A redcap-based 5g quantum encryption communication method and device

By using the RedCap-based 5G quantum encrypted communication method, which manages keys with encryption hardware and combines them with national cryptographic standard algorithms, low-power and high-efficiency data encrypted communication is achieved. This solves the problems of high power consumption and low resource utilization in existing 5G quantum encrypted communication devices, and improves the access flexibility and data security of power grid end-point service terminals.

CN119277378BActive Publication Date: 2025-11-25STATE GRID ANHUI ELECTRIC POWER CO LTD +2
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202411702072.0
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2024-11-26
Publication Date
2025-11-25
Estimated Expiration
2044-11-26

AI Technical Summary

Technical Problem

Existing 5G quantum encrypted communication technologies and terminals have high power consumption and low resource utilization, making them difficult to promote on a large scale.

Method used

The method adopts a 5G quantum encrypted communication method based on RedCap, including network access authentication, session key establishment and encryption process of 5G RedCap quantum CPE terminal, key management using encryption hardware such as U-shield or TF card, supporting offline quantum key filling and online distribution, and realizing encrypted tunnel communication by combining national cryptographic standard algorithms.

Benefits of technology

It reduces the power consumption of 5G quantum encrypted communication devices, improves resource utilization, enhances the security and flexibility of data transmission, supports the switching between 4G/5G communication and quantum keys, and solves the problems of flexibility and data acquisition security for power grid end-point business terminal access.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN119277378B_ABST
    Figure CN119277378B_ABST
Patent Text Reader

Abstract

The application forms a 5G RedCap quantum encryption method and device supporting 5G communication, quantum key and IPSec protocol for wireless public network access, aiming at productization, practicality and light weight, based on quantum key services platform, real-time distribution, better randomness and faster update frequency of quantum key, power 5G wireless virtual private network is used to build quantum encryption tunnel, and the security of 5G wireless channel transmission real-time business information and operation state monitoring data is improved. Based on the 5G RedCap quantum CPE terminal, safe, efficient and reliable access of power distribution automation, unmanned aerial vehicle inspection and inspection robot business can be realized, so as to improve the safety access level of power business.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This invention patent relates to the field of quantum secure communication technology, specifically to a 5G quantum encrypted communication method and device based on RedCap. Background Technology

[0002] Currently, new power system businesses such as distribution automation, drone inspection, and inspection robots are growing rapidly, and data interaction between terminals and business master stations is becoming more frequent, posing a risk of data transmission security breaches.

[0003] Quantum secure communication technology, based on the fundamental principles of quantum mechanics and combined with Shannon's "one-time pad" theory, can achieve unconditionally secure communication in information theory, providing a new technical means for power grid security. In the power grid field, quantum secure communication technology is mainly aimed at end-point service nodes, deploying 4G / 5G quantum CPE terminals, building a quantum key service platform, realizing offline quantum key refilling and online distribution, and transmitting real-time power grid business information and operational status monitoring data back to the main station via the 5G network.

[0004] However, existing 5G quantum encrypted communication technologies and terminals suffer from high power consumption and low resource utilization, making large-scale deployment difficult. Therefore, a lightweight 5G quantum encrypted communication method is urgently needed. Summary of the Invention

[0005] To address the problems of high power consumption and low resource utilization in existing 5G quantum encrypted communication technologies and terminals, this invention provides a 5G quantum encrypted communication method based on RedCap, comprising:

[0006] The S1 and 5G RedCap quantum CPE terminals initiate network access authentication to the quantum cryptographic service platform based on the pre-set charging key;

[0007] S2. After the quantum security platform passes the network access authentication verification, it establishes an application session between the 5G RedCap quantum CPE terminal and the quantum encryption gateway, and applies for a session key from the quantum security platform.

[0008] S3. Perform a consistency comparison between the session key in the quantum encryption gateway and the session key that the quantum encryption service platform is preparing to distribute to the 5G RedCap quantum CPE terminal, and schedule the session key that passes the consistency comparison to the 5G RedCap quantum CPE terminal.

[0009] The S4 and 5G RedCap quantum CPE terminals decrypt the session key issued by the quantum security service platform to obtain the plaintext data of the session key, and then use the session key to encrypt the plaintext business data, finally obtaining the ciphertext business data used for data transmission.

