A negotiation method for a point-to-point communication key center

By negotiating a shared key center between quantum security terminals, point-to-point communication is achieved, which solves the delay and resource occupation problems caused by base station relay in existing technologies and improves communication efficiency and security.

CN119299082BActive Publication Date: 2025-09-23MATRICTIME DIGITAL TECH CO LTD
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202411306529.6
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2024-09-19
Publication Date
2025-09-23
Estimated Expiration
2044-09-19

AI Technical Summary

Technical Problem

Existing quantum secure communication methods rely on accessing base stations for key relay, which leads to communication delays and resource occupation. Especially in application scenarios with high real-time requirements, it may lead to service quality degradation or even interruption.

Method used

A point-to-point communication key center negotiation method is provided. The shared key center is determined by the intersection of the access base station and the key center list, which enables direct communication between quantum security terminals, reduces dependence on base stations, and ensures the security and traceability of the key distribution process.

Benefits of technology

It improves the real-time and efficiency of quantum secure communication, reduces terminal complexity and cost, ensures the security of the key distribution process and resource scheduling efficiency, and prevents key leakage and unauthorized access.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN119299082B_ABST
    Figure CN119299082B_ABST
Patent Text Reader

Abstract

The present application discloses a negotiation method for a point-to-point communication key center. Since the first access base station and the second access base station search for possible shared key centers through the key center lists maintained by each of them, this distributed resource matching method can significantly improve the efficiency of resource scheduling. At the same time, by determining the shared key center through the intersection, it also avoids the waste of resources and increased complexity caused by selecting multiple key centers. The shared key center assigns a distribution identifier to the two quantum security terminals for point-to-point communication, ensuring the security and traceability of the key distribution process. The distribution identifier serves as a unique identifier for the session, so that each key distribution operation can be accurately tracked and verified, thereby effectively preventing the risk of key leakage and unauthorized access.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present application relates to the technical fields of information security and quantum encryption technology, and in particular to a negotiation method for a point-to-point communication key center. Background Art

[0002] With the rapid development of quantum information technology, quantum secure communication, due to its unbreakable security, has become an important means of ensuring the security of information transmission. In a global quantum secure communication network, achieving secure communication between any two quantum secure terminals is crucial. However, classical quantum secure communication methods rely on key relay via access base stations. While this method can provide a certain degree of communication security, it has significant limitations, especially in applications with extremely high real-time requirements.

[0003] Specifically, key relay via base station access requires a complex key transmission process between the encryption and decryption ends. This inevitably introduces latency and can lead to decryption failures due to key or ciphertext anomalies. Furthermore, the key relay process consumes valuable network bandwidth and terminal processing resources, increasing system complexity and operating costs. For services requiring extremely high real-time performance, such as driving navigation, remote surgery, and high-precision real-time monitoring, these delays and resource usage can directly lead to reduced service quality or even service interruption.

[0004] To overcome these limitations and improve the real-time performance and efficiency of quantum secure communication, a method for enabling direct point-to-point communication between two quantum secure terminals connected to a global quantum secure network can be considered. The key to this approach is to establish a direct communication link between the two quantum secure terminals, reducing or eliminating reliance on access base stations, thereby shortening communication latency and improving communication efficiency. However, enabling two quantum secure terminals connected to a global quantum secure network to autonomously negotiate whether to engage in point-to-point communication is a prerequisite for achieving point-to-point communication. Summary of the Invention

[0005] The present application provides a negotiation method for a point-to-point communication key center, which is used to enable autonomous negotiation between two quantum security terminals connected to a global quantum security network terminal on whether to conduct point-to-point communication.

[0006] The present application provides a method for negotiating a point-to-point communication key center, the method comprising:

[0007] The first quantum security terminal sends a pairing communication request to the first access base station to which it is connected; wherein the pairing communication request carries a symmetric allocation identifier, the first communication protocol parameter, a first network access identifier of the first quantum security terminal, and a second network access identifier of the second quantum security terminal;

[0008] The first access base station receives the pairing communication application; obtains a first key center list that can allocate a pairing key to the first quantum security terminal; and sends a point-to-point communication request to a second access base station connected to the second quantum security terminal using the second network access identifier; wherein the point-to-point communication request carries the first network access identifier, the first communication protocol parameters, and the first key center list;

[0009] The second access base station receives the point-to-point communication request; obtains a second key center list that can allocate a pairing key to the second quantum security terminal; determines the shared key center according to the intersection of the first key center list and the second key center list; and sends a pairing distribution application to the shared key center; wherein the pairing distribution application carries the first network access identifier and the second network access identifier;

[0010] The shared key center generates the distribution identifier in response to the pairing distribution application; stores the first network access identifier, the second network access identifier, and the distribution identifier in correspondence; and sends a pairing distribution response carrying the distribution identifier to the second access base station;

[0011] The second access base station receives the pairing distribution response; sends a point-to-point pairing request to the second quantum security terminal; wherein the point-to-point pairing request carries the central address information of the shared key center, the distribution identifier, and the first communication protocol parameter;

[0012] The second quantum security terminal receives the point-to-point pairing request; stores the center address information, the first communication protocol parameters, and the distribution identifier in correspondence; and sends the point-to-point pairing response to the second access base station; wherein the point-to-point pairing response carries the second communication protocol parameters of the second quantum security terminal;

[0013] The second access base station receives the point-to-point pairing response; sends a pairing communication response to the first access base station, so as to send the pairing communication response to the first quantum security terminal through the first access base station; wherein the pairing communication response carries the center address information, the second communication protocol parameters and the distribution identifier.

[0014] The beneficial effects of this application are as follows:

[0015] 1. The first and second access base stations use their respective lists of key centers to search for a possible shared key center. This distributed resource matching approach significantly improves resource scheduling efficiency. Determining the shared key center through intersection also avoids the resource waste and increased complexity associated with selecting multiple key centers.

[0016] 2. The shared key center assigns a distribution identifier to each quantum security terminal in point-to-point communication, ensuring the security and traceability of the key distribution process. As a unique identifier for the session, the distribution identifier allows each key distribution operation to be accurately tracked and verified, effectively preventing the risk of key leakage and unauthorized access.

