Method, apparatus, device, medium and product based on key communication

By determining the first key and generating the second key based on the number of times the quantum key is used, the problems of high cost and reduced USIM card life caused by frequent key refills are solved, and the multiple use of keys in the key resource pool and data security are realized.

CN119299089BActive Publication Date: 2026-04-24CHINA MOBILE COMM LTD RES INST +1
View PDF 3 Cites 0 Cited by

Patent Information

Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
CHINA MOBILE COMM LTD RES INST
Filing Date
2024-09-30
Publication Date
2026-04-24

AI Technical Summary

Technical Problem

In existing technologies, the frequent use of quantum keys leads to high key refill costs, and frequent refills also reduce the lifespan of the USIM card.

Method used

By determining the first key based on the number of times the quantum key is used in business applications, and generating a second key for encrypted communication, the multiple uses of each key in the key resource pool are realized, reducing the key filling frequency.

Benefits of technology

This increased the number of times the key was used and reduced the frequency of key refilling, thus ensuring the security of business data.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN119299089B_ABST
    Figure CN119299089B_ABST
Patent Text Reader

Abstract

The present disclosure relates to the technical field of information security, and particularly provides a method, device, equipment, medium and product based on key communication, comprising: in response to a key acquisition request of a business application, determining at least one key corresponding to the business application; determining a first key to be used currently based on the number of times of use of each key in a key resource pool by the business application; generating a target key based on the application identifier of the business application and the first key; encrypting and / or integrity protecting the business data of the business application according to the second key, and sending the encrypted and / or integrity protected business data to a business platform for processing.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This disclosure relates to the field of information security technology, and in particular to a method, apparatus, device, medium and product based on key communication. Background Technology

[0002] With the rapid development of internet technology, the cybersecurity risks of information systems continue to increase. Typically, it is necessary to encrypt the data to be transmitted using a key before transmission. For example, quantum key distribution can be used to encrypt the data to be transmitted, enabling business systems to achieve unconditional secure communication.

[0003] In existing technologies, each key needs to be discarded after use. For example, when using quantum key distribution for encryption, the key usage frequency is high when there is a large volume of business and many business applications. This leads to the need for frequent key refills to the USIM (Universal Subscriber Identity Module). However, key refills are costly, and repeated key refills can also reduce the lifespan of the USIM card. Summary of the Invention

[0004] This disclosure is made in view of the above-mentioned problems. This disclosure provides a method, apparatus, device, medium, and product based on key communication.

[0005] According to one aspect of this disclosure, a key-based communication method is provided for use in a secure terminal, comprising:

[0006] In response to a key acquisition request from a business application, at least one key corresponding to the business application is determined;

[0007] Based on the number of times each key in the key resource pool is used by the business application, the first key to be used is determined.

[0008] A second key is generated based on the application identifier of the business application and the first key;

[0009] The business data of the business application is encrypted and / or protected for integrity using the second key, and the encrypted and / or protected business data is sent to the business platform for processing.

[0010] Furthermore, according to another embodiment of one aspect of this disclosure, generating the second key based on the application identifier of the business application and the first key includes:

[0011] The first key and key generation parameters are processed according to a preset generation algorithm to obtain the second key; wherein, the key generation parameters include at least one of the following: a target random number, a first identifier, and the application identifier, wherein the first identifier is used to indicate the global user identification card identifier set in the secure terminal.

[0012] Furthermore, according to another embodiment of one aspect of this disclosure, determining the first key to be used currently based on the number of times the business application uses each key in the key resource pool includes:

[0013] Based on the key acquisition request, the security context information of the business application is obtained; wherein, the security context information is used to indicate the usage of the key by the business application, and the usage includes at least one of the following: the number of times the key is used;

[0014] Based on the lookup results of the security context information and the number of times the business application uses each key, the first key to be used is determined.

[0015] Furthermore, according to another embodiment of one aspect of this disclosure, determining the first key to be used currently based on the lookup result of the security context information and the number of times the business application uses each of the keys includes:

[0016] If the security context information is not found, determine any one of the keys corresponding to the business application as the first key, and set the first number of times the first key is used and the first maximum number of times it is used to obtain the security context information.

[0017] Furthermore, according to another embodiment of one aspect of this disclosure, determining the first key to be used currently based on the acquisition result of the security context information and the number of times the business application uses each of the keys includes:

[0018] If the security context information is found, the third key used in the last communication with the business platform is determined based on the security context information.

[0019] Determine the second number of times the business application uses the third key, and determine the second maximum number of times the business application uses the third key;

[0020] The second number of uses is incremented to obtain the third number of uses;

[0021] If the third number of uses is less than the second maximum number of uses, the third key is determined as the first key.

[0022] Furthermore, according to another embodiment of one aspect of this disclosure, the method further includes:

[0023] If it is determined that the third number of uses is greater than or equal to the second maximum number of uses, the key that has not been used by the business application among the at least one key is determined as the first key.

[0024] Furthermore, according to another embodiment of one aspect of this disclosure, the method further includes:

[0025] When the security terminal meets the key injection conditions, it initiates a key injection request to the business platform; wherein the key injection conditions include at least one of the following: the total number of times all keys of at least one business application are used exceeds the corresponding maximum number of times, or the total number of times all keys of each business application are used exceeds the corresponding maximum number of times.

[0026] Furthermore, according to another embodiment of one aspect of this disclosure, the method further includes:

[0027] During the process of sending the encrypted business data to the business platform for processing, a business access request is sent; wherein, the business access request includes at least one of the following: the identifier of the first key, the application identifier of the business application, a target random number, the first identifier, the real-time usage count of the first key, the maximum usage count of the first key, and a preset generation algorithm for the second key; the target random number is a parameter used to generate the second key.

