Key distribution method

By performing hash operations on randomly generated strings and combining them with the hardware value information of the Super SIM card, and using quantum communication and MDI-QKD methods, the problem of low key distribution security is solved, and high-security and reliable key transmission is achieved.

CN119276490BActive Publication Date: 2025-12-12CHINA MOBILE INTERNET CO LTD +1
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202411431326.X
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2024-10-14
Publication Date
2025-12-12
Estimated Expiration
2044-10-14

AI Technical Summary

Technical Problem

Existing key distribution methods have low security and are susceptible to being eavesdropped on and tampered with.

Method used

By performing a hash operation on a randomly generated string and combining it with the hardware value information of the Super SIM card, the initial key pool is determined and transmitted using either the initial key pool distribution method based on the Super SIM card and quantum communication or the MDI-QKD method. The principle of quantum entanglement is used to achieve lossless transmission and high-reliability distribution.

Benefits of technology

It improves the security of key distribution, reduces the risk of eavesdropping, and ensures the integrity and confidentiality of data.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN119276490B_ABST
    Figure CN119276490B_ABST
Patent Text Reader

Abstract

The application discloses a key distribution method, and aims at solving the problem of low security of key distribution. The scheme provided by the application comprises the following steps: a local device acquires a first hash value, the first hash value being obtained by performing hash operation on a first string randomly generated; based on the first hash value and first information, a transmission mode of an initial key pool is determined from at least two transmission modes, wherein the first information comprises at least one of a hardware value information of a super SIM card in the local device and a hardware value information of a super SIM card in a peer device; and based on the determined transmission mode, distribution of the initial key pool is completed with the peer device.
Need to check novelty before this filing date? Find Prior Art

Description

TECHNICAL FIELD

[0001] The present application relates to the technical field of key distribution, and particularly relates to a key distribution method. BACKGROUND

[0002] Key distribution is a process of exchanging secret keys between a local device and a peer device, and the main purpose of key distribution is to ensure confidentiality and data integrity in the communication process to prevent unauthorized access and data tampering. The key distribution method in the related art has the problem of low security, therefore, how to improve the security of key distribution is a technical problem to be solved by the present application. SUMMARY

[0003] The purpose of the embodiments of the present application is to provide a key distribution method to solve the problem of low security of key distribution.

[0004] In a first aspect, a key distribution method is provided, applied to a local device, comprising: obtaining a first hash value, the first hash value being obtained by performing a hash operation on a first string generated randomly; determining a transmission mode of an initial key pool from at least two transmission modes based on the first hash value and first information; wherein the first information comprises at least one of a hardware value information of a super SIM card in the local device and a hardware value information of a super SIM card in a peer device; and completing distribution of the initial key pool with the peer device based on the determined transmission mode.

[0005] In a second aspect, an electronic device is provided, the electronic device being a local device, comprising: an obtaining module configured to obtain a first hash value, the first hash value being obtained by performing a hash operation on a first string generated randomly; a processing module configured to determine a transmission mode of an initial key pool from at least two transmission modes based on the first hash value and first information; wherein the first information comprises at least one of a hardware value information of a super SIM card in the local device and a hardware value information of a super SIM card in a peer device; and a communication module configured to complete distribution of the initial key pool with the peer device based on the determined transmission mode.

[0006] In a third aspect, an electronic device is provided, which comprises a processor, a memory, and a computer program stored in the memory and executable on the processor, and when the computer program is executed by the processor, the steps of the method of the first aspect are implemented.

[0007] In a fourth aspect, a computer readable storage medium is provided, which stores a computer program, and when the computer program is executed by a processor, the steps of the method of the first aspect are implemented.

[0008] In a fifth aspect, a computer program product is provided, which includes a non-transitory computer readable storage medium storing a computer program operable to cause a computer to perform part or all of the method of the first aspect.

