threats have become increasingly serious. Traditional perimeter security architectures are proving inadequate in the face of these new challenges. Therefore, the zero-trust security architecture of Software Defined Perimeter (SDP) technology has emerged. In this architecture, authentication based on authentication keys has become a key security measure.
[0003] In the current SDP zero-trust security architecture, before establishing a connection with the SDP gateway, the SDP client needs to interact with the control center within the SDP gateway using a public authentication key. During this process, the SDP client obtains a private authentication key from the SDP gateway's control center. Subsequently, the SDP client uses this private authentication key for authorization and authentication, ultimately establishing a secure connection with the SDP gateway. This mechanism enhances network communication security, enabling the SDP zero-trust security architecture to better address the complex and ever-changing network security threats of today.
[0004] In current SDP applications, the control center in the SDP gateway uses relevant device identifiers to randomly generate authentication keys through a software implementation. These keys are then stored on the client side in the database, configuration file, or registry. Strictly speaking, the authentication keys generated by the software implementation are pseudo-random and can be cracked. Furthermore, the security of the client-side storage method depends on the system environment. As usage scenarios diversify, system environment issues become more prominent, easily leading to the leakage of authentication keys.
[0005] All of the above factors can affect the security of SDP client connections to the SDP gateway. Summary of the Invention
[0006] The purpose of this application is to provide a connection method, related hardware and software products for SDP gateways, which can improve the connection security of SDP clients to SDP gateways.
[0007] To achieve the above objectives, the embodiments of this application are implemented as follows:
[0008] Firstly, a connection method for an SDP gateway is provided, applicable to SDP clients, including:
[0009] The target quantum key is obtained by accessing the SIM card of a local mobile device; wherein the target quantum key is generated by the quantum security service platform based on truly random parameters.
[0010] Generate quantum key ciphertext based on the target quantum key;
[0011] A connection request carrying the quantum key ciphertext is initiated to the SDP gateway; wherein the connection request is used to request the SDP gateway to authorize and authenticate the quantum key ciphertext, so that the SDP gateway can establish a connection with the SDP client after the authorization and authentication are successful.
[0012] Secondly, a connection method for an SDP gateway is provided, applicable to an SDP gateway, including:
[0013] Receive a connection request sent by an SDP client carrying quantum key ciphertext; wherein the quantum key ciphertext is generated based on a target quantum key, which is generated by the quantum security service platform based on true random parameters;
[0014] Send an authorization and authentication request carrying the quantum key ciphertext to the quantum security service platform; wherein, the authorization and authentication request is used to request the quantum security service platform to authorize and authenticate the quantum key ciphertext based on the target quantum key;
[0015] The system receives the authorization and authentication result from the quantum security service platform. If the authorization and authentication result indicates that the authorization and authentication are successful, a connection is established with the SDP client.
[0016] Thirdly, a connection method for SDP gateways is provided, applicable to a quantum security service platform, including:
[0017] Receive an authorization and authentication request carrying quantum key ciphertext sent by the SDP gateway; wherein the quantum key ciphertext is generated by the SDP client based on the target quantum key, and the target quantum key is generated by the quantum security service platform based on true random parameters;
[0018] Authorize and authenticate the quantum key ciphertext based on the target quantum key;
[0019] The authorization and authentication result is fed back to the SDP gateway; wherein, the authorization and authentication result is used to indicate whether the SDP network establishes a connection with the SDP client.
[0020] Fourthly, an SDP client is provided, including:
[0021] The key storage module calls the SIM card of the local mobile device to obtain the target quantum key stored on the SIM card; wherein, the target quantum key is generated by the quantum security service platform based on true random parameters;
[0022] The ciphertext generation module generates quantum key ciphertext based on the target quantum key;
[0023] The connection request module initiates a connection request carrying the quantum key ciphertext to the SDP gateway; wherein, the connection request is used to request the SDP gateway to authorize and authenticate the quantum key ciphertext, so that the SDP gateway can establish a connection with the SDP client after the authorization and authentication are successful.
[0024] Fifthly, an SDP gateway is provided, comprising:
[0025] The connection receiving module receives a connection request sent by the SDP client carrying quantum key ciphertext; wherein the quantum key ciphertext is generated based on a target quantum key, which is generated by the quantum security service platform based on true random parameters.
[0026] The authentication request module sends an authorization authentication request carrying the quantum key ciphertext to the quantum security service platform; wherein, the authorization authentication request is used to request the quantum security service platform to authorize and authenticate the quantum key ciphertext based on the target quantum key.
[0027] The authentication receiving module receives the authorization authentication result fed back by the quantum security service platform. If the authorization authentication result indicates that the authorization authentication is successful, a connection is established with the SDP client.
[0028] Sixthly, a quantum security service platform is provided, including:
[0029] The authorization receiving module receives an authorization authentication request carrying quantum key ciphertext sent by the SDP gateway; wherein, the quantum key ciphertext is generated by the SDP client based on the target quantum key, and the target quantum key is generated by the quantum security service platform based on true random parameters;
[0030] The authorization execution module authorizes and authenticates the quantum key ciphertext based on the target quantum key;
[0031] The authorization feedback module sends the authorization authentication result back to the SDP gateway; wherein, the authorization authentication result is used to indicate whether the SDP network has established a connection with the SDP client.
[0032] A seventh aspect provides an electronic device comprising: a processor; and a memory configured to store computer-executable instructions, which, when executed, cause the processor to perform the methods described in the first to third aspects.
[0033] Eighthly, a computer program product is provided, the computer program product including a computer-readable storage medium storing a computer program operable to cause a computer to perform the methods described in the first to third aspects.