[0028] According to another aspect of this disclosure, a key-based communication method is provided for application in a business platform, comprising:

[0029] Obtain encrypted business data sent by a secure terminal;

[0030] Determine the decryption key for the encrypted business data;

[0031] The encrypted business data is decrypted using the decryption key to obtain the business data.

[0032] Furthermore, according to another embodiment of one aspect of this disclosure, determining the decryption key for the encrypted business data includes:

[0033] Send a key acquisition request to the target business platform; wherein the key acquisition request includes at least one of the following: the identifier of the first key, the application identifier of the business application, a target random number, the first identifier, the real-time usage count of the first key, the maximum usage count of the first key, and a preset generation algorithm for the second key; the target random number is a parameter used to generate the second key;

[0034] Obtain the decryption key returned by the target business platform based on the key acquisition request.

[0035] Furthermore, according to another embodiment of one aspect of this disclosure, determining the decryption key for the encrypted business data includes:

[0036] If the first key meets the policy requirements based on the key acquisition request, the first key is processed according to a preset generation algorithm to obtain the decryption key; wherein, the policy requirements are related to the number of times the business application uses the first key in real time.

[0037] Furthermore, according to another embodiment of one aspect of this disclosure, determining the decryption key for the encrypted business data includes:

[0038] If, based on the key acquisition request, it is determined that the first key does not meet the policy requirements, an error message is sent to the second key service platform; wherein, the error message is used to indicate that the decryption key cannot be determined.

[0039] According to another aspect of this disclosure, a key-based communication device is provided, comprising:

[0040] A response module is used to respond to a key acquisition request from a business application and determine at least one key corresponding to the business application.

[0041] The first determining module is used to determine the first key to be used currently based on the number of times the business application uses each key in the key resource pool;

[0042] The generation module is used to generate a second key based on the application identifier of the business application and the first key;

[0043] The encryption module is used to encrypt and / or protect the integrity of the business data of the business application according to the second key, and send the encrypted and / or integrity-protected business data to the business platform for processing.

[0044] According to another aspect of this disclosure, a key-based communication device is provided, comprising:

[0045] The acquisition module is used to acquire encrypted business data sent by the secure terminal;

[0046] The second determining module is used to determine the decryption key of the encrypted business data;

[0047] The decryption module is used to decrypt the encrypted business data using the decryption key to obtain the business data.

[0048] According to another aspect of this disclosure, a computer device is provided, including a memory, a processor, and a computer program stored in the memory, wherein the processor executes the computer program to implement the steps of a method for determining a log template.

[0049] According to another aspect of this disclosure, a computer-readable storage medium is provided having a computer program / instructions stored thereon, which, when executed by a processor, implements the steps of a method for determining a log template.

[0050] According to another aspect of this disclosure, a computer program product is provided, including a computer program / instructions that, when executed by a processor, implement steps of a method for determining a log template.

[0051] As will be described in detail below, a method, apparatus, device, medium, and product based on quantum key communication according to embodiments of this disclosure are disclosed. By determining a first key based on the number of times a key is used by a business application, keys that meet the usage requirements can be quickly filtered out for the business application. By generating a second key for encrypted communication using the first key and an application identifier, multiple uses of each key in the key resource pool can be achieved, thereby increasing the usage frequency of each key in the key resource pool and reducing the key replenishment frequency. Especially for quantum key-based communication processes, the security of business data can be further guaranteed because different second keys are generated.

[0052] It should be understood that both the foregoing general description and the following detailed description are exemplary and intended to provide further illustration of the claimed technology. Attached Figure Description

[0053] The above and other objects, features, and advantages of this disclosure will become more apparent from the more detailed description of the embodiments thereof in conjunction with the accompanying drawings. The drawings are provided to further illustrate the embodiments of this disclosure and form part of the specification. They are used together with the embodiments of this disclosure to explain the disclosure and do not constitute a limitation thereof. In the drawings, the same reference numerals generally represent the same components or steps.

[0054] Figure 1 A flowchart illustrating a quantum key-based communication method provided in this disclosure.

[0055] Figure 2 A flowchart of another quantum key-based communication method provided in an embodiment of this disclosure.

[0056] Figure 3 The flowchart illustrates the interaction of a key-based communication system provided in this embodiment.

[0057] Figure 4 This is a schematic diagram of a quantum key-based communication device provided in an embodiment of this disclosure.

[0058] Figure 5 A schematic diagram of another quantum key-based communication device provided in an embodiment of this disclosure.

[0059] Figure 6 This is a schematic diagram of an electronic device provided in an embodiment of the present disclosure. Detailed Implementation

[0060] To make the objectives, technical solutions, and advantages of this disclosure more apparent, exemplary embodiments according to this disclosure will now be described in detail with reference to the accompanying drawings. Obviously, the described embodiments are merely some embodiments of this disclosure, and not all embodiments of this disclosure. It should be understood that this disclosure is not limited to the exemplary embodiments described herein.

[0061] It should be noted that similar labels and letters in the following figures indicate similar items. Therefore, once an item is defined in one figure, it does not need to be further defined and explained in subsequent figures.

[0062] In this document, the term "and / or" merely describes a relationship, indicating that three relationships can exist. For example, A and / or B can represent three cases: A alone, A and B simultaneously, and B alone. Furthermore, the term "at least one" in this document means any combination of at least two of any one or more elements. For example, including at least one of A, B, and C can mean including any one or more elements selected from the set consisting of A, B, and C.