[0009] In the embodiments of the present application, the first hash value is obtained by performing a hash operation on the first string generated randomly, and the transmission mode of the initial key pool is determined based on the first hash value and the hardware value information of the super SIM card. The transmission mode of the initial key pool is related to the hardware value information of the super SIM card and the randomly generated string, which is beneficial to increase the initial monitoring difficulty and improve the security of key distribution. BRIEF DESCRIPTION OF DRAWINGS

[0010] The accompanying drawings, which are included to provide a further understanding of the present application, constitute a part of the present application and illustrate embodiments of the present application and the specification thereof, which are used to explain the present application and do not constitute improper limitations on the present application. In the drawings:

[0011] Figure 1 Fig. 1 shows a flow diagram of a key distribution method provided by an embodiment of the present application;

[0012] Figure 2 Fig. 1 shows a flow diagram of a key distribution method provided by an embodiment of the present application;

[0013] Figure 3 Fig. 1 shows a flow diagram of a key distribution method provided by an embodiment of the present application;

[0014] Figure 4 Fig. 1 shows a flow diagram of a key distribution method provided by an embodiment of the present application;

[0015] Figure 5 Fig. 1 shows a flow diagram of a key distribution method provided by an embodiment of the present application;

[0016] Figure 6 Fig. 1 shows a flow diagram of a key distribution method provided by an embodiment of the present application; DETAILED DESCRIPTION

[0017] The technical solutions in the embodiments of the present application will be described clearly and completely below with reference to the drawings in the embodiments of the present application. Obviously, the described embodiments are only part of the embodiments of the present application, rather than all the embodiments of the present application. Based on the embodiments in the present application, all other embodiments obtained by those of ordinary skill in the art without creative labor fall within the scope of the present application. The figure numbers in the present application are only used to distinguish each step in the solutions, and are not used to limit the execution order of each step, which is subject to the description in the specification.

[0018] Figure 1 A flow diagram of a key distribution method provided by an embodiment of the present application is shown, which can be executed by a local device, such as a terminal device or a server device, which can communicate with a peer device. As shown in Figure 1 the method can include the following steps.

[0019] S102: Obtain a first hash value, which is obtained by performing a hash operation on a randomly generated first string.

[0020] In one embodiment, as shown in Figure 2 the local device can generate a first string, where the first string is randomly generated, and the first string can be Reed-Solomon codes (RS code) or the like; the local device performs a hash operation on the first string to obtain a first hash value, and transmits the first hash value to the peer device through a public channel. In this step, the local device obtaining the first hash value includes: the local device performing a hash operation on the first string randomly generated by itself to obtain the first hash value.

[0021] In another embodiment, the peer device can generate a first string, where the first string is randomly generated, and the first string can be RS code or the like; the peer device performs a hash operation on the first string to obtain a first hash value, and transmits the first hash value to the local device through a public channel. In this step, the local device obtaining the first hash value includes: the local device receiving the first hash value from the peer device.

[0022] S104: Determine a transmission mode of an initial key pool from at least two transmission modes based on the first hash value and first information, where the first information includes at least one of a hardware value information of a super Subscriber Identity Module (SIM) card in the local device and a hardware value information of a super SIM card in the peer device.

[0023] In this embodiment, the local device and the peer device are both installed with a super SIM card. The local device and the peer device can interact through encrypted information, so that the local device can obtain the hardware value information of the super SIM card in the peer device; and the peer device can obtain the hardware value information of the super SIM card in the local device.

[0024] In an embodiment, the local device can determine the transmission mode of the initial key pool from at least two transmission modes based on the first hash value and the first information, using a formula agreed in advance by the local device and the peer device. For example, the agreed formula is: Select = Calculate (dispersion factor 1, dispersion factor 2, hash). The dispersion factor 1 is the hardware value information of the super SIM card in the local device, which can include at least one of: an integrate circuit card identity (ICCID), a security element identifier (SEID), etc. The dispersion factor 2 is the hardware value information of the super SIM card in the peer device, which can include at least one of: an ICCID, an SEID, etc. The hash in the formula represents the first hash value. The Select in the formula represents the determined transmission mode of the initial key pool.