[0017] 3. During the point-to-point communication process, the first and second quantum security terminals also exchanged communication protocol parameters, which is not only the foundation for establishing a communication link but also the key to ensuring protocol compatibility. By negotiating their respective supported communication protocol parameters, the first and second quantum security terminals achieve seamless protocol integration while ensuring security, providing a strong guarantee for subsequent quantum secure communications.

[0018] 4. During the point-to-point communication negotiation process with the key center, the quantum security terminal is primarily responsible for receiving, storing, and transmitting information, while the complex calculation and matching tasks are performed by the reliable access base station and key center in the global quantum security network. This design reduces the complexity and cost requirements of the quantum security terminal, allowing more devices to easily access the global quantum security network and ensuring the security of the entire negotiation process. BRIEF DESCRIPTION OF THE DRAWINGS

[0019] In order to more clearly illustrate the technical solutions in the embodiments of the present application, the following briefly introduces the drawings required for use in the description of the embodiments. Obviously, the drawings described below are only some embodiments of the present application. For ordinary technicians in this field, other drawings can be obtained based on these drawings without paying any creative labor.

[0020] Figure 1 A schematic diagram of a negotiation process of a point-to-point communication key center provided in an embodiment of the present application;

[0021] Figure 2 A schematic diagram of the negotiation process of a specific point-to-point communication key center provided in an embodiment of the present application;

[0022] Figure 3 This is a schematic diagram of a specific pairing key request process provided in an embodiment of the present application. DETAILED DESCRIPTION

[0023] To make the objectives, technical solutions, and advantages of this application more clear, this application will be further described in detail below with reference to the accompanying drawings. It should be understood that the embodiments described herein are only a portion of the embodiments of this application, and not all of them. All other embodiments derived by persons of ordinary skill in the art based on the embodiments of this application without inventive effort are intended to fall within the scope of protection of this application.

[0024] The global quantum secure network supports secure and efficient quantum communication between any quantum secure terminals connected to the network, regardless of their geographic location. A key element of this global quantum secure network is the use of access base stations as communication hubs, connecting quantum secure terminals to the global quantum secure network and enabling key relay between terminals connected to the global quantum secure network.

[0025] During the access process, when a quantum secure terminal connects to an access base station, the access base station assigns it a network access identifier—a unique terminal identifier for the entire global quantum secure network. This identifier carries information about the country, operator, region, cell, access base station, and terminal. With this network access identifier, the terminal can be identified within the global quantum secure network for the duration of its possession. Subsequently, the quantum secure terminal can request services and resources from the global quantum secure network through the access base station.

[0026] During key relay, the encryption end relays the key through the encryption end access base station and then through the global quantum secure network to the decryption end access base station. The decryption end access base station then forwards the key to the decryption end, thereby ensuring a symmetric quantum secure key between the encryption end and the decryption end, enabling encryption and decryption communications. The global quantum secure network also includes a key center, which distributes keys, or quantum keys, to quantum secure terminals connected to the global quantum secure network.

[0027] This global quantum secure network allows the key relay process to be separated from the ciphertext transmission process, further improving the security of ciphertext transmission. However, key relay via base station access requires a complex key transmission process between the encryption and decryption ends, which inevitably introduces latency and can lead to decryption failures due to key or ciphertext anomalies. Furthermore, the key relay process consumes valuable network bandwidth and terminal processing resources, increasing system complexity and operating costs. For services requiring extremely high real-time performance, such as driving navigation, remote surgery, and high-precision real-time monitoring, these delays and resource usage can directly lead to reduced service quality or even service interruption.

[0028] To overcome these limitations and improve the real-time performance and efficiency of quantum secure communication, a method for enabling direct point-to-point communication between two quantum secure terminals connected to a global quantum secure network can be considered. The key to this approach is to establish a direct communication link between the two quantum secure terminals, reducing or eliminating reliance on access base stations, thereby shortening communication latency and improving communication efficiency. However, enabling two quantum secure terminals connected to a global quantum secure network to autonomously negotiate whether to engage in point-to-point communication is a prerequisite for achieving point-to-point communication.

[0029] Based on this, the present application provides a negotiation method for a point-to-point communication key center to enable autonomous negotiation between two quantum security terminals connected to a global quantum security network terminal on whether to conduct point-to-point communication.

[0030] Example 1:

[0031] Figure 1 A schematic diagram of a negotiation process for a point-to-point communication key center provided in an embodiment of the present application, the process including:

[0032] S101: A first quantum security terminal sends a pairing communication request to a first access base station to which it is connected; wherein the pairing communication request carries a symmetric allocation identifier, the first communication protocol parameters, a first network access identifier of the first quantum security terminal, and a second network access identifier of the second quantum security terminal.

[0033] Each quantum secure terminal connected to the global quantum secure network is assigned a corresponding network access identifier, which accurately identifies the quantum secure terminal's location within the global quantum secure network. When a quantum secure terminal requires point-to-point communication with a specific quantum secure terminal within the global quantum secure network, it can proactively initiate a pairing communication request with the other quantum secure terminal through the global quantum secure network to negotiate whether to proceed with point-to-point communication. For ease of description, the quantum secure terminal that proactively initiates the pairing communication request is referred to as the first quantum secure terminal, and the quantum secure terminal that passively responds to the pairing communication request is referred to as the second quantum secure terminal.

[0034] Exemplarily, the first quantum security terminal may generate a pairing communication application and then send the pairing communication application to the access base station (referred to as the first access base station) to which the first quantum security terminal accesses. The pairing communication application carries a symmetric allocation identifier, the communication protocol parameters of the first quantum security terminal (referred to as the first communication protocol parameters), the network access identifier of the first quantum security terminal (referred to as the first network access identifier), and the network access identifier of the second quantum security terminal (referred to as the second network access identifier). The symmetric allocation identifier is used to characterize the shared key center that the global quantum security network needs to determine to allocate pairing keys for the first quantum security terminal and the second quantum security terminal. The first communication protocol parameters define the communication protocol specifications that must be followed during point-to-point communication between the first quantum security terminal and the second quantum security terminal, including but not limited to one or more of the following: the key size of the pairing key, the encryption algorithm, the key expansion algorithm, the hash algorithm, and the current communication identifier.