[0063] Research has revealed that with the rapid development of internet technology, the cybersecurity risks of information systems continue to increase. Quantum secure keys, based on the principles of quantum mechanics, utilize the non-cloning and non-measurable properties of quantum states to achieve a novel encrypted communication method. By employing quantum secure keys, business systems can achieve unconditional secure communication. Furthermore, quantum secure keys offer rapid distribution, enabling real-time encrypted communication and improving communication efficiency.

[0064] In existing technologies, each quantum key needs to be discarded after use. With high business volume and numerous applications, quantum keys are used frequently, leading to the need for frequent key refills to the USIM (Universal Subscriber Identity Module). However, key refilling is costly, and repeated refills can reduce the lifespan of the USIM card.

[0065] Based on the above research, this disclosure provides a method for quantum key communication. By determining the first key based on the number of times the quantum key is used by the business application, a quantum key that meets the application's requirements can be quickly selected. By generating a second key for encrypted communication using the first key and an application identifier, each quantum key in the quantum key pool can be used multiple times, thereby increasing the usage frequency of each quantum key and reducing the key replenishment frequency. Since the generated second key is different for each quantum communication process, the security of the business data can be further guaranteed.

[0066] To facilitate understanding of this embodiment, a quantum key-based communication method disclosed in this disclosure will first be described in detail. The execution entity of the quantum key-based communication method provided in this disclosure is generally an electronic device with a certain computing power. In some possible implementations, this quantum key-based communication method can be implemented by a processor calling computer-readable instructions stored in memory.

[0067] Figure 1 The diagram shows a flowchart of a key-based communication method provided in an embodiment of this disclosure. The method includes steps S101 to S104 and is applied to a secure terminal, wherein:

[0068] S101. In response to the key acquisition request of the business application, determine at least one key corresponding to the business application.

[0069] In the embodiments of this disclosure, when a business application installed on a secure terminal (i.e., a quantum secure terminal, Quantum Secure Equipment, QSE) needs to conduct quantum key-based secure communication with a business platform (i.e., a quantum cryptography service platform), a key acquisition request can be generated. The key acquisition request carries the application identifier of the business application.

[0070] Afterwards, business applications can send key acquisition requests to the quantum key management application on the global user identification card set in the secure terminal.

[0071] Here, after the quantum key management application receives a key acquisition request, it can determine at least one key (i.e., a quantum key) corresponding to the business application from the locally stored key resource pool based on the application identifier carried in the key acquisition request.

[0072] Here, the key resource pool includes at least one key sub-resource pool. When the key resource pool includes one key sub-resource pool (i.e., there exists one key resource pool), at least one key corresponding to the business application can be determined from the key resource pool in the following way:

[0073] Method 1: Some or all of the keys in the key resource pool can be identified as at least one key.

[0074] In this approach, all business applications installed on a secure terminal can share the quantum keys in the key resource pool.

[0075] Method 2: At least one key can be identified from the key resource pool that matches the business application.

[0076] In this approach, different keys from the key resource pool can be allocated to different business applications.

[0077] When the key resource pool includes multiple key sub-resource pools, one or more keys can be assigned to each key sub-resource pool. Then, each key sub-resource pool is matched with all business applications installed on the secure terminal to determine the key sub-resource pool dedicated to each business application. At this point, the quantum key in each business application's dedicated key sub-resource pool can be identified as at least one key.

[0078] S102. Based on the number of times each key in the key resource pool is used by the business application, determine the first key to be used.

[0079] In the embodiments of this disclosure, firstly, the quantum key management application can determine the key sub-resource pool corresponding to the business application. Secondly, it determines the number of times each key that the business application can use in the key sub-resource pool is used. Finally, based on the number of times each key that the business application can use is used, the key whose usage count at the current moment meets a preset condition is determined as the first key. The first key is a quantum key.

[0080] The preset usage limit indicates that the real-time usage count of a key is less than its maximum usage count. The maximum usage count can be determined based on the security requirements of the business application. The maximum usage count for the same key varies for different business applications.

[0081] S103. Generate a second key based on the application identifier and the first key of the business application.

[0082] In embodiments of this disclosure, a quantum key management application on a secure terminal can determine the key generation parameters of a first key and generate a second key based on the first key for the business application and the key generation parameters. The second key is a quantum key.

[0083] The key generation parameters include at least one of the following: a first identifier, or an application identifier for the business application.

[0084] S104. Encrypt and / or protect the integrity of the business data of the business application according to the second key, and send the encrypted and / or integrity-protected business data to the business platform for processing.

[0085] In embodiments of this disclosure, a secure terminal can use a second key to protect (i.e. encrypt) business data to obtain encrypted business data (i.e., ciphertext of business data).

[0086] Here, a secure terminal can send a service access request to the service platform. This service access request carries encrypted service data.

[0087] In the embodiments of this disclosure, firstly, in response to a key acquisition request from a business application, at least one key corresponding to the business application is determined; secondly, based on the number of times the business application uses each key in the key resource pool, a first key to be used is determined; thirdly, based on the application identifier of the business application and the first key, a second key is generated; finally, the business data of the business application is encrypted and / or its integrity is protected according to the second key, and the encrypted and / or integrity-protected business data is sent to the business platform for processing.

[0088] In the above embodiments, by determining the first key based on the number of times the key is used by the business application, keys that meet the usage requirements can be quickly filtered out for the business application. Generating a second key for encrypted communication using the first key and the application identifier allows for multiple uses of each key in the key resource pool, thereby increasing the usage frequency of each key and reducing the key replenishment frequency. Especially for quantum key-based communication processes, the security of business data can be further guaranteed because the generated second key is different.

