A quantum key replenishment method, device, system, storage medium and computer program product

By generating and encrypting the key for the identity recognition module through the quantum key server, the security and feasibility of the quantum key during the filling process are ensured, the risk of leakage during the quantum key filling process is solved, and a dual verification mechanism is realized.

CN119316127BActive Publication Date: 2026-01-23CHINA MOBILE COMM LTD RES INST +1
View PDF 1 Cites 0 Cited by

Patent Information

Application Number
CN202411289381.X
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2024-09-13
Publication Date
2026-01-23
Estimated Expiration
2044-09-13

AI Technical Summary

Technical Problem

There is a risk of leakage during the quantum key injection process, and the security and feasibility of quantum keys are insufficient.

Method used

The quantum key server generates a second encryption key for the identity recognition module, and encrypts it using the first encryption key. The key is then sent to the refilling service terminal for verification and decryption to ensure the security of the quantum key.

Benefits of technology

The quantum key injection process ensures the security and feasibility of the quantum key, reduces the risk of information leakage, and implements a dual verification mechanism.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN119316127B_ABST
    Figure CN119316127B_ABST
Patent Text Reader

Abstract

The quantum key charging method disclosed in the application comprises the following steps: if an allowed charging message including an authorization token sent by a charging service terminal is received, a first encryption key is obtained; a second encryption key corresponding to an identity recognition module is generated; the second encryption key is encrypted by using the first encryption key to obtain first encrypted information; the first token verification information and the first encrypted information are sent to the charging service terminal; the second token verification information and the second encryption key verification information sent by the charging service terminal are received; after the second token verification information and the second encryption key verification information are verified, m quantum keys allocated to the identity recognition module are determined; the m quantum keys are encrypted by using the second encryption key to obtain second encrypted information; and the first token verification information and the second encrypted information are sent to the charging service terminal. The application also discloses a quantum key charging device, a quantum key charging system, a storage medium and a computer program product.
Need to check novelty before this filing date? Find Prior Art

Description

TECHNICAL FIELD

[0001] The present application relates to the technical field of communication, in particular to a quantum key replenishment method, device, equipment, storage medium and computer program product. BACKGROUND

[0002] With the rapid development of wireless communication technology, the application of wireless communication technology is also more and more widely, how to ensure the safety of the information transmitted in the communication process in the communication process becomes the technical problem to be solved at present. At present, the commonly used technical means is to encrypt the transmitted information, so that the encrypted data is not easy to be cracked even if it is stolen, which ensures the safety of the transmitted information. At present, with the proposal of quantum secure communication technology, when using quantum key in the communication process, how to replenish the quantum key and ensure the safety of the quantum key becomes the technical problem to be solved at present.

[0003] APPLICATION

[0004] To solve the above technical problems, the present application expects to provide a quantum key replenishment method, device, equipment, storage medium and computer program product, which solves the problem of leakage risk in the current quantum key replenishment process, proposes a quantum key replenishment method, and ensures the safety of the quantum key and the realizability of the quantum key replenishment process in the quantum key replenishment process.

[0005] The technical scheme of the present application is realized as follows:

[0006] The present application provides a quantum key replenishment method, which is applied to a quantum key server, and the method comprises the following steps:

[0007] If an allowed replenishment message including an authorization token sent by a replenishment service terminal is received, a first encryption key is obtained; wherein the authorization token is authorization information allocated by a replenishment management terminal for an identity recognition module installed in the replenishment service terminal;

[0008] A second encryption key corresponding to the identity recognition module is generated;

[0009] The second encryption key is encrypted by using the first encryption key to obtain first encrypted information;

[0010] The first token verification information and the first encrypted information are sent to the replenishment service terminal, so that after the first token verification information is verified by the replenishment service terminal, the second encryption key is obtained by decrypting the first encrypted information based on a first decryption key through the identity recognition module, and the first token verification information and the authorization token have an association relationship;

[0011] receive second token verification information and second encryption key verification information sent by the refilling service terminal; the second encryption key verification information has an association relationship with the second encryption key;

[0012] After the second token verification information and the second encryption key verification information are verified, m quantum keys allocated to the identity recognition module are determined; the second token verification information has an association relationship with the authorization token, and m is an integer greater than or equal to 1;

[0013] The second encryption key is used to encrypt the m quantum keys to obtain second encryption information;

[0014] The first token verification information and the second encryption information are sent to the refilling service terminal, so that the identity recognition module stores the m quantum keys carried in the second encryption information.

[0015] The present application provides a quantum key refilling method, which is applied to a refilling service terminal installed with an identity recognition module, and the method comprises:

[0016] receive an authorization token sent by a refilling management end; the authorization token is token information allocated to the identity recognition module by the refilling management end after identity authentication of the identity recognition module by the refilling management end;

[0017] send an allowed refilling message including the authorization token to a quantum key server;

[0018] receive first token verification information and first encryption information sent by the quantum key server; the first token verification information is generated by the quantum key server based on the authorization token allocated to the identity recognition module by the refilling management end;

[0019] After the first token verification information is verified, the first encryption information is decrypted by the identity recognition module using a first decryption key to obtain a second encryption key; the first decryption key is stored in the identity recognition module;

[0020] generate second encryption key verification information based on the second encryption key by the identity recognition module;

[0021] send the stored second token verification information and the second encryption key verification information to the quantum key server;

[0022] receive the first token verification information and the second encrypted information sent by the quantum key server; wherein the first token verification information and the second encrypted information are sent by the quantum key server after the second token verification information and the second encryption key verification information are both verified;

[0023] after the first token verification information is verified, the second encrypted information is decrypted by the identity recognition module using the second encryption key to obtain m quantum keys;

[0024] store the m quantum keys in the key storage area of the identity recognition module through the identity recognition module.

[0025] The application provides a quantum key refilling method, which is applied to a refilling management end, and the method comprises the following steps:

[0026] determine an authorization token corresponding to an identity recognition module installed in a refilling service terminal;

[0027] send the authorization token to the refilling service terminal, so that the refilling service terminal sends the authorization token to the quantum key server, and the refilling service terminal and the quantum key server perform verification processing based on the authorization token.

[0028] The application provides a first quantum key refilling device, which is applied to a quantum key server, and the device comprises an acquisition unit, a first generation unit, an encryption processing unit, a first sending unit and a first determination unit; wherein:

[0029] the acquisition unit is configured to acquire a first encryption key if an allowed refilling message including an authorization token sent by a refilling service terminal is received; wherein the authorization token is authorization information allocated by a refilling management end for an identity recognition module installed in the refilling service terminal;

[0030] the first generation unit is configured to generate a second encryption key corresponding to the identity recognition module;

[0031] the encryption processing unit is configured to perform encryption processing on the second encryption key using the first encryption key to obtain first encrypted information;

[0032] the first sending unit is configured to send first token verification information and the first encrypted information to the refilling service terminal, so that, after the first token verification information is verified by the refilling service terminal, the second encryption key is obtained by decrypting the first encrypted information based on a first decryption key through the identity recognition module, and the first token verification information has an association relationship with the authorization token;

[0033] The acquisition unit is further configured to receive second token verification information and second encryption key verification information sent by the refilling service terminal, wherein the second encryption key verification information is associated with the second encryption key;

[0034] The first determination unit is configured to determine m quantum keys allocated to the identity recognition module after the second token verification information and the second encryption key verification information are both verified, wherein the second token verification information is associated with the authorization token, and m is an integer greater than or equal to 1;

[0035] The encryption processing unit is configured to perform encryption processing on the m quantum keys by using the second encryption key to obtain second encryption information;

[0036] The first sending unit is configured to send the first token verification information and the second encryption information to the refilling service terminal, so that the identity recognition module stores the m quantum keys carried in the second encryption information.

[0037] The present application provides a second quantum key refilling device, which is applied to a refilling service terminal installed with an identity recognition module, and includes a first receiving unit, a decryption processing unit, a second generation unit, a second sending unit and a first storage unit; wherein:

[0038] The first receiving unit is configured to receive an authorization token sent by a refilling management end, wherein the authorization token is token information allocated to the identity recognition module by the refilling management end after the identity recognition module is authenticated by the refilling management end;

[0039] The second sending unit is configured to send an allowed refilling message including the authorization token to a quantum key server;

[0040] The first receiving unit is further configured to receive first token verification information and first encryption information sent by the quantum key server, wherein the first token verification information is generated by the quantum key server based on the authorization token allocated to the identity recognition module by the refilling management end;

[0041] The decryption processing unit is configured to perform decryption processing on the first encryption information by using a first decryption key of the identity recognition module after the first token verification information is verified, to obtain a second encryption key, wherein the first decryption key is stored in the identity recognition module;

[0042] The second generation unit is configured to generate second encryption key verification information based on the second encryption key by using the identity recognition module;

[0043] The second sending unit is configured to send the stored second token verification information and the second encryption key verification information to the quantum key server.

[0044] The first receiving unit is further configured to receive the first token verification information and second encryption information sent by the quantum key server, wherein the first token verification information and the second encryption information are sent by the quantum key server after the second token verification information and the second encryption key verification information are verified.

[0045] The decryption processing unit is further configured to, after the first token verification information is verified, decrypt the second encryption information by using the second encryption key through the identity recognition module to obtain m quantum keys.

[0046] The first storage unit is configured to store the m quantum keys in the key storage area of the identity recognition module through the identity recognition module.

[0047] The application provides a third quantum key refilling device, which is applied to a refilling management end and includes a second determination unit and a third sending unit.

[0048] The second determination unit is configured to determine an authorization token corresponding to an identity recognition module installed in a refilling service terminal.

[0049] The third sending unit is configured to send the authorization token to the refilling service terminal, so that the refilling service terminal sends the authorization token to the quantum key server, and the refilling service terminal and the quantum key server perform verification processing based on the authorization token.

[0050] The application provides a quantum key refilling system, which includes at least a quantum key server, a refilling service terminal installed with an identity recognition module, and a refilling management end.

[0051] The quantum key server is configured to implement the steps of the quantum key refilling method according to any one of the above.

[0052] The refilling service terminal is configured to implement the steps of the quantum key refilling method according to any one of the above.

[0053] The refilling management end is configured to implement the steps of the quantum key refilling method according to any one of the above.

[0054] The application provides a storage medium, which stores a quantum key refilling program. When the quantum key refilling program is executed, it is used to implement the steps of the quantum key refilling method according to any one of the above.

[0055] The present application provides a computer program product comprising a computer program which, when executed by a processor, implements the steps of the quantum key replenishment method according to any one of the above.

[0056] The embodiment of the application provides a quantum key filling method, device, equipment, storage medium and computer program product, through the filling management end determining the authorization token corresponding to the identity recognition module installed in the filling service terminal, sending the authorization token to the filling service terminal, the filling service terminal receiving the authorization token sent by the filling management end, and sending the filling permission message including the authorization token to the quantum key service end, if the filling permission message including the authorization token sent by the filling service terminal is received, the quantum key service end obtains the first encryption key, generates the second encryption key corresponding to the identity recognition module, and adopts the first encryption key to encrypt the second encryption key, obtains the first encryption information, and then sends the first token verification information and the first encryption information to the filling service terminal, the filling service terminal receiving the first token information and the first encryption information sent by the quantum key service end, after the first token verification information is verified, the first decryption key is used to decrypt the first encryption information through the identity recognition module, the second encryption key is obtained, and the second encryption key verification information is generated based on the second encryption key through the identity recognition module, and then the stored second token verification information and the second encryption key verification information are sent to the quantum key service end, the quantum key service end receives the second token verification information and the second encryption key verification information sent by the filling service terminal, and after the second token verification information and the second encryption key verification information are verified, the m quantum keys allocated to the identity recognition module are determined, the second encryption key is used to encrypt the m quantum keys, the second encryption information is obtained, and the first token verification information and the second encryption information are sent to the filling service terminal, the filling service terminal receives the first token verification information and the second encryption information sent by the quantum key service end, after the first token verification information is verified, the second encryption key is used to decrypt the second encryption information through the identity recognition module, the m quantum keys are obtained, and finally the m quantum keys are stored in the key storage area of the identity recognition module through the identity recognition module.In this way, after receiving the authorization token from the charging management terminal, the charging service terminal notifies the quantum key server that quantum key charging can be performed through a charging permission message including the authorization token. Then, the quantum key server uses a first encryption key to encrypt the second encryption key used for communication between the quantum key server and the identity recognition module installed in the charging service terminal, and sends it to the identity recognition module. After confirming that the identity recognition module has received the second encryption key and that the received second encryption key is correct, the terminal uses the second encryption key, which is only available to the identity recognition module, to encrypt the m quantum keys allocated to the identity recognition module, obtaining second encrypted information, and sends the second encrypted information to the identity recognition module. In this way, the identity recognition module can use the second encryption key to decrypt the received second encrypted information, obtain m quantum keys, and store them in the storage area of ​​the identity recognition module. Throughout the process, only the quantum key server and the identity recognition module have the second encryption key, ensuring the security of the transmitted quantum keys. In addition, the corresponding verification information is verified based on the authorization token throughout the process, ensuring that if the transmitted information is tampered with, it will be detected in time. This solves the problem of leakage risk in the current quantum key filling process and proposes a quantum key filling method that ensures the security of quantum keys and the feasibility of the quantum key filling process. Attached Figure Description

[0057] Figure 1 A flowchart illustrating the quantum key injection method provided in the embodiments of this application. Figure 1 ;

[0058] Figure 2 A flowchart illustrating the quantum key injection method provided in the embodiments of this application. Figure 2 ;

[0059] Figure 3 A flowchart illustrating the quantum key injection method provided in the embodiments of this application. Figure 3 ;

[0060] Figure 4 A flowchart illustrating the quantum key injection method provided in the embodiments of this application. Figure 4 ;

[0061] Figure 5 This is a schematic diagram illustrating an application scenario of a quantum key injection method provided in an embodiment of this application;

[0062] Figure 6 A schematic diagram of the structure of a first quantum key injection device provided in an embodiment of this application;

[0063] Figure 7 A schematic diagram of the structure of a second quantum key injection device provided in an embodiment of this application;

[0064] Figure 8 A third quantum key replenishment device structure schematic diagram provided by an embodiment of the application is shown in the figure.