[0035] In one possible implementation, a quantum security terminal connected to the global quantum security network maintains a symmetric key with the access base station it connects to, enabling quantum encryption communication between the quantum security terminal and the access base station. Based on this, in this application, the first quantum security terminal can encrypt a pairing communication request and send it to the first access base station based on the symmetric key to protect the security of the data carried in the pairing communication request. Upon receiving the encrypted pairing communication request, the first access base station can also decrypt the encrypted pairing communication request based on the symmetric key paired with the first quantum security terminal.

[0036] S102: The first access base station receives the pairing communication application; obtains a first key center list that can allocate a pairing key to the first quantum security terminal; and sends a point-to-point communication request to the second access base station to which the second quantum security terminal is connected through the second network access identifier; wherein the point-to-point communication request carries the first network access identifier, the first communication protocol parameters, and the first key center list.

[0037] An access base station in the global quantum security network maintains a key center information library that supports key distribution for quantum security terminals under the access base station. This key center information library contains detailed information on multiple key centers, which is used to evaluate and determine which key center is most suitable for distributing keys to the quantum security terminals connected to the access base station. This key center information library includes, but is not limited to, whether the key center supports pairing key distribution, key center load information, key center location information, and key center address information. When the first access base station receives a pairing communication request sent by the first quantum security terminal, it can generate a list of multiple candidate key centers and their detailed information from the maintained key center information library, namely, the first key center list. Each key center in this key center list is capable of distributing pairing keys for the first quantum security terminal.

[0038] Next, the first access base station generates a point-to-point communication request based on the first key center list and the pairing communication request. Using the second network access identifier of the second quantum security terminal, the point-to-point communication request is sent to the access base station connected to the second quantum security terminal (referred to as the second access base station). This point-to-point communication request contains several key pieces of information: the first network access identifier, the first communication protocol parameters, and the first key center list.

[0039] S103: The second access base station receives the point-to-point communication request; obtains a second key center list that can allocate pairing keys to the second quantum security terminal; determines the shared key center based on the intersection of the first key center list and the second key center list; and sends a pairing distribution application to the shared key center; wherein the pairing distribution application carries the first network access identifier and the second network access identifier.

[0040] In the global quantum security network, when the second access base station receives a point-to-point communication request from the first access base station, it will process and respond to this request according to a series of steps to ensure that the second quantum security terminal can securely establish a communication connection with the first quantum security terminal.

[0041] Exemplarily, after receiving the point-to-point communication request, the second access base station queries the key center information library it maintains to obtain a list of key centers that can distribute pairing keys for the second quantum security terminal (referred to as the second key center list). This second key center list also contains information about multiple candidate key centers and their detailed information. These key centers all have the ability to generate and distribute pairing keys for the second quantum security terminal.

[0042] To ensure that the first and second quantum security terminals can use the same key center for key distribution, the second access base station compares the first and second key center lists to find their intersection. Key centers in this intersection can distribute pairing keys for both the first and second quantum security terminals. A key center is determined from this intersection as the shared key center, i.e., the key center used to distribute pairing keys for the first and second quantum security terminals.

[0043] In one example, if the network access identifier of the quantum security terminal includes country information, operator information, region information, and cell information, the second access base station determines the shared key center according to the intersection of the first key center list and the second key center list, including:

[0044] For each key center in the intersection, determining, based on the first network access identifier and the second network access identifier, a sum of distances from the first quantum security terminal and the second quantum security terminal to the key center;

[0045] Determining a key center corresponding to the sum of the minimum distances as the shared key center;

[0046] Wherein, for any key center, determining the distance between the quantum security terminal and the key center based on the network access identifier of the quantum security terminal includes:

[0047] If it is determined based on the network access identifier that the quantum security terminal and the key center are located in the same cell, then the distance is a pre-configured first-level distance;

[0048] If, based on the network access identifier, it is determined that the quantum security terminal and the key center are located in different cells of the same region, then the distance is a pre-configured second-level distance;

[0049] If, based on the network access identifier, it is determined that the quantum security terminal and the key center are located in different regions of the same operator, then the distance is a pre-configured third-level distance;

[0050] If, based on the network access identifier, it is determined that the quantum security terminal and the key center are located in different operators in the same country, the distance is a pre-configured fourth level distance;

[0051] If it is determined based on the network access identifier that the quantum security terminal and the key center are located in different countries, the distance is a pre-configured fifth-level distance;

[0052] In the order of the first level to the fifth level, the distance of the latter level is greater than twice the distance of the previous level, and the distance of the first level is greater than or equal to 0.

[0053] In this application, when determining a shared key center based on the intersection of the first key center list and the second key center list, the second access base station may consider the distances from the first quantum security terminal and the second quantum security terminal to the shared key center to minimize the sum of the distances. The distances may be calculated based on the network access identifier of the quantum security terminal, which includes country information, operator information, regional information, and cell information.

[0054] Exemplarily, the second access base station first finds the intersection of the first key center list and the second key center list. The key centers in these intersections are potential shared key center candidates. For each key center in the intersection, the second access base station needs to determine the distance from the first quantum security terminal to the key center (referred to as the first distance) based on the network access identifier of the first quantum security terminal and the geographical location information of the key center, and determine the distance from the second quantum security terminal to the key center (referred to as the second distance) based on the network access identifier of the second quantum security terminal and the geographical location information of the key center, and add these two distances to obtain the sum of the distances. After determining the sum of the distances corresponding to all key centers in the intersection, the second access base station can determine the key center corresponding to the minimum distance sum as the shared key center.

[0055] Specifically, when determining the distance between the quantum security terminal and the key center based on the network access identifier of the quantum security terminal and the geographic location information of the key center, if the quantum security terminal and the key center are located in the same cell, the distance is a pre-configured first-level distance, for example, 0 or a very small positive number. If the quantum security terminal and the key center are located in different cells in the same region, the distance is a second-level distance. If the quantum security terminal and the key center are located in different regions of the same operator, the distance is a third-level distance. If the quantum security terminal and the key center are located in different operators in the same country, the distance is a fourth-level distance. If the quantum security terminal and the key center are located in different countries, the distance is a fifth-level distance. These levels of distance are pre-configured, and in order from level 1 to level 5, the distance of each subsequent level is greater than twice the distance of the previous level, to ensure that geographical proximity has a significant impact on distance calculation.

