User roaming method, device, system, electronic device and computer storage medium

The user's charging location and target quantum cryptography service node are determined through the quantum cryptography service management platform, and a target charging key distribution request is sent, which solves the security and network transmission performance issues when the user terminal moves across domains and realizes the establishment of a secure connection.

CN119277370BActive Publication Date: 2025-09-19CHINA TELECOM QUANTUM TECH CO LTD
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202411560751.9
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2024-11-04
Publication Date
2025-09-19
Estimated Expiration
2044-11-04

AI Technical Summary

Technical Problem

When a user terminal moves across security domains, the network transmission performance in the key transmission process in the prior art is degraded and the link security is insufficient, especially when the terminal device is connected to the original security domain via a secure medium.

Method used

The quantum cryptography service management platform obtains the query request of the user terminal, determines the user charging location and the nearest target quantum cryptography service node, and sends a target charging key distribution request to the original quantum cryptography service node to ensure that the target quantum cryptography service node verifies the identity of the user terminal.

Benefits of technology

When the user terminal moves across domains, security and network transmission performance are guaranteed. The user terminal is verified through the target quantum cryptography service node to ensure the establishment of a secure connection.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN119277370B_ABST
    Figure CN119277370B_ABST
Patent Text Reader

Abstract

Embodiments of the present invention provide a user roaming method, apparatus, electronic device, and computer-readable storage medium, relating to the field of quantum communication technology. The method comprises: obtaining a query request sent by a user terminal for querying routing information; determining, based on the query request, the user charging location corresponding to the user terminal and the target quantum cryptography service node closest to the user terminal; if the original quantum cryptography service node corresponding to the user charging location is different from the target quantum cryptography service node, sending a target charging key distribution request to the original quantum cryptography service node; and sending first node information of the target quantum cryptography service node to the user terminal. Embodiments of the present invention ensure the security of cross-domain mobility of user terminals.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the field of quantum communication technology, and in particular to a user roaming method, a user roaming device, a user roaming system, an electronic device and a computer-readable storage medium. Background Art

[0002] Using secure media with pre-charged keys, and then using these pre-charged keys to protect working keys, can secure data transmission for VoIP, Volt, satellite calls, official documents, and other applications. When a user moves a terminal device using secure media across security domains, if the terminal device remains connected to the original security domain via the secure media, network transmission performance during key transmission will be reduced. Furthermore, if the transmission link is too long, the overall link security will be compromised. Summary of the Invention

[0003] In view of the above problems, embodiments of the present invention are proposed to provide a user roaming method, a user roaming device, a user roaming system, an electronic device and a computer-readable storage medium that overcome the above problems or at least partially solve the above problems.

[0004] In order to solve the above problem, an embodiment of the present invention discloses a user roaming method, which includes:

[0005] Obtaining a query request sent by a user terminal for querying routing information;

[0006] Determining, based on the query request, a user charging location corresponding to the user terminal and a target quantum cryptography service node closest to the user terminal;

[0007] If the original quantum cryptography service node corresponding to the user charging location is different from the target quantum cryptography service node, sending a target charging key distribution request to the original quantum cryptography service node, so that the original quantum cryptography service node responds to the target charging key distribution request and sends the target charging key to the target quantum cryptography service node;

[0008] The first node information of the target quantum cryptography service node is sent to the user terminal, so that when the user terminal establishes a connection with the target quantum cryptography service node based on the first node information, the target quantum cryptography service node verifies the user terminal based on the target charging key.

[0009] In one or more embodiments, determining the user charging location corresponding to the user terminal and the target quantum cryptography service node closest to the user terminal based on the query request includes:

[0010] Using the terminal information of the user terminal in the query request to query, obtain the user charging location corresponding to the user terminal;

[0011] The address information in the query request is used to query to obtain the target quantum cryptography service node closest to the user terminal.

[0012] In one or more embodiments, sending a target injection key distribution request to the original quantum cryptography service node includes:

[0013] Sending a target key injection distribution request directly to the original quantum cryptography service node;

[0014] or,

[0015] The second node information of the original quantum cryptography service node is sent to the user terminal, so that the user terminal uses the second node information to send a target injection key distribution request to the original quantum cryptography service node.

[0016] In one or more embodiments, the original quantum cryptography service node responds to the target injection key distribution request by obtaining relay routing information of the quantum network and sending the target injection key to the quantum key distribution node corresponding to the target quantum cryptography service node through the corresponding quantum key distribution node according to the relay routing information.

[0017] In one or more embodiments, the target charging key is a full charging key or a partial charging key of a complete charging key.