[0034] In this embodiment, the SDP client requests a target quantum key generated based on truly random parameters from the quantum security service platform and uses this target quantum key as an authentication key to store it on the SIM card. Subsequently, when the SDP client needs to connect to the SDP gateway, it generates quantum key ciphertext based on the target quantum key and then initiates a connection request carrying the quantum key ciphertext to the SDP gateway. Correspondingly, after receiving the connection request, the SDP gateway sends an authorization and authentication request carrying the quantum key ciphertext to the quantum security service platform. The quantum security service platform then authorizes and authenticates the quantum key ciphertext based on the created target quantum key and feeds back the authorization and authentication result to the SDP gateway, allowing the SDP gateway to decide whether to establish a connection with the SDP client based on the authorization and authentication result. Compared to traditional connection schemes targeting SDP gateways, the target quantum key in this embodiment, being a truly random key, has a higher cracking difficulty than a pseudo-random key. Furthermore, since the target quantum key is stored in the SIM card, its security does not depend on the system environment of the mobile device, making it more difficult to steal. Attached Figure Description
[0035] To more clearly illustrate the technical solutions in the embodiments of this application or the prior art, the drawings used in the description of the embodiments or the prior art will be briefly introduced below. Obviously, the drawings described below are only some embodiments recorded in the embodiments of this application. For those skilled in the art, other drawings can be obtained based on these drawings without creative effort.
[0036] Figure 1 This is a schematic diagram illustrating the process of applying the connection method for the SDP gateway to the SDP client side according to an embodiment of this application.
[0037] Figure 2 This is a schematic diagram illustrating the process of applying the connection method for an SDP gateway to the SDP gateway side according to an embodiment of this application.
[0038] Figure 3 This is a schematic diagram illustrating the process of applying the connection method for the SDP gateway in this application to the quantum security service platform side.
[0039] Figure 4 This is a schematic diagram of the architecture of the connection method for an SDP gateway according to an embodiment of this application.
[0040] Figure 5 This is a flowchart illustrating the connection method for an SDP gateway in a specific application scenario according to an embodiment of this application.
[0041] Figure 6 This is a schematic diagram of the structure of the SDP client in an embodiment of this application.
[0042] Figure 7 This is a schematic diagram of the structure of the SDP gateway in an embodiment of this application.
[0043] Figure 8 This is a schematic diagram of the structure of the quantum security service platform according to an embodiment of this application.
[0044] Figure 9 This is a schematic diagram of the structure of an electronic device according to an embodiment of this application. Detailed Implementation
[0045] As mentioned earlier, existing SDP gateways use a control center with relevant device identifiers to randomly generate authentication keys through a software implementation. These keys are then stored on the client's database, configuration file, or registry using an end-user storage method. Strictly speaking, the authentication keys generated by this software implementation are pseudo-random and can be cracked. Furthermore, the security of end-user storage depends on the system environment. As usage scenarios diversify, system environment issues become more prominent, easily leading to authentication key leaks. All of these factors affect the connection security of SDP clients to the SDP gateway.
[0046] In view of this, this application aims to propose a connection scheme for SDP gateways that can improve the connection security of SDP clients to SDP gateways.
[0047] To enable those skilled in the art to better understand the technical solutions in this specification, the technical solutions in the embodiments of this application will be clearly and completely described below with reference to the accompanying drawings. Obviously, the described embodiments are only some embodiments of this specification, and not all embodiments. Based on the embodiments in this specification, all other embodiments obtained by those skilled in the art without creative effort should fall within the scope of protection of this specification.
[0048] Figure 1 This is a flowchart illustrating the application of the connection method for an SDP gateway to the SDP client side according to an embodiment of this application, including the following steps:
[0049] S102, call the SIM card of the local mobile device to obtain the target quantum key stored in the SIM card; wherein, the target quantum key is generated based on true random parameters.
[0050] In this embodiment, the SDP client can apply to a trusted quantum security service platform to obtain a standard quantum key. That is, the quantum key is generated by the quantum security service platform based on truly random parameters, and is a truly random key, which is more difficult to crack than a pseudo-random key.
[0051] In one implementation, the SDP client requests the distribution of a quantum key from a quantum security service platform to obtain encoded information fed back by the platform. This encoded information is obtained by the quantum security service platform encoding truly random parameters based on light of multiple intensities. These intensities include light in signal states and light in weakly decoy states. The signal states correspond to the same basis vector (a basis vector is a vector in the quantum realm), while the weakly decoy states correspond to either a first basis vector or a second basis vector chosen with different probabilities. Next, the SDP client measures the encoded information with different probabilities under either the first or second basis vector to obtain the raw code. Then, based on the basis vectors selected by the quantum security service platform, the light intensities, and the locally selected first or second basis vectors, the SDP client selects the target quantum key from the raw code.
[0052] For ease of understanding, the SDP client is defined as Alice, and the quantum security service platform is defined as Bob. The specific distribution details of the above stream key distribution are as follows:
[0053] 1. There are two people, Alice (as the receiving mobile device) and Bob (as the sending quantum-safe service platform), connected by a quantum channel (such as an optical fiber) and a classical channel.
[0054] 2. Alice generates a string of 0s and 1s randomly and encodes them with a certain probability into different intensities of light, specifically the signal state, the weak decoy state, and the vacuum state.
[0055] 3. Asymmetric basis selection:
[0056] ① For signal states, Alice encodes all states on a basis vector, such as the Z basis vector.
[0057] ② For a weak decoy state, Alice encodes it on the X basis with a certain probability and on the Z basis with a certain probability. Generally speaking, these two probabilities are not the same.
[0058] ③ Alice does not need to encode the vacuum state.
[0059] Furthermore, Alice sends these encoded states to Bob, who selects to measure using the X basis vector with a certain probability and the Z basis vector with a certain probability.
[0060] 4. Alice and Bob perform post-processing to obtain the final target quantum key from the original quantum key. This includes the following steps:
[0061] ① Alice and Bob publish their chosen basis vectors for encoding and measurement. Alice also publishes the intensity of the light she chose to encode, and then filters and post-processes the original code. Only when they choose the same basis for encoding and measurement can Alice and Bob obtain the filtered key from the original code.
[0062] ② Alice and Bob ensure their keys are identical through error correction steps and estimate the maximum amount of information the other party could obtain. They then use a secret amplification method to obtain the final secure key.