[0089] In an optional implementation, the above steps generate a second key based on the application identifier of the business application and the first key, specifically including the following steps:

[0090] The first key and key generation parameters are processed according to a preset generation algorithm to obtain the second key; wherein the key generation parameters include at least one of the following: target random number, first identifier, application identifier, the first identifier being used to indicate the global user identification card identifier set in the secure terminal.

[0091] In the embodiments of this disclosure, the quantum key management application in the global user identification card of the secure terminal can generate a target random number. The target random number can be a timestamp.

[0092] Here, the preset generation algorithms include: KDF (Key Derivation Function) algorithm and hash algorithm. Among them, the KDF algorithm includes: HMAC_SHA256 encryption algorithm and HMAC_SHA512 encryption algorithm.

[0093] Here, any preset generation algorithm can be determined based on the calculation method, core algorithm, and length of the first key. Then, the target random number, the first identifier, the application identifier, and the first key are processed using this preset generation algorithm to obtain the second key.

[0094] For example, if the default generation algorithm is the KDF algorithm, the second key QKey meets the following conditions:

[0095] QKey=KDF(QK_i, R_UE, CS);

[0096] Where QK_i is the first key, R_UE is the target random number, and CS is the key generation parameter. With the default generation algorithm being a hash algorithm, the second key QKey satisfies the following condition:

[0097] QKey=hash(QK_i, R_UE, CS).

[0098] In an optional implementation, the above steps determine the first key to be used based on the number of times each key in the key resource pool is used by the business application, including:

[0099] First, based on the key acquisition request, the security context information of the business application is obtained; wherein, the security context information is used to indicate the usage of the key by the business application, and the usage includes at least one of the following: the number of times the key is used;

[0100] Then, based on the security context information lookup results and the number of times each key is used by the business application, the first key to be used is determined.

[0101] In embodiments of this disclosure, the quantum key management application can determine whether a business application is requesting the use of a key for the first time based on the business identifier carried in the key acquisition request.

[0102] Here, when a business application is requesting the key for the first time, its security context information cannot be found (i.e., the quantum key management application does not store the business application's security context information). When a business application is not requesting the key for the first time, its security context information can be found.

[0103] Based on the search results for security context information (e.g., found or not found), different methods can be used to determine the first key to be used at the moment, depending on the number of times the key has been used.

[0104] In this embodiment of the disclosure, for cases where the security context information of a business application is not stored in the quantum key management application, it is necessary to create the security context information of the business application after determining the first key. For example, the security context information of the business application can be obtained by initializing the key generation parameters of the first key.

[0105] In an optional implementation, the above steps, based on the lookup results of security context information and the number of times each key is used by the business application, determine the first key to be used, including:

[0106] If no security context information is found, determine any one of the keys corresponding to the business application as the first key, and set the first number of times the first key is used and the first maximum number of times it is used to obtain the security context information.

[0107] In the embodiments of this disclosure, if the quantum key management application fails to find the security context information of the business application, a key can be arbitrarily selected from at least one key as the first key.

[0108] In addition, the first use count of the first key (i.e., the number of times the business application uses the first key) can be initialized to 1, and the maximum number of times the key can be used can be determined according to the security requirements of the business application.

[0109] For example, when the security requirements of a business application are low, the maximum number of times the first key can be used by the business application is set to 10,000; when the security requirements of a business application are moderate, the maximum number of times the first key can be used by the business application is set to 1,000; and when the security requirements of a business application are high, the maximum number of times the first key can be used by the business application is set to 100.

[0110] Here, after determining the first number of times the first key is used and the first maximum number of times it is used, the first number of times the first key is used, the first key identifier, and the business application identifier can be identified as security context information.

[0111] In an optional implementation, the above steps, based on the security context information acquisition results and the number of times each key is used by the business application, determine the first key to be used, including:

[0112] First, if the security context information is found, the third key used in the last communication with the business platform is determined based on the security context information;

[0113] Secondly, determine the second number of times the business application uses the third key, and determine the second maximum number of times the business application uses the third key;

[0114] Secondly, the second number of uses is incremented to obtain the third number of uses;

[0115] Finally, if the third number of uses is less than the second maximum number of uses, the third key is determined as the first key.

[0116] In the embodiments of this disclosure, when the quantum key management application finds the security context information, that is, when the business application requests the quantum key management application to use the key, the second usage count in the security context information can be processed.

[0117] Here, the second usage count can be incremented, for example, by 1, to obtain the third usage count of the third key (i.e., the quantum key used by the business application in its last communication with the business platform). The third key is a quantum key.

[0118] If the third key's usage count is less than the second maximum usage count, it can be determined that the usage count corresponding to the completion of the current communication with the third key is less than or equal to the second maximum usage count. In this case, the third key can be used at the current moment to complete the communication between the business application and the business platform. Therefore, the third key can be determined as the first key used at the current moment.

[0119] The third key can be determined by the key identifier of the key in the key sub-resource pool corresponding to the business application. For example, the quantum keys in the key sub-resource pool are sorted, with the first key having a quantum key identifier of QKID_1, the second key having a quantum key identifier of QKID_2, and the i-th key having a quantum key identifier of QKID_i. Then, the first key in the key sub-resource pool can be used as the third key (i.e., the key with quantum key identifier QKID_1).

[0120] In an optional implementation, based on the above embodiments, the method further includes the following steps:

[0121] If it is determined that the third number of uses is greater than or equal to the second maximum number of uses, then at least one key that has not been used by the business application is identified as the first key.

[0122] In the embodiments of this disclosure, if the third usage count is greater than or equal to the second maximum usage count, it can be determined that the usage count corresponding to the completion of the current communication with the third key will exceed the second maximum usage count. Therefore, the business application can no longer use the third key to communicate with the business platform.