[0065] Figure 9 A quantum key replenishment system structure schematic diagram provided by an embodiment of the application is shown in the figure. DETAILED DESCRIPTION

[0066] The technical solutions in the embodiments of the application will be described clearly and completely below with reference to the drawings in the embodiments of the application.

[0067] An embodiment of the application provides a quantum key replenishment method, referring to Figure 1 The method is applied to a quantum key server, and the method comprises the following steps:

[0068] In step 101, if an allowed replenishment message including an authorization token sent by a replenishment service terminal is received, a first encryption key is obtained.

[0069] The authorization token is authorization information allocated by a replenishment management terminal for an identity recognition module installed in the replenishment service terminal.

[0070] In the embodiments of the application, the quantum key server can be a server terminal with a computing management function, providing a quantum password service terminal, for example, a server device, a cloud, a platform, etc. The replenishment service terminal is a terminal device that specifically provides a quantum key replenishment service, which can be applied to a communication business hall and other scenes. The replenishment management terminal can be a management terminal that manages the quantum key replenishment process, for example, a server, a computer device, etc., or a management center, a management platform, etc. The identity recognition module can be a module for uniquely identifying a communication object, for example, a universal subscriber identity module (USIM) card.

[0071] In step 102, a second encryption key corresponding to the identity recognition module is generated.

[0072] In the embodiments of the application, the quantum key server uses a preset key generation algorithm to generate a corresponding second encryption key and allocate it to the identity recognition module. The second encryption key is a key used for encrypting the transmitted quantum key subsequently.

[0073] In step 103, the second encryption key is encrypted using the first encryption key to obtain first encryption information.

[0074] In the embodiments of the application, based on a preset encryption algorithm, the second encryption key is encrypted using the first encryption key to obtain first encryption information.

[0075] Step 104, sending the first token verification information and the first encrypted information to the refilling service terminal.

[0076] The first token verification information and the first encrypted information are sent to the refilling service terminal, so that after the first token verification information is verified by the refilling service terminal, the first encrypted information is decrypted by the identity recognition module based on the first decryption key to obtain the second encryption key, and the first token verification information has an association relationship with the authorized token.

[0077] In the embodiment of the present application, the quantum key service end sends the first token verification information and the first encrypted information to the refilling service terminal at the same time, wherein the refilling service terminal verifies the first token verification information, and the first encrypted information is verified by the identity recognition module in the refilling service terminal.

[0078] Step 105, receiving the second token verification information and the second encrypted key verification information sent by the refilling service terminal.

[0079] The second encrypted key verification information has an association relationship with the second encrypted key.

[0080] In the embodiment of the present application, the second token verification information has an association relationship with the authorized token sent by the refilling management end, and the second encrypted key verification information is the verification information obtained by the identity recognition module in the refilling service terminal after corresponding processing of the second encrypted key, which is used to feed back to the quantum key service end for verification, so as to determine whether the second encrypted key received by the refilling service terminal is tampered or replaced, and thus reduce the risk of information leakage.

[0081] Step 106, determining the m quantum keys allocated to the identity recognition module after the second token verification information and the second encrypted key verification information are verified.

[0082] The second token verification information has an association relationship with the authorized token, and m is an integer greater than or equal to 1.

[0083] In the embodiment of the present application, m can be determined by the channel allowed to transfer data size of the information transmission channel between the quantum key service end and the identity recognition module, or can be a pre-agreed experience value, which can be determined by actual conditions. The quantum key service end verifies the second token verification information and the second encryption key verification information respectively, and determines m quantum keys allocated to the identity recognition module when the second token verification information and the second encryption key verification information are both verified, i.e., both information have no problem. The m quantum keys can be part of the quantum keys generated in advance, or can be generated according to the identity recognition module, which can be determined by actual conditions.

[0084] Step 107, encrypting the m quantum keys by using the second encryption key to obtain second encryption information.

[0085] In the embodiment of the present application, based on a preset encryption algorithm, the determined m quantum keys are encrypted by using the second encryption key to obtain the second encryption information.

[0086] Step 108, sending the first token verification information and the second encryption information to the refilling service terminal.

[0087] Among them, the first token verification information and the second encryption information are sent to the refilling service terminal, so that the identity recognition module stores the m quantum keys carried in the second encryption information.

[0088] In the embodiment of the present application, after the second encryption information is generated, the first token verification information and the second encryption information are sent to the refilling service terminal, so that the refilling service terminal verifies the received first token verification information, and after verification, the second encryption information is decrypted by the identity recognition module to obtain the m quantum keys.

[0089] The quantum key charging method provided by the embodiments of the present application, if the charging service terminal sends the charging permission message including the authorization token, the quantum key server obtains the first encryption key, generates the second encryption key corresponding to the identity recognition module, and encrypts the second encryption key by using the first encryption key to obtain the first encrypted information, and then sends the first token verification information and the first encrypted information to the charging service terminal, so that the charging service terminal receives the first token information and the first encrypted information sent by the quantum key server, and after the first token verification information is verified, the first encrypted information is decrypted by using the first decryption key through the identity recognition module to obtain the second encryption key, and after the second encryption key verification information is generated based on the second encryption key through the identity recognition module, the stored second token verification information and the second encryption key verification information are sent to the quantum key server, the quantum key server receives the second token verification information and the second encryption key verification information sent by the charging service terminal, and after the second token verification information and the second encryption key verification information are verified, m quantum keys allocated to the identity recognition module are determined, the m quantum keys are encrypted by using the second encryption key to obtain the second encrypted information, and the first token verification information and the second encrypted information are sent to the charging service terminal, so that the charging service terminal receives the first token verification information and the second encrypted information sent by the quantum key server, and after the first token verification information is verified, the second encrypted information is decrypted by using the second encryption key through the identity recognition module to obtain the m quantum keys, and the m quantum keys are stored in the key storage area of the identity recognition module through the identity recognition module.In this way, after the refilling service terminal receives the authorization token sent by the refilling management end, the quantum key service end can be notified that the quantum key refilling can be performed through the refilling permission message including the authorization token, and then the quantum key service end encrypts the second encryption key for communication between the quantum key service end and the installed identity recognition module of the refilling service terminal, and sends it to the identity recognition module. After determining that the identity recognition module receives the second encryption key and determining that the second encryption key received by the identity recognition module is correct, the second encryption key possessed by the identity recognition module is used to encrypt the m quantum keys allocated to the identity recognition module to obtain second encryption information, and the second encryption information is sent to the identity recognition module. In this way, the identity recognition module can use the second encryption key to decrypt the received second encryption information to obtain the m quantum keys, and store them in the storage area of the identity recognition module. Only the quantum key service end and the identity recognition module have the second encryption key in the whole process, which ensures the security of the transmitted quantum key. In the whole process, the corresponding verification information is also verified based on the authorization token, which ensures that the information being transmitted will be discovered in time when it is tampered with. The problem of leakage risk in the current quantum key refilling process is solved. A quantum key refilling method is proposed to ensure the security of the quantum key and the realizability of the quantum key refilling process.

[0090] Based on the foregoing embodiment, the embodiment of the present application provides a quantum key refilling method. The method is applied to a refilling service terminal installed with an identity recognition module. Referring to FIG. 1, the method comprises the following steps: Figure 2

[0091] Step 201, receiving an authorization token sent by a refilling management end.

[0092] The authorization token is token information allocated to the identity recognition module by the refilling management end after the identity recognition module is authenticated by the refilling management end.

[0093] Step 202, sending a refilling permission message including the authorization token to a quantum key service end.

[0094] Step 203, receiving first token verification information and first encryption information sent by the quantum key service end.

[0095] The first token verification information is generated by the quantum key server based on the authorization token allocated to the identity recognition module by the refilling management end.

[0096] Step 204, after the first token verification information is verified, the first decryption key possessed by the identity recognition module is used to decrypt the first encryption information to obtain the second encryption key.

[0097] ​The first decryption key is stored in the identity recognition module.

[0098] In the embodiment of the present application, the filling service terminal performs verification processing on the received first token verification information, and instructs the identity recognition module to perform decryption processing on the first encrypted information by using the first decryption key after the first token verification information is verified.

[0099] Step 205, generating second encrypted key verification information by the identity recognition module based on the second encrypted key.

[0100] In the embodiment of the present application, the identity recognition module of the filling service terminal performs processing on the second encrypted key after the second encrypted key is decrypted, and obtains the second encrypted key verification information.

[0101] Step 206, sending the stored second token verification information and the second encrypted key verification information to the quantum key service end.

[0102] Step 207, receiving the first token verification information and the second encrypted information sent by the quantum key service end.

[0103] The first token verification information and the second encrypted information are sent by the quantum key service end after the second token verification information and the second encrypted key verification information are both verified.

[0104] Step 208, performing decryption processing on the second encrypted information by the identity recognition module by using the second encrypted key after the first token verification information is verified, and obtaining m quantum keys.

[0105] In the embodiment of the present application, the filling service terminal performs verification processing on the first token verification information, and instructs the identity recognition module to perform decryption processing on the received second encrypted information by using the second encrypted key decrypted by the identity recognition module after the first token verification information is verified, so that the identity recognition module obtains m quantum keys.

[0106] Step 209, storing the m quantum keys in the key storage area of the identity recognition module by the identity recognition module.

[0107] In this way, the first encrypted information is decrypted by the identity recognition module to obtain the second encryption key, the second encrypted information is decrypted to obtain the m quantum keys, the quantum key server charges the quantum keys for the identity recognition module, and the second encryption key for decrypting the m quantum keys and the second encrypted information including the m quantum keys are not processed by the charging service terminal, but are decrypted and stored by the identity recognition module installed in the charging service terminal, thereby reducing the risk of leakage of the second encryption key and the m quantum keys at the charging service terminal. Further, the first token verification information corresponding to the authorization token is verified in each transmission process, double verification is realized, the security of the information is ensured, and the possibility of miscommunication or modification of the information is reduced.

[0108] The quantum key charging method provided by the embodiments of the present application comprises the following steps: receiving, by a charging service terminal, an authorization token sent by a charging management terminal; sending, by the charging service terminal, an allow charging message comprising the authorization token to a quantum key server; after the quantum key server receives the allow charging message comprising the authorization token sent by the charging service terminal, obtaining a first encryption key, generating a second encryption key corresponding to an identity recognition module, encrypting the second encryption key by using the first encryption key to obtain first encrypted information, and then sending the first token verification information and the first encrypted information to the charging service terminal; after the charging service terminal receives the first token information and the first encrypted information sent by the quantum key server, verifying the first token verification information, and after the verification is passed, decrypting the first encrypted information by using the first decryption key through the identity recognition module to obtain the second encryption key, generating second encryption key verification information based on the second encryption key through the identity recognition module, and then sending the stored second token verification information and the second encryption key verification information to the quantum key server; after the quantum key server receives the second token verification information and the second encryption key verification information sent by the charging service terminal, and after the verification of the second token verification information and the second encryption key verification information is passed, determining m quantum keys allocated to the identity recognition module, encrypting the m quantum keys by using the second encryption key to obtain second encrypted information, and sending the first token verification information and the second encrypted information to the charging service terminal; in this way, after the charging service terminal receives the first token verification information and the second encrypted information sent by the quantum key server, and after the verification of the first token verification information is passed, the second encrypted information is decrypted by using the second encryption key through the identity recognition module to obtain the m quantum keys, and finally the m quantum keys are stored in the key storage area of the identity recognition module through the identity recognition module.In this way, after the refilling service terminal receives the authorization token sent by the refilling management terminal, the quantum key service terminal can perform quantum key refilling through the refilling permission message including the authorization token. Then, the quantum key service terminal encrypts the second encryption key for communication between the quantum key service terminal and the installed identity recognition module of the refilling service terminal, and sends the second encryption key to the identity recognition module. After determining that the identity recognition module receives the second encryption key and that the second encryption key received by the identity recognition module is correct, the identity recognition module performs encryption processing on the m quantum keys allocated to the identity recognition module by using the second encryption key possessed by the identity recognition module, obtains second encryption information, and sends the second encryption information to the identity recognition module. In this way, the identity recognition module can decrypt the received second encryption information by using the second encryption key, obtain the m quantum keys, and store the m quantum keys in the storage area of the identity recognition module. In the entire process, only the quantum key service terminal and the identity recognition module possess the second encryption key, which ensures the security of the transmitted quantum key. In the entire process, the corresponding verification information is also verified based on the authorization token, which ensures that the information being transmitted will be discovered in time when it is tampered with. The application provides a quantum key refilling method, which ensures the security of the quantum key in the quantum key refilling process and the realizability of the quantum key refilling process.