[0056] In a possible implementation, if it is determined that the sum of the minimum distances corresponds to multiple key centers, then a key center may be randomly determined from the multiple key centers as the shared key center.

[0057] In another possible implementation, if the sum of the minimum distances is determined to correspond to multiple key centers, the second access base station may determine a shared key center from the multiple key centers in a round-robin manner. The specific implementation of the round-robin process may depend on various factors, such as the key center's ID, name, and timestamp of entry into the list. For example, if the multiple key centers are arranged in a certain order (e.g., in ascending order by ID), the first key center ranked first may be simply selected as the shared key center. The next time a shared key center needs to be selected, the next key center in the order is selected, and so on.

[0058] In one possible implementation, after determining the shared key center, the second access base station may record the selection result so that it can refer to or update the selection in future communication requests, for example, if the shared key center fails or performance degrades, a new shared key center may be reallocated.

[0059] Once the shared key center is determined, the second access base station will send a pairing distribution request to the shared key center. This pairing distribution request contains the network access identifiers of the first quantum security terminal and the second quantum security terminal (i.e., the first network access identifier and the second network access identifier), so that the shared key center can identify and process subsequent pairing key application requests from the two quantum security terminals.

[0060] In some possible implementations, the method further includes:

[0061] If the second access base station determines that there is no intersection between the first key center list and the second key center list, a request failure response is generated; and the request failure response is notified to the first quantum security terminal through the first access base station.

[0062] In a global quantum security network, if it discovers that there's no intersection between the first and second key center lists, this means there's no common key center that can simultaneously serve both quantum security terminals. In this case, the second access base station generates a request failure response. This request failure response can include a failure reason, allowing the first quantum security terminal to understand why the pairing communication request failed. The second access base station then sends this request failure response to the first access base station, which then forwards it to the first quantum security terminal.

[0063] S104: The shared key center generates the distribution identifier in response to the pairing distribution application; stores the first network access identifier, the second network access identifier, and the distribution identifier in correspondence; and sends the pairing distribution response carrying the distribution identifier to the second access base station.

[0064] In a global quantum security network, when two quantum security terminals request secure communication, the shared key center plays a crucial role. It handles the distribution and management of pairing keys, ensuring the confidentiality and integrity of point-to-point communication. When the shared key center receives a pairing distribution request from the second access base station, it generates a unique distribution identifier. This distribution identifier is used to track and verify each step of the key distribution process during the point-to-point communication, ensuring that only the two quantum security terminals in the point-to-point communication can request key distribution from the shared key center. The shared key center then stores the first network access identifier, the second network access identifier, and the newly generated distribution identifier in a corresponding manner. This correspondence ensures that subsequently generated keys are correctly distributed to the two parties requesting communication. Once the distribution identifiers are generated and the necessary correspondence is stored, the shared key center sends a pairing distribution response carrying the distribution identifier to the second access base station. This pairing distribution response notifies the second access base station that the key distribution process has begun and provides the distribution identifier for subsequent steps.

[0065] S105: The second access base station receives the pairing distribution response; sends a point-to-point pairing request to the second quantum security terminal; wherein the point-to-point pairing request carries the central address information of the shared key center, the distribution identifier, and the first communication protocol parameters.

[0066] After receiving the pairing distribution response sent by the shared key center, the second access base station can generate a point-to-point pairing request based on the distribution identifier, the central address information of the shared key center, and the first communication protocol parameter, and then send the point-to-point pairing request to the second quantum security terminal.

[0067] In one possible implementation, the second access base station may encrypt the point-to-point pairing request and send it to the second quantum security terminal based on a symmetric key paired with the second quantum security terminal. The second quantum security terminal may decrypt the received encrypted point-to-point pairing request based on the symmetric key paired with the second access base station to obtain the point-to-point pairing request.

[0068] S106: The second quantum security terminal receives the point-to-point pairing request; stores the center address information, the first communication protocol parameters, and the distribution identifier in correspondence; and sends the point-to-point pairing response to the second access base station; wherein the point-to-point pairing response carries the second communication protocol parameters of the second quantum security terminal.

[0069] Upon receiving a point-to-point pairing request, the second quantum security terminal can store the central address information, first communication protocol parameters, and distribution identifier carried in the point-to-point pairing request to ensure accurate and secure subsequent communication with the first quantum security terminal in accordance with established rules and protocols, and also to manage and maintain various communication sessions in the network. Subsequently, the second quantum security terminal will send a point-to-point pairing response to the second access base station. This point-to-point pairing response not only confirms acceptance of the first quantum security terminal's pairing communication request, but also carries the second quantum security terminal's communication protocol parameters (referred to as the second communication protocol parameters).

[0070] In a possible implementation, the second quantum security terminal may send a point-to-point pairing response to the second access base station using encrypted communication.

[0071] In one example, after the second quantum security terminal receives the point-to-point pairing request and before the corresponding storage of the center address information, the first communication protocol parameters, and the distribution identifier, the method further includes:

[0072] Determine support for a first communication protocol parameter; wherein the first communication protocol parameter includes one or more of the following: a key size of the pairing key, an encryption algorithm, a key expansion algorithm, a hash algorithm, and a current communication identifier.

[0073] To ensure the feasibility of subsequent point-to-point communication, in this application, upon receiving a point-to-point pairing request, the second quantum security terminal can, based on its own configuration and capabilities, check whether the first communication protocol parameters are within its supported range. If all or some of the first communication protocol parameters are not supported, the second quantum security terminal can take some measures, such as forwarding an error response to the first quantum security terminal through the second access base station, indicating which parameters are not supported, or attempting to negotiate the use of alternative communication protocol parameters. If the second quantum security terminal determines that the first communication protocol parameters are supported, it will continue to execute subsequent steps, namely, saving the corresponding center address information, the first communication protocol parameters, and the distribution identifier, and sending a point-to-point pairing response to the second access base station. In this way, it can be ensured that the communicating parties have reached a consensus on the communication protocol parameters before the communication begins, thereby avoiding compatibility issues or security vulnerabilities that may arise later.