[0010] Furthermore, the 5G RedCap quantum CPE terminal supports offline quantum key refilling / online distribution, supports the 3GPP Release 17 (5G RedCap) protocol, supports 4G / 5G communication, supports the national cryptographic standard IPSec protocol to achieve encrypted tunnel communication, supports national cryptographic SM2, SM3, and SM4 algorithm encryption, and supports remote network management using the TR069 protocol.

[0011] Furthermore, the 5G RedCap quantum CPE terminal has a pre-installed charging key that is a QRNG key, which is charged using encrypted hardware, such as a USB key or a TF card.

[0012] Furthermore, the specific steps of the network access authentication are as follows:

[0013] Step 11: After the 5G RedCap quantum CPE terminal device is started, it initiates the first frame of network access authentication to the quantum cryptographic service platform;

[0014] Step 12: After receiving the first frame of network access authentication, the quantum cryptographic platform queries the database for information on the exchange cryptographic machine that provides the pre-set key source and the key information.

[0015] Step 13: The quantum security platform selects the charging key identifier from the queried charging key information, generates a random number a, and returns the charging key identifier and random number a to the 5G RedCap quantum CPE terminal to complete the response of the first frame of network access authentication;

[0016] Step 14: After the 5G RedCap quantum CPE terminal receives the response of the first frame of network access, it parses the charging key identifier and random number a obtained from the response;

[0017] Step 15: The encryption hardware generates a random number b as local information for authentication and confirmation. Based on the key identifier, the encrypted key is found in the key file and decrypted to obtain the plaintext key. The authentication verification code MAC1 is calculated using the CBC_MAC algorithm of the national cryptographic algorithm SM4, and the key used this time is immediately destroyed.

[0018] Step 16: The encryption hardware returns the calculated authentication verification code MAC1 to the 5G RedCap quantum CPE terminal, and at the same time sends the authentication verification code MAC1, random number a, random number b, and charging key identifier to the quantum security service platform to initiate the second frame of network access authentication.

[0019] Step 17: After receiving the second frame of network access authentication, the quantum cryptographic platform queries the random number 'a' and the charging key identifier used for authentication from its local cache, compares them with the information in the first frame of network access authentication, and if the comparison results match, it sends an instruction to the exchange cryptographic machine described in Step 1 to calculate the authentication MAC.

[0020] Step 18: The cipher machine queries the corresponding ciphertext of the charging key in the quantum key repository based on the charging key identifier provided by the quantum cryptographic service platform, decrypts it using the internal cryptographic card, and returns the obtained authentication verification code MAC2 to the quantum cryptographic service platform.

[0021] Step 19: The quantum security platform compares the two authentication verification codes MAC1 and MAC2. If the comparison results match, it generates an authentication token for the 5G RedCap quantum CPE terminal and sets an expiration date for the authentication token.

[0022] Step 110: The 5G RedCap quantum CPE terminal obtains the authentication token, completes network access authentication, and obtains the session key online within the validity period of the authentication token.

[0023] Furthermore, step S2 includes the following steps:

[0024] Step 21: Using the 5G RedCap quantum CPE terminal as the transmitter and the quantum encryption gateway as the receiver, establish an application session and apply for a session key from the quantum encryption platform;

[0025] Step 22: After verifying the identity authentication token, the quantum cryptographic service platform queries the exchange cryptographic machine device information of the sending end and the receiving end. The quantum cryptographic service platform then sends a session key acquisition instruction to the exchange cryptographic machines of the sending end and the receiving end respectively.

[0026] Step 23: The sending end's cryptographic exchange receives the session key retrieval command and returns the sending end's session key to the quantum cryptographic service platform. The ciphertext of the key pre-loaded in the 5G RedCap quantum CPE terminal and the ciphertext of the session key to be output are decrypted in the cryptographic card of the sending end's cryptographic exchange. The decrypted plaintext of the key is then used to encrypt the plaintext of the session key to obtain the ciphertext of the session key. Simultaneously, the QKD device ensures that the receiving end possesses the same session key as the sending end.

[0027] Step 24: The quantum cryptography platform returns the ciphertext of the sending session key to the 5G RedCap quantum CPE terminal, and temporarily caches the ciphertext of the receiving session key locally, waiting for the receiving quantum encryption gateway to retrieve it.

[0028] Furthermore, step S4 includes the following steps:

[0029] Step 41: The power service terminal sends service data to the locally accessed 5G RedCap quantum CPE terminal;

[0030] Step 42: The 5G RedCap quantum CPE terminal uses its internal encryption hardware to decrypt the session key ciphertext, calls the cryptographic module of the encryption hardware to encrypt the plaintext of the service data, and returns the ciphertext of the service data to the 5G RedCap quantum CPE terminal, which then sends it to the quantum encryption gateway through the wireless network.