[0063] In this embodiment, Alice and Bob asymmetrically select the basis vectors for preparation and measurement, thereby simplifying the system and improving the code generation rate. Furthermore, encoding the light using decoy states of the asymmetric basis vectors can improve the code generation rate while ensuring security.
[0064] After obtaining the target quantum key, a quantum key management application can be created. This quantum key management application is configured with an Application Protocol Data Unit (APDU) protocol for interacting with the SIM card. In this embodiment, the SDP client uses the quantum key management application to call the SIM card of the mobile device to store the target quantum key.
[0065] Correspondingly, the APDU protocol is configured with a first command to instruct the SIM card to provide the target quantum key; when the target quantum key is needed (connected to the SDP gateway), the first command can be issued to the SIM card of the mobile device based on the quantum key management application to call the SIM card to provide the locally stored target quantum key.
[0066] S104, Generate quantum key ciphertext based on the target quantum key.
[0067] In this embodiment, the SDP client requests a temporary session key from the quantum security service platform, along with an identifier (such as the ID of the temporary session key) corresponding to the temporary session key. Then, the SDP client encrypts the target quantum key based on the temporary session key to obtain the quantum key ciphertext. The connection request also carries the identifier of the temporary session key, and is used to request the SDP gateway to authorize and authenticate the quantum key ciphertext through the quantum security service platform based on the temporary session key corresponding to the identifier.
[0068] Taking the APDU protocol call to the SIM card as an example, in relevant applications, the APDU protocol in this embodiment is also configured with a second command to instruct the SIM card to encrypt the target quantum key; correspondingly, this step can issue a second command to the SIM card of the mobile device based on the quantum key management application to call the SIM card to encrypt the target quantum key based on the temporary session key, so as to obtain the quantum key ciphertext.
[0069] S106, initiate a connection request carrying the quantum key ciphertext to the SDP gateway; wherein, the connection request is used to request the SDP gateway to authorize and authenticate the quantum key ciphertext, so that the SDP gateway can establish a connection with the SDP client after the authorization and authentication are successful.
[0070] The authorization and authentication process for the SDP gateway can be referenced here. Figure 2 As shown.
[0071] Figure 2 This is a flowchart illustrating the connection method for an SDP gateway according to an embodiment of this application, applied to the SDP gateway side, including the following steps:
[0072] S202, Receive a connection request sent by the SDP client carrying quantum key ciphertext; wherein, the quantum key ciphertext is generated based on the target quantum key, and the target quantum key is generated based on true random parameters.
[0073] S204, Send an authorization and authentication request carrying the quantum key ciphertext to the quantum security service platform; wherein, the authorization and authentication request is used to request the quantum security service platform to authorize and authenticate the quantum key ciphertext based on the target quantum key.
[0074] Based on the foregoing, in this embodiment, the quantum key ciphertext is obtained by the SDP client encrypting the target quantum key using a temporary session key; the temporary session key is obtained by the SDP client from the quantum security service platform; and the connection request also carries an identifier for the temporary session key. Correspondingly, the SDP gateway sends an authorization and authentication request carrying the quantum key ciphertext and the identifier to the quantum security service platform; this authorization and authentication request is used to request the quantum security service platform to decrypt the quantum key ciphertext based on the temporary session key matching the identifier, and then to authorize and authenticate the decryption result based on the target quantum key.
[0075] S206: Receive the authorization and authentication results from the quantum security service platform. If the authorization and authentication results indicate that the authorization and authentication are successful, establish a connection with the SDP client.
[0076] The authorization and authentication process for the quantum security service platform can be referenced here. Figure 3 As shown.
[0077] Figure 3 This is a flowchart illustrating the application of the connection method for an SDP gateway in this application to a quantum security service platform, including the following steps:
[0078] S302, receive an authorization and authentication request carrying a quantum key ciphertext sent by the SDP gateway; wherein the quantum key ciphertext is generated by the SDP client based on the target quantum key, and the target quantum key is generated by the quantum security service platform based on true random parameters.
[0079] In one implementation, the quantum security service platform receives a quantum key distribution request from an SDP client. It then encodes truly random parameters using light of multiple intensities to obtain encoded information. The multiple intensities include signal-state light and weakly decoy-state light. The signal-state light encoding the truly random parameters corresponds to the same basis vector, while the weakly decoy-state light encoding the truly random parameters corresponds to a first or second basis vector selected based on different probabilities. The quantum security service platform then feeds back the encoded information to the SDP client, which uses this information to filter for target quantum keys.
[0080] S304, Authorizes and authenticates quantum key ciphertext based on the target quantum key.
[0081] As can be seen from the foregoing, the quantum key ciphertext in this embodiment is obtained by the SDP client encrypting the target quantum key based on the temporary session key; the temporary session key is obtained by the SDP client from the quantum security service platform; and the authorization and authentication request also carries the identifier of the temporary session key.
[0082] Correspondingly, in this step, the quantum security service platform determines a matching temporary session key based on the identifier in the authorization and authentication request. Next, the quantum security service platform decrypts the quantum key ciphertext based on the temporary session key to obtain the decryption result. Then, the quantum security service platform performs authorization and authentication on the decryption result based on the target quantum key. If the target quantum key matches the decryption result, the authorization and authentication result indicates success; otherwise, the authorization and authentication result indicates failure.
[0083] S306 sends the authorization and authentication result back to the SDP gateway; the authorization and authentication result is used to indicate whether the SDP network has established a connection with the SDP client.
[0084] In summary, based on the method of this embodiment, the SDP client requests a target quantum key generated based on truly random parameters from the quantum security service platform and uses this target quantum key as an authentication key to access the SIM card for storage. Subsequently, when the SDP client needs to connect to the SDP gateway, it generates quantum key ciphertext based on the target quantum key and then initiates a connection request carrying the quantum key ciphertext to the SDP gateway. Correspondingly, after receiving the connection request, the SDP gateway sends an authorization and authentication request carrying the quantum key ciphertext to the quantum security service platform. The quantum security service platform then authorizes and authenticates the quantum key ciphertext based on the created target quantum key and feeds back the authorization and authentication result to the SDP gateway, allowing the SDP gateway to decide whether to establish a connection with the SDP client based on the authorization and authentication result. Compared to traditional connection schemes targeting SDP gateways, the target quantum key in this embodiment is a truly random key, which has a higher cracking difficulty than pseudo-random keys. Furthermore, the target quantum key is stored in the SIM card, and its security does not depend on the system environment of the mobile device, making it more difficult to steal.