[0109] Based on the foregoing embodiment, the embodiment of the application provides a quantum key refilling method. The method is applied to a refilling management terminal. Referring to FIG. 8, the method comprises the following steps: Figure 3

[0110] Step 301: Determine the authorization token corresponding to the identity recognition module installed in the refilling service terminal.

[0111] In the embodiment of the application, the authorization token can be token information generated by the refilling management terminal for the identity recognition module by using a token generation method in advance.

[0112] Step 302: Send the authorization token to the refilling service terminal.

[0113] The authorization token is sent to the refilling service terminal, so that the refilling service terminal sends the authorization token to the quantum key service terminal, so that the refilling service terminal and the quantum key service terminal perform verification processing based on the authorization token.

[0114] ​The quantum key charging method provided by the embodiment of the application includes the following steps: determining, by a charging management terminal, an authorization token corresponding to an identity recognition module installed in a charging service terminal, and sending the authorization token to the charging service terminal, so that the charging service terminal receives the authorization token sent by the charging management terminal and sends an allowed charging message including the authorization token to a quantum key service terminal; if the quantum key service terminal receives the allowed charging message including the authorization token sent by the charging service terminal, the quantum key service terminal obtains a first encryption key, generates a second encryption key corresponding to the identity recognition module, and performs encryption processing on the second encryption key by using the first encryption key to obtain first encrypted information, and then sends first token verification information and the first encrypted information to the charging service terminal; after the charging service terminal receives the first token information and the first encrypted information sent by the quantum key service terminal, the charging service terminal performs decryption processing on the first encrypted information by using the first decryption key through the identity recognition module to obtain the second encryption key, and generates second encryption key verification information based on the second encryption key through the identity recognition module, and then sends stored second token verification information and the second encryption key verification information to the quantum key service terminal; the quantum key service terminal receives the second token verification information and the second encryption key verification information sent by the charging service terminal, and determines m quantum keys allocated to the identity recognition module after the second token verification information and the second encryption key verification information are verified, performs encryption processing on the m quantum keys by using the second encryption key to obtain second encrypted information, and sends the first token verification information and the second encrypted information to the charging service terminal; after the charging service terminal receives the first token verification information and the second encrypted information sent by the quantum key service terminal, the charging service terminal performs decryption processing on the second encrypted information by using the second encryption key through the identity recognition module to obtain the m quantum keys, and finally stores the m quantum keys in a key storage area of the identity recognition module.In this way, after the refilling service terminal receives the authorization token sent by the refilling management end, the quantum key service end can perform quantum key refilling through the refilling message including the authorization token. Then, the quantum key service end encrypts the second encryption key for communication between the quantum key service end and the identity recognition module installed in the refilling service terminal, and sends the second encryption key to the identity recognition module. After determining that the identity recognition module receives the second encryption key and that the second encryption key received by the identity recognition module is correct, the identity recognition module encrypts the m quantum keys allocated to the identity recognition module by using the second encryption key possessed by the identity recognition module to obtain second encryption information, and sends the second encryption information to the identity recognition module. In this way, the identity recognition module decrypts the received second encryption information by using the second encryption key to obtain the m quantum keys, and stores the m quantum keys in the storage area of the identity recognition module. In the whole process, only the quantum key service end and the identity recognition module possess the second encryption key, which ensures the security of the transmitted quantum key. In the whole process, the corresponding verification information is also verified based on the authorization token, which ensures that the information being transmitted will be discovered in time when it is tampered with. The application provides a quantum key refilling method, which ensures the security of the quantum key in the quantum key refilling process and the realizability of the quantum key refilling process.

[0115] Based on the foregoing embodiments, the embodiments of the application provide a quantum key refilling method, as shown in Figure 4 The method comprises the following steps:

[0116] Step 401, the refilling management end determines the authorization token corresponding to the identity recognition module installed in the refilling service terminal.

[0117] In the embodiments of the application, after the refilling management end determines the identity recognition module that needs to perform quantum key refilling according to the request sent by the refilling service terminal, the refilling management end determines the authorization token corresponding to the identity recognition module. The authorization token can be generated by the token authorization center of the refilling management end according to the module identification information of the identity recognition module, or can be determined by the token authorization center of the refilling management end according to the module identification information of the identity recognition module, and the authorization token has been generated in advance.

[0118] Step 402, the refilling management end sends the authorization token to the refilling service terminal.

[0119] The authorization token is sent to the refilling service terminal, so that the refilling service terminal sends the authorization token to the quantum key service end, so that the refilling service terminal and the quantum key service end perform verification processing based on the authorization token.

[0120] Step 403, the refilling service terminal receives the authorization token sent by the refilling management end.

[0121] The authorization token is token information allocated by the refilling management terminal to the identity recognition module after the identity recognition module passes identity authentication of the refilling management terminal.

[0122] At step 404, the refilling service terminal sends a refilling permission message including the authorization token to the quantum key service terminal.

[0123] In the embodiment of the present application, after the refilling service terminal receives the authorization token sent by the refilling management terminal, it is determined that the refilling management terminal has agreed to refill the quantum key for the identity recognition module. Therefore, the refilling service terminal generates a refilling permission message based on the authorization token and sends a refilling permission message to the quantum key service terminal, so that the quantum key service terminal determines that the refilling operation of refilling the quantum key for the identity recognition module needs to be performed, and also obtains the authorization token corresponding to the identity recognition module, so as to perform corresponding verification processing based on the received authorization token subsequently.

[0124] At step 405, if the quantum key service terminal receives the refilling permission message including the authorization token sent by the refilling service terminal, the quantum key service terminal obtains the first encryption key.

[0125] The authorization token is authorization information allocated by the refilling management terminal to the identity recognition module installed in the refilling service terminal.

[0126] In the embodiment of the present application, after the quantum key service terminal receives the refilling permission message including the authorization token sent by the refilling service terminal, it parses the cloud refilling message to obtain the authorization token, stores the authorization token, and responds to the refilling permission message to obtain the first encryption key.

[0127] At step 406, the quantum key service terminal generates a second encryption key corresponding to the identity recognition module.

[0128] In the embodiment of the present application, the quantum key service terminal can generate the second encryption key by using a key generation algorithm, for example, a symmetric key generation algorithm. The second encryption key is an encryption key for transmitting the quantum key.

[0129] At step 407, the quantum key service terminal encrypts the second encryption key by using the first encryption key to obtain first encryption information.

[0130] At step 408, the quantum key service terminal sends the first token verification information and the first encryption information to the refilling service terminal.

[0131] The first token verification information and the first encrypted information are sent to the refilling service terminal, so that the first token verification information is verified by the refilling service terminal, and the first encrypted information is decrypted by the identity recognition module based on the first decryption key to obtain the second encryption key, and the first token verification information has an association relationship with the authorization token.

[0132] In the embodiment of the application, the quantum key server obtains the first token verification information based on the authorization token. For example, the first token verification information can be a token hash value corresponding to the authorization token. The quantum key server sends the first token verification information and the first encrypted information to the refilling service terminal.

[0133] Step 409, the refilling service terminal receives the first token verification information and the first encrypted information sent by the quantum key server.

[0134] The first token verification information is generated by the quantum password server based on the authorization token allocated by the refilling management terminal for the identity recognition module.

[0135] Step 410, after the first token verification information is verified, the refilling service terminal decrypts the first encrypted information by the identity recognition module using the first decryption key to obtain the second encryption key.

[0136] The first decryption key is stored in the identity recognition module.

[0137] In the embodiment of the application, the refilling service terminal verifies the first token verification information. After the first token verification information is verified, the first encrypted information is sent to the identity recognition module. The identity recognition module decrypts the first encrypted information using the first decryption key stored in the identity recognition module to obtain the second encryption key. The first decryption key and the first encryption key form a key pair.

[0138] Step 411, the refilling service terminal generates second encryption key verification information based on the second encryption key by the identity recognition module.

[0139] In the embodiment of the application, the identity recognition module of the refilling service terminal performs key processing on the decrypted second encryption key to obtain the second encryption key verification information. In this way, the second encryption key is transmitted in a non-plaintext manner. Even if it is leaked during transmission, it may not be cracked, ensuring the security of the second encryption key during transmission.

[0140] Step 412, the refilling service terminal sends the stored second token verification information and the second encryption key verification information to the quantum key server.

[0141] In the embodiment of the present application, the second token verification information is generated by the refilling service terminal for the authorization token of the received identity recognition module, that is, the second token verification information is the verification information of the authorization token generated by the authorization token on the side of the refilling service terminal.

[0142] In step 413, the quantum key service end receives the second token verification information and the second encryption key verification information sent by the refilling service terminal.

[0143] The second encryption key verification information has an association relationship with the second encryption key.

[0144] In step 414, the quantum key service end determines the m quantum keys allocated for the identity recognition module after the second token verification information and the second encryption key verification information are both verified.

[0145] The second token verification information has an association relationship with the authorization token, and m is an integer greater than or equal to 1.

[0146] In the embodiment of the present application, the quantum key service end respectively verifies the received second token verification information and second encryption key verification information to exclude the risk that the second token verification information and the second encryption key verification information are leaked, replaced, etc. on the side of the refilling service terminal or in the transmission process.

[0147] In step 415, the quantum key service end encrypts the m quantum keys by using the second encryption key to obtain second encryption information.

[0148] In the embodiment of the present application, after the second token verification information and the second encryption key verification information pass the verification of the quantum key service end, the quantum key service end determines that the refilling service terminal and the identity recognition module have no problem, and thus the second encryption key generated for the identity recognition module can be used to encrypt the determined m quantum keys, thereby obtaining the second encryption information.

[0149] The m can be a pre-set key number of quantum keys allowed to be transmitted each time, can be a key number of all quantum keys actually allocated for the identity recognition module, can be a key number of quantum keys requested by the identity recognition module, or can be determined according to the channel size between the transmission channel between the quantum key service end and the identity recognition module each time, in which case the value of m each time is determined by the actual size of the transmission channel, and the value of m each time can be different. Therefore, the specific value of m can be determined by the actual situation.

[0150] In step 416, the quantum key service end sends the first token verification information and the second encryption information to the refilling service terminal.

[0151] The first token verification information and the second encrypted information are sent to the refilling service terminal, so that the identity recognition module stores the m quantum keys carried in the second encrypted information.

[0152] In step 417, the refilling service terminal receives the first token verification information and the second encrypted information sent by the quantum key service end.

[0153] The first token verification information and the second encrypted information are sent by the quantum key service end after the second token verification information and the second encrypted key verification information are verified.

[0154] In step 418, after the first token verification information is verified, the refilling service terminal decrypts the second encrypted information by using the second encrypted key through the identity recognition module, and obtains the m quantum keys.

[0155] In the embodiment of the application, the refilling service terminal verifies the received first token verification, and after the first token verification information is verified by the refilling service terminal, the refilling service terminal sends the second encrypted information to the identity recognition module through the content communication channel between the refilling service terminal and the identity recognition module, so that the identity recognition module directly decrypts the second encrypted information. In this way, the second encrypted information does not pass through the refilling service terminal for processing, but is directly decrypted by the identity recognition module, thereby reducing the risk of leakage of the m quantum keys allocated for the identity recognition module at the refilling service terminal, and ensuring the security of the decryption process and the m quantum keys.

[0156] In step 419, the refilling service terminal stores the m quantum keys in the key storage area of the identity recognition module through the identity recognition module.

[0157] In the embodiment of the application, the identity recognition module stores the decrypted m quantum keys in the key storage area, for example, in the quantum key storage pool of the identity recognition module, so that the security and convenience of the quantum keys applied at the identity recognition module can be ensured.

[0158] Based on the foregoing embodiment, in other embodiments of the application, in step 405, the quantum key service end performing the step of "obtaining a first encrypted key" can be realized by steps 405a-405b:

[0159] In step 405a, the quantum key service end sends first token verification information and a key negotiation request to the refilling service terminal.

[0160] In the embodiment of the present application, after the quantum key service end receives the refill permission message including the authorization token, the quantum key service end can also send a key negotiation request to the refill service terminal, so that the identity recognition module on the refill service terminal side generates a corresponding encryption key, i.e., the first encryption key. At the same time that the quantum key service end sends the key negotiation request to the refill service terminal, the quantum key service end also sends the first token verification information to the refill service terminal, so as to reduce the possibility of the key negotiation request being modified in the transmission process, and ensure the security of the transmission process of the key negotiation request.