[0025] As shown in Figure 2 The peer device can also determine the transmission mode of the initial key pool from at least two transmission modes based on the first hash value and the first information in the same way as the local device, so that the local device and the peer device determine the same transmission mode of the initial key pool.

[0026] In an embodiment, the determined transmission mode includes: 1) using an initial key pool distribution mode based on a super SIM card and quantum communication; or 2) using a measurement-device-independent quantum key distribution (MDI-QKD) mode. The above two transmission modes can achieve lossless transmission of quantum keys and ensure high-reliable and secure distribution of keys through the principle of quantum entanglement.

[0027] S106: Distribute the initial key pool with the peer device based on the determined transmission mode.

[0028] The key distribution method provided by the embodiments of the present application performs hash operation on the randomly generated first string to obtain a first hash value, determines the transmission mode of the initial key pool based on the first hash value and the hardware value information of the super SIM card, and the transmission mode of the initial key pool is related to the hardware value information of the super SIM card and the randomly generated string, which is beneficial to increase the initial monitoring difficulty and improve the security of key distribution.

[0029] The key distribution method provided by the embodiments of the present application can be applied to high-security key exchange scenarios in government and enterprise, group, and financial related industries, and secure and trusted products such as trusted 5G calls, trusted 5G messages, trusted short messages, etc., and has high commercial value.

[0030] In one embodiment, the transmission mode determined by the local device and the opposite device includes: using an initial secret key pool distribution mode based on a super SIM card and quantum communication. As shown in Figure 3 The initial secret key pool distribution mode based on the determined transmission mode includes:

[0031] 1) The local device (referred to as A) uses the public key (publicKeyB) of the super SIM card in the opposite device (referred to as B) to encrypt the first string to obtain the first ciphertext (encryptData).

[0032] In this embodiment, the first string can be randomly generated by the local device.

[0033] 2) A performs binary operation on the first ciphertext to obtain first bit data (byteData0), and sends the first bit data (byteData0) to the opposite device using a single-photon signal.

[0034] The opposite device is also used to receive second bit data (byteData1); the opposite device is also used to use the private key (privateKeyB) of its own super SIM card to decrypt the received second bit data to obtain first decryption data (decryptData1); the first decryption data is hashed to obtain a second hash value; and in the case that the second hash value is the same as the first hash value, it is indicated that the transmission process has not been monitored, and the first string can be used as the initial secret key pool. At this time, the opposite device can also notify the local device through a public channel that the first string is used as the initial secret key pool.

[0035] In one embodiment, the method further includes: the local device receives second information from the opposite device; in the case that the second hash value is determined to be different from the first hash value based on the second information, jumping to the step of obtaining the first hash value. Since the second hash value is different from the first hash value, it is indicated that the first string may be tampered with or monitored, and the data is incomplete and incorrect, therefore, the local device can discard the initial secret key pool by the opposite device, that is, the first string will not be used as the initial secret key pool. At this time, the opposite device can also notify the local device through a public channel to jump to S102 again to re-distribute the initial secret key pool to improve security.

[0036] In any one of the above embodiments, the method further includes: storing the initial secret key pool in the auxiliary security domain of the super SIM card in the local device for subsequent encrypted communication, and thus the local device and the opposite device complete the transmission of the initial secret key pool.

[0037] The above uses the initial key pool distribution mode based on the super SIM card and quantum communication, realizes the fusion of the super SIM card and quantum communication technology, uses a single photon signal to send the first bit data to the opposite end device, avoids the waste of data verification in the key distribution technology, and reduces the amount of data transmission; meanwhile, the quantum entanglement principle can realize lossless transmission of the quantum key and ensure high reliable and safe distribution of the key, reduces the risk of eavesdropping, and improves the security of the key distribution.

[0038] In addition, the initial key is stored in the auxiliary security domain of the super SIM card without being taken out of the card, further improving the security of the key distribution.