[0085] The application scenarios of the method in this embodiment are described below.
[0086] I. Overall Architecture of Application Scenarios
[0087] refer to Figure 4 As shown, the overall architecture of this application scenario includes: a quantum security service platform, an SDP client, an SDP gateway, and a business system.
[0088] Quantum security service platform: The quantum security service platform injects quantum keys into quantum key management applications through a quantum key distribution protocol.
[0089] SDP Client: The SDP client is used to connect quantum key management applications and quantum security service platforms, serving as a data "transfer station" between them.
[0090] SDP Gateway: As a business logic processing module, the SDP gateway can perform functions such as business data forwarding, seed verification and authentication, and traffic access.
[0091] Business systems: Systems that users need to access or interact with after authenticating through seed knocking.
[0092] II. Implementation Process of Application Scenarios
[0093] Step 1: The SDP client connects to the quantum security service platform. The quantum security service platform generates a quantum key and sends it to the SDP client through the quantum key distribution mechanism. The SDP client then uses the SIM card to store the quantum key.
[0094] Specifically, after obtaining the quantum key from the quantum security service platform, the SDP client sends a seed storage command to the SIM card using a custom APDU command. Upon receiving the instruction from the SDP client, the SIM card analyzes and obtains the card application to be invoked (the quantum key management application), the encryption method for cryptographic operations on the quantum key, and the key's index. The quantum key management application first uses the SIM card's cryptographic capabilities to encrypt the quantum key, then creates a file to store the quantum key data and assigns read permissions to that file to the user.
[0095] Step 2: The SDP client reads the quantum key from the SIM card and performs a knock-on authentication to the SDP gateway.
[0096] refer to Figure 5 As shown, the process for this step is as follows:
[0097] S1: The user triggers authorization authentication on the SDP client. The SDP client sends a custom APDU command to the SIM card to read the quantum key, and at the same time requests a temporary session key and temporary session key ID from the quantum security service platform.
[0098] After the user triggers authorization authentication on the SDP client, the SDP client sends a quantum key reading command to the SIM card according to the APDU protocol and the custom SIM card application interface.
[0099] To ensure ease of data use, the data format of the quantum key can be customized. This data format includes two options: LZMY-DATA and LZMY_PACK.
[0100] The LZMY-DATA data format is shown in Table 1:
[0101]
[0102] Table 1
[0103] The LZMY_PACK data format is shown in Table 2:
[0104]
[0105] Table 2
[0106] Furthermore, the SDP client defines a unique data format for reporting commands according to the ISO7816-4 specification, and reports relevant identity information to the SIM via the APDU protocol. The data format of the reporting commands is shown in Table 3.
[0107]
[0108] Table 3
[0109] S2: When reading the quantum key, the SDP customer asynchronously requests a temporary session key and a temporary session key ID (identifier) from the quantum security service platform.
[0110] The ephemeral session key is used to encrypt the quantum key, forming the quantum key ciphertext for transmission over the network. The ephemeral session key ID is required for door-knocking authentication.
[0111] S3: The SDP client uses a temporary session key to encrypt the quantum key to form a quantum key ciphertext. The SDP client then sends the quantum key ciphertext and the temporary session key ID to the SDP gateway for authentication to request a connection.
[0112] During communication, to ensure secure transmission of the quantum key, the SDP client can encrypt the quantum key using a temporarily generated session key, generating quantum key ciphertext. The ciphertext, along with the temporary session key ID, is then sent to the SDP gateway. This step not only protects the quantum key from potential security threats but also enhances the reliability and security of communication between the SDP client and the SDP gateway by sending the temporary session key ID for authentication.
[0113] S4: After receiving the quantum key ciphertext and temporary key ID, the SDP gateway sends the quantum key ciphertext and temporary key ID to the quantum security service platform for verification through an authorization authentication request.
[0114] In this application scenario, when the SDP gateway receives the quantum key ciphertext and temporary key ID sent by the SDP client, to ensure the security and reliability of communication, it forwards the received quantum key ciphertext and temporary key ID to the quantum security service platform. The quantum security service platform then uses its powerful computing resources to verify the data. Through this verification mechanism, the SDP architecture can provide a higher level of data protection, effectively preventing potential security threats and malicious attacks.
[0115] S5: The quantum security service platform feeds back the authorization and authentication results to the SDP gateway. The SDP gateway analyzes and processes the authorization and authentication results and notifies the SDP client whether to accept the connection.
[0116] Regardless of whether authentication succeeds or fails, the notification sent by the SDP gateway to the SDP client includes the authentication result and any relevant details (such as the reason for failure). If the SDP gateway accepts the connection request from the SDP client, then refer to... Figure 4 As shown, the SDP gateway will then establish a secure access channel to the business system.
[0117] Corresponding to Figure 1 The method shown in this application is another embodiment of an SDP client. Figure 6 This is a structural diagram of the SDP client 600, including:
[0118] The key storage module 610 calls the SIM card of the local mobile device to obtain the target quantum key stored in the SIM card; wherein, the target quantum key is generated by the quantum security service platform based on true random parameters.
[0119] In this embodiment, the SDP client can apply to a trusted quantum security service platform to obtain a standard quantum key. That is, the quantum key is generated by the quantum security service platform based on truly random parameters, and is a truly random key, which is more difficult to crack than traditional pseudo-random keys.
[0120] The ciphertext generation module 620 generates quantum key ciphertext based on the target quantum key.
[0121] The connection request module 630 initiates a connection request carrying the quantum key ciphertext to the SDP gateway; wherein, the connection request is used to request the SDP gateway to authorize and authenticate the quantum key ciphertext, so that the SDP gateway can establish a connection with the SDP client after the authorization and authentication are successful.