[0018] Accordingly, an embodiment of the present invention discloses a user roaming device, the device comprising:

[0019] An acquisition module, configured to acquire a query request sent by a user terminal for querying routing information;

[0020] a determination module, configured to determine, based on the query request, a user charging location corresponding to the user terminal and a target quantum cryptography service node closest to the user terminal;

[0021] a sending module, configured to send a target charging key distribution request to the original quantum cryptography service node if the original quantum cryptography service node corresponding to the user charging location is different from the target quantum cryptography service node, so that the original quantum cryptography service node responds to the target charging key distribution request and sends the target charging key to the target quantum cryptography service node;

[0022] The sending module is further configured to send the first node information of the target quantum cryptography service node to the user terminal, so that when the user terminal establishes a connection with the target quantum cryptography service node based on the first node information, the target quantum cryptography service node verifies the user terminal based on the target charging key.

[0023] In one or more embodiments, the determining module is specifically configured to:

[0024] Using the terminal information of the user terminal in the query request to query, obtain the user charging location corresponding to the user terminal;

[0025] The address information in the query request is used to query to obtain the target quantum cryptography service node closest to the user terminal.

[0026] In one or more embodiments, the sending module is specifically configured to:

[0027] Sending a target key injection distribution request directly to the original quantum cryptography service node;

[0028] or,

[0029] The second node information of the original quantum cryptography service node is sent to the user terminal, so that the user terminal uses the second node information to send a target injection key distribution request to the original quantum cryptography service node.

[0030] In one or more embodiments, the original quantum cryptography service node responds to the target injection key distribution request by obtaining relay routing information of the quantum network and sending the target injection key to the quantum key distribution node corresponding to the target quantum cryptography service node through the corresponding quantum key distribution node according to the relay routing information.

[0031] In one or more embodiments, the target charging key is a full charging key or a partial charging key of a complete charging key.

[0032] Accordingly, an embodiment of the present invention discloses a user roaming system, which includes a user terminal, a quantum cryptography service management platform, an original quantum cryptography service node, and a target quantum cryptography service node;

[0033] The user terminal sends a query request for querying routing information to the quantum cryptography service management platform;

[0034] The quantum cryptography service management platform obtains a query request for querying routing information sent by a user terminal;

[0035] If the original quantum cryptography service node corresponding to the user charging location is different from the target quantum cryptography service node, the quantum cryptography service management platform or the user terminal sends a target charging key distribution request to the original quantum cryptography service node;

[0036] The original quantum cryptography service node sends the target charging key to the target quantum cryptography service node in response to the target charging key distribution request;

[0037] The quantum cryptography service management platform sends the first node information of the target quantum cryptography service node to the user terminal;

[0038] When the user terminal establishes a connection with the target quantum cryptography service node based on the first node information, the target quantum cryptography service node verifies the user terminal based on the target charging key.

[0039] Accordingly, an embodiment of the present invention discloses an electronic device, comprising: a processor, a memory, and a computer program stored in the memory and capable of running on the processor. When the computer program is executed by the processor, the various steps of the above-mentioned user roaming method embodiment are implemented.

[0040] Accordingly, an embodiment of the present invention discloses a computer-readable storage medium, on which a computer program is stored. When the computer program is executed by a processor, each step of the above-mentioned user roaming method embodiment is implemented.

[0041] The embodiments of the present invention include the following advantages:

[0042] After obtaining a query request for querying routing information sent by a user terminal, the quantum cryptography service management platform may determine, based on the query request, a user charging location corresponding to the user terminal and a target quantum cryptography service node closest to the user terminal; if the original quantum cryptography service node corresponding to the user charging location is different from the target quantum cryptography service node, a target charging key distribution request is sent to the original quantum cryptography service node, so that the original quantum cryptography service node responds to the target charging key distribution request and sends the target charging key to the target quantum cryptography service node; and then the first node information of the target quantum cryptography service node is sent to the user terminal, so that when the user terminal establishes a connection with the target quantum cryptography service node based on the first node information, the target quantum cryptography service node verifies the user terminal based on the target charging key. In this way, when the user terminal moves across domains, causing the quantum cryptography service node that the user terminal needs to connect to be different from the quantum cryptography service node corresponding to the user's charging location, the quantum cryptography service node corresponding to the user's charging location can be notified to send the charging key to the quantum cryptography service node that the user terminal needs to connect to. When the user terminal successfully establishes a connection with the quantum cryptography service node that needs to be connected, the quantum cryptography service node that needs to be connected can use the charging key to verify the user terminal, thereby ensuring the security of the user terminal's cross-domain movement. BRIEF DESCRIPTION OF THE DRAWINGS

[0043] Figure 1 is a flowchart of steps of an embodiment of a user roaming method of the present invention;

[0044] Figure 2 is a schematic diagram of the architecture of the user roaming system of the present invention;

[0045] Figure 3 It is a structural block diagram of an embodiment of a user roaming device of the present invention. DETAILED DESCRIPTION

[0046] In order to make the above-mentioned objects, features and advantages of the present invention more obvious and easy to understand, the present invention is further described in detail below with reference to the accompanying drawings and specific embodiments.