[0039] In one embodiment, the transmission mode determined by the local device and the opposite end device includes an MDI-QKD mode. As shown in Figure 4 Based on the determined transmission mode, the distribution of the initial key pool between the opposite end device includes repeatedly performing the following steps to obtain the initial key pool:

[0040] 1) Modulate a bit of optical quantum based on a randomly selected polarization basis, and send the optical quantum to a third party E through a quantum channel; wherein the opposite end device is used to modulate a bit of optical quantum based on a randomly selected polarization basis, and send the optical quantum to a third party through a quantum channel.

[0041] 2) In the case that the third party gets a successful measurement result, and the polarization basis selected by the local device and the polarization basis selected by the opposite end are the same, the bit is reserved.

[0042] By repeatedly performing the above steps, the reserved multiple bits can be used as the initial key pool.

[0043] In the preparation of the quantum state, the key is encoded in the relative phase. In this embodiment, the local device and the opposite end device can randomly select a polarization basis x, y∈{0,1,...M-1} from multiple polarization bases, and modulate a corresponding bit of optical quantum a, b∈{0,1} to prepare a coherent state, and send the optical quantum to a third party through a quantum channel. In this embodiment, the local device and the opposite end device can use the polarization basis x=0(y=0) as the key basis, and use the x>=1(y>=1) basis as the test basis.

[0044] The third party receives the optical quantum sent by the local device and the opposite end device, after the quantum involvement of the 50:50 BS, guides the output pulse to two single photon detectors, and announces the Bell state measurement result z∈{Q + ,Q _ ,J}, J represents an erroneous measurement result. For a successful measurement result Q + or Q _, the local device and the opposite device can publish their selected polarization bases, and when they select the same polarization base x=y=v, they reserve the corresponding bits. In addition, if a third party announces the measurement result as Q _ The local device or the opposite device can flip his bits.

[0045] The above steps 1) and 2) can be repeatedly performed multiple times, and when the local device and the opposite device select the same polarization base y, the local device and the opposite device can also sacrifice part of the bits to estimate the success probability P y succ of the Bell state measurement, and the corresponding quantum bit error rate e y succ , where succ∈{Q + , Q _}, to improve the accuracy of the obtained secret key pool.

[0046] Optionally, the local device and the opposite device can also perform an error correction and privacy amplification step to extract a final initial secret key pool.

[0047] In any one of the above embodiments of the MDI-QKD method, the method further comprises: storing the initial secret key pool in an auxiliary security domain of a super SIM card in the local device, for subsequent encrypted communication, and thus the local device and the opposite device complete the transmission of the initial secret key pool.

[0048] The above MDI-QKD method, by combining the capabilities of MDI-QKD and super SIM cards, distributes a secret key pool as a generated secret key pool for each subsequent interaction encrypted secret key, improving the security of key distribution.

[0049] On the basis of any one of the above embodiments, after completing the distribution of the initial secret key pool, the method further comprises: the local device selecting an encrypted secret key from the initial secret key pool; encrypting plaintext data using the encrypted secret key to obtain a second ciphertext; and sending the second ciphertext and secret key description information of the encrypted secret key to the opposite device.

[0050] This embodiment is described from the perspective of the sender, and the following embodiment will be described from the perspective of the receiver.

[0051] On the basis of any one of the above embodiments, after completing the distribution of the initial secret key pool, the method further comprises: receiving a third ciphertext and secret key description information of an encrypted secret key of the third ciphertext; determining a decryption secret key based on the secret key description information and the initial secret key pool; and decrypting the third ciphertext based on the decryption secret key.

[0052] The key description information in the two embodiments can include: a starting position of a string in the initial key pool and a key length.

[0053] Optionally, in a case where all the keys in the initial key pool are used up, jumping to the step of obtaining the first hash value.

[0054] In a specific embodiment, a ciphertext sender (such as a local device) reads a required encryption key (PrivateKey) in sequence from a key pool in a super SIM card as a starting point with a random length as a key length, encrypts plaintext data, and records key description information: a starting position n and a key length l (the key string from n to l will be marked as not used); the ciphertext sender sends ciphertext + key description information (n, l) to a ciphertext receiver, and the ciphertext receiver reads a specified starting position n from the super SIM card according to the key description information and calculates a string from n to l as a decryption key (the key string from n to l will be marked as not used). This cycle continues until all the keys in the key pool are used up and are marked as not used, and then the initial key pool is redistributed.