[0031] Step 43: After receiving the encrypted business data, the quantum encryption gateway parses the data and then calls the internal encryption hardware to decrypt it;

[0032] Step 44: The encryption hardware of the quantum encryption gateway returns the decrypted business data to the quantum encryption gateway, which then sends the plaintext business data to the business master station system.

[0033] Furthermore, S4 ensures the security of business data encryption and decryption through physical hardware mechanisms. The decryption of session key ciphertext is only performed when business data encryption and decryption are required, and both session key ciphertext decryption and business data encryption and decryption operations are performed within the encryption hardware.

[0034] This invention also discloses a 5G quantum encrypted communication device based on RedCap, which, when in operation, can implement the steps of the aforementioned method. The device includes:

[0035] The 5G RedCap quantum CPE terminal is used to charge quantum keys; encrypt plaintext business data using session keys; and establish application calls with the quantum encryption gateway to transmit encrypted business data.

[0036] The quantum cryptographic platform is used to perform consistency comparison of session keys; to perform network access authentication for 5G RedCap quantum CPE terminals; and to issue session keys.

[0037] A quantum encryption gateway is used to receive encrypted business data and decrypt it.

[0038] Beneficial Effects: This invention overcomes the challenges of integrating 5G wireless communication, IPsec protocol, RedCap, and quantum encryption technologies. It proposes a "5G + Quantum + Channel Encryption" application scheme based on RedCap and a 5G RedCap quantum CPE device supporting 5G communication, quantum keys, and the IPSec protocol. Based on real-time updated quantum keys, a quantum encrypted tunnel is constructed, solving problems such as insufficient access flexibility, low data acquisition security, and low reliability of power grid end-point service terminals (e.g., distribution automation, drone inspection, and inspection robots). While improving the security of 5G wireless channel transmission of service data, it effectively reduces data encryption complexity and device development costs, representing a lightweight 5G quantum encrypted communication method. Attached Figure Description

[0039] Figure 1 This is a structural diagram of the 5G RedCap quantum CPE terminal hardware architecture;

[0040] Figure 2 This is a structural diagram of the 5G RedCap quantum CPE terminal software architecture;

[0041] Figure 3 This is a schematic diagram of the 5G RedCap quantum CPE terminal network access certification process;

[0042] Figure 4 This is a schematic diagram of the process by which a 5G RedCap quantum CPE terminal obtains a session key;

[0043] Figure 5 This is a schematic diagram of the session key consistency comparison process;

[0044] Figure 6 This is a schematic diagram illustrating the process of establishing an encrypted tunnel for business data encryption and decryption by a 5G RedCap quantum CPE terminal.

[0045] Figure 7 This is a schematic diagram illustrating the process of distributing quantum encryption from a 5G RedCap quantum CPE terminal to an instance online. Detailed Implementation

[0046] The present invention will be further illustrated below with reference to the accompanying drawings and specific embodiments. It should be understood that the following specific embodiments are for illustrative purposes only and are not intended to limit the scope of the invention. After reading the present invention, any modifications of the present invention in various equivalent forms by those skilled in the art will fall within the scope defined by the appended claims.

[0047] The 5G RedCap quantum CPE terminal was developed according to the principles of "lightweight design, stability priority, shared reuse, and standardized interfaces." While ensuring the needs of business applications, unnecessary functions were removed from the general architecture of wireless encrypted communication equipment to achieve a lightweight design for quantum encryption devices and meet differentiated requirements in terms of power consumption, form factor, interface, and electromagnetic compatibility. The specific functions of the 5G RedCap quantum CPE terminal meet the following requirements:

[0048] It supports offline quantum key refilling / online distribution, supports the 3GPP Release 17 (5G RedCap) protocol, supports 4G / 5G communication, supports switching between quantum keys and classical keys, supports the national cryptographic standard IPSec protocol to achieve encrypted tunnel communication, supports national cryptographic SM2, SM3, and SM4 algorithm encryption, and supports remote network management using the TR069 protocol.