[0047] One of the core concepts of the embodiments of the present invention is that when a user terminal moves across domains, resulting in the quantum cryptography service node that the user terminal needs to connect to being different from the quantum cryptography service node corresponding to the user's charging location, the quantum cryptography service node corresponding to the user's charging location can be notified to send the charging key to the quantum cryptography service node that the user terminal needs to connect to. When the user terminal successfully establishes a connection with the quantum cryptography service node to be connected, the quantum cryptography service node to be connected can use the charging key to verify the user terminal, thereby ensuring the security of the user terminal's cross-domain movement.

[0048] Reference Figure 1 , shows a step flow chart of an embodiment of a user roaming method of the present invention. The method can be applied to a quantum cryptography service management platform, and the quantum cryptography service management platform can be deployed in a user roaming system.

[0049] Reference Figure 2 , shows a schematic diagram of the user roaming system architecture. Specifically, the user roaming system may include user terminals, a quantum cryptography service management platform, quantum cryptography service nodes, and QKD (Quantum Key Distribution) nodes.

[0050] The quantum cryptography service management platform includes all quantum cryptography service node data and user data. All built and deployed quantum cryptography service nodes will be registered in the quantum cryptography service management platform, and quantum cryptography service nodes and the quantum cryptography service management platform will have a one-way connection.

[0051] Quantum cryptography service nodes provide encryption keys and identity authentication functions.

[0052] QKD is a secure method for transmitting keys between two distant communication endpoints. During confidential communication, keys are required to encrypt and decrypt information, and the security of the keys ensures the security of the information. Existing quantum key distribution systems primarily use the BB84 protocol, proposed by Bennett and Brassard in 1984. Unlike classical cryptography, the security of quantum key distribution is based on the fundamental principles of quantum mechanics. Even if an eavesdropper controls the channel, as long as the eavesdropper lacks the ability to break into the legitimate user's device, quantum key distribution technology allows spatially separated users to share secure keys. Academics refer to this type of security as "information-theoretic security" (also known as "unconditional security"), which refers to security that is rigorously mathematically proven.

[0053] Since its introduction in 1984, QKD technology has been researched for over 30 years and has yielded fruitful results. From the initial BB84 protocol, which encodes photon polarization or phase in discrete variables, to the E91 protocol based on entangled light sources, the DPS and COW phase-distributed reference protocols, to continuous variable QKD protocols and measurement device-independent (MDI-QKD) protocols, continuous progress has been made in both theory and experiment. Furthermore, the global rollout of commercial QKD systems, the establishment of QKD networks, and the research into QKD applications all signal the advancement of QKD technology toward practical application.

[0054] Unlike existing cryptographic technologies, QKD's security is based on physical principles. Its fundamental approach is to use quantum states to encode information, securely distributing random numbers—the keys—through the preparation, transmission, and detection of these quantum states. The specific methods for encoding, transmitting, and measuring quantum states are known as the QKD protocol. The security of the QKD protocol is based on the following principles of quantum physics:

[0055] A single quantum is indivisible. A quantum is the smallest unit of change in a physical quantity, and a single quantum is indivisible. If quantum key distribution uses a single quantum (usually a single photon) as an information carrier, an attacker cannot obtain key information by stealing a portion of a single quantum and measuring its state.

[0056] Unknown single quantum states cannot be precisely measured. According to the Heisenberg uncertainty principle, a pair of non-commutative quantum quantities cannot be simultaneously measured accurately. An eavesdropper might wish to intercept a single photon, measure its state, and then send a new photon to the receiver based on the measurement result. However, due to the Heisenberg uncertainty principle, the eavesdropper cannot accurately measure the state of the intercepted photon, and the retransmitted photon will be inconsistent with the original photon. Therefore, the sender and receiver can detect the eavesdropper's measurement of the photon, thereby verifying the security of the key established between them.

[0057] Unknown single quantum states cannot be precisely replicated. An eavesdropper might hope to intercept a single photon and then replicate it to eavesdrop, but the no-cloning principle of quantum mechanics ensures that unknown quantum states cannot be precisely replicated.

[0058] The security of quantum key distribution (QKD) is based on the fundamental principles of quantum mechanics, as described above. It does not rely on computational complexity requirements or assumptions, and its security and theoretical completeness are fully guaranteed. Even when quantum computing technology matures, its key distribution process remains reliably secure. Quantum key distribution can effectively address the serious threats to traditional cryptographic systems posed by the rapid development of computing technology and quantum computing.

[0059] QKD nodes can be based on internationally accepted quantum key distribution protocols such as the BB84 protocol and BBM92, allowing both communicating parties to generate and share a random, secure key for encrypting and decrypting messages.