[0123] Here, the next key in the key sub-resource pool corresponding to the business application can be used as the first key.

[0124] For example, if the quantum key identifier of the third key is QKID_i, the key with the quantum key identifier QKID_(i+1) is used as the first key.

[0125] If the third key is the last key in the key sub-resource pool (that is, the real-time usage count of each key in the key sub-resource pool is greater than or equal to the maximum usage count), QKID_1 can be determined as the first key; a key refill request can also be initiated to the business platform through the quantum key management application.

[0126] In an optional implementation, in the above... Figure 1 Based on the described embodiments, the method further includes the following steps:

[0127] When the security terminal meets the key injection conditions, it initiates a key injection request to the business platform; wherein the key injection conditions include at least one of the following: the total number of times all keys of at least one business application are used exceeds the corresponding maximum number of times, or the total number of times all keys of each business application are used exceeds the corresponding maximum number of times.

[0128] In the embodiments of this disclosure, the quantum key management application initiates a key injection request to the service platform when it determines that the key sub-resource pool meets the key injection conditions (i.e., the secure terminal meets the key injection conditions).

[0129] Here, the total number of times all keys of at least one business application are used exceeds the corresponding maximum number of times, which means that the number of times the keys in the key sub-resource pool corresponding to at least one business application are used exceeds the corresponding maximum number of times.

[0130] Here, the total number of times all keys for each business application have been used exceeds the corresponding maximum number of times they can be used. In other words, the number of times all keys in the key sub-resource pool corresponding to each business application have been used exceeds the corresponding maximum number of times they can be used.

[0131] In an optional implementation, in the above... Figure 1 Based on the described embodiments, the method further includes the following steps:

[0132] During the process of sending encrypted business data to the business platform for processing, a business access request is sent; wherein, the business access request includes at least one of the following: the identifier of the first key, the application identifier of the business application, the target random number, the first identifier, the real-time usage count of the first key, the maximum usage count of the first key, and the preset generation algorithm of the second key; the target random number is a parameter used to generate the second key.

[0133] In the embodiments of this disclosure, after determining the encrypted service data, the secure terminal can generate a service access request carrying the encrypted service data. Then, the service access request carrying the encrypted service data is sent to the service platform.

[0134] Figure 2 The diagram shows a flowchart of another quantum key-based communication method provided in this embodiment of the present disclosure. The method includes steps S201 to S203 and is applied to a service platform, wherein:

[0135] S201. Obtain encrypted business data sent by the secure terminal.

[0136] In the embodiments of this disclosure, the encrypted business data is obtained by the secure terminal encrypting the data using the methods described in S101 to S104 above.

[0137] Here, the business platform can obtain the business access request sent by the secure terminal and determine the encrypted business data carried in the business access request.

[0138] S202. Determine the decryption key for the encrypted business data.

[0139] In the embodiments of this disclosure, the service platform can determine the identifier of the first key, the application identifier of the service application, the target random number, the first identifier, and the preset generation algorithm of the second key carried in the service access request.

[0140] Then, the first key can be determined based on the identifier of the first key, and the application identifier of the business application, the target random number, the first identifier and the first key can be processed based on the preset generation algorithm to obtain the decryption key.

[0141] S203. Decrypt the encrypted business data using the decryption key to obtain the business data.

[0142] In the embodiments of this disclosure, the service platform can process the encrypted service data using the decryption key to restore the service data sent by the secure terminal.

[0143] Here, the business platform can respond to business data and obtain business response information. Then, the business response information can be protected (i.e., encrypted) using a decryption key to obtain encrypted business response information.

[0144] After obtaining the encrypted business response information, the encrypted business response information can be sent to the secure terminal.

[0145] After the secure terminal receives the encrypted service response information sent by the service platform, it can use the second key to decrypt the encrypted service response information and restore the service response information sent by the service platform.

[0146] In an optional implementation, the above steps determine the decryption key for the encrypted business data, specifically including the following steps:

[0147] First, a key acquisition request is sent to the target business platform; wherein, the key acquisition request includes at least one of the following: the identifier of the first key, the application identifier of the business application, the target random number, the first identifier, the real-time usage count of the first key, the maximum usage count of the first key, and the preset generation algorithm of the second key; the target random number is a parameter used to generate the second key;

[0148] Then, obtain the decryption key from the second key service platform based on the key acquisition request.

[0149] In embodiments of this disclosure, the business platform may include a secondary business platform and a target business platform (i.e., a primary business platform).

[0150] Here, after the secondary business platform receives the business access request sent by the secure terminal, it can send a key acquisition request to the target business platform (i.e., the primary business platform).

[0151] Among these, the business platform can determine the key acquisition request based on the business access request.

[0152] Here, the target business platform can determine the decryption key based on the key acquisition request; then, the decryption key can be fed back to the secondary business platform through the secure channel between the primary business platform and the target business platform.

[0153] In an optional implementation, the above steps determine the decryption key for the encrypted business data, specifically including the following steps:

[0154] If the first key meets the policy requirements based on the key acquisition request, the first key is processed according to the preset generation algorithm to obtain the decryption key; wherein, the policy requirements are related to the number of times the first key is used in real time by the business application.

[0155] In embodiments of this disclosure, the policy requirement is that the real-time number of times the first key is used (i.e., the third number of times it is used as described above) is less than or equal to the maximum number of times the first key is used (i.e., the second maximum number of times it is used as described above).