[0049] Based on the application requirements of different business scenarios, the 5G RedCap quantum CPE terminal is designed with hardware considering factors such as application form, power supply method, overall power consumption requirements, main control CPU processing power, memory configuration, peripheral resource configuration, protection level, communication capabilities, and performance indicators. In this embodiment, the hardware platform architecture is divided into functional modules, such as... Figure 1 As shown. The main hardware configuration is as follows:

[0050] DDR RAM memory of no less than 4Gbit; FLASH storage of no less than 4Gbit; 4G or 5G wireless communication modules can be used according to site requirements, or Ethernet port transmission can be used; Ethernet port communication or RS232 serial port communication can be used according to site requirements; USIM card or eSIM chip can be used according to site requirements; quantum-safe TF card for storing quantum charging keys, used for identity authentication and session key acquisition protection with the quantum security platform.

[0051] The software system of the 5G RedCap quantum CPE terminal in this embodiment is as follows: Figure 2 As shown, based on the characteristics of power business, it can be divided into two main parts: underlying software and application software.

[0052] The underlying software mainly includes a modified Linux kernel, low-level drivers, and software that supports application development.

[0053] Based on the terminal's interface requirements, the underlying drivers include serial port, USB, and network card drivers. The USB serial port connected to the communication module can be virtualized as a network port, facilitating application-layer network communication design. Additionally, it includes memory management for Flash and RAM low-level operations, as well as kernel clock management. Other default kernel-related drivers, such as process management and interrupts, use modules provided by the operating system. The underlying software should also include the establishment of a UBI or ramdisk file system, the porting of the TCP / IP protocol stack, the creation of relevant library files, and compiler integration.

[0054] Application software mainly includes a quantum encryption authentication module, a serial port forwarding module, a data communication module, a configuration management module, and a communication network management module.

[0055] The quantum encryption authentication module is responsible for identity authentication and obtaining quantum keys with the quantum encryption service platform, and simultaneously conducts identity authentication and key negotiation with the peer gateway based on digital certificates to establish a quantum encryption tunnel; the serial port forwarding module is responsible for connecting serial port-type service terminals. After the device establishes a socket with the master station, it packages the serial port data into TCP / IP packets and forwards them to the master station; the data communication module is responsible for dialing the wireless module, reading Ethernet communication data, and forwarding the data; the configuration management module is responsible for managing the system's relevant parameters, configurations, and parameter storage, providing configuration and parameter support for other modules; the communication network management module is responsible for system fault alarms, parameter configuration, remote upgrades, status monitoring, log downloads, and remote resets, providing communication support for the communication equipment to meet the requirements of the wireless communication resource management and integrated monitoring system.

[0056] The following section will further illustrate the 5G quantum encrypted communication method of the present invention with reference to this embodiment.

[0057] The S1 5G RedCap quantum CPE terminal initiates network access authentication via the quantum cryptographic service platform based on a pre-installed QRNG charging key. The detailed process of the 5G RedCap quantum CPE terminal performing network access authentication via the quantum cryptographic service platform is as follows: Figure 3 As shown. The specific steps of S1 are explained below:

[0058] Step 11: After the 5G RedCap Quantum CPE terminal device is started, it initiates the first frame of network access authentication to the Quantum Security Service Platform, and uploads the device application information and the U-shield / TF card information of the access via HTTPS protocol to the Quantum Security Service Platform.

[0059] Step 12: After receiving the first frame of network access authentication, the quantum security platform begins to query the database for information on the exchange cryptographic machine that provides the pre-set charging key source to the U-shield / TF card and related information on the charging key in the U-shield / TF card.

[0060] Step 13: The quantum security service platform selects the charging key identifier required for this network access authentication from the queried charging key information and generates a random number 'a' for authentication. At the same time, the selected key identifier information and random number 'a' are cached within the quantum security service platform. Finally, the charging key identifier and random number 'a' are returned to the 5G RedCap quantum CPE terminal to complete the response of the first frame of network access authentication.

[0061] Step 14: After the 5G RedCap quantum CPE terminal receives the response of the first frame of network access, it parses the response to obtain the charging key identifier required for authentication and the random number 'a' issued by the platform. The 5G RedCap quantum CPE terminal then starts to call the quantum key and cryptographic algorithm in the U-shield / TF card to calculate the authentication verification code MAC.