[0060] Furthermore, an access routing service can be deployed within the quantum cryptography service management platform, and the access routing service is used to query routing information. Of course, the access routing service can also be deployed independently of the quantum cryptography service management platform. In this embodiment of the present invention, the deployment of the access routing service within the quantum cryptography service management platform is used as an example for illustration. In actual applications, the deployment method of the access routing service can be adjusted based on actual needs, and this embodiment of the present invention does not impose any restrictions on this.

[0061] The specific steps may include:

[0062] Step 101: Obtain a query request for querying routing information sent by a user terminal.

[0063] Specifically, when a user terminal establishes a connection with a quantum cryptography service node, it can initiate a query request to the access routing service to query the user terminal's routing information. In other words, the access routing service in the quantum cryptography management service management platform can obtain query requests initiated by user terminals in real time.

[0064] Step 102: Determine, based on the query request, a user charging location corresponding to the user terminal and a target quantum cryptography service node closest to the user terminal.

[0065] Since the quantum cryptography service management platform includes all quantum cryptography service node data and user data, after obtaining the query request, the user charging location corresponding to the user terminal can be determined according to the query request (the user charging location belongs to "user data"), as well as the quantum cryptography service node closest to the user terminal (the quantum cryptography service node belongs to "quantum cryptography service node data"; for easy distinction, it is recorded as "target quantum cryptography service node").

[0066] In an embodiment of the present invention, determining the user charging location corresponding to the user terminal and the target quantum cryptography service node closest to the user terminal based on the query request includes:

[0067] Using the terminal information of the user terminal in the query request to query, obtain the user charging location corresponding to the user terminal;

[0068] The address information in the query request is used to query to obtain the target quantum cryptography service node closest to the user terminal.

[0069] Specifically, since the query request can include the terminal information of the user terminal, after obtaining the query request, the quantum cryptography service management platform can query the user data according to the terminal information to obtain the user charging address corresponding to the user terminal.

[0070] Furthermore, the query request can also include the address information of the query request, such as the IP (Internet Protocol) address. In this way, after obtaining the query request, the quantum cryptography service management platform can also query the quantum cryptography service node data according to the address information to obtain the target quantum cryptography service node closest to the user terminal.

[0071] Step 103: If the original quantum cryptography service node corresponding to the user charging location is different from the target quantum cryptography service node, a target charging key distribution request is sent to the original quantum cryptography service node, so that the original quantum cryptography service node responds to the target charging key distribution request and sends the target charging key to the quantum key distribution node corresponding to the target quantum cryptography service node through the corresponding quantum key distribution node.

[0072] After determining the user charging location and the target quantum cryptography service node, the quantum cryptography service management platform can detect whether the quantum cryptography service node corresponding to the user charging location (referred to as the "original quantum cryptography service node") is the same as the target quantum cryptography service node.

[0073] If the two are not the same, a distribution request for the target charging key can be sent to the original quantum cryptography service node. After receiving the target charging key distribution request, the original quantum cryptography service node sends the target charging key of the user terminal through the corresponding quantum key distribution node (referred to as the "original quantum key distribution node") to the quantum key distribution node corresponding to the target quantum cryptography service node (referred to as the "target quantum key distribution node"). The target quantum cryptography service node can then obtain the target charging key from the target quantum key distribution node.

[0074] In an embodiment of the present invention, the sending of the target injection key distribution request to the original quantum cryptography service node includes:

[0075] Sending a target key injection distribution request directly to the original quantum cryptography service node;

[0076] or,

[0077] The second node information of the original quantum cryptography service node is sent to the user terminal, so that the user terminal uses the second node information to send a target injection key distribution request to the original quantum cryptography service node.

[0078] Specifically, the quantum cryptography service management platform can send a target injection key distribution request directly to the original quantum cryptography service node through the access routing service.

[0079] The quantum cryptography service management platform can also send the node information of the original quantum cryptography service node (recorded as "second node information") to the user terminal through the access routing service. After the user terminal obtains the second node information, it indicates that the original quantum cryptography service node is different from the target quantum cryptography service node. At this time, the user terminal can use the second node information to send a target injection key distribution request to the original quantum cryptography service node.

[0080] Furthermore, the user terminal can be equipped with quantum-safe middleware, which handles key reading and data encryption on the quantum-safe chip, as well as interaction with the quantum cryptography management service system. Based on this, the user terminal can use the quantum-safe middleware to send a target-filled key distribution request. Of course, the user terminal can also use other methods to send the target-filled key distribution request to the original quantum cryptography service node. In actual applications, the specific sending method can be configured based on actual needs and is not limited in this embodiment of the present invention.

[0081] Furthermore, after obtaining the target injection key distribution request, the original quantum cryptography service node can obtain the relay routing information of the quantum network, and then send the target injection key to the target quantum cryptography service node according to the relay routing information.