[0055] Figure 5 A structure schematic diagram of an electronic device 500 provided by an embodiment of the present application is shown, the electronic device 500 is a local device, and includes the following modules.

[0056] The obtaining module 502 is configured to obtain a first hash value, the first hash value being obtained by performing a hash operation on a first randomly generated string.

[0057] The processing module 504 is configured to determine a transmission mode of an initial key pool from at least two transmission modes based on the first hash value and first information, wherein the first information includes at least one of a hardware value information of a super SIM card in the local device and a hardware value information of a super SIM card in a peer device.

[0058] The communication module 506 is configured to complete distribution of the initial key pool with the peer device based on the determined transmission mode.

[0059] In the embodiments of the present application, a first hash value is obtained by performing a hash operation on a first randomly generated string, and a transmission mode of an initial key pool is determined based on the first hash value and a hardware value information of a super SIM card. The transmission mode of the initial key pool is related to the hardware value information of the super SIM card and the randomly generated string, which is beneficial to increasing initial monitoring difficulty and improving security of key distribution.

[0060] In an embodiment, the determined transmission mode includes: an initial key pool distribution mode based on a super SIM card and quantum communication; or an MDI-QKD mode.

[0061] In one embodiment, the communication module 506 is configured to encrypt the first string using a public key of a super SIM card in the peer device to obtain first ciphertext, perform binary operation on the first ciphertext to obtain first bit data, and send the first bit data to the peer device using a single-photon signal; the peer device is further configured to decrypt the received second bit data using a private key of the super SIM card to obtain first decrypted data, perform hash operation on the first decrypted data to obtain a second hash value, and in a case where the second hash value is the same as the first hash value, take the first string as the initial secret key pool.

[0062] In one embodiment, the communication module 506 is further configured to receive second information from the peer device, and in a case where it is determined based on the second information that the second hash value is not the same as the first hash value, trigger the acquisition module 502.

[0063] In one embodiment, the communication module 506 is configured to repeatedly perform the following steps to obtain the initial secret key pool: modulate a bit of light quantum based on a randomly selected polarization basis, and send the light quantum to a third party through a quantum channel; the peer device is configured to modulate a bit of light quantum based on a randomly selected polarization basis, and send the light quantum to the third party through a quantum channel; in a case where it is determined that the third party obtains a successful measurement result and the polarization basis selected by the local device is the same as the polarization basis selected by the peer, the bit is retained.

[0064] In one embodiment, the processing module 504 is configured to store the initial secret key pool in an auxiliary security domain of a super SIM card in the local device.

[0065] In one embodiment, the communication module 506 is further configured to select an encryption key from the initial secret key pool, encrypt plaintext data using the encryption key to obtain second ciphertext, and send the second ciphertext and key description information of the encryption key to the peer device.

[0066] In one embodiment, the communication module 506 is further configured to receive third ciphertext and key description information of an encryption key of the third ciphertext, determine a decryption key based on the key description information and the initial secret key pool, and decrypt the third ciphertext based on the decryption key.

[0067] In one embodiment, the key description information includes a starting position of a string in the initial secret key pool and a key length.

[0068] In one embodiment, the communication module 506 is further configured to trigger the obtaining module 502 when all the keys in the initial key pool are used up.

[0069] The electronic device 500 provided by the embodiments of the present application can execute any of the embodiments of the foregoing method embodiments, and achieve the functions and beneficial effects of any of the embodiments of the foregoing method embodiments, which will not be described herein again.

[0070] The modules in the electronic device provided by the embodiments of the present application can also implement the method steps provided by the foregoing method embodiments. Alternatively, the electronic device provided by the embodiments of the present application can further include other modules in addition to the foregoing modules to implement the method steps provided by the foregoing method embodiments. The electronic device provided by the embodiments of the present application can achieve the technical effects achieved by the foregoing method embodiments.