[0161] Correspondingly, the refill service terminal executes steps 420-423:

[0162] Step 420, the refill service terminal receives the first token verification information and the key negotiation request sent by the quantum key service end.

[0163] Step 421, after the first token verification information is verified, the refill service terminal generates the first encryption key and the first decryption key by responding to the key negotiation request through the identity recognition module.

[0164] In the embodiment of the present application, after the refill service terminal receives the first token verification information and the key negotiation request, the refill service terminal performs verification processing on the first token verification information. After the first token verification information passes the verification of the refill service terminal, the key negotiation request is sent to the identity recognition module installed in the refill service terminal, so that the identity recognition module responds to the key negotiation request and generates a key pair using a corresponding key encryption algorithm to obtain the first encryption key and the first decryption key. In this way, since the key pair is also generated in the identity recognition module, the risk of leakage and tampering of the key pair at the refill service terminal is reduced.

[0165] Step 422, the refill service terminal sends the second token verification information and the first encryption key to the quantum key service end.

[0166] Step 405b, the quantum key service end receives the second token verification information and the first encryption key sent by the refill service terminal.

[0167] In the embodiment of the present application, the refill service terminal sends the first encryption key to the quantum key service end, so as to realize the encryption information agreement process between the refill service terminal and the quantum key service end, and ensure that subsequent encryption and decryption processing can be accurately performed.

[0168] Step 423, the refill service terminal stores the first decryption key through the identity recognition module.

[0169] In the embodiment of the present application, after the identity recognition module generates the first encryption key and the first decryption key, the identity recognition module is stored in the storage area corresponding to the identity recognition module, so that the identity recognition module subsequently decrypts the information encrypted by the first encryption key using the first decryption key.

[0170] Correspondingly, step 406 can be implemented by the following steps: the quantum key server generates a second encryption key after the second token verification information is verified.

[0171] In the embodiment of the present application, after the quantum key server receives the second token verification information and the first encryption key sent by the refilling service terminal, the quantum key server verifies the second token verification information, and generates an encryption information, i.e., a second encryption key, for encrypting the quantum key transmitted between the quantum key server and the identity recognition module after the second token verification information is verified.

[0172] Based on the foregoing embodiment, in other embodiments of the present application, before the refilling management end performs step 401, the refilling management end further performs steps 424-427.

[0173] Step 424: The refilling management end determines the module identification information of the identity recognition module installed in the refilling service terminal.

[0174] In the embodiment of the present application, the module identification information can be identification information for uniquely identifying the identity recognition module, for example, can be a module code, a module name, a module serial number, etc. of the identity recognition module. The module identification information of the identity recognition module installed in the refilling service terminal can be sent by the refilling service terminal to the refilling management end.

[0175] Step 425: The refilling management end determines a start time of the refilling operation of the quantum key for the identity recognition module.

[0176] In the embodiment of the present application, the start time determined by the refilling management end can be the time when the refilling management end sends the authorization token to the refilling service terminal.

[0177] Step 426: The refilling management end stores the module identification information and the start time.

[0178] In the embodiment of the present application, when storing, the refilling management end can store the module identification information as key information and the start time as attribute information. The data storage can be stored in the form of a list or a database.

[0179] Step 427: The refilling management end sends record indication information to the quantum key server.

[0180] The record indication information is used to instruct the quantum key server to perform the refilling operation of the quantum key for the identity recognition module.

[0181] In the embodiment of the present application, after the filling management end stores the identification information and the start time, the record instruction information is sent to the quantum key service end, so that the quantum key service end starts the corresponding quantum key filling operation.

[0182] Correspondingly, the quantum key service end performs step 428:

[0183] Step 428, the quantum key service end receives the record instruction information sent by the filling management end.

[0184] The record instruction information is used to indicate that the filling operation of filling the quantum key to the identity recognition module has been recorded.

[0185] Based on the foregoing embodiment, in other embodiments of the present application, before the quantum key service end performs the "obtains the first encryption key" in step 405, it is also used to perform steps 429-430:

[0186] Step 429, the quantum key service end generates first token verification information based on the authorization token.

[0187] Step 430, the quantum key service end sends the first token verification information to the filling management end, so that the filling management end performs verification processing on the first token verification information to determine whether to send the record instruction information.

[0188] Correspondingly, the filling management end is used to perform steps 431-432:

[0189] Step 431, the filling management end receives the first token verification information sent by the quantum key service end.

[0190] The first token verification information is generated by the quantum key service end based on the authorization token.

[0191] Step 432, the filling management end verifies the first token verification information and the authorization token to obtain a third verification result.

[0192] In the embodiment of the present application, the filling management end performs verification processing on the filling management end sent by the quantum key service end, so as to determine whether the quantum key service end receives the correct authorization token, and further ensure the reliability of the subsequent operation related to the authorization token or the first token verification information.

[0193] Correspondingly, step 427 can be implemented by the following steps: if the third verification result indicates that the first token verification information passes the verification, the record instruction information is sent to the quantum key service end.

[0194] In the embodiment of the present application, after the third verification result indicates that the first token verification information is verified, it indicates that the identity of the quantum key service end is reliable, therefore, the charging management end can send record indication information to the quantum key service end to formally start the process of quantum key charging.

[0195] Based on the foregoing embodiment, in other embodiments of the present application, before the charging service terminal performs step 403, it is further used to perform steps 433 and 437-439.

[0196] Step 433, the charging service terminal sends an authentication request to the charging management end.

[0197] The authentication request is used to request identity authentication of the identity recognition module.

[0198] In the embodiment of the present application, after the charging service terminal detects that the identity recognition module is installed at the installation position of the identity recognition module, it generates an authentication request to the charging management end, and requests the charging management end to perform identity authentication processing on the installed identity recognition module.

[0199] Correspondingly, the charging management end performs steps 434-436 and step 440.

[0200] Step 434, the charging management end receives the authentication request sent by the charging service terminal.

[0201] The authentication request is used to request identity authentication of the identity recognition module.

[0202] Step 435, the charging management end determines first identity authentication information corresponding to the identity recognition module in response to the authentication request.

[0203] In the embodiment of the present application, the first identity authentication information is identity authentication information generated by the charging management end for the identity recognition module when the identity recognition module is produced by the manufacturer. After receiving the authentication request, the charging management end determines the first identity authentication information corresponding to the identity recognition module.

[0204] Step 436, the charging management end sends the first identity authentication information to the charging service terminal.

[0205] Step 437, the charging service terminal receives the first identity authentication information sent by the charging management end.

[0206] The first identity authentication information is authentication information allocated by the charging management end for the identity recognition module in advance.

[0207] Step 438, the charging service terminal performs authentication processing on the first identity authentication information and the second identity authentication information stored in advance by the identity recognition module, to obtain an authentication result.

[0208] In the embodiment of the present application, the manufacturer fills the second identity authentication information of the identity recognition module into the identity recognition module before the identity recognition module is manufactured and leaves the factory, so as to facilitate subsequent identity authentication of the identity recognition module. The identity recognition module in the filling service terminal matches and authenticates the received first identity authentication information and the second identity authentication information, determines whether they match, for example, whether they are the same, and obtains an authentication result.

[0209] Step 439, if the authentication result indicates that the first identity authentication information matches the second identity authentication information, the filling service terminal sends an identity authentication pass message to the filling management end.

[0210] In the embodiment of the present application, if the authentication result indicates that the first identity authentication information does not match the second identity authentication information, the filling service terminal does not perform subsequent operations, and further, the filling service terminal can generate a prompt message indicating that the identity authentication of the identity recognition module fails.

[0211] When the authentication result indicates that the first identity authentication information matches the second identity authentication information, for example, the first identity authentication information is the same as the second identity authentication information, the filling service terminal sends an identity authentication pass message to the filling management end.

[0212] Step 440, the filling management end receives the identity authentication pass message sent by the filling service terminal.

[0213] The identity authentication pass message is generated by the filling service terminal after authenticating the first identity authentication information.

[0214] After the filling management end performs step 440, it performs step 401. In this way, after the filling management end determines that the identity authentication of the identity recognition module installed in the filling service terminal is passed, it performs subsequent corresponding operations related to the identity recognition module, thereby ensuring the reliability of the subsequent related operations.

[0215] Based on the foregoing embodiment, in other embodiments of the present application, the quantum key service end is further configured to perform step 441:

[0216] Step 441, if the filling control operation is detected, the quantum key service end sends filling instruction information corresponding to the filling control operation to the filling service terminal.

[0217] The filling instruction information indicates that the identity recognition module in the filling service terminal is filled with a quantum key.

[0218] In the embodiment of the present application, the refilling control operation can be a refilling control operation detected by the quantum key server when an operator operates the quantum key server, that is, after the quantum key server detects the refilling control operation on the identity recognition module in the refilling service terminal, the quantum key server generates refilling indication information and sends the refilling indication information to the refilling service terminal.

[0219] Correspondingly, step 433 can be implemented by the following steps: if the refilling indication information sent by the quantum key server is received, the refilling service terminal sends an authentication request to the refilling management end.

[0220] In the embodiment of the present application, after the refilling service terminal receives the refilling indication information sent by the quantum key server, the refilling service terminal generates an authentication request in response to the refilling indication information and sends the authentication request to the refilling management end.

[0221] Based on the foregoing embodiment, in other embodiments of the present application, after the refilling service terminal performs step 419, it is further used to perform step 442:

[0222] Step 442, the refilling service terminal sends second token verification information and stored indication information to the quantum key server.

[0223] The stored indication information is used to indicate that the m quantum keys have been stored.

[0224] In the embodiment of the present application, after the identity recognition module stores the m quantum keys, the stored indication information is generated and sent to the quantum key server through the refilling service terminal, and at the same time, the refilling service terminal also sends the second token verification information to the quantum key server.

[0225] Correspondingly, the quantum key server is used to perform steps 443-446:

[0226] Step 443, the quantum key server receives the second token verification information and the stored indication information sent by the refilling service terminal.

[0227] The stored indication information is used to indicate that the m quantum keys have been stored.

[0228] Step 444, after the second token verification information is verified, the quantum key server responds to the stored indication information to detect whether the quantum keys allocated for the identity recognition module have been sent, and obtains a detection result.

[0229] In the embodiment of the present application, the quantum key server performs verification processing on the received second token verification information, and after the second token verification information is verified, responds to the stored indication information to detect whether all the quantum keys allocated for the identity recognition module have been sent to the identity recognition module, and obtains a detection result.

[0230] Step 445, in the case that the detection result indicates that the quantum keys allocated for the identity recognition module are not sent completely, the quantum key server repeatedly executes the step of "determining m quantum keys allocated for the identity recognition module" until the detection result indicates that the quantum keys allocated for the identity recognition module are sent completely.

[0231] In the embodiments of the present application, in the case that the detection result indicates that the quantum keys allocated for the identity recognition module are not sent completely, i.e., the quantum keys still need to be sent for the identity recognition module, the quantum key server repeatedly executes the step of "determining m quantum keys allocated for the identity recognition module" in step 414 to step 445 until all the quantum keys allocated for the identity recognition module are sent to the identity recognition module.

[0232] Step 446, in the case that the detection result indicates that the quantum keys allocated for the identity recognition module are sent completely, the quantum key server sends the first token verification information and the end-of-recharging indication information to the recharging management end.

[0233] The end-of-recharging indication information is used to indicate that the recharging operation of the quantum keys for the identity recognition module is completed.

[0234] In this way, in the case that the detection result indicates that the quantum keys allocated for the identity recognition module are sent completely, the quantum key server generates the end-of-recharging indication information, and sends the first token verification information and the end-of-recharging indication information to the recharging management end.

[0235] Correspondingly, the recharging management end is also used to execute steps 447-451.

[0236] Step 447, the recharging management end receives the first token verification information and the end-of-recharging indication information sent by the quantum key server.

[0237] Step 448, the recharging management end verifies the first token verification information against the authorized token to obtain a fourth verification result.

[0238] In the embodiments of the present application, the recharging management end verifies the first token verification information against the authorized token to obtain the fourth verification result. When the first token verification information matches the authorized token, it is determined that the fourth verification result is that the first token verification information is verified successfully, and when the first token verification information does not match the authorized token, it is determined that the fourth verification result is that the first token verification information is not verified successfully.

[0239] Step 449, if the fourth verification result indicates that the first token verification information is verified successfully, the recharging management end responds to the end-of-recharging indication information to determine the end time of the recharging operation.

[0240] In the embodiment of the present application, when the fourth verification result is that the at least first token verification information fails to pass the verification, the refilling management end does not perform a related operation, and further, an alarm prompt information can be generated so as to start a leakage risk investigation by a corresponding personnel.

[0241] Step 450, the refilling management end stores the end time.

[0242] Step 451, the refilling management end records the end of the refilling operation.