[0082] It should be noted that the target charging key can be the entire charging key of a complete charging key, or a partial charging key of a complete charging key. That is, in embodiments of the present invention, whether to obtain the complete charging key can be determined based on actual needs. For example, when the quantum network bandwidth is low, the partial charging key for verification can be obtained from the complete charging key. When the quantum network bandwidth is high, the complete charging key can be obtained. In practical applications, whether to obtain the complete charging key can be determined based on actual needs, and embodiments of the present invention do not impose any restrictions on this.

[0083] Step 104: Send the first node information of the target quantum cryptography service node to the user terminal, so that when the user terminal establishes a connection with the target quantum cryptography service node based on the first node information, the target quantum cryptography service node verifies the user terminal based on the target charging key.

[0084] After determining the target quantum cryptography service node, the quantum cryptography service management platform can send the node information of the target quantum cryptography service node (recorded as "first node information") to the user terminal.

[0085] After obtaining the first node information, the user terminal can use the first node information to establish a connection with the target quantum cryptography service node. When the connection is successfully established, the target quantum cryptography service node can use the target injection key to authenticate the user terminal.

[0086] In an embodiment of the present invention, after obtaining a query request for querying routing information sent by a user terminal, the quantum cryptography service management platform may determine, based on the query request, a user charging location corresponding to the user terminal and a target quantum cryptography service node closest to the user terminal; if the original quantum cryptography service node corresponding to the user charging location is different from the target quantum cryptography service node, a target charging key distribution request is sent to the original quantum cryptography service node, so that the original quantum cryptography service node responds to the target charging key distribution request and sends the target charging key to the target quantum cryptography service node; and then the first node information of the target quantum cryptography service node is sent to the user terminal, so that when the user terminal establishes a connection with the target quantum cryptography service node based on the first node information, the target quantum cryptography service node verifies the user terminal based on the target charging key. In this way, when the user terminal moves across domains, causing the quantum cryptography service node that the user terminal needs to connect to be different from the quantum cryptography service node corresponding to the user's charging location, the quantum cryptography service node corresponding to the user's charging location can be notified to send the charging key to the quantum cryptography service node that the user terminal needs to connect to. When the user terminal successfully establishes a connection with the quantum cryptography service node that needs to be connected, the quantum cryptography service node that needs to be connected can use the charging key to verify the user terminal, thereby ensuring the security of the user terminal's cross-domain movement.

[0087] It should be noted that for the sake of simplicity, the method embodiments are described as a series of actions. However, those skilled in the art should be aware that the embodiments of the present invention are not limited by the order of the actions described, because according to the embodiments of the present invention, certain steps can be performed in other orders or simultaneously. Secondly, those skilled in the art should also be aware that the embodiments described in this specification are all preferred embodiments, and the actions involved are not necessarily required by the embodiments of the present invention.

[0088] Reference Figure 3 , shows a structural block diagram of an embodiment of a user roaming device of the present invention, which may specifically include the following modules:

[0089] An acquisition module 301 is configured to acquire a query request sent by a user terminal for querying routing information;

[0090] A determination module 302 is configured to determine, based on the query request, a user charging location corresponding to the user terminal and a target quantum cryptography service node closest to the user terminal;

[0091] The sending module 303 is configured to send a target charging key distribution request to the original quantum cryptography service node if the original quantum cryptography service node corresponding to the user charging location is different from the target quantum cryptography service node, so that the original quantum cryptography service node responds to the target charging key distribution request and sends the target charging key to the target quantum cryptography service node;

[0092] The sending module is further configured to send the first node information of the target quantum cryptography service node to the user terminal, so that when the user terminal establishes a connection with the target quantum cryptography service node based on the first node information, the target quantum cryptography service node verifies the user terminal based on the target charging key.

[0093] In an embodiment of the present invention, the determining module is specifically configured to:

[0094] Using the terminal information of the user terminal in the query request to query, obtain the user charging location corresponding to the user terminal;

[0095] The address information in the query request is used to query to obtain the target quantum cryptography service node closest to the user terminal.

[0096] In the embodiment of the present invention, the sending module is specifically configured to:

[0097] Sending a target key injection distribution request directly to the original quantum cryptography service node;

[0098] or,

[0099] The second node information of the original quantum cryptography service node is sent to the user terminal, so that the user terminal uses the second node information to send a target injection key distribution request to the original quantum cryptography service node.

[0100] In an embodiment of the present invention, the original quantum cryptography service node responds to the target charging key distribution request by obtaining relay routing information of the quantum network and sends the target charging key to the target quantum cryptography service node according to the relay routing information.

[0101] In an embodiment of the present invention, the target charging key is the entire charging key or a partial charging key of a complete charging key.

[0102] As for the device embodiment, since it is basically similar to the method embodiment, the description is relatively simple, and the relevant parts can be referred to the partial description of the method embodiment.