[0074] S107: The second access base station receives the point-to-point pairing response; sends a pairing communication response to the first access base station, so as to send the pairing communication response to the first quantum security terminal through the first access base station; wherein, the pairing communication response carries the center address information, the second communication protocol parameters and the distribution identifier.

[0075] In a global quantum security network, when a second quantum security terminal successfully responds to a pairing communication request from a first quantum security terminal and sends a point-to-point pairing response containing its second communication protocol parameters, this point-to-point pairing response is first received by the second access base station. The second access base station then further processes this point-to-point pairing response, generates a pairing communication response, and forwards it to the first access base station for ultimate transmission to the first quantum security terminal. This pairing communication response carries the central address information of the shared key center, the second communication protocol parameters, and a distribution identifier.

[0076] Through the above method, negotiation between the first and second quantum security terminals can be achieved, providing a foundation for subsequent point-to-point communication. For each quantum security terminal in this point-to-point communication (including the first and second quantum security terminals), the quantum security terminal can obtain a pairing key from the assigned shared key center. Subsequently, based on this pairing key, it can conduct point-to-point communication with the other quantum security terminal.

[0077] The beneficial effects of this application are as follows:

[0078] 1. The first and second access base stations use their respective lists of key centers to search for a possible shared key center. This distributed resource matching approach significantly improves resource scheduling efficiency. Determining the shared key center through intersection also avoids the resource waste and increased complexity associated with selecting multiple key centers.

[0079] 2. The shared key center assigns a distribution identifier to each quantum security terminal in point-to-point communication, ensuring the security and traceability of the key distribution process. As a unique identifier for the session, the distribution identifier allows each key distribution operation to be accurately tracked and verified, effectively preventing the risk of key leakage and unauthorized access.

[0080] 3. During the point-to-point communication process, the first and second quantum security terminals also exchanged communication protocol parameters, which is not only the foundation for establishing a communication link but also the key to ensuring protocol compatibility. By negotiating their respective supported communication protocol parameters, the first and second quantum security terminals achieve seamless protocol integration while ensuring security, providing a strong guarantee for subsequent quantum secure communications.

[0081] 4. During the point-to-point communication negotiation process with the key center, the quantum security terminal is primarily responsible for receiving, storing, and transmitting information, while the complex calculation and matching tasks are performed by the reliable access base station and key center in the global quantum security network. This design reduces the complexity and cost requirements of the quantum security terminal, allowing more devices to easily access the global quantum security network and ensuring the security of the entire negotiation process.

[0082] Example 2:

[0083] To ensure the security of point-to-point communication, based on the above embodiment, in this application, if the quantum security terminal includes the first quantum security terminal and the second quantum security terminal, the quantum security terminal obtains the pairing key from the shared key center including:

[0084] The quantum security terminal sends an encryption key request to the shared key center through the access base station to which it is connected; wherein the encryption key request carries the distribution identifier, the network access identifier of the quantum security terminal, encryption key requirement information, and the center address information;

[0085] The shared key center allocates an encryption key to the quantum security terminal based on the received encryption key request, and stores the encryption key, the network access identifier, and the distribution identifier in correspondence; and sends the encryption key to the quantum security terminal through the access base station;

[0086] When the quantum security terminal obtains the encryption key, it encrypts a key download request based on the quantum key in the encryption key; wherein the key download request carries the pairing key requirement information and the distribution identifier; and sends the encrypted key download request to the shared key center according to the center address information;

[0087] The shared key center decrypts the received encrypted key download request based on the quantum key in the encryption key; obtains the pairing key allocated to the quantum security terminal according to the key download request; and encrypts the pairing key using the quantum key in the encryption key and sends it to the quantum security terminal;

[0088] The quantum security terminal decrypts the received encrypted pairing key based on the quantum key in the encryption key to obtain the pairing key.

[0089] To ensure that quantum secure terminals connected to the global quantum secure network can communicate quantum securely point-to-point, this application requires assigning a pairing key to each quantum secure terminal so that the two quantum secure terminals can communicate quantum securely based on the pairing key. The following describes the process by which any quantum secure terminal obtains the pairing key from the shared key center:

[0090] First, the quantum security terminal needs to request an encryption key from the shared key center. This encryption key is used to encrypt the distributed pairing key, thus preventing the pairing key from being transmitted in plaintext over the network. For example, the quantum security terminal can obtain the encryption key from the shared key center through the access base station it connects to. This prevents third-party devices from eavesdropping on communications between the quantum security terminal and the shared key center and obtaining the encryption key, thereby compromising the security of subsequent encryption of the pairing key using the encryption key. Specifically, the quantum security terminal generates an encryption key request and then sends it to the access base station it connects to. The encryption key request carries a distribution identifier, encryption key requirement information, the quantum security terminal's network access identifier, and the shared key center's central address information. This encryption key requirement information guides the shared key center in allocating encryption keys and includes requirements for encryption key type, length, size, and other requirements. Upon receiving the encryption key request, the access base station can forward it to the shared key center based on the central address information. The shared key center receives the encryption key request forwarded by the access base station, and based on the encryption key request, allocates an encryption key to the quantum security terminal, and saves the encryption key, network access identifier and distribution identifier in correspondence.

[0091] In a possible implementation, when the shared key center determines that the distribution identifier is stored and the distribution identifier is associated with the network access identifier, an encryption key is allocated to the quantum security terminal based on the encryption key requirement information.

[0092] After the shared key center obtains the encryption key assigned to the quantum security terminal, it can transmit the encryption key to the access base station so that the encryption key can be sent to the quantum security terminal through the access base station.

[0093] After obtaining the encryption key, the quantum security terminal can use it to conduct encrypted communication with the shared key center. For example, the quantum security terminal can generate a key download request based on the pairing key requirement information and the distribution identifier. This key download request is encrypted based on the quantum key in the encryption key. The encrypted key download request is then sent to the shared key center according to the center's address information.