[0071] The embodiments of the present application further provide an electronic device including a processor, a memory, and a computer program stored in the memory and executable on the processor. When the computer program is executed by the processor, the computer program implements the processes of the foregoing key distribution embodiments and achieves the same technical effects. To avoid repetition, the foregoing will not be described herein again.

[0072] Figure 6 A hardware structure schematic diagram of an electronic device executing the embodiments of the present application is shown. Referring to the diagram, at the hardware level, the electronic device includes a processor, and can further include an internal bus, a network interface, and a memory. The memory can include a memory such as a high-speed random access memory (RAM), and can further include a non-volatile memory such as at least one disk memory. Of course, the electronic device can further include other hardware required by a business.

[0073] The processor, the network interface, and the memory can be connected to each other through the internal bus. The internal bus can be an Industry Standard Architecture (ISA) bus, a Peripheral Component Interconnect (PCI) bus, or an Extended Industry Standard Architecture (EISA) bus, etc. The bus can be divided into an address bus, a data bus, a control bus, etc. For the convenience of representation, only one bidirectional arrow is used in the diagram, but it does not mean that there is only one bus or only one type of bus.

[0074] The memory is configured to store a program. Specifically, the program can include program code including computer operation instructions. The memory can include an internal memory and a non-volatile memory, and provide instructions and data for the processor.

[0075] The processor reads the corresponding computer program from the non-volatile memory into the internal memory and then runs, and forms the device for locating the target user at a logical level. The processor executes the program stored in the memory, and is specifically configured to execute: Figures 1-4 The method disclosed in the embodiments shown above and the functions and advantages of the method disclosed in the foregoing method embodiments are not repeated here.

[0076] The above as described in the present application Figures 1-4 The method disclosed in the embodiments shown above can be applied to a processor or implemented by the processor. The processor can be an integrated circuit chip having a processing capability of signals. In the implementation process, each step of the above method can be completed by an integrated logic circuit of hardware in the processor or an instruction in the form of software. The processor described above can be a general processor including a central processing unit (CPU), a network processor (NP), etc., and can also be a digital signal processor (DSP), an application specific integrated circuit (ASIC), a field-programmable gate array (FPGA) or other programmable logic devices, discrete gate or transistor logic devices, discrete hardware components. Each method, step and logic block diagram disclosed in the embodiments of the present application can be implemented or executed. The general processor can be a microprocessor or the processor can also be any conventional processor. The steps of the method disclosed in combination with the embodiments of the present application can be directly embodied as a hardware code processor for execution, or a combination of hardware and software modules in the code processor for execution. The software module can be located in a random access memory, a flash memory, a read-only memory, a programmable read-only memory or an electrically erasable programmable memory, a register, etc. The storage medium is located in the memory, and the processor reads the information in the memory and combines the hardware to complete the steps of the above method.

[0077] The electronic device can also execute any of the foregoing method embodiments and achieve the functions and advantages of any of the foregoing method embodiments, which are not repeated here.

[0078] Of course, in addition to the software implementation, the electronic device of the present application does not exclude other implementation manners, such as a logic device or a combination of software and hardware, and the like, that is, the execution subject of the following processing flow is not limited to the logical unit, but can also be hardware or a logic device.

[0079] The embodiment of the present application further provides a computer readable storage medium, and the computer readable storage medium stores a computer program. The computer program is executed by a processor to realize each process of the key distribution method embodiment and achieve the same technical effects. To avoid repetition, details are not described herein. The computer readable storage medium includes a read-only memory (ROM), a random access memory (RAM), a magnetic disk or an optical disk, and the like.

[0080] The embodiment of the present application further provides a computer program product, which includes a non-transitory computer readable storage medium storing a computer program. The computer program is operable to cause a computer to perform some or all of the steps of the key distribution method embodiment and achieve the same technical effects. To avoid repetition, details are not described herein.