[0103] An embodiment of the present invention further provides a user roaming system, which includes a user terminal, a quantum cryptography service management platform, an original quantum cryptography service node, and a target quantum cryptography service node;

[0104] The user terminal sends a query request for querying routing information to the quantum cryptography service management platform;

[0105] The quantum cryptography service management platform obtains a query request for querying routing information sent by a user terminal;

[0106] If the original quantum cryptography service node corresponding to the user charging location is different from the target quantum cryptography service node, the quantum cryptography service management platform or the user terminal sends a target charging key distribution request to the original quantum cryptography service node;

[0107] The original quantum cryptography service node sends the target charging key to the target quantum cryptography service node in response to the target charging key distribution request;

[0108] The quantum cryptography service management platform sends the first node information of the target quantum cryptography service node to the user terminal;

[0109] When the user terminal establishes a connection with the target quantum cryptography service node based on the first node information, the target quantum cryptography service node verifies the user terminal based on the target charging key.

[0110] Specifically, when a user terminal establishes a connection with a quantum cryptography service node, it can initiate a query request to the access routing service to query the user terminal's routing information. In other words, the access routing service in the quantum cryptography management service management platform can obtain query requests initiated by user terminals in real time.

[0111] Since the quantum cryptography service management platform includes all quantum cryptography service node data and user data, after obtaining the query request, the user charging location corresponding to the user terminal can be determined according to the query request (the user charging location belongs to "user data"), as well as the quantum cryptography service node closest to the user terminal (the quantum cryptography service node belongs to "quantum cryptography service node data"; for easy distinction, it is recorded as "target quantum cryptography service node").

[0112] In an embodiment of the present invention, determining the user charging location corresponding to the user terminal and the target quantum cryptography service node closest to the user terminal based on the query request includes:

[0113] Using the terminal information of the user terminal in the query request to query, obtain the user charging location corresponding to the user terminal;

[0114] The address information in the query request is used to query to obtain the target quantum cryptography service node closest to the user terminal.

[0115] Specifically, since the query request can include the terminal information of the user terminal, after obtaining the query request, the quantum cryptography service management platform can query the user data according to the terminal information to obtain the user charging address corresponding to the user terminal.

[0116] Furthermore, the query request can also include the address information of the query request, such as the IP (Internet Protocol) address. In this way, after obtaining the query request, the quantum cryptography service management platform can also query the quantum cryptography service node data according to the address information to obtain the target quantum cryptography service node closest to the user terminal.

[0117] After determining the user charging location and the target quantum cryptography service node, the quantum cryptography service management platform can detect whether the quantum cryptography service node corresponding to the user charging location (referred to as the "original quantum cryptography service node") is the same as the target quantum cryptography service node.

[0118] If the two are not the same, a distribution request for the target charging key can be sent to the original quantum cryptography service node. After receiving the target charging key distribution request, the original quantum cryptography service node sends the target charging key of the user terminal through the corresponding quantum key distribution node (referred to as the "original quantum key distribution node") to the quantum key distribution node corresponding to the target quantum cryptography service node (referred to as the "target quantum key distribution node"). The target quantum cryptography service node can then obtain the target charging key from the target quantum key distribution node.

[0119] In an embodiment of the present invention, the sending of the target injection key distribution request to the original quantum cryptography service node includes:

[0120] Sending a target key injection distribution request directly to the original quantum cryptography service node;

[0121] or,

[0122] The second node information of the original quantum cryptography service node is sent to the user terminal, so that the user terminal uses the second node information to send a target injection key distribution request to the original quantum cryptography service node.

[0123] Specifically, the quantum cryptography service management platform can send a target injection key distribution request directly to the original quantum cryptography service node through the access routing service.

[0124] The quantum cryptography service management platform can also send the node information of the original quantum cryptography service node (recorded as "second node information") to the user terminal through the access routing service. After the user terminal obtains the second node information, it indicates that the original quantum cryptography service node is different from the target quantum cryptography service node. At this time, the user terminal can use the second node information to send a target injection key distribution request to the original quantum cryptography service node.

[0125] Furthermore, the user terminal can be equipped with quantum-safe middleware, which handles key reading and data encryption on the quantum-safe chip, as well as interaction with the quantum cryptography management service system. Based on this, the user terminal can use the quantum-safe middleware to send a target-filled key distribution request. Of course, the user terminal can also use other methods to send the target-filled key distribution request to the original quantum cryptography service node. In actual applications, the specific sending method can be configured based on actual needs and is not limited in this embodiment of the present invention.

[0126] Furthermore, after obtaining the target injection key distribution request, the original quantum cryptography service node can obtain the relay routing information of the quantum network, and then send the target injection key to the target quantum cryptography service node according to the relay routing information.