[0243] Based on the foregoing embodiment, in other embodiments of the present application, before the refilling service terminal performs step 412, steps 452-453 can also be performed:

[0244] Step 452, the refilling service terminal generates second token verification information based on the authorized token.

[0245] In the embodiment of the present application, the second token verification information is generated by the refilling service terminal by processing the authorized token.

[0246] Step 453, the refilling service terminal stores the second token verification information.

[0247] Based on the foregoing embodiment, in other embodiments of the present application, the "second token verification information passes the verification" can be realized by the following steps: verifying the second token verification information by using the authorized token to obtain a first verification result; wherein the first verification result indicates that the second token verification information passes the verification, or the second token verification information fails to pass the verification; or verifying the second token verification information by using the first token verification information to obtain the first verification result.

[0248] Based on the foregoing embodiment, in other embodiments of the present application, the "first token verification information verification" can be realized by the following steps: verifying the first token verification information by using the authorized token to obtain a second verification result; wherein the second verification result indicates that the first token verification information passes the verification, or the first token verification information fails to pass the verification; or verifying the first token verification information by using the second token verification information to obtain the second verification result.

[0249] Based on the foregoing embodiment, in other embodiments of the present application, an organization framework for realizing the quantum key refilling method is provided, as shown in Figure 5 corresponding, based on Figure 5The organization structure shown, to fill in the terminal is deployed in the communication business service hall terminal equipment, for example, can be a handheld device as an example to illustrate, when the user needs to fill in the USIM card quantum key, the USIM card is inserted into the filling terminal, the filling terminal fills in the quantum key for the inserted USIM card through the Internet, the precondition is: in the production preparation stage, the filling center generates a security credential, which is sent to the card vendor in offline or traditional security tunnel mode, and the card vendor preinstalls a security credential for the USIM card when the USIM card is produced, Figure 5 The arrow direction in the figure corresponds to the specific steps of the flow as follows:

[0250] Step a101, the quantum cryptography service platform sends a filling instruction to the filling terminal.

[0251] Among them, step a101 can be a selected execution step, that is, step a101 can not be executed. The filling instruction corresponds to the filling control operation described above, and the quantum cryptography service platform sends the filling instruction to the filling terminal after the relevant personnel performs the corresponding operation on the quantum cryptography service platform.

[0252] Step a102, the filling terminal sends an authentication request to the filling center.

[0253] Among them, the authentication request is used to request identity authentication of the USIN card, and to request to obtain the security credential hash value corresponding to the security credential of the USIM card.

[0254] Step a103, the filling center provides the security credential hash value to the filling terminal.

[0255] Among them, the filling center acquires the security credential hash value corresponding to the USIM card in response to the received authentication request, and provides the security credential hash value to the filling terminal.

[0256] Step a104, the filling terminal sends a filling request to the USIM card.

[0257] Among them, the filling request carries the security credential hash value provided by the filling center. The security credential hash value matches the first identity authentication information described above.

[0258] Step a105, the self-authentication module in the USIM card performs a security credential hash value verification operation, if the security credential hash value verification is passed, step a106 is executed, otherwise, the operation is ended.

[0259] Among them, the specific process of the USIM card performing the security credential hash value verification operation is: verifying whether the security credential hash value matches the security credential pre-stored in the USIM card. The security credential corresponds to the second identity authentication information described above.

[0260] Step a106, the USIM card returns an identity authentication pass instruction to the refilling terminal.

[0261] The identity authentication pass instruction indicates that the security credential hash value is verified to pass, and the subsequent related quantum key refilling operation can be authorized.

[0262] Step a107, the refilling terminal sends an authorization acquisition notification message to the refilling center.

[0263] The authorization acquisition notification message is used to notify the refilling center that the quantum key refilling authorization of the USIM card has been acquired.

[0264] Step a108, the refilling center sends an authorization token to the refilling terminal,

[0265] The authorization token can be denoted as sToken. The process corresponds to the process of sending the aforementioned allow refilling message including the authorization token. After the refilling center receives the authorization acquisition notification message sent by the refilling terminal, the authorization token corresponding to the USIM card is generated, and then the authorization token is sent to the refilling terminal.

[0266] Step a109, the refilling terminal sends a notification message including the authorization token to the quantum cryptography service platform.

[0267] Step a110, the quantum cryptography service platform verifies the authorization token, and after the authorization token is verified to pass, the quantum cryptography service platform sends an authorization token hash value to the refilling center.

[0268] The authorization token hash value is obtained by processing the authorization token.

[0269] Step a111, the refilling center verifies the authorization token hash value, and after the authorization token hash value is verified to pass, the refilling center sends a verification pass notification message to the quantum cryptography service platform, and the refilling center records the start of this refilling at the same time.

[0270] The implementation process of the refilling center verifying the authorization token hash value can be that whether the authorization token hash value matches the authorization token is verified.

[0271] Step a112, after the quantum cryptography service platform receives the verification pass notification message, the quantum cryptography service platform sends the authorization token hash value and a key negotiation request to the refilling terminal.

[0272] Step a113, the refilling terminal verifies the authorization token hash value, and after the authorization token hash value is verified to pass, the refilling terminal only forwards the key negotiation request to the USIM card.

[0273] Step a114, after receiving the key agreement request, the USIM card generates a public key Public-Key and a private key Secret-Key using a key generation algorithm, and then sends the public key Public-Key to the top-up terminal.

[0274] The USIM card stores the private key Secret-Key in a storage area of the USIM card.

[0275] Step a115, the top-up terminal sends the public key Public-Key and the authorization token hash value to the quantum cryptography service platform.

[0276] Step a116, the quantum cryptography service platform verifies the authorization token hash value, and after the authorization token hash value is verified, the quantum cryptography service platform generates a secure channel key Channel-Key.

[0277] Step a117, the quantum cryptography service platform encrypts the secure channel key Channel-Key using the public key Public-Key to obtain Encryption-Channel-Key.

[0278] Encryption-Channel-Key = Encryption(Channel-Key, Public-Key).

[0279] Step a118, the quantum cryptography service platform sends the Encryption-Channel-Key and the authorization token hash value to the USIM card through the top-up terminal.

[0280] Step a119, the top-up terminal verifies the authorization token hash value, and when the authorization token hash value is verified, the top-up terminal only sends the Encryption-Channel-Key to the USIM card.

[0281] Step a120, the USIM card decrypts the Encryption-Channel-Key using the private key Secret-Key to obtain the secure channel key Channel-Key.

[0282] The decryption process can be denoted as Channel-Key = Decryption(Encryption-Channel-Key, Secret-Key).

[0283] Step a121, the USIM card sends the Channel-Key hash value and the authorization token hash value to the quantum cryptography service platform through the top-up terminal.

[0284] Wherein, the Channel-Key hash value can be recorded as Hash-Channel-Key = Hash(Channel-Key), and the hash value obtained by the USIN card after hashing the Channel-Key.

[0285] Step a122, the quantum cryptography service platform verifies the authorization token hash value and Hash-Channel-Key, and after the authorization token hash value and Hash-Channel-Key are both verified, uses the Channel-Key to encrypt one or more quantum keys QK to obtain Encryption(QK, Channel-Key), and sends Encryption(QK, Channel-Key) and the authorization token hash value to the refilling terminal.

[0286] Wherein, the process that the quantum cryptography uses the Channel-Key to encrypt one or more quantum keys QK to obtain Encryption(QK, Channel-Key) can be recorded as Encryption-QK = Encryption(QK, Channel-Key).

[0287] Step a123, the refilling terminal verifies the authorization token hash value, and after the authorization token hash value is verified, the refilling terminal sends Encryption(QK, Channel-Key) to the USIM card.

[0288] Step a124, the USIM card decrypts Encryption(QK, Channel-Key) using the Channel-Key to obtain one or more quantum keys QK.

[0289] Wherein, the process that the USIM card decrypts Encryption(QK, Channel-Key) using the Channel-Key to obtain one or more quantum keys QK can be recorded as QK = Decryption(Encryption-QK, Channel-Key).

[0290] Step a125, the USIM card writes the decrypted one or more quantum keys QK into the self key storage pool.

[0291] Step a126, the USIM card sends a notification message and the authorization token hash value to the quantum cryptography service platform through the refilling terminal after the writing is completed.

[0292] Step a127, the quantum cryptography service platform verifies the authorization token hash value, and if the authorization token hash value is verified, and if the quantum cryptography service platform detects that there are more quantum keys QKs to be written into the USIM card, the quantum cryptography service platform repeats the process of step a122 "encrypting one or more quantum keys QKs using Channel-Key to obtain Encryption(QK, Channel-Key), and sending Encryption(QK, Channel-Key) and the authorization token hash value to the refilling terminal" to step a127 until all quantum keys to be written into the USIM card are written into the USIM card.

[0293] Step a128, if the quantum cryptography service platform does not have more quantum keys QKs to be written into the USIM card, the quantum cryptography service platform sends a refilling completion message and the authorization token hash value to the refilling center.

[0294] Step a129, after the refilling center verifies the authorization token hash value, the refilling event is recorded as ended.

[0295] In this way, the refilling center creates a secure credential, locally saves a copy, and sends the secure credential to the USIM card manufacturer to pre-load the secure credential into the USIM card. In this way, before the refilling starts, the USIM card can authenticate the refilling center according to the secure credential, so that if an attacker tampers with the authorization token in an individual USIM card at the USIM card manufacturer, it is also difficult for the attacker to tamper with the authorization token of the refilling center, resulting in that the individual USIM card cannot pass the authentication, and thus the USIM card is scrapped and cannot be further refilled with quantum keys, thereby avoiding the problem of quantum key leakage or theft.

[0296] Further, after the USIM card performs identity authentication, the refilling center also issues an authorization token sToken to the refilling terminal, and the refilling terminal also sends the sToken to the quantum cryptography service platform, so that the quantum cryptography service platform requests the refilling center to verify the sToken, thereby realizing that the refilling center, the refilling terminal, and the quantum cryptography service platform all authenticate each other.

[0297] Further, in each information transmission interaction process between the refilling terminal and the quantum cryptography service platform, the sToken is used to verify the corresponding hash value to prevent man-in-the-middle attacks.

[0298] Further, the public key and the private key are generated by the USIM card, and then sent to the quantum cryptography server platform through a secure channel similar to the Hypertext Transfer Protocol Secure (https), thereby reducing the public key storage cost, providing protection for the public key, and prolonging the storage time.

[0299] In summary, the refilling center is a network SIM card management unit, which authenticates the SIM card to prevent counterfeiting. In the refilling process, the quantum key plaintext does not appear in any device or any link in the middle. Instead, the quantum cryptography service platform directly sends the quantum key to the USIM card through the refilling terminal after encryption, and the USIM card performs decryption and encryption processing, thereby reducing the possibility of quantum key leakage in plaintext. In addition, the quantum cryptography service platform records the relevant information of the quantum key of each USIM card during the refilling process, which can be traced and analyzed subsequently. In this way, the security of the quantum key is ensured.

[0300] It should be noted that the descriptions of the same steps and contents in this embodiment and other embodiments can refer to the descriptions in other embodiments, and will not be repeated here.

[0301] The quantum key charging method provided by the embodiment of the application, the charging management end determines the authorization token corresponding to the identity recognition module installed in the charging service terminal, sends the authorization token to the charging service terminal, the charging service terminal receives the authorization token sent by the charging management end, and sends the permission charging message including the authorization token to the quantum key service end, if the quantum key service end receives the permission charging message including the authorization token sent by the charging service terminal, the quantum key service end obtains the first encryption key, generates the second encryption key corresponding to the identity recognition module, and encrypts the second encryption key by using the first encryption key to obtain the first encrypted information, and then sends the first token verification information and the first encrypted information to the charging service terminal, after the charging service terminal receives the first token information and the first encrypted information sent by the quantum key service end, the first token verification information is verified, the first encrypted information is decrypted by using the first decryption key through the identity recognition module to obtain the second encryption key, and after the second encryption key verification information is generated based on the second encryption key through the identity recognition module, the stored second token verification information and the second encryption key verification information are sent to the quantum key service end, the quantum key service end receives the second token verification information and the second encryption key verification information sent by the charging service terminal, and after the second token verification information and the second encryption key verification information are verified, the quantum key service end determines the m quantum keys allocated to the identity recognition module, encrypts the m quantum keys by using the second encryption key to obtain the second encrypted information, and sends the first token verification information and the second encrypted information to the charging service terminal, after the charging service terminal receives the first token verification information and the second encrypted information sent by the quantum key service end, the first token verification information is verified, the second encrypted information is decrypted by using the second encryption key through the identity recognition module to obtain the m quantum keys, and finally the m quantum keys are stored in the key storage area of the identity recognition module through the identity recognition module.In this way, after receiving the authorization token from the charging management terminal, the charging service terminal notifies the quantum key server that quantum key charging can be performed through a charging permission message including the authorization token. Then, the quantum key server uses a first encryption key to encrypt the second encryption key used for communication between the quantum key server and the identity recognition module installed in the charging service terminal, and sends it to the identity recognition module. After confirming that the identity recognition module has received the second encryption key and that the received second encryption key is correct, the terminal uses the second encryption key, which is only available to the identity recognition module, to encrypt the m quantum keys allocated to the identity recognition module, obtaining second encrypted information, and sends the second encrypted information to the identity recognition module. The identification module uses a second encryption key to decrypt the received second encrypted information, obtaining m quantum keys, which are stored in the identification module's storage area. Throughout the process, only the quantum key server and the identification module possess the second encryption key, ensuring the security of the transmitted quantum keys. Furthermore, the system verifies the corresponding verification information based on an authorization token, ensuring that any information tampering is detected promptly. This solves the leakage risk problem present in current quantum key injection processes and proposes a quantum key injection method that guarantees both the security and feasibility of the quantum key injection process.