[0081] Those skilled in the art should understand that the embodiments of the present application can be provided as a method, a system, or a computer program product. Therefore, the present application can be in the form of an entirely hardware embodiment, an entirely software embodiment, or an embodiment combining software and hardware aspects. Moreover, the present application can be in the form of a computer program product implemented on one or more computer-usable storage media (including, but not limited to, a disk memory, a CD-ROM, an optical memory, and the like) containing computer-usable program code.

[0082] The present application is described with reference to flowcharts and / or block diagrams according to the method, device (system), and computer program product of the embodiments of the present application. It should be understood that each flow and / or block in the flowcharts and / or block diagrams, and the combination of the flows and / or blocks in the flowcharts and / or block diagrams can be implemented by computer program instructions. These computer program instructions can be provided to a general-purpose computer, a special-purpose computer, an embedded processor, or other programmable data processing devices to produce a machine, so that the instructions executed by the computer or other programmable data processing devices produce a device that implements the functions specified in the flowcharts and / or block diagrams. Figure 1 The function of one flow or multiple flows and / or blocks Figure 1 The function of one block or multiple blocks.

[0083] These computer program instructions can also be stored in a computer- readable memory that can direct a computer or other programmable data processing apparatus to function in a particular manner, such that the instructions stored in the computer-readable memory produce an article of manufacture including instructions which implement the Figure 1 function specified in the flow or flows and / or blocks Figure 1 of the block or blocks.

[0084] These computer program instructions can also be loaded onto a computer or other programmable data processing apparatus to cause a series of operational steps to be performed on the computer or other programmable apparatus to produce a computer implemented process such that the instructions that are executed on the computer or other programmable apparatus provide steps for implementing the Figure 1 function specified in the flow or flows and / or blocks Figure 1 of the block or blocks.

[0085] In a typical configuration, a computing device includes one or more processors (CPUs), input / output interfaces, network interfaces, and memory.

[0086] The memory can include non-persistent memory and / or volatile memory, such as random access memory (RAM) and / or cache memory, non-volatile memory, such as read-only memory (ROM), EPROM, and / or flash memory, etc. The memory is an example of computer readable media.

[0087] Computer readable media includes permanent and non-permanent, removable and non-removable media implemented in any method or technology for storage of information such as computer readable instructions, data structures, program modules or other data. Examples of computer storage media include, but are not limited to, phase change memory (PRAM), static random access memory (SRAM), dynamic random access memory (DRAM), other types of random access memory (RAM), read-only memory (ROM), electrically erasable programmable read-only memory (EEPROM), flash memory or other memory technology, compact disc read-only memory (CD-ROM), digital versatile disc (DVD), or other optical storage, magnetic cassettes, magnetic tapes, magnetic disk storage or other magnetic storage devices, or any other non-transmission medium that can be used to store information accessible to computing devices. According to the definition herein, computer readable media does not include transitory media, such as modulated data signals and carrier waves.

[0088] It is also to be noted that the terms "comprising", "including", and any other variation thereof, are intended to cover a non-exclusive inclusion, such that a process, method, article, or apparatus that comprises a list of elements does not include only those elements but can include other elements not expressly listed or inherent to such process, method, article, or apparatus. An element proceeded by "comprises a... " does not, without more constraints, exclude the existence of additional identical elements in the process, method, article, or apparatus that comprises the recited element.

[0089] Those skilled in the art will appreciate that embodiments of the present application can be devised for a method, a system, or a computer program product. Accordingly, the present application can take the form of an entirely hardware embodiment, an entirely software embodiment or an embodiment combining software and hardware aspects. Furthermore, the present application can take the form of a computer program product on one or more computer-usable storage media (including, but not limited to, disk storage, CD-ROMs, optical storage devices, etc.) embodying computer-readable program code.

[0090] The embodiments of the present application described above are only used to explain the technical solutions of the present application and not to limit the present application. Although the present application has been described in detail, those skilled in the art will understand that the present application can make various modifications and changes without departing from the spirit and scope of the present application. Any modification, equivalent replacement, improvement, etc. made within the spirit and principle of the present application shall be included in the scope of the claims of the present application.