[0127] It should be noted that the target charging key can be the entire charging key of a complete charging key, or a partial charging key of a complete charging key. That is, in embodiments of the present invention, whether to obtain the complete charging key can be determined based on actual needs. For example, when the quantum network bandwidth is low, the partial charging key for verification can be obtained from the complete charging key. When the quantum network bandwidth is high, the complete charging key can be obtained. In practical applications, whether to obtain the complete charging key can be determined based on actual needs, and embodiments of the present invention do not impose any restrictions on this.

[0128] After determining the target quantum cryptography service node, the quantum cryptography service management platform can send the node information of the target quantum cryptography service node (recorded as "first node information") to the user terminal.

[0129] After obtaining the first node information, the user terminal can use the first node information to establish a connection with the target quantum cryptography service node. When the connection is successfully established, the target quantum cryptography service node can use the target injection key to authenticate the user terminal.

[0130] In an embodiment of the present invention, when a user terminal moves across domains, resulting in the quantum cryptography service node that the user terminal needs to connect to being different from the quantum cryptography service node corresponding to the user's charging location, the quantum cryptography service node corresponding to the user's charging location can be notified to send the charging key to the quantum cryptography service node that the user terminal needs to connect to. When the user terminal successfully establishes a connection with the quantum cryptography service node that needs to be connected, the quantum cryptography service node that needs to be connected can use the charging key to verify the user terminal, thereby ensuring the security of the user terminal's cross-domain movement.

[0131] An embodiment of the present invention further provides an electronic device, including:

[0132] The present invention includes a processor, a memory, and a computer program stored in the memory and capable of running on the processor. When the computer program is executed by the processor, each process of the above-mentioned user roaming method embodiment is implemented and the same technical effect can be achieved. To avoid repetition, it will not be described here.

[0133] An embodiment of the present invention further provides a computer-readable storage medium, on which a computer program is stored. When the computer program is executed by a processor, the various processes of the above-mentioned user roaming method embodiment are implemented, and the same technical effects can be achieved. To avoid repetition, they are not described here.

[0134] The various embodiments in this specification are described in a progressive manner, and each embodiment focuses on the differences from other embodiments. The same or similar parts between the various embodiments can be referenced to each other.

[0135] Those skilled in the art will appreciate that embodiments of the present invention may be provided as methods, apparatus, or computer program products. Thus, embodiments of the present invention may take the form of a fully hardware embodiment, a fully software embodiment, or an embodiment combining software and hardware. Furthermore, embodiments of the present invention may take the form of a computer program product implemented on one or more computer-usable storage media (including but not limited to magnetic disk storage, CD-ROM, optical storage, etc.) containing computer-usable program code.

[0136] The embodiments of the present invention are described with reference to the flowcharts and / or block diagrams of the methods, terminal devices (systems), and computer program products according to the embodiments of the present invention. It should be understood that each process and / or block in the flowchart and / or block diagram, as well as the combination of the processes and / or blocks in the flowchart and / or block diagram, can be implemented by computer program instructions. These computer program instructions can be provided to a processor of a general-purpose computer, a special-purpose computer, an embedded processor, or other programmable data processing terminal device to produce a machine, so that the instructions executed by the processor of the computer or other programmable data processing terminal device generate instructions for implementing the process in the flowchart and / or block diagram. Figure 1 a process or multiple processes and / or boxes Figure 1 A device that provides the functions specified in a block or multiple blocks.

[0137] These computer program instructions may also be stored in a computer readable memory that can direct a computer or other programmable data processing terminal device to operate in a specific manner, so that the instructions stored in the computer readable memory produce a manufactured product including an instruction device, which implements the process Figure 1 a process or multiple processes and / or boxes Figure 1 The function specified in one or more boxes.

[0138] These computer program instructions can also be loaded onto a computer or other programmable data processing terminal device so that a series of operating steps are executed on the computer or other programmable terminal device to produce a computer-implemented process, thereby providing instructions for executing on the computer or other programmable terminal device to implement the process. Figure 1 a process or multiple processes and / or boxes Figure 1 A step that specifies a function in one or more boxes.

[0139] Although the preferred embodiments of the present invention have been described, those skilled in the art may make additional changes and modifications to these embodiments once they become aware of the basic creative concepts. Therefore, the appended claims are intended to be interpreted as including the preferred embodiments and all changes and modifications that fall within the scope of the embodiments of the present invention.

[0140] Finally, it should be noted that, in this document, relational terms such as first and second, etc., are used only to distinguish one entity or operation from another entity or operation, and do not necessarily require or imply any actual relationship or order between these entities or operations. Moreover, the terms "comprises," "comprising," or any other variations thereof are intended to cover non-exclusive inclusion, such that a process, method, article, or terminal device that includes a series of elements includes not only those elements, but also other elements not explicitly listed, or elements inherent to such process, method, article, or terminal device. In the absence of further limitations, an element defined by the phrase "comprising a ..." does not exclude the presence of additional identical elements in the process, method, article, or terminal device that includes the element.