[0302] Based on the foregoing embodiments, embodiments of this application provide a first quantum key injection device, which is applied to a quantum key server. This device can be used in… Figures 1-2 and Figure 4 In the quantum key injection method provided in the corresponding embodiments, refer to Figure 6 As shown, the first quantum key injection device 5 may include: an acquisition unit 51, a first generation unit 52, an encryption processing unit 53, a first sending unit 54, and a first determining unit 55; wherein:

[0303] The acquisition unit 51 is used to acquire the first encryption key if it receives a recharge permission message including an authorization token sent by the recharge service terminal; wherein, the authorization token is authorization information assigned by the recharge management terminal to the identity recognition module installed in the recharge service terminal;

[0304] The first generation unit 52 is used to generate the second encryption key corresponding to the identity recognition module;

[0305] The encryption processing unit 53 is used to encrypt the second encryption key using the first encryption key to obtain the first encrypted information;

[0306] The first sending unit 54 is configured to send the first token verification information and the first encrypted information to the refilling service terminal, so that the first token verification information passes the verification of the refilling service terminal, and the first encrypted information is decrypted based on the first decryption key by the identity recognition module to obtain the second encryption key, and the first token verification information has an association relationship with the authorization token;

[0307] The obtaining unit 51 is further configured to receive second token verification information and second encryption key verification information sent by the refilling service terminal, wherein the second encryption key verification information has an association relationship with the second encryption key;

[0308] The first determining unit 55 is configured to determine m quantum keys allocated to the identity recognition module after the second token verification information and the second encryption key verification information both pass the verification, wherein the second token verification information has an association relationship with the authorization token, and m is an integer greater than or equal to 1.

[0309] The encryption processing unit 53 is configured to perform encryption processing on the m quantum keys by using the second encryption key to obtain second encrypted information.

[0310] The first sending unit 54 is configured to send the first token verification information and the second encrypted information to the refilling service terminal, so that the identity recognition module stores the m quantum keys carried in the second encrypted information.

[0311] In other embodiments of the present application, when the obtaining unit performs the step of obtaining the first encryption key, the following steps can be implemented:

[0312] The first token verification information and the key negotiation request are sent to the refilling service terminal.

[0313] The second token verification information and the first encryption key sent by the refilling service terminal are received.

[0314] In other embodiments of the present application, the first generating unit is specifically configured to implement the following steps:

[0315] The second encryption key is generated after the second token verification information passes the verification.

[0316] In other embodiments of the present application, before obtaining the first encryption key, the obtaining unit is further configured to implement the following steps:

[0317] The record indication information sent by the refilling management terminal is received, wherein the record indication information is used to indicate that the refilling operation of refilling quantum keys to the identity recognition module has been recorded.

[0318] In other embodiments of the present application, before the obtaining unit performs the step of obtaining the first encryption key, the following steps are further implemented:

[0319] Based on the authorization token, first token verification information is generated;

[0320] The first token verification information is sent to the refilling management terminal, so that the refilling management terminal performs verification processing on the first token verification information to determine whether to send record instruction information.

[0321] In other embodiments of the present application, after the first sending unit performs the step of sending the first token verification information and the second encrypted information to the refilling service terminal, the device further comprises a second receiving unit, a responding unit and a repeated execution unit; wherein:

[0322] The second receiving unit is configured to receive the second token verification information and the stored instruction information sent by the refilling service terminal; wherein the stored instruction information is used to indicate that the m quantum keys have been stored.

[0323] The responding unit is configured to, after the second token verification information is verified, respond to the stored instruction information, detect whether the quantum keys allocated to the identity recognition module have been sent, and obtain a detection result.

[0324] The repeated execution unit is configured to, in the case that the detection result indicates that the quantum keys allocated to the identity recognition module have not been sent, repeatedly perform the step of "determining the m quantum keys allocated to the identity recognition module" until the detection result indicates that the quantum keys allocated to the identity recognition module have been sent.

[0325] The first sending unit is further configured to, in the case that the detection result indicates that the quantum keys allocated to the identity recognition module have been sent, send the first token verification information and a refilling end instruction information to the refilling management terminal; wherein the refilling end instruction information is used to indicate that the refilling operation of the quantum keys for the identity recognition module has been completed.

[0326] In other embodiments of the present application, the first sending unit is further configured to, if the refilling control operation is detected, send refilling instruction information corresponding to the refilling control operation to the refilling service terminal; wherein the refilling instruction information indicates that the quantum keys are refilled for the identity recognition module in the refilling service terminal.

[0327] In other embodiments of the present application, the device further comprises a first verification unit; wherein:

[0328] The first verification unit is configured to verify the second token verification information by using the authorization token to obtain a first verification result; wherein the first verification result indicates that the second token verification information is verified or the second token verification information is not verified.

[0329] Alternatively, the first verification unit is configured to verify the second token verification information by using the first token verification information to obtain a first verification result.

[0330] It should be noted that the process of information interaction between units and modules in this embodiment can refer to the description in other embodiments, which will not be repeated here.

[0331] The first quantum key charging device provided by the embodiment of the application, if the charging service terminal sends the charging permission message including the authorization token, the quantum key service end acquires the first encryption key, generates the second encryption key corresponding to the identity recognition module, and encrypts the second encryption key using the first encryption key to obtain the first encrypted information, and then sends the first token verification information and the first encrypted information to the charging service terminal, receives the second token verification information and the second encryption key verification information sent by the charging service terminal, and after the second token verification information and the second encryption key verification information are both verified, determines the m quantum keys allocated to the identity recognition module, encrypts the m quantum keys using the second encryption key to obtain the second encrypted information, and sends the first token verification information and the second encrypted information to the charging service terminal, so that after the charging service terminal receives the first token verification information and the second encrypted information sent by the quantum key service end, the second encrypted information is decrypted using the second encryption key through the identity recognition module to obtain the m quantum keys, and the m quantum keys are stored in the key storage area of the identity recognition module. In this way, after the charging service terminal receives the authorization token sent by the charging management end, the quantum key service end is notified through the charging permission message including the authorization token that the quantum key charging can be performed, and then the quantum key service end encrypts the second encryption key between the quantum key service end and the identity recognition module installed in the charging service terminal using the first encryption key, and sends it to the identity recognition module, and after the identity recognition module receives the second encryption key and determines that the second encryption key received by the identity recognition module is correct, the second encryption key possessed by the identity recognition module is used to encrypt the m quantum keys allocated to the identity recognition module to obtain the second encrypted information, and the second encrypted information is sent to the identity recognition module. In this way, the identity recognition module can decrypt the received second encrypted information using the second encryption key to obtain the m quantum keys, and store them in the storage area of the identity recognition module. Only the quantum key service end and the identity recognition module possess the second encryption key in the whole process, which ensures the security of the transmitted quantum key, and the corresponding verification information is verified based on the authorization token in the whole process, which ensures that the information being transmitted will be discovered in time when it is tampered with, solves the problem of leakage risk in the current quantum key charging process, and proposes a quantum key charging method, which ensures the security of the quantum key and the realizability of the quantum key charging process.

[0332] Based on the foregoing embodiments, the embodiments of the present application provide a second quantum key replenishment device, which is applied to a replenishment service terminal installed with an identity recognition module, and the device can be applied to Figures 1-4 The quantum key replenishment method provided by the corresponding embodiments of the present application is shown in Figure 7 The second quantum key replenishment device 6 can include a first receiving unit 61, a decryption processing unit 62, a second generating unit 63, a second sending unit 64, and a first storage unit 65.

[0333] The first receiving unit 61 is configured to receive an authorization token sent by a replenishment management end, wherein the authorization token is token information allocated by the replenishment management end to the identity recognition module after the identity recognition module is authenticated by the replenishment management end.

[0334] The second sending unit 64 is configured to send an allowed replenishment message including the authorization token to a quantum key service end.

[0335] The first receiving unit 61 is further configured to receive first token verification information and first encrypted information sent by the quantum key service end, wherein the first token verification information is generated by the quantum key service end based on the authorization token allocated by the replenishment management end to the identity recognition module.

[0336] The decryption processing unit 62 is configured to, after the first token verification information is verified, decrypt the first encrypted information by using a first decryption key of the identity recognition module to obtain a second encryption key, wherein the first decryption key is stored in the identity recognition module.

[0337] The second generating unit 63 is configured to generate second encryption key verification information based on the second encryption key by using the identity recognition module.

[0338] The second sending unit 64 is configured to send the stored second token verification information and the second encryption key verification information to the quantum key service end.

[0339] The first receiving unit 61 is further configured to receive first token verification information and second encrypted information sent by the quantum key service end, wherein the first token verification information and the second encrypted information are sent by the quantum key service end after the second token verification information and the second encryption key verification information are both verified.

[0340] The decryption processing unit 62 is further configured to, after the first token verification information is verified, decrypt the second encrypted information by using a second encryption key of the identity recognition module to obtain m quantum keys.

[0341] The first storage unit 65 is configured to store the m quantum keys in a key storage area of the identity recognition module by using the identity recognition module.

[0342] In other embodiments of the present application, before the first receiving unit performs the step of receiving the first token verification information and the first encryption information sent by the quantum key service end, the first receiving unit is further configured to receive the first token verification information and the key negotiation request sent by the quantum key service end;

[0343] The second generating unit is further configured to, after the first token verification information is verified, generate the first encryption key and the first decryption key by responding to the key negotiation request through the identity recognition module;

[0344] The second sending unit is further configured to send the second token verification information and the first encryption key to the quantum key service end;

[0345] The first storage unit is further configured to store the first decryption key through the identity recognition module.

[0346] In other embodiments of the present application, before the first receiving unit performs the step of receiving the authorization token sent by the refilling management end, the device further comprises an authentication unit; wherein:

[0347] The second sending unit is further configured to send an authentication request to the refilling management end; wherein the authentication request is used to request identity authentication of the identity recognition module;

[0348] The second receiving unit is further configured to receive the first identity authentication information sent by the refilling management end; wherein the first identity authentication information is the authentication information pre-allocated by the refilling management end for the identity recognition module;

[0349] The authentication unit is configured to perform authentication processing on the first identity authentication information and the pre-stored second identity authentication information through the identity recognition module to obtain an authentication result;

[0350] The second sending unit is further configured to, if the authentication result indicates that the first identity authentication information matches the second identity authentication information, send an identity authentication pass message to the refilling management end.

[0351] In other embodiments of the present application, before the second sending unit performs the step of sending the stored second token verification information and the second encryption key verification information to the quantum key service end, the device further comprises a second storage unit; wherein:

[0352] The second generating unit is further configured to generate the second token verification information based on the authorization token;

[0353] The second storage unit is further configured to store the second token verification information.

[0354] In the embodiment of the present application, after the first storage unit stores the m quantum keys into the key storage area of the identity recognition module through the identity recognition module, the second sending unit is further configured to send the second token verification information and the stored indication information to the quantum key server; wherein the stored indication information is used to indicate that the m quantum keys have been stored.

[0355] In other embodiments of the present application, the device further comprises a second verification unit; wherein:

[0356] The second verification unit is configured to verify the first token verification information using the authorized token to obtain a second verification result; wherein the second verification result indicates that the first token verification information is verified successfully or the first token verification information is not verified successfully.

[0357] Alternatively, the second verification unit is configured to verify the first token verification information using the second token verification information to obtain a second verification result.

[0358] In other embodiments of the present application, when the second sending unit sends the authentication request to the refilling management end, the following steps can be used to achieve it:

[0359] If the refilling indication information sent by the quantum key server is received, the authentication request is sent to the refilling management end.

[0360] It should be noted that the process of information interaction between the units and modules in the present embodiment can refer to the description in other embodiments, which will not be repeated here.