[0156] Here, firstly, the real-time usage count and maximum usage count of the first key in the key acquisition request can be determined. Then, based on the real-time usage count and maximum usage count of the first key, it can be determined whether the first key meets the policy requirements.

[0157] If the real-time usage count of the first key is less than or equal to the maximum usage count, the first key is deemed to meet the policy requirements. Subsequently, the application identifier, target random number, first identifier, and first key in the key acquisition request can be processed based on a preset generation algorithm to obtain the decryption key.

[0158] In an optional implementation, the above steps determine the decryption key for the encrypted business data, specifically including the following steps:

[0159] If the first key does not meet the policy requirements based on the key acquisition request, an error message is sent to the second key service platform; the error message indicates that the decryption key cannot be determined.

[0160] In the embodiments of this disclosure, if the real-time usage count of the first key exceeds the maximum usage count, it is determined that the first key does not meet the policy requirements. Subsequently, an error message can be sent to the target business platform through the primary business platform.

[0161] After the target business platform receives the error message, it can send the error message to the secure terminal. Upon receiving the error message, the secure terminal can re-select a key from the key sub-resource pool corresponding to the business application and re-establish a communication connection with the business platform.

[0162] Those skilled in the art will understand that, in the above-described method of the specific implementation, the order in which each step is written does not imply a strict execution order and does not constitute any limitation on the implementation process. The specific execution order of each step should be determined by its function and possible internal logic.

[0163] Based on the same inventive concept, this disclosure also provides a key-based communication system corresponding to the key-based communication method. Since the principle of the system in this disclosure for solving the problem is similar to the key-based communication method described above in this disclosure, the implementation of the system can refer to the implementation of the method, and the repeated parts will not be described again.

[0164] In one specific embodiment provided in this disclosure, see [link to specific embodiment]. Figure 3The diagram shown is an interaction flowchart of a key-based communication system provided in this embodiment of the present disclosure, wherein:

[0165] Key-based communication systems include: secure terminals, primary service platforms, and secondary service platforms.

[0166] S10. The secure terminal responds to the key acquisition request of the business application and determines at least one quantum key corresponding to the business application.

[0167] S20. The secure terminal determines the first key to be used based on the number of times each quantum key is used by the business application and the maximum number of times each quantum key can be used.

[0168] Here, based on the key acquisition request, the security context information of the business application is searched; wherein, the security context information is used to indicate the number of times the business application requests the quantum key; based on the search result of the security context information and the number of times the business application uses each of the quantum keys, the first key to be used is determined.

[0169] Here, if the security context information is not found, any quantum key is determined as the first key from at least one quantum key corresponding to the business application, and the first number of uses and the first maximum number of uses of the first key are set to obtain the security context information.

[0170] Here, if the security context information is found, the third key used in the last communication with the business platform is determined based on the security context information;

[0171] Determine the second number of times the business application uses the third key, and determine the second maximum number of times the business application uses the third key;

[0172] The second number of uses is incremented to obtain the third number of uses;

[0173] If the third number of uses is less than the second maximum number of uses, the third key is determined as the first key.

[0174] Wherein, if it is determined that the third number of uses is greater than or equal to the second maximum number of uses, the quantum key that has not been used by the business application among the at least one quantum key is determined as the first key.

[0175] S30. The secure terminal generates a target random number and processes the first key, the application identifier of the business application, the first identifier, and the target random number based on a preset generation algorithm to obtain the second key.

[0176] S40. The secure terminal uses the second key to encrypt the business data of the business application, and obtains the encrypted business data (i.e., the ciphertext of the business information).

[0177] The S50 and secure terminal generate a business access request based on the encrypted business information and send the business access request to the secondary business platform.

[0178] Based on the business access request, the S60 and secondary business platforms generate a key acquisition request and send the key acquisition request to the primary business platform.

[0179] S70, the first-level business platform determines the first key based on the business access request, and generates a decryption key based on the first key and the business access request.

[0180] S80, the first-level business platform sends the decryption key to the second-level business platform.

[0181] S90 and the secondary business platform process the decrypted business data using the decryption key to determine the response information.

[0182] The S100 and secondary business platforms use the decryption key to encrypt the response information to obtain the encrypted response information.

[0183] The S110 and secondary business platforms will send the encrypted response information to the secure terminal.

[0184] S120, The secure terminal processes the encrypted response information using the second key to obtain the response information.

[0185] Based on the same inventive concept, this disclosure also provides a quantum key-based communication device corresponding to the quantum key-based communication method. Since the principle of the system problem-solving in this disclosure is similar to the quantum key-based communication method described above in this disclosure, the implementation of the device can refer to the implementation of the method, and the repeated parts will not be described again.

[0186] Reference Figure 4 The diagram shown is a schematic of a key-based communication device according to an embodiment of this disclosure. The device includes: a response module 11, a first determination module 12, a generation module 13, and an encryption module 14; wherein:

[0187] A response module is used to respond to a key acquisition request from a business application and determine at least one key corresponding to the business application.

[0188] The first determining module is used to determine the first key to be used currently based on the number of times the business application uses each key in the key resource pool;

[0189] The generation module is used to generate a second key based on the application identifier of the business application and the first key;

[0190] The encryption module is used to encrypt and / or protect the integrity of the business data of the business application according to the second key, and send the encrypted and / or integrity-protected business data to the business platform for processing.

[0191] Reference Figure 5 The diagram shown illustrates another key-based communication device provided in this embodiment of the present disclosure. The device includes: an acquisition module 21, a second determination module 22, and a decryption module 23; wherein:

[0192] The acquisition module is used to acquire encrypted business data sent by the secure terminal;

[0193] The second determining module is used to determine the decryption key of the encrypted business data;

[0194] The decryption module is used to decrypt the encrypted business data using the decryption key to obtain the business data.