[0141] The user roaming method and user roaming device provided by the present invention are described in detail above. Specific examples are used herein to illustrate the principles and implementation methods of the present invention. The description of the above embodiments is only intended to help understand the method and core concept of the present invention. At the same time, for those skilled in the art, according to the concept of the present invention, there may be changes in the specific implementation methods and application scopes. In summary, the contents of this specification should not be understood as limiting the present invention.

Claims

1. A user roaming method, characterized in that: The method comprises: Obtaining a query request sent by a user terminal for querying routing information; Determining, based on the query request, a user charging location corresponding to the user terminal and a target quantum cryptography service node closest to the user terminal; If the original quantum cryptography service node corresponding to the user charging location is different from the target quantum cryptography service node, sending a target charging key distribution request to the original quantum cryptography service node, so that the original quantum cryptography service node responds to the target charging key distribution request and sends the target charging key to the target quantum cryptography service node; The first node information of the target quantum cryptography service node is sent to the user terminal, so that when the user terminal establishes a connection with the target quantum cryptography service node based on the first node information, the target quantum cryptography service node verifies the user terminal based on the target charging key.

2. The user roaming method according to claim 1, characterized in that: The determining, based on the query request, a user charging location corresponding to the user terminal and a target quantum cryptography service node closest to the user terminal includes: Using the terminal information of the user terminal in the query request to query, obtain the user charging location corresponding to the user terminal; The address information in the query request is used to query to obtain the target quantum cryptography service node closest to the user terminal.

3. The user roaming method according to claim 1, wherein: The sending a target injection key distribution request to the original quantum cryptography service node includes: Sending a target key injection distribution request directly to the original quantum cryptography service node; or, The second node information of the original quantum cryptography service node is sent to the user terminal, so that the user terminal uses the second node information to send a target injection key distribution request to the original quantum cryptography service node.

4. The user roaming method according to claim 1, wherein: The original quantum cryptography service node responds to the target charging key distribution request by obtaining the relay routing information of the quantum network and sends the target charging key to the quantum key distribution node corresponding to the target quantum cryptography service node through the corresponding quantum key distribution node according to the relay routing information.

5. The user roaming method according to claim 1 or 4, characterized in that: The target charging key is the entire charging key or a partial charging key of a complete charging key.

6. A user roaming device, characterized in that: The device comprises: An acquisition module, configured to acquire a query request sent by a user terminal for querying routing information; a determination module, configured to determine, based on the query request, a user charging location corresponding to the user terminal and a target quantum cryptography service node closest to the user terminal; a sending module, configured to send a target charging key distribution request to the original quantum cryptography service node if the original quantum cryptography service node corresponding to the user charging location is different from the target quantum cryptography service node, so that the original quantum cryptography service node responds to the target charging key distribution request and sends the target charging key to the target quantum cryptography service node; The sending module is further configured to send the first node information of the target quantum cryptography service node to the user terminal, so that when the user terminal establishes a connection with the target quantum cryptography service node based on the first node information, the target quantum cryptography service node verifies the user terminal based on the target charging key.

7. The user roaming device according to claim 6, characterized in that: The determining module is specifically configured to: Using the terminal information of the user terminal in the query request to query, obtain the user charging location corresponding to the user terminal; The address information in the query request is used to query to obtain the target quantum cryptography service node closest to the user terminal.

8. A user roaming system, characterized in that: The user roaming system includes a user terminal, a quantum cryptography service management platform, an original quantum cryptography service node and a target quantum cryptography service node; The user terminal sends a query request for querying routing information to the quantum cryptography service management platform; The quantum cryptography service management platform obtains a query request for querying routing information sent by a user terminal; If the original quantum cryptography service node corresponding to the user charging location is different from the target quantum cryptography service node, the quantum cryptography service management platform or the user terminal sends a target charging key distribution request to the original quantum cryptography service node; The original quantum cryptography service node sends the target charging key to the target quantum cryptography service node in response to the target charging key distribution request; The quantum cryptography service management platform sends the first node information of the target quantum cryptography service node to the user terminal; When the user terminal establishes a connection with the target quantum cryptography service node based on the first node information, the target quantum cryptography service node verifies the user terminal based on the target charging key.

9. An electronic device, characterized in that: include: A processor, a memory, and a computer program stored in the memory and capable of running on the processor, wherein when the computer program is executed by the processor, the steps of the user roaming method according to any one of claims 1 to 5 are implemented.

10. A computer-readable storage medium, characterized in that The computer-readable storage medium stores a computer program, and when the computer program is executed by a processor, the steps of the user roaming method according to any one of claims 1 to 5 are implemented.

Citation Information

Patent Citations

  • Quantum cryptography network dynamic routing method

    CN103001875A

  • Communication method and device based on quantum key, storage medium and electronic equipment

    CN118802370A