[0094] In one possible implementation, after the quantum security terminal obtains the encryption key, it can determine whether the encryption key passes the security verification. Exemplarily, the security verification includes one or more of the following:

[0095] 1. Integrity check.

[0096] To ensure that the encryption key has not been tampered with or damaged during transmission or storage, in this application, the quantum security terminal can perform an integrity check on the received encryption key. For example, by performing a hash check on the encryption key to determine whether the encryption key passes the integrity check. If the encryption key passes the integrity check, the quantum security terminal retains the encryption key; if the encryption key fails the integrity check, the quantum security terminal discards the encryption key.

[0097] 2. Consistency check

[0098] To prevent errors or inconsistencies in the distribution or storage of encryption keys, the quantum security terminal can also perform consistency checks on the encryption keys with the access base station. For example, the quantum security terminal can compare the hash value of the encryption key with the hash value of the encryption key received from the access base station to determine whether the encryption key meets the consistency check. If the encryption key passes the consistency check, the quantum security terminal retains the encryption key; if the encryption key fails the consistency check, the quantum security terminal discards the encryption key.

[0099] It should be noted that the quantum security terminal can perform security verification on the encryption key using one or more of the methods described above. When this security verification includes multiple verification methods, namely, combining integrity and consistency checks to ensure the security of the encryption key, the quantum security terminal first performs an integrity check to ensure that the encryption key has not been tampered with during transmission or storage. Then, it performs a consistency check to ensure the consistency of the encryption key with the encryption key generated by the shared key center. If the encryption key passes both checks, it is considered secure and reliable and can be used for subsequent encrypted communications. If the encryption key fails any of the checks, appropriate security measures must be taken, such as discarding the encryption key, requesting a new encryption key, or reporting a security incident.

[0100] After receiving the encrypted key download request sent by the quantum security terminal, the shared key center can obtain the encryption key paired with the quantum security terminal. For example, it can obtain the stored encryption key associated with the network access identifier. Then, based on the encryption key, it decrypts the encrypted key download request to obtain the key download request. Based on the key download request, it obtains the pairing key assigned to the quantum security terminal. For example, the shared key center can determine whether it has a stored pairing key associated with the distribution identifier. If so, it uses the associated pairing key as the pairing key for the quantum security terminal. If not, it allocates a pairing key to the quantum security terminal based on the pairing key requirement information carried in the key download request and stores the pairing key in association with the distribution identifier. After obtaining the pairing key, the shared key center encrypts the pairing key using the quantum key in the encryption key paired with the quantum security terminal and sends it to the quantum security terminal.

[0101] The quantum security terminal receives the encrypted pairing key sent by the shared key center and can decrypt the encrypted pairing key based on the quantum key in the encryption key to obtain the pairing key.

[0102] In one possible implementation, after obtaining the pairing key, the quantum security terminal may also perform security verification on the pairing key. The method for performing security verification on the pairing key by the quantum security terminal can refer to the method for performing security verification on the encryption key described above. For details, please refer to the above embodiments and will not be repeated here.

[0103] It should be noted that because a reliable encrypted communication channel has not yet been established between a quantum security terminal and its peer, communication between the two quantum security terminals is not absolutely secure and reliable. Therefore, in this application, a shared key center can be introduced as a trusted third party, and pairing key consistency verification can be performed between the quantum security terminal and the shared key center. This ensures that the pairing keys between the two quantum security terminals in point-to-point communication are consistent, effectively reducing these security risks.

[0104] In some possible implementations, after a quantum security terminal successfully downloads a paired key, the shared key center records the quantum security terminal's key download status as "successfully downloaded." For example, "successfully downloaded" is associated with the distribution identifier and the quantum security terminal's network access identifier.

[0105] To ensure that the peer quantum security terminal in point-to-point communication has successfully downloaded the pairing key, in this application, the quantum security terminal can generate a query status request based on the distribution identifier and the network access identifier of the peer quantum security terminal. The query status request is then encrypted using the quantum key in the stored encryption key and sent to the shared key center.

[0106] After receiving the encrypted query status request, the shared key center can decrypt it using the same quantum key. It then locates the corresponding key distribution record based on the distribution identifier carried in the query status request and, based on the network access identifier carried in the query status request, obtains the target key download status of the peer quantum security terminal. Using the quantum key in the encryption key, the shared key center encrypts the query status response carrying the target key download status and sends it to the quantum security terminal that initiated the request.

[0107] After receiving the encrypted query status response, the quantum security terminal also uses the same quantum key to decrypt the encrypted query status response. Based on the decrypted content (i.e., the target key download status), it determines whether the quantum security terminal on the other end has successfully downloaded the pairing key. If the target key download status indicates that the quantum security terminal on the other end has successfully downloaded the pairing key, then the quantum security terminal can determine that the two parties have the ability to communicate in point-to-point quantum encryption. If the target key download status indicates that the quantum security terminal on the other end has not successfully downloaded the pairing key, the quantum security terminal can choose to repeatedly send the query status request until it confirms that the quantum security terminal on the other end has successfully downloaded the pairing key. This repeated query mechanism ensures that the communicating parties can conduct encrypted communication when the key is ready.

[0108] Example 3:

[0109] The following describes the specific peer-to-peer communication key center negotiation method provided by this application through specific embodiments. Figure 2 A schematic diagram of a specific point-to-point communication key center negotiation process provided in an embodiment of the present application, the process includes:

[0110] S201: The first quantum security terminal sends a pairing communication request to the first access base station to which it is connected.

[0111] The pairing communication application carries a symmetric allocation identifier, a first communication protocol parameter, a first network access identifier of the first quantum security terminal, and a second network access identifier of the second quantum security terminal.

[0112] S202: The first access base station obtains a first key center list that can allocate a pairing key to the first quantum security terminal.

[0113] S203: The first access base station sends a point-to-point communication request to the second access base station to which the second quantum security terminal accesses through the second network access identifier.

[0114] The point-to-point communication request carries a first network access identifier, a first communication protocol parameter, and a first key center list.

[0115] S204: The second access base station obtains a second key center list that can allocate pairing keys to the second quantum security terminal, and determines whether there is an intersection between the first key center list and the second key center list. If so, execute S205; otherwise, execute S207.