[0062] Step 15: The U-Shield / TF Card generates a random number b as local information for authentication confirmation of the 5G RedCap quantum CPE terminal. Then, based on the charging key identifier, the ciphertext of the charging key is found in the key file. The cryptographic algorithm in the U-Shield / TF Card is called to load the ciphertext of the charging key into the secure area of ​​the U-Shield / TF Card for decryption. Then, the plaintext of the decrypted charging key and the random numbers a and b are used to calculate the authentication verification code MAC1 using the CBC_MAC algorithm of the national cryptographic algorithm SM4. The charging key used this time is then destroyed immediately.

[0063] Step 16: The U-shield / TF card returns the calculated authentication verification code MAC1 to the 5G RedCap quantum CPE terminal, which then sends this authentication verification code MAC1, along with random numbers a and b, and the charging key identifier used for authentication, to the quantum security service platform to initiate the second frame of network access authentication.

[0064] Step 17: After receiving the second frame of network access authentication, the quantum security platform queries the random number 'a' and the charging key identifier used for authentication from its local cache, and compares them with the information in the first frame of network access authentication to see if they match. If the information matches, it sends an instruction to the exchange cryptographic machine that provides the pre-set charging key source to the U-shield / TF card to calculate the authentication MAC.

[0065] Step 18: The cipher machine queries the quantum key repository for the corresponding ciphertext of the ...

[0066] Step 19: The quantum security platform compares the two authentication verification codes MAC1 and MAC2 to check if they match. If they match, an authentication token is generated for the 5G RedCap quantum CPE terminal. The platform sets an expiration date for the authentication token and caches it locally to ensure that one device account can only log in to one 5G RedCap quantum CPE terminal at a time, thus enhancing the security of the device account.

[0067] Step 110: After obtaining the authentication token, the 5G RedCap quantum CPE terminal can acquire the session key online within the token's validity period. By default, the authentication token is valid for 24 hours. The validity period can be manually modified in the quantum security platform's management interface. If the validity period expires, the 5G RedCap quantum CPE terminal needs to re-enter the network to obtain the authentication token.

[0068] S2. After the network access authentication verification is passed by the quantum security platform, an application session is established between the 5G RedCap quantum CPE terminal and the quantum encryption gateway, and a session key is requested from the quantum security platform. The detailed process for the 5G RedCap quantum CPE terminal to obtain the session key is as follows: Figure 4 As shown. The specific steps of S2 are explained below:

[0069] Step 21: After the 5G RedCap quantum CPE terminal establishes an application session with the quantum encryption gateway, it applies to the quantum encryption platform for the session key required for business encryption based on the application session ID, the information of the sending 5G RedCap quantum CPE terminal, the information of the receiving quantum encryption gateway, and the identity authentication token.

[0070] Step 22: After verifying the identity authentication token of the 5G RedCap quantum CPE terminal, the quantum encryption platform queries the information of the exchange cryptographic device that fills the U-shield / TF card in the sending end and the receiving end with the key information based on the information of the sending end 5G RedCap quantum CPE terminal and the receiving end quantum encryption gateway.

[0071] Since the charging keys for the sending and receiving ends originate from different exchange cryptosystems, QKD devices are required to ensure that the two devices have the same session key. In this embodiment, during the session key acquisition process, the quantum cryptographic service platform only needs to check whether the amount of quantum keys stored between the sending and receiving exchange cryptosystems is sufficient. If the key quantity is sufficient, the quantum cryptographic service platform will send session key acquisition instructions to the sending and receiving exchange cryptosystems respectively. If the key quantity is insufficient, a quantum key generation instruction will be issued to the exchange cryptosystem. Considering the number of power system application terminal devices connected, the exchange cryptosystem will locally cache a certain amount of quantum keys negotiated between QKD transceivers. When the amount falls below the cached amount, a quantum key generation instruction will be automatically triggered to obtain quantum keys from the QKD quantum network distribution system to supplement the key quantity, thereby ensuring a sufficient amount of session keys between quantum application devices in the power system.

[0072] Step 23: After receiving the session key retrieval instruction from the quantum cryptographic service platform, the sending end's cryptographic exchange machine queries the pre-loaded key ciphertext and the session key ciphertext to be output in the sending end's 5G RedCap quantum CPE terminal locally. It decrypts the loaded key ciphertext and the session key ciphertext in the sending end's cryptographic card, and then uses the decrypted loaded key plaintext to encrypt the session key plaintext to obtain the session key ciphertext. To ensure the integrity of the transmitted session key ciphertext, the transmitted information is generally signed using the SM3 national cryptographic algorithm. Finally, the sending end's cryptographic exchange machine returns the session key ciphertext and signature information to the quantum cryptographic service platform. Similarly, under the unified scheduling of the quantum cryptographic service platform, the receiving end's cryptographic exchange machine returns the session key ciphertext of the receiving end's quantum encryption gateway.