[0195] This disclosure, by determining the first key based on the number of times the key is used by the business application, can quickly filter out keys that meet the usage requirements of the business application. By generating a second key for encrypted communication using the first key and the application identifier, the multiple uses of each key in the key resource pool can be achieved, thereby increasing the usage frequency of each key in the key resource pool and reducing the key replenishment frequency. Especially for quantum key-based communication processes, the security of business data can be further guaranteed because the generated second key is different.

[0196] The processing flow of each module in the device and the interaction flow between each module can be referred to the relevant descriptions in the above method embodiments, and will not be detailed here.

[0197] Corresponding to Figure 1 In addition to the quantum key-based communication method, this disclosure also provides an electronic device 600, such as... Figure 6 The diagram shown is a structural schematic of an electronic device 600 provided in an embodiment of this disclosure, including:

[0198] The system includes a processor 61, a memory 62, and a bus 63. The memory 62 stores execution instructions and includes main memory 621 and external memory 622. The main memory 621, also called internal memory, temporarily stores the computational data in the processor 61, as well as data exchanged with external memory such as a hard disk. The processor 61 exchanges data with the external memory 622 through the main memory 621. When the electronic device 600 is running, the processor 61 communicates with the memory 62 through the bus 63, causing the processor 61 to execute the following instructions:

[0199] In response to a key acquisition request from a business application, at least one key corresponding to the business application is determined;

[0200] Based on the number of times each quantum key in the key resource pool is used by the business application, the first key to be used is determined.

[0201] A second key is generated based on the application identifier of the business application and the first key;

[0202] The business data of the business application is encrypted and / or protected for integrity using the second key, and the encrypted and / or protected business data is sent to the business platform for processing.

[0203] The processor 61 can also execute the following instructions:

[0204] Obtain encrypted business data sent by a secure terminal;

[0205] Determine the decryption key for the encrypted business data;

[0206] The encrypted business data is decrypted using the decryption key to obtain the business data.

[0207] The basic principles of this disclosure have been described above with reference to specific embodiments. However, it should be noted that the advantages, benefits, and effects mentioned in this disclosure are merely examples and not limitations, and should not be considered as essential features of each embodiment of this disclosure. Furthermore, the specific details disclosed above are for illustrative and facilitative purposes only, and are not limitations. These details do not limit the scope of this disclosure to the necessity of employing the aforementioned specific details for implementation.

[0208] The block diagrams of devices, apparatuses, devices, and systems disclosed herein are merely illustrative examples and are not intended to require or imply that they must be connected, arranged, or configured in the manner shown in the block diagrams. As those skilled in the art will recognize, these devices, apparatuses, devices, and systems can be connected, arranged, and configured in any manner. Words such as “comprising,” “including,” “having,” etc., are open-ended terms meaning “including but not limited to,” and are used interchangeably with them. The terms “or” and “and” as used herein refer to the terms “and / or,” and are used interchangeably with them unless the context clearly indicates otherwise. The term “such as” as used herein refers to the phrase “such as but not limited to,” and is used interchangeably with it.

[0209] Additionally, as used herein, the “or” used in a list of items beginning with “at least one” indicates a separate list, such that a list of, for example, “at least one of A, B, or C” means A or B or C, or AB or AC or BC, or ABC (i.e., A and B and C). Furthermore, the word “exemplary” does not imply that the described example is preferred or better than other examples.

[0210] It should also be noted that in the systems and methods of this disclosure, the components or steps can be decomposed and / or recombined. These decompositions and / or recombinations should be considered as equivalent solutions to this disclosure.

[0211] Various changes, substitutions, and modifications can be made to the technology described herein without departing from the teachings defined by the appended claims. Furthermore, the scope of the claims of this disclosure is not limited to the specific aspects of the processes, machines, manufactures, events, means, methods, and actions described above. Currently existing or later-developed processes, machines, manufactures, events, means, methods, or actions that perform substantially the same function or achieve substantially the same result as the corresponding aspects described herein can be utilized. Therefore, the appended claims include such processes, machines, manufactures, events, means, methods, or actions within their scope.

[0212] The above description of the disclosed aspects is provided to enable any person skilled in the art to make or use this disclosure. Various modifications to these aspects will be readily apparent to those skilled in the art, and the general principles defined herein may be applied to other aspects without departing from the scope of this disclosure. Therefore, this disclosure is not intended to be limited to the aspects shown herein, but rather to be carried out within the widest scope consistent with the principles and novel features disclosed herein.

[0213] The above description has been given for purposes of illustration and description. Furthermore, this description is not intended to limit the embodiments of this disclosure to the forms disclosed herein. Although numerous exemplary aspects and embodiments have been discussed above, those skilled in the art will recognize certain variations, modifications, alterations, additions, and sub-combinations therein.

Claims

1. A key-based communication method, characterized in that, Applied to secure endpoints, including: In response to a key acquisition request from a business application, at least one key corresponding to the business application is determined; Based on the number of times each key in the key resource pool is used by the business application, the first key to be used is determined. A second key is generated based on the application identifier of the business application and the first key; The business data of the business application is encrypted and / or protected for integrity according to the second key, and the encrypted and / or protected business data is sent to the business platform for processing. The step of determining the first key to be used based on the number of times each key in the key resource pool is used by the business application includes: Based on the key acquisition request, the security context information of the business application is obtained; wherein, the security context information is used to indicate the usage of each key by the business application, and the usage includes at least one of the following: the number of times the key is used; Based on the security context information acquisition results and the number of times the business application uses each key, the first key to be used is determined; The step of determining the first key to be used currently based on the security context information acquisition result and the number of times the business application uses each key includes: If the security context information is found, the third key used in the last communication with the business platform is determined based on the security context information. Determine the second number of times the business application uses the third key, and determine the second maximum number of times the business application uses the third key; The second number of uses is incremented to obtain the third number of uses; If the third number of uses is less than the second maximum number of uses, the third key is determined as the first key.