[0122] Optionally, the ciphertext generation module 620 generates quantum key ciphertext based on the target quantum key, including: applying for a temporary session key from the quantum security service platform, wherein the temporary session key corresponds to an identifier; encrypting the target quantum key based on the temporary session key to obtain quantum key ciphertext; wherein the connection request also carries the identifier of the temporary session key, and the connection request is used to request the SDP gateway to authorize and authenticate the quantum key ciphertext through the quantum security service platform based on the temporary session key corresponding to the identifier.
[0123] Optionally, before calling the SIM card of the local mobile device to obtain the target quantum key stored on the SIM card, the key storage module 610 is further configured to: create a quantum key management application on the local mobile device, the quantum key management application being configured with an Application Protocol Data Unit (APDU) protocol for interacting with the SIM card, and the APDU protocol being configured with a first command for instructing the SIM card to provide the target quantum key. Correspondingly, the key storage module 610 calling the SIM card of the local mobile device to obtain the target quantum key stored on the SIM card includes: issuing a first command to the SIM card of the mobile device based on the quantum key management application to call the SIM card to provide the locally stored target quantum key.
[0124] Optionally, the APDU protocol is further configured with a second command to instruct the SIM card to encrypt the target quantum key; the ciphertext generation module 620 encrypts the target quantum key based on the temporary session key to obtain quantum key ciphertext, including: issuing a second command to the SIM card of the mobile device based on the quantum key management application to invoke the SIM card to encrypt the target quantum key based on the temporary session key to obtain quantum key ciphertext.
[0125] Optionally, before calling the SIM card of the local mobile device to obtain the target quantum key stored in the SIM card, the key storage module 610 is further configured to: send a quantum key distribution request to the quantum security service platform to obtain the encoding information fed back by the quantum security service platform; wherein, the encoding information is obtained by encoding true random parameters based on light of multiple intensities; the multiple intensities of light include light in a signal state and light in a weakly decoy state; the quantum security service platform selects to encode the true random parameters under the same basis vector for the light in the signal state; the quantum security service platform selects to encode the true random parameters under a first basis vector or a second basis vector with different probabilities for the light in the weakly decoy state; measure the encoding information under the first basis vector or the second basis vector with different probabilities to obtain the original code; and filter out the target quantum key from the original code according to the basis vector corresponding to the encoding information, the intensity of the light, and the first basis vector or the second basis vector selected and measured locally.
[0126] It should be noted that the SDP client in this embodiment can be used as... Figure 1 The execution body of the method shown is therefore able to achieve... Figure 1 The steps and functions of the method shown will not be repeated here.
[0127] Corresponding to Figure 2 The method shown in this application is another embodiment of an SDP gateway. Figure 7This is a structural diagram of the SDP gateway 700, including:
[0128] The connection receiving module 710 receives a connection request sent by the SDP client carrying quantum key ciphertext; wherein the quantum key ciphertext is generated based on a target quantum key, which is generated by the quantum security service platform based on true random parameters.
[0129] The authentication request module 720 sends an authorization authentication request carrying the quantum key ciphertext to the quantum security service platform; wherein, the authorization authentication request is used to request the quantum security service platform to authorize and authenticate the quantum key ciphertext based on the target quantum key.
[0130] The authentication receiving module 730 receives the authorization authentication result fed back by the quantum security service platform. If the authorization authentication result indicates that the authorization authentication is successful, a connection is established with the SDP client.
[0131] Optionally, the quantum key ciphertext is obtained by the SDP client encrypting the target quantum key based on a temporary session key; the temporary session key is obtained by the SDP client from the quantum security service platform; the connection request also carries an identifier of the temporary session key; the authentication request module 720 sends an authorization authentication request carrying the quantum key ciphertext to the quantum security service platform, including: sending an authorization authentication request carrying the quantum key ciphertext and the identifier to the quantum security service platform; wherein, the authorization authentication request is used to request the quantum security service platform to decrypt the quantum key ciphertext based on a temporary session key matching the identifier, and then authorize and authenticate the decryption result based on the target quantum key.
[0132] It should be noted that the SDP gateway in this embodiment can be used as... Figure 2 The execution body of the method shown is therefore able to achieve... Figure 2 The steps and functions of the method shown will not be repeated here.
[0133] Corresponding to Figure 3 The method shown in this application, in another embodiment, provides a quantum security service platform. Figure 8 This is a structural diagram of the quantum security service platform 800, including:
[0134] The authorization receiving module 810 receives an authorization authentication request carrying quantum key ciphertext sent by the SDP gateway; wherein the quantum key ciphertext is generated by the SDP client based on the target quantum key, and the target quantum key is generated by the quantum security service platform based on true random parameters.
[0135] The authorization execution module 820 performs authorization authentication on the quantum key ciphertext based on the target quantum key.
[0136] The authorization feedback module 830 feeds back the authorization authentication result to the SDP gateway; wherein the authorization authentication result is used to indicate whether the SDP network has established a connection with the SDP client.
[0137] Optionally, the quantum key ciphertext is obtained by the SDP client encrypting the target quantum key based on a temporary session key; the temporary session key is obtained by the SDP client from the quantum security service platform; the authorization authentication request also carries an identifier of the temporary session key; the authorization execution module 820 performs authorization authentication on the quantum key ciphertext based on the target quantum key, including: determining a matching temporary session key based on the identifier in the authorization authentication request; decrypting the quantum key ciphertext based on the temporary session key to obtain a decryption result; and performing authorization authentication on the decryption result based on the target quantum key; wherein, if the target quantum key matches the decryption result, the authorization authentication result indicates success; if the target quantum key matches the decryption result, the authorization authentication result indicates failure.
[0138] Optionally, before receiving the authorization and authentication request sent by the SDP gateway, the authorization receiving module 810 is further configured to: receive a quantum key distribution request sent by the SDP client; encode true random parameters based on light of multiple intensities to obtain encoding information; wherein, the multiple intensities of light include light in a signal state and light in a weak decoy state; the light in the signal state encodes the true random parameters with the same basis vector; the light in the weak decoy state encodes the true random parameters with a first basis vector or a second basis vector selected based on different probabilities; and feed back the encoding information to the SDP client; wherein, the encoding information is used by the SDP client to filter out the target quantum key.