[0073] Step 24: The quantum encryption platform returns the ciphertext of the session key from the sending end to the 5G RedCap quantum CPE terminal, and temporarily caches the ciphertext of the session key from the receiving end locally, waiting for the quantum encryption gateway at the receiving end to obtain it. This caching method greatly shortens the time it takes for the quantum encryption gateway to obtain the session key and improves the timeliness of decrypting power business data.

[0074] S3. Perform a consistency comparison between the session key in the quantum encryption gateway and the session key that the quantum cryptographic service platform is preparing to distribute to the 5G RedCap quantum CPE terminal, and schedule the session key that passes the consistency comparison to the 5G RedCap quantum CPE terminal; the consistency comparison process is as follows: Figure 5 As shown, for the session key to be issued to the 5G RedCap quantum CPE terminal, the quantum cryptographic service platform transmits the data carrying the hash value of N keys and the key number to the quantum encryption gateway, compares it with the session key existing in the quantum encryption gateway, and the quantum encryption gateway returns the key number and verification result.

[0075] The S4 and 5G RedCap quantum CPE terminals decrypt the session key issued by the quantum security service platform to obtain the plaintext data of the session key, and then use the session key to encrypt the plaintext business data, finally obtaining the ciphertext business data used for data transmission.

[0076] The session keys obtained by the 5G RedCap quantum CPE terminal and quantum encryption gateway from the quantum encryption platform are all encrypted. The session key needs to be decrypted before it can be used to encrypt or decrypt service data. To ensure the security of the quantum key in the power service terminal, the decryption of the encrypted session key is only performed when service data encryption or decryption is required. Furthermore, both the decryption of the encrypted session key and the encryption / decryption of service data are performed within the U-shield / TF card, with physical hardware mechanisms guaranteeing the security of service data encryption and decryption. The detailed process for establishing an encrypted tunnel for service data encryption and decryption by the 5G RedCap quantum CPE terminal is as follows: Figure 6 As shown.

[0077] Step 41: The power service terminal sends service data to the locally accessed 5G RedCap quantum CPE terminal.

[0078] Step 42: After the 5G RedCap quantum CPE terminal successfully applies for and obtains the session key ciphertext from the quantum cryptographic service platform, it decrypts the session key ciphertext using its internal U-shield / TF card, calls the cryptographic module of the U-shield / TF card to encrypt the plaintext of the service data using the SM4 national cryptographic algorithm, and returns the ciphertext of the service data to the 5G RedCap quantum CPE terminal, which then sends it to the remote quantum encryption gateway via the wireless network.

[0079] Step 43: After receiving the encrypted business data, the quantum encryption gateway parses the data to obtain the session key information for decryption, and then calls the internal U-shield / TF card to decrypt it. The decryption operation is similar to the encryption process of the SM4 national cryptographic algorithm.

[0080] Step 44: The U-shield / TF card of the quantum encryption gateway returns the decrypted business data to the quantum encryption gateway, which then sends the business data in plaintext to the business master station system.

[0081] like Figure 7 The diagram illustrates the online distribution process of quantum encryption from the 5G RedCap quantum CPE terminal to the instance. A QRNG key generated by a quantum random number generator is used as the charging key and charged into the 5G RedCap quantum CPE terminal via encryption hardware. A QKD key generated by a quantum key generator on the quantum cryptographic platform is used as the session key. The session key is encrypted using the charging key and transmitted in real-time to the quantum encryption gateway and the 5G RedCap quantum CPE terminal. The quantum encryption gateway and the 5G RedCap quantum CPE terminal establish an encrypted tunnel using the QKD key to achieve encrypted transmission of service data.