2. The method as described in claim 1, characterized in that, The process of generating a second key based on the application identifier of the business application and the first key includes: The first key and key generation parameters are processed according to a preset generation algorithm to obtain the second key; wherein, the key generation parameters include at least one of the following: a target random number, a first identifier, and the application identifier, wherein the first identifier is used to indicate the global user identification card identifier set in the secure terminal.

3. The method as described in claim 1, characterized in that, The step of determining the first key to be used based on the lookup results of the security context information and the number of times the business application uses each key includes: If the security context information is not found, determine any one of the keys corresponding to the business application as the first key, and set the first number of times the first key is used and the first maximum number of times it is used to obtain the security context information.

4. The method as described in claim 1, characterized in that, The method further includes: If it is determined that the third number of uses is greater than or equal to the second maximum number of uses, the key that has not been used by the business application among the at least one key is determined as the first key.

5. The method as described in claim 1, characterized in that, The method further includes: When the security terminal meets the key injection conditions, it initiates a key injection request to the business platform; wherein the key injection conditions include at least one of the following: the total number of times all keys of at least one business application are used exceeds the corresponding maximum number of times, or the total number of times all keys of each business application are used exceeds the corresponding maximum number of times.

6. The method as described in claim 1, characterized in that, The method further includes: During the process of sending the encrypted business data to the business platform for processing, a business access request is sent; wherein, the business access request includes at least one of the following: the identifier of the first key, the application identifier of the business application, a target random number, a first identifier, the real-time usage count of the first key, the maximum usage count of the first key, and a preset generation algorithm for the second key; the target random number is a parameter used to generate the second key.

7. A quantum key-based communication method, characterized in that, Applied to business platforms, including: The encrypted service data sent by the secure terminal is obtained by the secure terminal encrypting the data using the method described in any one of claims 1 to 6. Determine the decryption key for the encrypted business data; The encrypted business data is decrypted using the decryption key to obtain the business data.

8. The method as described in claim 7, characterized in that, Determining the decryption key for the encrypted business data includes: Send a key acquisition request to the target business platform; wherein, the key acquisition request includes at least one of the following: the identifier of a first key, the application identifier of the business application, a target random number, a first identifier, the real-time usage count of the first key, the maximum usage count of the first key, and a preset generation algorithm for a second key; the target random number is a parameter used to generate the second key; Obtain the decryption key returned by the target business platform based on the key acquisition request.

9. The method as described in claim 7 or 8, characterized in that, Determining the decryption key for the encrypted business data includes: If, based on the key acquisition request, it is determined that the first key meets the policy requirements, the first key is processed according to a preset generation algorithm to obtain the decryption key; wherein, the policy requirements are related to the number of times the business application uses the first key in real time.

10. The method as described in claim 9, characterized in that, Determining the decryption key for the encrypted business data includes: If, based on the key acquisition request, it is determined that the first key does not meet the policy requirements, an error message is sent to the second key service platform; wherein, the error message is used to indicate that the decryption key cannot be determined.

11. A key-based communication device, characterized in that, include: A response module is used to respond to a key acquisition request from a business application and determine at least one key corresponding to the business application. The first determining module is used to determine the first key to be used currently based on the number of times the business application uses each key in the key resource pool; The generation module is used to generate a second key based on the application identifier of the business application and the first key; The encryption module is used to encrypt and / or protect the integrity of the business data of the business application according to the second key, and send the encrypted and / or integrity-protected business data to the business platform for processing; The first determining module is further configured to obtain security context information of the business application based on the key acquisition request; wherein the security context information is used to indicate the usage of each key by the business application, and the usage includes at least one of the following: the number of times the key is used; determining the first key to be used currently based on the acquisition result of the security context information and the number of times the business application uses each key; if the security context information is found, determining the third key used in the last communication with the business platform based on the security context information; determining the second number of times the business application uses the third key, and determining the second maximum number of times the business application uses the third key; incrementing the second number of times to obtain a third number of times; if the third number of times is less than the second maximum number of times, determining the third key as the first key.

12. A quantum key-based communication device, characterized in that, include: An acquisition module is used to acquire encrypted service data sent by a secure terminal; wherein the encrypted service data is obtained by the secure terminal encrypting the data using the method described in any one of claims 1 to 6. The second determining module is used to determine the decryption key of the encrypted business data; The decryption module is used to decrypt the encrypted business data using the decryption key to obtain the business data.

13. A computer device comprising a memory, a processor, and a computer program stored in the memory, characterized in that, The processor executes the computer program to implement the steps of the method as described in any one of claims 1 to 10.

14. A computer-readable storage medium having a computer program / instructions stored thereon, characterized in that, When the computer program / instructions are executed by the processor, they implement the steps of the method as described in any one of claims 1 to 10.

15. A computer program product comprising a computer program / instructions, characterized in that, When the computer program / instructions are executed by the processor, they implement the steps of the method as described in any one of claims 1 to 10.

Citation Information

Patent Citations

  • Method and device for providing encrypted information for light application, and intelligent equipment

    CN111901287A

  • Method and system for realizing encryption and decryption of network data message by adopting quantum distribution key

    CN115567206A

  • Key information processing method and system

    CN118157858A