Claims

1. A key distribution method characterized by comprising: The method is applied to a local device, and comprises: obtaining a first hash value, the first hash value being obtained by performing a hash operation on a first string randomly generated; determining a transmission mode of an initial secret key pool from at least two transmission modes based on the first hash value and first information, wherein the first information comprises at least one of a hardware value of a super SIM card in the local device and a hardware value of a super SIM card in a peer device; distributing the initial secret key pool to the peer device based on the determined transmission mode.

2. The method of claim 1, wherein, The determined transmission mode comprises: an initial secret key pool distribution mode based on a super SIM card and quantum communication; or a measurement device independent quantum key distribution (MDI-QKD) mode.

3. The method of claim 2, wherein, The distributing the initial secret key pool to the peer device based on the determined transmission mode comprises: encrypting the first string using a public key of the super SIM card in the peer device to obtain first ciphertext; performing a binary operation on the first ciphertext to obtain first bit data, and sending the first bit data to the peer device using a single-photon signal; wherein the peer device is further configured to decrypt second bit data received using a private key of the super SIM card to obtain first decryption data, perform a hash operation on the first decryption data to obtain second hash value, and in a case where the second hash value is the same as the first hash value, use the first string as the initial secret key pool.

4. The method of claim 3, wherein, The method further comprises: receiving second information from the peer device; in a case where it is determined based on the second information that the second hash value is not the same as the first hash value, jumping to the step of obtaining the first hash value.

5. The method of claim 2, wherein, The distributing the initial secret key pool to the peer device based on the determined transmission mode comprises: repeatedly performing the following steps to obtain the initial secret key pool: modulating a bit of optical quantum based on a randomly selected polarization basis, and sending the optical quantum to a third party through a quantum channel, wherein the peer device is configured to modulate a bit of optical quantum based on a randomly selected polarization basis, and send the optical quantum to a third party through a quantum channel; in a case where it is determined that the third party obtains a successful measurement result, and the polarization basis selected by the local device is the same as the polarization basis selected by the peer device, retaining the bit.

6. The method according to any one of claims 1 to 5, characterized in that, The method further comprises: storing the initial secret key pool in an auxiliary security domain of the super SIM card in the local device.

7. The method of claim 1, wherein, The method further comprises: selecting an encryption secret key from the initial secret key pool; encrypting plaintext data using the encryption secret key to obtain second ciphertext; sending the second ciphertext and secret key description information of the encryption secret key to the peer device.

8. The method of claim 1, wherein, The method further comprises: receiving third ciphertext and secret key description information of an encryption secret key of the third ciphertext; determining a decryption secret key based on the secret key description information and the initial secret key pool; decrypting the third ciphertext based on the decryption secret key.

9. The method according to claim 7 or 8, characterized in that, The secret key description information comprises a starting position of a string in the initial secret key pool and a secret key length.

10. The method of claim 9, wherein, In a case where the keys in the initial key pool are all used up, jumping to the step of obtaining the first hash value.

11. An electronic device, comprising: The electronic device is a local device, comprising: an obtaining module, configured to obtain a first hash value, the first hash value being obtained by performing a hash operation on a first string randomly generated; a processing module, configured to determine a transmission mode of an initial key pool from at least two transmission modes based on the first hash value and first information, wherein the first information comprises at least one of a hardware value information of a super SIM card in the local device and a hardware value information of a super SIM card in a peer device; a communication module, configured to complete distribution of the initial key pool with the peer device based on the determined transmission mode.

12. An electronic device, comprising: a processor, a memory, and a computer program stored on the memory and executable on the processor, the computer program, when executed by the processor, implements the steps of the method according to any one of claims 1-10.

13. A computer readable storage medium, the computer readable storage medium storing a computer program, the computer program, when executed by a processor, implements the steps of the method according to any one of claims 1-10.

Citation Information

Patent Citations

  • 5G AKA protocol security enhancement system for Tarmarin analysis security

    CN113541936A

  • Payment medium opening method and device, equipment and storage medium

    CN117078247A