[0139] It should be noted that the quantum security service platform in this embodiment can be used as... Figure 3 The execution body of the method shown is therefore able to achieve... Figure 3 The steps and functions of the method shown will not be repeated here.
[0140] Figure 9 This is a schematic diagram of the structure of an electronic device provided in one embodiment of this application. Please refer to it. Figure 9At the hardware level, the electronic device includes a processor, and optionally also includes an internal bus, a network interface, and memory. The memory may include main memory, such as high-speed random-access memory (RAM), or non-volatile memory, such as at least one disk drive. Of course, the electronic device may also include other hardware required for other business operations.
[0141] The processor, network interface, and memory can be interconnected via an internal bus, which can be an ISA (Industry Standard Architecture) bus, a PCI (Peripheral Component Interconnect) bus, or an EISA (Extended Industry Standard Architecture) bus, etc. This bus can be divided into address bus, data bus, control bus, etc. For ease of representation, Figure 9 The symbol is represented by a single double-headed arrow, but this does not mean that there is only one bus or one type of bus.
[0142] Memory is used to store programs. Specifically, programs may include program code, which includes computer operation instructions. Memory may include main memory and non-volatile memory, and provides instructions and data to the processor.
[0143] The processor reads the corresponding computer program from the non-volatile memory into the memory and then runs it, forming the aforementioned image propagation device at the logical level.
[0144] In one implementation, the processor executes a program stored in memory, specifically for performing the following operations:
[0145] The target quantum key is obtained by calling the SIM card of the local mobile device; wherein the target quantum key is generated by the quantum security service platform based on true random parameters.
[0146] Quantum key ciphertext is generated based on the target quantum key.
[0147] A connection request carrying the quantum key ciphertext is initiated to the SDP gateway; wherein the connection request is used to request the SDP gateway to authorize and authenticate the quantum key ciphertext, so that the SDP gateway can establish a connection with the SDP client after the authorization and authentication are successful.
[0148] In one implementation, the processor executes a program stored in memory, specifically for performing the following operations:
[0149] Receive a connection request sent by an SDP client carrying quantum key ciphertext; wherein the quantum key ciphertext is generated based on a target quantum key, which is generated by the quantum security service platform based on true random parameters.
[0150] Send an authorization and authentication request carrying the quantum key ciphertext to the quantum security service platform; wherein the authorization and authentication request is used to request the quantum security service platform to authorize and authenticate the quantum key ciphertext based on the target quantum key.
[0151] The system receives the authorization and authentication result from the quantum security service platform. If the authorization and authentication result indicates that the authorization and authentication are successful, a connection is established with the SDP client.
[0152] In one implementation, the processor executes a program stored in memory, specifically for performing the following operations:
[0153] Receive an authorization and authentication request carrying quantum key ciphertext sent by the SDP gateway; wherein the quantum key ciphertext is generated by the SDP client based on the target quantum key, and the target quantum key is generated by the quantum security service platform based on true random parameters;
[0154] The quantum key ciphertext is authorized and authenticated based on the target quantum key.
[0155] The authorization and authentication result is fed back to the SDP gateway; wherein, the authorization and authentication result is used to indicate whether the SDP network establishes a connection with the SDP client.
[0156] In the electronic device of this embodiment, the SDP client requests a target quantum key generated based on truly random parameters from the quantum security service platform and uses this target quantum key as an authentication key to access the SIM card for storage. Subsequently, when the SDP client needs to connect to the SDP gateway, it generates quantum key ciphertext based on the target quantum key and then initiates a connection request carrying the quantum key ciphertext to the SDP gateway. Correspondingly, after receiving the connection request, the SDP gateway sends an authorization and authentication request carrying the quantum key ciphertext to the quantum security service platform. The quantum security service platform then authorizes and authenticates the quantum key ciphertext based on the created target quantum key and feeds back the authorization and authentication result to the SDP gateway, allowing the SDP gateway to decide whether to establish a connection with the SDP client based on the authorization and authentication result. Compared to traditional connection schemes targeting SDP gateways, the target quantum key in this embodiment, as a truly random key, has a higher cracking difficulty than a pseudo-random key. Furthermore, since the target quantum key is stored in the SIM card, its security does not depend on the system environment of the mobile device, making it more difficult to steal.
[0157] The above is as stated in this application. Figures 1 to 3 The methods disclosed in the illustrated embodiments can be applied to or implemented by a processor. The processor may be an integrated circuit chip with signal processing capabilities. During implementation, each step of the above methods can be completed by integrated logic circuits in the processor's hardware or by instructions in software form. The processor can be a general-purpose processor, including a Central Processing Unit (CPU), a Network Processor (NP), etc.; it can also be a Digital Signal Processor (DSP), an Application Specific Integrated Circuit (ASIC), a Field-Programmable Gate Array (FPGA), or other programmable logic devices, discrete gate or transistor logic devices, or discrete hardware components. It can implement or execute the methods, steps, and logic block diagrams disclosed in one or more embodiments of this application. The general-purpose processor can be a microprocessor or any conventional processor. The steps of the methods disclosed in one or more embodiments of this application can be directly embodied in the execution of a hardware decoding processor, or executed by a combination of hardware and software modules in the decoding processor. The software module can reside in a mature storage medium in the field, such as random access memory, flash memory, read-only memory, programmable read-only memory, electrically erasable programmable memory, or registers. This storage medium is located in memory, and the processor reads information from the memory and, in conjunction with its hardware, completes the steps of the above method.
[0158] Of course, in addition to software implementation, the electronic device of this application does not exclude other implementation methods, such as logic devices or a combination of hardware and software, etc. In other words, the execution subject of the following processing flow is not limited to each logic unit, but can also be hardware or logic devices.
[0159] This application also proposes a computer program product, which includes a computer-readable storage medium storing a computer program.