Claims

1. A RedCap-based 5G quantum encryption communication method, characterized in that, The method comprises the following steps: S1, the 5G RedCap quantum CPE terminal initiates network access authentication to the quantum service platform based on the preset charging key vector; S2, after the quantum service platform verifies the network access authentication, an application session of the 5G RedCap quantum CPE terminal and the quantum encryption gateway is established, and a session key is applied to the quantum service platform; S3, the session key in the quantum encryption gateway and the session key prepared by the quantum service platform and sent to the 5G RedCap quantum CPE terminal are compared for consistency, and the session key passing the consistency comparison is scheduled to the 5G RedCap quantum CPE terminal; S4, the 5G RedCap quantum CPE terminal decrypts the session key sent by the quantum service platform, obtains the session key plaintext data, encrypts the business data plaintext by using the session key, and finally obtains the business data ciphertext used for data transmission; The charging key preset by the 5G RedCap quantum CPE terminal is a QRNG key, which is charged in the form of encryption hardware, and the encryption hardware is a U disk or a TF card; The specific steps of the network access authentication are as follows: Step 11: after the 5G RedCap quantum CPE terminal device is started, the first frame of network access authentication is initiated to the quantum service platform; Step 12: after the quantum service platform receives the first frame of network access authentication, the information of the exchange password machine providing the preset charging key source and the charging key information is queried from the database; Step 13: the quantum service platform selects the charging key identifier in the queried charging key information, generates a random number a, returns the charging key identifier and the random number a to the 5G RedCap quantum CPE terminal, and completes the response of the first frame of network access authentication; Step 14: after the 5G RedCap quantum CPE terminal obtains the response of the first frame of network access, the charging key identifier and the random number a obtained by the response are parsed; Step 15: the encryption hardware generates a random number b as local information for authentication confirmation, finds the charging key ciphertext in the charging key file according to the charging key identifier, decrypts to obtain the charging key plaintext, calculates the authentication check code MAC1 by using the CBC_MAC algorithm of the SM4 national secret algorithm, and immediately destroys the charging key used this time; Step 16: the encryption hardware returns the calculated authentication check code MAC1 to the 5G RedCap quantum CPE terminal, and sends the authentication check code MAC1, the random number a, the random number b and the charging key identifier to the quantum service platform to initiate the second frame of network access authentication; Step 17: after the quantum service platform receives the second frame of network access authentication, the random number a and the charging key identifier for authentication are queried from the local cache, and the information of the first frame of network access authentication is compared; if the comparison result is consistent, the instruction for calculating the authentication MAC is sent to the exchange password machine in step 1; Step 18: the exchange password machine queries the corresponding charging key ciphertext in the quantum key storage according to the charging key identifier provided by the quantum service platform, decrypts to obtain the authentication check code MAC2 by using the internal password card, and returns the authentication check code MAC2 to the quantum service platform; Step 19: The quantum service platform compares the two authentication check codes MAC1 and MAC2, and if the comparison result is consistent, an authentication token is generated for the 5G RedCap quantum CPE terminal, and the validity period of the authentication token is set; Step 110: The 5G RedCap quantum CPE terminal obtains the authentication token and completes the network access authentication, and obtains the session key online within the validity period of the authentication token.

2. The encrypted communication method of claim 1, wherein, The S2 includes the following steps: Step 21: The 5G RedCap quantum CPE terminal is taken as the sending terminal, and the quantum encryption gateway is taken as the receiving terminal, an application session is established, and a session key is applied to the quantum service platform; Step 22: After verifying the identity authentication token, the quantum service platform queries the exchange password machine device information of the sending terminal and the receiving terminal, and sends a session key acquisition instruction to the exchange password machine of the sending terminal and the receiving terminal respectively; Step 23: The exchange password machine of the sending terminal receives the session key acquisition instruction, and returns the sending terminal session key to the quantum service platform; Step 24: The quantum service platform returns the sending terminal session key ciphertext to the 5G RedCap quantum CPE terminal, and temporarily caches the receiving terminal session key ciphertext locally, waiting for the receiving terminal quantum encryption gateway to acquire it.

3. The encrypted communication method of claim 2, wherein, In the step 23, the sending terminal session key ciphertext acquisition process is as follows: the key ciphertext pre-filled in the 5G RedCap quantum CPE terminal and the session key ciphertext to be output are decrypted in the password card of the sending terminal exchange password machine, and the session key ciphertext is obtained by encrypting the session key plaintext with the decrypted pre-filled key plaintext; meanwhile, the receiving terminal has the same session key as the sending terminal by means of QKD device.

4. The encrypted communication method of claim 1, wherein, The S3 adopts a quantum key consistency verification technology, and for the session key to be prepared for the 5G RedCap quantum CPE terminal, the quantum service platform transmits data carrying N blocks of key hash values and key numbers to the quantum encryption gateway, and compares them with the existing session key in the quantum encryption gateway, and the quantum encryption gateway returns the key number and the verification result.