[0116] S205: The second access base station sends a request failure response to the first access base station.

[0117] S206: The first access base station forwards the request failure response to the first quantum security terminal.

[0118] S207: For each key center in the determined intersection, the second access base station determines the sum of the distances from the first quantum security terminal and the second quantum security terminal to the key center based on the first network access identifier and the second network access identifier.

[0119] S208: The second access base station determines a key center corresponding to the sum of the minimum distances as the shared key center.

[0120] In a possible implementation, if the sum of the minimum distances corresponds to multiple key centers, a shared key center is determined from the multiple key centers in a round-robin manner.

[0121] S209: The second access base station sends a pairing distribution application to the shared key center.

[0122] The pairing distribution application carries the first network access identifier and the second network access identifier.

[0123] S210: The shared key center generates a distribution identifier in response to the pairing distribution application, and stores the first network access identifier, the second network access identifier, and the distribution identifier in correspondence.

[0124] S211: The shared key center sends a pairing distribution response carrying a distribution identifier to the second access base station.

[0125] S212: The second access base station sends a point-to-point pairing request to the second quantum security terminal.

[0126] The point-to-point pairing request carries the central address information of the shared key center, the distribution identifier, and the first communication protocol parameter.

[0127] S213: When the second quantum security terminal determines that it supports the first communication protocol parameters, it stores the center address information, the first communication protocol parameters, and the distribution identifier in correspondence.

[0128] S214: The second quantum security terminal sends a point-to-point pairing response to the second access base station.

[0129] The point-to-point pairing response carries the second communication protocol parameter of the second quantum security terminal.

[0130] S215: The second access base station sends a pairing communication response to the first access base station.

[0131] The pairing communication response carries the center address information, the second communication protocol parameters and the distribution identifier.

[0132] S216: The first access base station sends a pairing communication response to the first quantum security terminal.

[0133] Based on the above embodiment, the first quantum security terminal and the second quantum security terminal obtain the central address information and distribution identifier of the shared key center. Both quantum security terminals can request a pairing key from the shared key center using the distribution identifier and central address information. The following describes the process of either quantum security terminal obtaining a pairing key from the shared key center. Figure 3 A schematic diagram of a specific pairing key request process provided in an embodiment of the present application includes:

[0134] S301: The quantum security terminal sends an encryption key request to the access base station to which the quantum security terminal accesses.

[0135] Among them, the encryption key request carries the distribution identifier, the network access identifier of the quantum security terminal, the encryption key requirement information and the central address information of the shared key center.

[0136] S302: The access base station forwards the encryption key request to the shared key center based on the center address information carried in the encryption key request.

[0137] S303: The shared key center allocates an encryption key to the quantum security terminal based on the received encryption key request, and stores the encryption key, network access identifier, and distribution identifier in correspondence.

[0138] S304: The shared key center sends the encryption key to the access base station.

[0139] S305: The access base station encrypts the encryption key based on the symmetric key paired with the quantum security terminal and sends it to the quantum security terminal.

[0140] S306: When the quantum security terminal obtains the encryption key, it performs an integrity check on the encryption key and performs a consistency check on the encryption key with the access base station.

[0141] S307: When the quantum security terminal determines that the encryption key passes the integrity check and the consistency check, it encrypts the key download request based on the quantum key in the encryption key.

[0142] The key download request carries pairing key requirement information and a distribution identifier.

[0143] S308: The quantum security terminal sends an encrypted key download request to the shared key center according to the center address information.

[0144] S309: The shared key center decrypts the received encrypted key download request based on the quantum key in the encryption key.

[0145] S310: The shared key center obtains the pairing key allocated to the quantum security terminal according to the key download request.

[0146] S311: The shared key center encrypts the pairing key using the quantum key in the encryption key and sends it to the quantum security terminal.

[0147] S312: The quantum security terminal decrypts the received encrypted pairing key based on the quantum key in the encryption key, performs an integrity check on the pairing key, and performs a consistency check on the pairing key with the shared key center.

[0148] S313: When it is determined that the paired key passes the integrity check and the consistency check, the shared key center records the key download status of the quantum security terminal as successful download.

[0149] S314: The quantum security terminal encrypts and sends a query status request to the shared key center using the quantum key in the encryption key.

[0150] The query status request carries the distribution identifier and the network access identifier of the quantum security terminal on the other end.

[0151] S315: The shared key center decrypts the received encrypted query status request based on the quantum key in the encryption key, and obtains the target key download status corresponding to the network access identifier based on the distribution identifier.

[0152] S316: The shared key center encrypts the query status response carrying the target key download status and sends it to the quantum security terminal based on the quantum key in the encryption key.

[0153] S317: The quantum security terminal decrypts the received encrypted query status response based on the quantum key in the encryption key, and determines whether the target key download status indicates that the quantum security terminal with the network access identification has successfully downloaded the paired key. If so, execute S318; otherwise, execute S314.

[0154] S318: The quantum security terminal determines that the quantum security terminal and the quantum security terminal identified by the network access identifier have point-to-point quantum encryption communication capabilities.

[0155] It should be noted that after the quantum security terminal determines that the quantum security terminal and the quantum security terminal of the network access identifier have the capability of point-to-point quantum encryption communication, the quantum security terminal can conduct point-to-point communication with the quantum security terminal of the network access identifier based on the pairing key.