[0361] The second quantum key charging device provided by the embodiment of the application receives the authorization token sent by the charging management terminal through the charging service terminal, and sends the charging permission message including the authorization token to the quantum key service terminal, so that the quantum key service terminal, after receiving the charging permission message including the authorization token sent by the charging service terminal, obtains the first encryption key, generates the second encryption key corresponding to the identity recognition module, and performs encryption processing on the second encryption key by using the first encryption key to obtain the first encrypted information, and then sends the first token verification information and the first encrypted information to the charging service terminal. After the charging service terminal receives the first token information and the first encrypted information sent by the quantum key service terminal, after the first token verification information is verified, the first encrypted information is decrypted by using the first decryption key through the identity recognition module to obtain the second encryption key, and after the second encryption key verification information is generated based on the second encryption key through the identity recognition module, the stored second token verification information and the second encryption key verification information are sent to the quantum key service terminal, so that the quantum key service terminal receives the second token verification information and the second encryption key verification information sent by the charging service terminal, and after the second token verification information and the second encryption key verification information are verified, the m quantum keys allocated to the identity recognition module are determined, the m quantum keys are encrypted by using the second encryption key to obtain the second encrypted information, and the first token verification information and the second encrypted information are sent to the charging service terminal. In this way, after the charging service terminal receives the first token verification information and the second encrypted information sent by the quantum key service terminal, after the first token verification information is verified, the second encrypted information is decrypted by using the second encryption key through the identity recognition module to obtain the m quantum keys, and finally the m quantum keys are stored in the key storage area of the identity recognition module through the identity recognition module.In this way, after receiving the authorization token sent by the refilling management terminal, the refilling service terminal informs the quantum key service terminal that the quantum key refilling can be performed through the refilling permission message including the authorization token, and then the quantum key service terminal sends the second encryption key for communication between the quantum key service terminal and the installed identity recognition module of the refilling service terminal after performing encryption processing on the second encryption key by using the first encryption key, and determines that the second encryption key is received by the identity recognition module and that the second encryption key received by the identity recognition module is correct, and then performs encryption processing on the m quantum keys allocated to the identity recognition module by using the second encryption key possessed by the identity recognition module to obtain second encryption information, and sends the second encryption information to the identity recognition module. In this way, the identity recognition module can perform decryption processing on the received second encryption information by using the second encryption key to obtain the m quantum keys, and store the m quantum keys in the storage area of the identity recognition module. Only the quantum key service terminal and the identity recognition module possess the second encryption key in the whole process, which ensures the security of the transmitted quantum key, and the corresponding verification information is verified based on the authorization token in the whole process, which ensures that the information being transmitted will be discovered in time when it is tampered with. The problem of leakage risk in the current quantum key refilling process is solved. A quantum key refilling method is proposed to ensure the security of the quantum key and the realizability of the quantum key refilling process.

[0362] Based on the foregoing embodiments, the embodiments of the present application provide a third quantum key refilling device, which is applied to a refilling management terminal. The device can be applied to Figures 2-4 In the quantum key refilling method provided by the corresponding embodiments, referring to Figure 7 The third quantum key refilling device 7 can include a second determination unit 71 and a third sending unit 72, where:

[0363] The second determination unit 71 is configured to determine the authorization token corresponding to the identity recognition module installed in the refilling service terminal.

[0364] The third sending unit 72 is configured to send the authorization token to the refilling service terminal, so that the refilling service terminal sends the authorization token to the quantum key service terminal, so that the refilling service terminal and the quantum key service terminal perform verification processing based on the authorization token.

[0365] In other embodiments of the present application, before the second determination unit performs the step of determining the authorization token corresponding to the identity recognition module installed in the refilling service terminal, the device further includes a third storage unit, where:

[0366] The second determination unit is further configured to determine the module identification information of the identity recognition module installed in the refilling service terminal.

[0367] The second determining unit is further configured to determine a start time of the refilling operation on the quantum key of the identity recognition module.

[0368] The third storage unit is configured to store the module identification information and the start time.

[0369] The third sending unit is further configured to send record indication information to the quantum key server, wherein the record indication information is used to instruct the quantum key server to perform the refilling operation on the quantum key of the identity recognition module.

[0370] In other embodiments of the present application, before the second determining unit determines the module identification information of the identity recognition module installed in the refilling service terminal, the device further comprises a third receiving unit, wherein:

[0371] The third receiving unit is configured to receive an authentication request sent by the refilling service terminal, wherein the authentication request is used to request identity authentication on the identity recognition module.

[0372] The second determining unit is further configured to determine first identity authentication information corresponding to the identity recognition module in response to the authentication request.

[0373] The third sending unit is further configured to send the first identity authentication information to the refilling service terminal.

[0374] The third receiving unit is further configured to receive an identity authentication pass message sent by the refilling service terminal, wherein the identity authentication pass message is generated after the refilling service terminal performs authentication processing on the first identity authentication information.

[0375] In other embodiments of the present application, after the third sending unit sends the record indication information to the quantum key server, the device further comprises a third verification unit, wherein:

[0376] The third receiving unit is further configured to receive first token verification information sent by the quantum key server, wherein the first token verification information is generated by the quantum key server based on the authorization token.

[0377] The third verification unit is configured to verify the first token verification information and the authorization token to obtain a third verification result.

[0378] In other embodiments of the present application, when the third sending unit sends the record indication information to the quantum key server, the following steps can be used to achieve the sending:

[0379] If the third verification result indicates that the first token verification information passes the verification, the record indication information is sent to the quantum key server.

[0380] In other embodiments of the present application, after the third sending unit sends the record indication information to the quantum key server, the device further comprises a recording unit, wherein:

[0381] The third receiving unit is further configured to receive first token verification information and end-of-recharge indication information sent by the quantum key server.

[0382] The third verification unit is further configured to verify the first token verification information and the authorization token to obtain a fourth verification result.

[0383] The second determination unit is further configured to, if the fourth verification result indicates that the first token verification information is verified, determine an end time of the recharge operation in response to the end-of-recharge indication information.

[0384] The third storage unit is further configured to store the end time.

[0385] The recording unit is configured to record the end of the recharge operation.

[0386] It should be noted that the process of information interaction between the units and modules in this embodiment can refer to the description in other embodiments, which will not be described here.

[0387] The third quantum key filling device provided by the embodiment of the application determines the authorization token corresponding to the identity recognition module installed in the filling service terminal through the filling management end, sends the authorization token to the filling service terminal, so that the filling service terminal receives the authorization token sent by the filling management end and sends the filling permission message including the authorization token to the quantum key service end. If the filling permission message including the authorization token sent by the filling service terminal is received, the quantum key service end obtains a first encryption key, generates a second encryption key corresponding to the identity recognition module, and performs encryption processing on the second encryption key by using the first encryption key to obtain first encryption information, and then sends the first token verification information and the first encryption information to the filling service terminal. After the filling service terminal receives the first token information and the first encryption information sent by the quantum key service end, the first token verification information is verified to pass, the first encryption information is decrypted by using the first decryption key through the identity recognition module to obtain the second encryption key, and after the second encryption key verification information is generated based on the second encryption key through the identity recognition module, the stored second token verification information and the second encryption key verification information are sent to the quantum key service end. The quantum key service end receives the second token verification information and the second encryption key verification information sent by the filling service terminal, and after the second token verification information and the second encryption key verification information are verified to pass, m quantum keys allocated to the identity recognition module are determined, the m quantum keys are encrypted by using the second encryption key to obtain second encryption information, and the first token verification information and the second encryption information are sent to the filling service terminal. After the filling service terminal receives the first token verification information and the second encryption information sent by the quantum key service end, the first token verification information is verified to pass, the second encryption information is decrypted by using the second encryption key through the identity recognition module to obtain the m quantum keys, and finally the m quantum keys are stored in the key storage area of the identity recognition module through the identity recognition module.In this way, after receiving the authorization token from the charging management terminal, the charging service terminal notifies the quantum key server that quantum key charging can be performed through a charging permission message including the authorization token. Then, the quantum key server uses a first encryption key to encrypt the second encryption key used for communication between the quantum key server and the identity recognition module installed in the charging service terminal, and sends it to the identity recognition module. After confirming that the identity recognition module has received the second encryption key and that the received second encryption key is correct, the terminal uses the second encryption key, which is only available to the identity recognition module, to encrypt the m quantum keys allocated to the identity recognition module, obtaining second encrypted information, and sends the second encrypted information to the identity recognition module. The identification module uses a second encryption key to decrypt the received second encrypted information, obtaining m quantum keys, which are stored in the identification module's storage area. Throughout the process, only the quantum key server and the identification module possess the second encryption key, ensuring the security of the transmitted quantum keys. Furthermore, the module verifies the corresponding verification information based on an authorization token, ensuring that any information tampering will be detected promptly. This solves the problem of leakage risks in current quantum key injection processes and proposes a quantum key injection method that guarantees both the security and feasibility of the quantum key injection process.

[0388] Based on the foregoing embodiments, this application provides a quantum key injection system, which can be applied to the quantum key injection method provided in the foregoing embodiments, with reference to... Figure 9 As shown, the quantum key injection system 8 includes at least: a quantum key server 81, an injection service terminal 82 equipped with an identity recognition module, and an injection management terminal 83; wherein:

[0389] Quantum key server 81 is used to implement, for example... Figures 1-2 and Figure 4 The implementation process of the quantum key injection method provided in the corresponding embodiments will not be described in detail here;

[0390] Refilling service terminal 82 is used to achieve, for example Figures 1-4 The implementation process of the quantum key injection method provided in the corresponding embodiments will not be described in detail here;

[0391] The filling management terminal 83 is used to achieve, for example, Figures 2-4 The implementation process of the quantum key injection method provided in the corresponding embodiment will not be described in detail here.

[0392] Based on the foregoing embodiments, embodiments of this application provide a computer-readable storage medium, simply referred to as a storage medium, which stores one or more programs that can be executed by one or more processors to implement the reference.Figures 1-2 and Figure 4 、 Figures 1-4 , or Figures 2-4 The corresponding embodiments provide an implementation process in the method for quantum key replenishment. Details are not described herein.

[0393] Based on the foregoing embodiments, the embodiments of the present application further provide a computer program product, comprising a computer program, which can be executed by a processor of a quantum key server, or a processor of a replenishment service terminal, or a replenishment management terminal, to complete any of the foregoing method steps.

[0394] Those skilled in the art should understand that the embodiments of the present application can be provided as a method, a system, or a computer program product. Therefore, the present application can take the form of a hardware embodiment, a software embodiment, or an embodiment combining software and hardware aspects. Moreover, the present application can take the form of a computer program product implemented on one or more computer-usable storage media (including, but not limited to, disk storage and optical storage, etc.) containing computer-usable program code.

[0395] The present application is described with reference to flowcharts and / or block diagrams according to the methods, devices (systems), and computer program products of the embodiments of the present application. It should be understood that each flow and / or block in the flowcharts and / or block diagrams, and the combination of flows and / or blocks in the flowcharts and / or block diagrams can be implemented by computer program instructions. These computer program instructions can be provided to a general-purpose computer, a special-purpose computer, an embedded processor, or other programmable data processing devices to produce a machine, so that the instructions executed by the computer or other programmable data processing devices produce a device that implements the functions specified in the flowcharts and / or block diagrams. Figure 1 one or more flows and / or blocks Figure 1 an apparatus that implements the functions specified in one or more flows and / or blocks.

[0396] These computer program instructions can also be stored in a computer-readable memory that can direct the computer or other programmable data processing devices to work in a specific manner, so that the instructions stored in the computer-readable memory produce a manufactured product including instruction apparatus, which implements the functions specified in the flowcharts and / or block diagrams. Figure 1 one or more flows and / or blocks Figure 1 an apparatus that implements the functions specified in one or more flows and / or blocks.

[0397] These computer program instructions can also be loaded into a computer or other programmable data processing device, so that a series of operation steps are performed on the computer or other programmable device to produce a computer-implemented process, so that the instructions executed on the computer or other programmable device provide a process for implementing the functions specified in the flowcharts and / or block diagrams. Figure 1 one or more flows and / or blocks Figure 1steps of the functions specified in the one or more blocks.

[0398] The above descriptions are merely specific embodiments of the present application, but not for limiting the protection range of the present application.

Claims

1. A quantum key injection method, characterized in that, The method is applied to a quantum key distribution server, and the method includes: If a recharge permission message containing an authorization token is received from the recharge service terminal, the first encryption key is obtained; wherein, the authorization token is authorization information assigned by the recharge management terminal to the identity recognition module installed in the recharge service terminal; Generate the second encryption key corresponding to the identity recognition module; The first encryption key is used to encrypt the second encryption key to obtain the first encrypted information; Send the first token verification information and the first encrypted information to the recharge service terminal, so that after the first token verification information is verified by the recharge service terminal, the first encrypted information is decrypted by the identity recognition module based on the first decryption key to obtain the second encryption key. The first token verification information is associated with the authorization token. The system receives a second token verification message and a second encryption key verification message sent by the recharge service terminal; wherein the second encryption key verification message is associated with the second encryption key. After both the second token verification information and the second encryption key verification information are verified successfully, m quantum keys are determined to be allocated to the identity recognition module; wherein, the second token verification information is associated with the authorization token, and m is an integer greater than or equal to 1; The m quantum keys are encrypted using the second encryption key to obtain the second encrypted information; The first token verification information and the second encryption information are sent to the recharge service terminal so that the identity recognition module stores the m quantum keys carried in the second encryption information.