[0160] In one implementation, the computer program is operable to cause the computer to perform the following operations:
[0161] The target quantum key is obtained by calling the SIM card of the local mobile device; wherein the target quantum key is generated by the quantum security service platform based on true random parameters.
[0162] Quantum key ciphertext is generated based on the target quantum key.
[0163] A connection request carrying the quantum key ciphertext is initiated to the SDP gateway; wherein the connection request is used to request the SDP gateway to authorize and authenticate the quantum key ciphertext, so that the SDP gateway can establish a connection with the SDP client after the authorization and authentication are successful.
[0164] In one implementation, the computer program is operable to cause the computer to perform the following operations:
[0165] Receive a connection request sent by an SDP client carrying quantum key ciphertext; wherein the quantum key ciphertext is generated based on a target quantum key, which is generated by the quantum security service platform based on true random parameters.
[0166] Send an authorization and authentication request carrying the quantum key ciphertext to the quantum security service platform; wherein the authorization and authentication request is used to request the quantum security service platform to authorize and authenticate the quantum key ciphertext based on the target quantum key.
[0167] The system receives the authorization and authentication result from the quantum security service platform. If the authorization and authentication result indicates that the authorization and authentication are successful, a connection is established with the SDP client.
[0168] In one implementation, the computer program is operable to cause the computer to perform the following operations:
[0169] Receive an authorization and authentication request carrying a quantum key ciphertext sent by the SDP gateway; wherein the quantum key ciphertext is generated by the SDP client based on a target quantum key, and the target quantum key is generated by the quantum security service platform based on true random parameters.
[0170] The quantum key ciphertext is authorized and authenticated based on the target quantum key.
[0171] The authorization and authentication result is fed back to the SDP gateway; wherein, the authorization and authentication result is used to indicate whether the SDP network establishes a connection with the SDP client.
[0172] In summary, the above description is merely a preferred embodiment of this application and is not intended to limit the scope of protection of this application. Any modifications, equivalent substitutions, improvements, etc., made within the spirit and principles of one or more embodiments of this application should be included within the scope of protection of one or more embodiments of this application.
[0173] The systems, devices, and modules described in the above embodiments can be implemented by computer chips or physical entities, or by products with certain functions. A typical implementation device is a computer. Specifically, a computer can be, for example, a personal computer, laptop computer, cellular phone, camera phone, smartphone, personal digital assistant, media player, navigation device, email device, game console, tablet computer, wearable device, or any combination of these devices.
[0174] Computer-readable media includes both permanent and non-permanent, removable and non-removable media that can store information using any method or technology. Information can be computer-readable instructions, data structures, modules of programs, or other data. Examples of computer storage media include, but are not limited to, phase-change memory (PRAM), static random access memory (SRAM), dynamic random access memory (DRAM), other types of random access memory (RAM), read-only memory (ROM), electrically erasable programmable read-only memory (EEPROM), flash memory or other memory technologies, CD-ROM, digital versatile optical disc (DVD) or other optical storage, magnetic tape, magnetic disk storage or other magnetic storage devices, or any other non-transferable medium that can be used to store information accessible by a computing device. As defined herein, computer-readable media does not include transient computer-readable media, such as modulated data signals and carrier waves.
[0175] It should also be noted that the terms "comprising," "including," or any other variations thereof are intended to cover non-exclusive inclusion, such that a process, method, article, or apparatus that comprises a list of elements includes not only those elements but also other elements not expressly listed, or elements inherent to such a process, method, article, or apparatus. Without further limitation, an element defined by the phrase "comprising one..." does not exclude the presence of other identical elements in the process, method, article, or apparatus that includes said element.
[0176] The various embodiments in this application are described in a progressive manner. Similar or identical parts between embodiments can be referred to mutually. Each embodiment focuses on describing the differences from other embodiments. In particular, the system embodiments are basically similar to the method embodiments, so the description is relatively simple; relevant parts can be referred to the descriptions of the method embodiments.
Claims
1. A connection method for an SDP gateway, applied to an SDP client, characterized in that, include: The target quantum key is obtained by accessing the SIM card of a local mobile device; wherein the target quantum key is generated by the quantum security service platform based on truly random parameters. Generate quantum key ciphertext based on the target quantum key; A connection request carrying the quantum key ciphertext is initiated to the SDP gateway; wherein, the connection request is used to request the SDP gateway to authorize and authenticate the quantum key ciphertext through the quantum security service platform, so that the SDP gateway can establish a connection with the SDP client after the authorization and authentication are successful.
2. The method according to claim 1, characterized in that, Generating quantum key ciphertext based on the target quantum key includes: Apply for a temporary session key from the quantum security service platform, wherein the temporary session key corresponds to a specific identifier; The target quantum key is encrypted using the temporary session key to obtain the quantum key ciphertext; The connection request also carries an identifier of the temporary session key. The connection request is used to request the SDP gateway to authorize and authenticate the quantum key ciphertext through the quantum security service platform based on the temporary session key corresponding to the identifier.
3. The method according to claim 2, characterized in that, Before accessing the SIM card of a local mobile device to obtain the target quantum key stored on the SIM card, the method further includes: A quantum key management application is created on a local mobile device. The quantum key management application is configured with an Application Protocol Data Unit (APDU) protocol for interacting with a SIM card. The APDU protocol is configured with a first command for instructing the SIM card to provide a target quantum key. Accessing the target quantum key stored on the SIM card of a local mobile device includes: The quantum key management application issues a first command to the SIM card of the mobile device to invoke the target quantum key stored locally by the SIM card.
4. The method according to claim 3, characterized in that, The APDU protocol is also configured with a second command to instruct the SIM card to encrypt the target quantum key; The target quantum key is encrypted based on the temporary session key to obtain quantum key ciphertext, including: The quantum key management application sends a second command to the SIM card of the mobile device to invoke the SIM card to encrypt the target quantum key based on the temporary session key, thereby obtaining the quantum key ciphertext.