Claims

1. A method for negotiating a key center for point-to-point communication, characterized in that: The method comprises: The first quantum security terminal sends a pairing communication request to the first access base station to which it is connected; wherein the pairing communication request carries a symmetric allocation identifier, a first communication protocol parameter, a first network access identifier of the first quantum security terminal, and a second network access identifier of the second quantum security terminal; The first access base station receives the pairing communication application; obtains a first key center list that can allocate a pairing key to the first quantum security terminal; and sends a point-to-point communication request to a second access base station connected to the second quantum security terminal using the second network access identifier; wherein the point-to-point communication request carries the first network access identifier, the first communication protocol parameters, and the first key center list; The second access base station receives the point-to-point communication request; obtains a second key center list that can allocate a pairing key to the second quantum security terminal; determines a shared key center based on the intersection of the first key center list and the second key center list; and sends a pairing distribution application to the shared key center; wherein the pairing distribution application carries the first network access identifier and the second network access identifier; The shared key center generates a distribution identifier in response to the pairing distribution application; stores the first network access identifier, the second network access identifier, and the distribution identifier in correspondence; and sends a pairing distribution response carrying the distribution identifier to the second access base station; The second access base station receives the pairing distribution response; sends a point-to-point pairing request to the second quantum security terminal; wherein the point-to-point pairing request carries the central address information of the shared key center, the distribution identifier, and the first communication protocol parameter; The second quantum security terminal receives the point-to-point pairing request; stores the center address information, the first communication protocol parameters, and the distribution identifier in correspondence; and sends the point-to-point pairing response to the second access base station; wherein the point-to-point pairing response carries the second communication protocol parameters of the second quantum security terminal; The second access base station receives the point-to-point pairing response; sends a pairing communication response to the first access base station, so as to send the pairing communication response to the first quantum security terminal through the first access base station; wherein the pairing communication response carries the center address information, the second communication protocol parameters and the distribution identifier.

2. The method according to claim 1, wherein The method further comprises: If the second access base station determines that there is no intersection between the first key center list and the second key center list, a request failure response is generated; and the request failure response is notified to the first quantum security terminal through the first access base station.

3. The method according to claim 1, wherein If the network access identifier of the quantum security terminal includes country information, operator information, region information, and cell information, the second access base station determines the shared key center according to the intersection of the first key center list and the second key center list, including: For each key center in the intersection, determining, based on the first network access identifier and the second network access identifier, a sum of distances from the first quantum security terminal and the second quantum security terminal to the key center; Determining a key center corresponding to the sum of the minimum distances as the shared key center; Wherein, for any key center, determining the distance between the quantum security terminal and the key center based on the network access identifier of the quantum security terminal includes: If it is determined based on the network access identifier that the quantum security terminal and the key center are located in the same cell, then the distance is a pre-configured first-level distance; If, based on the network access identifier, it is determined that the quantum security terminal and the key center are located in different cells of the same region, then the distance is a pre-configured second-level distance; If, based on the network access identifier, it is determined that the quantum security terminal and the key center are located in different regions of the same operator, then the distance is a pre-configured third-level distance; If, based on the network access identifier, it is determined that the quantum security terminal and the key center are located in different operators in the same country, the distance is a pre-configured fourth level distance; If it is determined based on the network access identifier that the quantum security terminal and the key center are located in different countries, the distance is a pre-configured fifth-level distance; In the order of the first level to the fifth level, the distance of the latter level is greater than twice the distance of the previous level, and the distance of the first level is greater than or equal to 0.

4. The method according to claim 3, wherein The second access base station determines a key center corresponding to the sum of the minimum distances as the shared key center, including: If the sum of the minimum distances corresponds to multiple key centers, the shared key center is determined from the multiple key centers in a round-robin manner.

5. The method according to claim 1, wherein After the second quantum security terminal receives the point-to-point pairing request and before the center address information, the first communication protocol parameters, and the distribution identifier are correspondingly saved, the method further includes: Determine support for the first communication protocol parameters; wherein the first communication protocol parameters include one or more of the following: the key size of the pairing key, the encryption algorithm, the key expansion algorithm, the hash algorithm, and the current communication identifier.

6. The method according to claim 1, wherein If the quantum security terminal includes the first quantum security terminal and the second quantum security terminal, obtaining, by the quantum security terminal, a pairing key from the shared key center includes: The quantum security terminal sends an encryption key request to the shared key center through the access base station to which it is connected; wherein the encryption key request carries the distribution identifier, the network access identifier of the quantum security terminal, encryption key requirement information, and the center address information; The shared key center allocates an encryption key to the quantum security terminal based on the received encryption key request, and stores the encryption key, the network access identifier, and the distribution identifier in correspondence; and sends the encryption key to the quantum security terminal through the access base station; When the quantum security terminal obtains the encryption key, it encrypts a key download request based on the quantum key in the encryption key; wherein the key download request carries the pairing key requirement information and the distribution identifier; and sends the encrypted key download request to the shared key center according to the center address information; The shared key center decrypts the received encrypted key download request based on the quantum key in the encryption key; obtains the pairing key allocated to the quantum security terminal according to the key download request; and encrypts the pairing key using the quantum key in the encryption key and sends it to the quantum security terminal; The quantum security terminal decrypts the received encrypted pairing key based on the quantum key in the encryption key to obtain the pairing key.

7. The method according to claim 6, wherein After the quantum security terminal decrypts the received encrypted pairing key based on the quantum key in the encryption key to obtain the pairing key, the method further includes: The shared key center and the quantum security terminal determine that the pairing key passes the consistency check.

8. The method according to claim 7, wherein The method further comprises: The shared key center records the key download status of the quantum security terminal as successful download; The quantum security terminal encrypts and sends a query status request to the shared key center using the quantum key in the encryption key; wherein the query status request carries the distribution identifier and the network access identifier of the quantum security terminal of the other end; The shared key center decrypts the received encrypted query status request based on the quantum key in the encryption key; obtains the target key download status corresponding to the network access identifier based on the distribution identifier; and encrypts the query status response carrying the target key download status and sends it to the quantum security terminal based on the quantum key in the encryption key; The quantum security terminal decrypts the received encrypted query status response based on the quantum key in the encryption key; if it is determined that the target key download status represents that the quantum security terminal of the network access identifier has successfully downloaded the pairing key, it is determined that the quantum security terminal and the quantum security terminal of the network access identifier have point-to-point quantum encryption communication capabilities; if it is determined that the target key download status represents that the quantum security terminal of the network access identifier has not successfully downloaded the pairing key, the query status request is repeatedly sent to the shared key center in an encrypted manner until it is determined that the quantum security terminal and the quantum security terminal of the network access identifier have point-to-point quantum encryption communication capabilities.

Citation Information

Patent Citations

  • Quantum session key distribution method and system

    CN111756529A

  • PSI method and device with wrong pairing key negotiation based on key multiplexing

    CN118101177A