2. The method according to claim 1, characterized in that, Obtaining the first encryption key includes: Send the first token verification information and key negotiation request to the refill service terminal; Receive the second token verification information and the first encryption key sent by the recharge service terminal.

3. The method according to claim 2, characterized in that, The generation of the second encryption key corresponding to the identity recognition module includes: After the second token verification information is verified, the second encryption key is generated.

4. The method according to claim 1, characterized in that, Before obtaining the first encryption key, the method further includes: The system receives a recording instruction message sent by the charging management terminal; wherein the recording instruction message is used to indicate that a charging operation for the identity recognition module to charge a quantum key has been recorded.

5. The method according to claim 1, characterized in that, Before obtaining the first encryption key, the method further includes: Based on the authorization token, the first token verification information is generated; The first token verification information is sent to the recharge management terminal so that the recharge management terminal can verify the first token verification information and determine whether to send the record indication information.

6. The method according to claim 1, characterized in that, After sending the first token verification information and the second encryption information to the recharge service terminal, the method further includes: The system receives the second token verification information and the stored indication information sent by the recharge service terminal; wherein the stored indication information is used to indicate that m of the quantum keys have been stored. After the second token verification information is verified, in response to the stored indication information, it detects whether the quantum key allocated to the identity recognition module has been sent and obtains the detection result; If the detection result indicates that the quantum key allocated to the identity recognition module has not been completely sent, the step "determine the m quantum keys allocated to the identity recognition module" is repeated until the detection result indicates that the quantum key allocated to the identity recognition module has been completely sent. If the detection result indicates that the quantum key allocated to the identity recognition module has been sent, the first token verification information and the charging end indication information are sent to the charging management terminal; wherein, the charging end indication information is used to indicate that the charging operation of charging the quantum key for the identity recognition module has been completed.

7. The method according to claim 1, characterized in that, The method further includes: If a charging control operation is detected, a charging instruction message corresponding to the charging control operation is sent to the charging service terminal; wherein, the charging instruction message indicates that the identity recognition module in the charging service terminal is charging the quantum key.

8. The method according to any one of claims 1 to 7, characterized in that, The method further includes: The authorization token is used to verify the second token verification information to obtain a first verification result; wherein, the first verification result indicates that the second token verification information has been verified successfully, or that the second token verification information has failed to be verified. Alternatively, the first token verification information can be used to verify the second token verification information to obtain the first verification result.

9. A quantum key injection method, characterized in that, The method is applied to a refill service terminal equipped with an identity recognition module, and the method includes: Receive an authorization token sent by the recharge management terminal; wherein, the authorization token is token information assigned to the identity recognition module by the recharge management terminal after the identity recognition module has been authenticated by the identity of the recharge management terminal; Send a refill permission message, including the authorization token, to the quantum key server; The system receives first token verification information and first encryption information sent by the quantum key server; wherein, the first token verification information is generated by the quantum cryptography server based on the authorization token allocated to the identity recognition module by the recharge management terminal; After the first token verification information is verified, the identity recognition module uses the first decryption key to decrypt the first encrypted information to obtain the second encryption key; wherein, the first decryption key is stored in the identity recognition module; The identity recognition module generates second encryption key verification information based on the second encryption key. Send the stored second token verification information and the second encryption key verification information to the quantum key server; The quantum key server receives the first token verification information and the second encryption information sent by the quantum key server; wherein the first token verification information and the second encryption information are sent by the quantum key server after both the second token verification information and the second encryption key verification information have been verified. After the first token verification information is verified, the identity recognition module uses the second encryption key to decrypt the second encryption information to obtain m quantum keys; The identity recognition module stores m quantum keys in the key storage area of ​​the identity recognition module.

10. The method according to claim 9, characterized in that, Before receiving the first token verification information and the first encryption information sent by the quantum key server, the method further includes: Receive the first token verification information and key negotiation request sent by the quantum key server; After the first token verification information is verified, the identity recognition module responds to the key negotiation request and generates the first encryption key and the first decryption key. Send the second token verification information and the first encryption key to the quantum key server; The first decryption key is stored through the identity recognition module.

11. The method according to claim 9, characterized in that, Before receiving the authorization token sent by the recharge management terminal, the method further includes: Send an authentication request to the filling management terminal; wherein, the authentication request is used to request identity authentication of the identity recognition module; The system receives first identity authentication information sent by the recharge management terminal; wherein the first identity authentication information is authentication information pre-assigned by the recharge management terminal to the identity recognition module. The identity recognition module performs authentication processing on the first identity authentication information and the pre-stored second identity authentication information to obtain the authentication result. If the authentication result indicates that the first identity authentication information matches the second identity authentication information, an identity authentication pass message is sent to the recharge management terminal.

12. The method according to claim 9, characterized in that, Before sending the stored second token verification information and second encryption key verification information to the quantum key server, the method further includes: Based on the authorization token, generate the second token verification information; Store the verification information of the second token.

13. The method according to claim 9, characterized in that, After storing m quantum keys into the key storage area of ​​the identity recognition module, the method further includes: Send the second token verification information and the stored indication information to the quantum key server; wherein, the stored indication information is used to indicate that m of the quantum keys have been stored.

14. The method according to any one of claims 9 to 13, characterized in that, The method further includes: The authorization token is used to verify the first token verification information to obtain a second verification result; wherein, the second verification result indicates that the first token verification information has been verified successfully, or that the first token verification information has failed to be verified. Alternatively, the first token verification information can be verified using the second token verification information to obtain the second verification result.

15. The method according to claim 11, characterized in that, Sending the authentication request to the refill management terminal includes: If a charging instruction is received from the quantum key server, the authentication request is sent to the charging management terminal.

16. A quantum key injection method, characterized in that, The method is applied to the filling management terminal, and the method includes: Determine the authorization token corresponding to the identity recognition module installed in the refill service terminal; The authorization token is sent to the recharge service terminal, so that the recharge service terminal sends the authorization token to the quantum key server, so that the recharge service terminal and the quantum key server can perform verification processing based on the authorization token; wherein, the verification processing of the recharge service terminal and the quantum key server based on the authorization token includes at least the following: the recharge service terminal verifies the quantum key server based on the first token verification information sent by the quantum key server that is associated with the authorization token, and after the first token verification information passes verification, sends the second token verification information and the second encryption key information associated with the authorization token to the quantum key server, so that the quantum key server verifies the second token verification information and the second encryption key information.

17. The method according to claim 16, characterized in that, Before determining the authorization token corresponding to the identity recognition module installed in the refill service terminal, the method further includes: Determine the module identification information of the identity recognition module installed in the refill service terminal; Determine the start time of the quantum key injection operation for the identity recognition module; Store the module identification information and the start time; Send a record instruction message to the quantum key server; wherein the record instruction message is used to instruct the quantum key server to perform a quantum key filling operation for the identity recognition module.

18. The method according to claim 17, characterized in that, Before determining the module identification information of the identity recognition module installed in the refill service terminal, the method further includes: Receive an authentication request sent by the recharge service terminal; wherein the authentication request is used to request identity authentication of the identity recognition module; In response to the authentication request, determine the first identity authentication information corresponding to the identity recognition module; Send the first identity authentication information to the refill service terminal; The system receives an authentication pass message sent by the recharge service terminal; wherein the authentication pass message is generated by the recharge service terminal after authenticating the first identity authentication information.

19. The method according to claim 17, characterized in that, After sending the record indication information to the quantum key server, the method further includes: Receive first token verification information sent by the quantum key server; wherein, the first token verification information is generated by the quantum key server based on the authorization token; The first token verification information is verified against the authorization token to obtain a third verification result.

20. The method according to claim 19, characterized in that, The sending of the record indication information to the quantum key server includes: If the third verification result indicates that the first token verification information has been verified, the record indication information is sent to the quantum key server.

21. The method according to claim 17, characterized in that, After sending the record indication information to the quantum key server, the method further includes: Receive the first token verification information and the filling end indication information sent by the quantum key server; The first token verification information and the authorization token are verified to obtain the fourth verification result; If the fourth verification result indicates that the first token verification information has been verified, respond to the recharge end indication information and determine the end time of the recharge operation; Store the end time; The filling operation is now complete.

22. A first quantum key injection device, characterized in that, The device is applied to a quantum key distribution server and includes: an acquisition unit, a first generation unit, an encryption processing unit, a first transmission unit, and a first determination unit; wherein: The acquisition unit is used to acquire a first encryption key if it receives a recharge permission message including an authorization token sent by the recharge service terminal; wherein, the authorization token is authorization information assigned by the recharge management terminal to the identity recognition module installed in the recharge service terminal; The first generation unit is used to generate the second encryption key corresponding to the identity recognition module; The encryption processing unit is used to encrypt the second encryption key using the first encryption key to obtain the first encrypted information; The first sending unit is configured to send first token verification information and first encrypted information to the recharge service terminal, so that after the first token verification information is verified by the recharge service terminal, the first encrypted information is decrypted by the identity recognition module based on the first decryption key to obtain the second encrypted key, and the first token verification information is associated with the authorization token; The acquisition unit is further configured to receive second token verification information and second encryption key verification information sent by the recharge service terminal; wherein the second encryption key verification information is associated with the second encryption key; The first determining unit is configured to determine m quantum keys allocated to the identity recognition module after both the second token verification information and the second encryption key verification information have been verified; wherein the second token verification information is associated with the authorization token, and m is an integer greater than or equal to 1; The encryption processing unit is used to encrypt the m quantum keys using the second encryption key to obtain the second encrypted information. The first sending unit is used to send the first token verification information and the second encryption information to the refill service terminal, so that the identity recognition module stores the m quantum keys carried in the second encryption information.

23. A second quantum key injection device, characterized in that, The device is applied to a refill service terminal equipped with an identity recognition module, and the device includes: a first receiving unit, a decryption processing unit, a second generating unit, a second sending unit, and a first storage unit; wherein: The first receiving unit is used to receive an authorization token sent by the recharge management terminal; wherein, the authorization token is token information assigned to the identity recognition module by the recharge management terminal after the identity recognition module has been authenticated by the identity of the recharge management terminal; The second sending unit is used to send a refill permission message, including the authorization token, to the quantum key server; The first receiving unit is further configured to receive first token verification information and first encryption information sent by the quantum key server; wherein, the first token verification information is generated by the quantum cryptography server based on the authorization token allocated to the identity recognition module by the recharge management terminal; The decryption processing unit is used to decrypt the first encrypted information using the first decryption key through the identity recognition module after the first token verification information is verified to obtain the second encryption key; wherein, the first decryption key is stored in the identity recognition module; The second generation unit is used to generate second encryption key verification information based on the second encryption key through the identity recognition module; The second sending unit is used to send the stored second token verification information and the second encryption key verification information to the quantum key server; The first receiving unit is further configured to receive the first token verification information and the second encryption information sent by the quantum key server; wherein the first token verification information and the second encryption information are sent by the quantum key server after both the second token verification information and the second encryption key verification information have passed verification; The decryption processing unit is further configured to, after the first token verification information is verified, use the second encryption key through the identity recognition module to decrypt the second encrypted information to obtain m quantum keys; The first storage unit is used to store m of the quantum keys into the key storage area of ​​the identity recognition module.

24. A third quantum key injection device, characterized in that, The device is used in a filling management terminal, and the device includes: a second determining unit and a third sending unit; wherein: The second determining unit is used to determine the authorization token corresponding to the identity recognition module installed in the refill service terminal; The third sending unit is configured to send the authorization token to the recharge service terminal, so that the recharge service terminal sends the authorization token to the quantum key server, so that the recharge service terminal and the quantum key server perform verification processing based on the authorization token; wherein, the verification processing of the recharge service terminal and the quantum key server based on the authorization token includes at least: the recharge service terminal verifies the quantum key server based on the first token verification information associated with the authorization token sent by the quantum key server, and after the first token verification information passes verification, sends the second token verification information and the second encryption key information associated with the authorization token to the quantum key server, so that the quantum key server verifies the second token verification information and the second encryption key information.

25. A quantum key injection system, characterized in that, The system includes at least: a quantum key server, a refill service terminal equipped with an identity recognition module, and a refill management terminal; wherein: The quantum key server is used to implement the steps of the quantum key filling method as described in any one of claims 1 to 8; The filling service terminal is used to implement the steps of the quantum key filling method as described in any one of claims 9 to 15; The filling management terminal is used to implement the steps of the quantum key filling method as described in any one of claims 16 to 21.

26. A storage medium, characterized in that, The storage medium stores a quantum key injection program, which, when executed, implements the steps of the quantum key injection method as described in any one of claims 1 to 8, or claims 9 to 15, or claims 16 to 21.

27. A computer program product, comprising a computer program, characterized in that, When the computer program is executed by a processor, it implements the steps of the quantum key injection method as described in any one of claims 1 to 8, or claims 9 to 15, or claims 16 to 21.

Citation Information

Patent Citations

  • Quantum key charging method, system and component based on quantum cryptography service platform

    CN116418485A