5. The method according to claim 1, characterized in that, Before accessing the SIM card of a local mobile device to obtain the target quantum key stored on the SIM card, the method further includes: A quantum key distribution request is sent to the quantum security service platform to obtain the encoded information fed back by the quantum security service platform; wherein, the encoded information is obtained by encoding true random parameters based on light of multiple intensities; the multiple intensities of light include light in signal state and light in weak decoy state; the light in signal state corresponds to the same basis vector; the light in weak decoy state corresponds to a first basis vector or a second basis vector selected with different probabilities; The encoded information is measured under the first basis vector or the second basis vector with different probabilities to obtain the original code; The target quantum key is selected from the original code based on the basis vectors corresponding to the encoded information, the intensity of the light, and the first or second basis vectors measured locally.
6. A connection method for an SDP gateway, applied to an SDP gateway, characterized in that, include: Receive a connection request sent by an SDP client carrying quantum key ciphertext; wherein the quantum key ciphertext is generated based on a target quantum key, which is generated by the quantum security service platform based on true random parameters; Send an authorization and authentication request carrying the quantum key ciphertext to the quantum security service platform; wherein, the authorization and authentication request is used to request the quantum security service platform to authorize and authenticate the quantum key ciphertext based on the target quantum key; The system receives the authorization and authentication result from the quantum security service platform. If the authorization and authentication result indicates that the authorization and authentication are successful, a connection is established with the SDP client.
7. The method according to claim 6, characterized in that, The quantum key ciphertext is obtained by the SDP client encrypting the target quantum key based on a temporary session key; the temporary session key is obtained by the SDP client from the quantum security service platform; the connection request also carries an identifier of the temporary session key; Sending an authorization and authentication request carrying the quantum key ciphertext to the quantum security service platform, including: Send an authorization and authentication request carrying the quantum key ciphertext and the identifier to the quantum security service platform; wherein, the authorization and authentication request is used to request the quantum security service platform to decrypt the quantum key ciphertext based on a temporary session key that matches the identifier, and then authorize and authenticate the decryption result based on the target quantum key.
8. A connection method for an SDP gateway, applied to a quantum security service platform, characterized in that, include: Receive an authorization and authentication request carrying quantum key ciphertext sent by the SDP gateway; wherein the quantum key ciphertext is generated by the SDP client based on the target quantum key, and the target quantum key is generated by the quantum security service platform based on true random parameters; The quantum key ciphertext is authorized and authenticated through the quantum security service platform based on the target quantum key; The authorization and authentication result is fed back to the SDP gateway; wherein, the authorization and authentication result is used to indicate whether the SDP network establishes a connection with the SDP client.
9. The method according to claim 8, characterized in that, The quantum key ciphertext is obtained by the SDP client encrypting the target quantum key based on a temporary session key; the temporary session key is obtained by the SDP client from the quantum security service platform. The authorization and authentication request also carries an identifier of the temporary session key; Authorization and authentication of the quantum key ciphertext based on the target quantum key includes: Based on the identifier in the authorization and authentication request, determine the matching temporary session key; The quantum key ciphertext is decrypted using the temporary session key to obtain the decryption result; The decryption result is authenticated based on the target quantum key; wherein, if the target quantum key is consistent with the decryption result, the authentication result indicates success; if the target quantum key is consistent with the decryption result, the authentication result indicates failure.
10. The method according to claim 8, characterized in that, Before receiving the authorization and authentication request sent by the SDP gateway, the method further includes: Receive quantum key distribution requests sent by SDP clients; Encoding information is obtained by encoding true random parameters based on light of multiple intensities; wherein, the multiple intensities of light include light in a signal state and light in a weak decoy state; the light in the signal state corresponds to the same basis vector; the light in the weak decoy state corresponds to a first basis vector or a second basis vector selected with different probabilities; The encoded information is fed back to the SDP client; wherein the encoded information is used by the SDP client to filter out the target quantum key.
11. An SDP client, characterized in that, include: The key storage module calls the SIM card of the local mobile device to obtain the target quantum key stored on the SIM card; wherein, the target quantum key is generated by the quantum security service platform based on true random parameters; The ciphertext generation module generates quantum key ciphertext based on the target quantum key; The connection request module initiates a connection request carrying the quantum key ciphertext to the SDP gateway; wherein, the connection request is used to request the SDP gateway to authorize and authenticate the quantum key ciphertext through the quantum security service platform, so that the SDP gateway can establish a connection with the SDP client after the authorization and authentication are successful.
12. An SDP gateway, characterized in that, include: The connection receiving module receives a connection request sent by the SDP client carrying quantum key ciphertext; wherein the quantum key ciphertext is generated based on a target quantum key, which is generated by the quantum security service platform based on true random parameters; The authentication request module sends an authorization authentication request carrying the quantum key ciphertext to the quantum security service platform; wherein, the authorization authentication request is used to request the quantum security service platform to authorize and authenticate the quantum key ciphertext based on the target quantum key; The authentication receiving module receives the authorization authentication result fed back by the quantum security service platform. If the authorization authentication result indicates that the authorization authentication is successful, a connection is established with the SDP client.
13. A quantum-secure service platform, characterized in that, include: The authorization receiving module receives an authorization authentication request carrying quantum key ciphertext sent by the SDP gateway; wherein, the quantum key ciphertext is generated by the SDP client based on the target quantum key, and the target quantum key is generated by the quantum security service platform based on true random parameters; The authorization execution module authorizes and authenticates the quantum key ciphertext based on the target quantum key; The authorization feedback module sends the authorization authentication result back to the SDP gateway; wherein, the authorization authentication result is used to indicate whether the SDP network has established a connection with the SDP client.
14. An electronic device comprising: processor; And a memory arranged to store computer-executable instructions, characterized in that, when executed, the executable instructions cause the processor to perform the method as described in any one of claims 1 to 10.
15. A computer program product, the computer program product comprising a computer-readable storage medium storing a computer program, characterized in that, The computer program is operable to cause the computer to perform the method as described in any one of claims 1 to 10.
Citation Information
Patent Citations
Identity authentication method and system, storage medium and processor
CN113411187A
IPSec VPN establishing method and device
CN118074968A
SPA single packet authentication method and system based on quantum cryptography
CN118523914A