5. The encrypted communication method of claim 1, wherein, The S4 includes the following steps: Step 41: The power service terminal sends service data to the 5G RedCap quantum CPE terminal accessed locally; Step 42: The 5G RedCap quantum CPE terminal decrypts the session key ciphertext by using the internal encryption hardware, calls the password module of the encryption hardware to encrypt the service data plaintext, and returns the service data ciphertext to the 5G RedCap quantum CPE terminal, which sends the service data ciphertext to the quantum encryption gateway through the wireless network; Step 43: After receiving the service data ciphertext, the quantum encryption gateway adopts AES, DES, etc. National encryption algorithm, calls the quantum key to decrypt the data, and verifies the integrity and authenticity of the data; Step 44: The encryption hardware of the quantum encryption gateway returns the decrypted service data to the quantum encryption gateway, and the quantum encryption gateway sends the service data plaintext to the business host system.

6. The encrypted communication method of claim 5, wherein, S4 is guaranteed by physical hardware mechanism to encrypt and decrypt the security of service data, and the decryption of session key ciphertext is implemented when service data needs to be encrypted and decrypted, and the operation of session key ciphertext decryption and service data encryption and decryption is performed in the encryption hardware. 7.A RedCap-based 5G quantum encryption communication device, characterized in that, It comprises: 5G RedCap quantum CPE terminal, for filling quantum key; Using the session key to encrypt the plaintext of the service data; Establishing application call with quantum encryption gateway, transmitting encrypted service data; Quantum encryption platform, for consistency comparison of session key; for network access authentication of 5G RedCap quantum CPE terminal; Issuing session key; Quantum encryption gateway, for receiving encrypted service data; decrypting encrypted service data; The preloaded filling key of the 5G RedCap quantum CPE terminal is a QRNG key, which is filled in the form of encryption hardware, and the encryption hardware is a U disk or a TF card; The specific steps of the network access authentication are as follows: Step 11: after the 5G RedCap quantum CPE terminal device is started, the first frame of network access authentication is initiated to the quantum encryption platform; Step 12: after the quantum encryption platform receives the first frame of network access authentication, the information of the exchange password machine providing the preloaded filling key source and the filling key information is queried from the database; Step 13: the quantum encryption platform selects the filling key identifier in the queried filling key information, generates a random number a, returns the filling key identifier and the random number a to the 5G RedCap quantum CPE terminal, and completes the response of the first frame of network access authentication; Step 14: after the 5G RedCap quantum CPE terminal obtains the response of the first frame of network access, the filling key identifier and the random number a obtained by the response are parsed; Step 15: the encryption hardware generates a random number b as local information for authentication confirmation, finds the filling key ciphertext in the filling key file according to the filling key identifier, decrypts to obtain the filling key plaintext, calculates the authentication check code MAC1 using the CBC_MAC algorithm of the SM4 national secret algorithm, and immediately destroys the filling key used this time; Step 16: the encryption hardware returns the calculated authentication check code MAC1 to the 5G RedCap quantum CPE terminal, and sends the authentication check code MAC1, the random number a, the random number b and the filling key identifier to the quantum encryption platform, and initiates the second frame of network access authentication; Step 17: after the quantum encryption platform receives the second frame of network access authentication, the random number a and the filling key identifier for authentication are queried from the local cache, and the information of the first frame of network access authentication is compared, and the comparison result is consistent, then the instruction for calculating the authentication MAC is issued to the exchange password machine in step 1; Step 18: the exchange password machine queries the corresponding filling key ciphertext in the quantum key storage according to the filling key identifier provided by the quantum encryption platform, decrypts to obtain the authentication check code MAC2 using the internal password card, and returns the authentication check code MAC2 to the quantum encryption platform; Step 19: The quantum secret service platform compares the two authentication check codes MAC1 and MAC2, and if the comparison result is consistent, an authentication token is generated for the 5G RedCap quantum CPE terminal, and the validity period of the authentication token is set; Step 110: The 5G RedCap quantum CPE terminal obtains the authentication token and completes the network access authentication, and obtains the session key online within the validity period of the authentication token.

8. The quantum cryptographic communication device of claim 7, wherein, When the device is running, the steps of the method of claims 1-6 are implemented.

Citation Information

Patent Citations

  • Ground meteorological observation data transmission key negotiation method and system based on quantum security tunnel

    CN117527228A

  • Secondary authentication method and authentication system of longitudinal encryption system and longitudinal encryption system

    CN118283618A