A cross-domain user login system, method and device based on a quantum key distribution network

CN119449284BActive Publication Date: 2026-09-18CHINA TELECOM QUANTUM TECH CO LTD
View PDF 1 Cites 0 Cited by

Patent Information

Application Number
CN202411417759.X
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2024-10-11
Publication Date
2026-09-18
Estimated Expiration
2044-10-11

AI Technical Summary

Technical Problem

这样,用户在登录系统时,系统即可按照一定策略分配请求到某一业务中心,但是,有些情况下,用户本身的身份信息有可能并不在此中心,导致跨域用户登录系统失败

Benefits of technology

[0052] The cross-domain user login scheme based on quantum key distribution networks provided in this application, on the one hand, ensures that the two communicating parties can generate and share a secure key known only to them, which is used to encrypt and decrypt communication content, thereby preventing potential eavesdropping and data leakage and improving communication security. On the other hand, through quantum key distribution (QKD) technology, multiple business centers can share a single key, which can then be used by multiple business centers to encrypt and decrypt user authentication information (such as passwords, fingerprints, authentication codes, etc.) for transmission, thus enabling successful cross-trust domain login for users.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN119449284B_ABST
    Figure CN119449284B_ABST
Patent Text Reader

Abstract

The application provides a cross-domain user login system, method and device based on a quantum key distribution network. The system comprises: an access routing service for routing user requests to corresponding service centers; a plurality of service centers for receiving and processing user requests and sending key requests and identity authentication requests to corresponding quantum cryptography service modules; a quantum cryptography service module for providing encryption keys for key requests and identity authentication for identity authentication requests; a quantum exchange password machine for receiving quantum keys from a quantum random number generator and providing key services, which stores pre-generated quantum keys from the quantum random number generator and quantum security keys stored in the quantum security chip as symmetric keys; and a quantum key distribution module for generating and sharing the same quantum key between communication parties based on a quantum key distribution protocol and encrypting and decrypting based on the quantum key. The application improves the communication security in a multi-center scenario.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This application relates to the fields of instant messaging and network security technologies, and in particular to a cross-domain user login system, method, and apparatus based on a quantum key distribution network. Background Technology

[0002] With the rapid development of internet technology and the expansion of network application systems, various services and resources are distributed across different domains. Different services and resources are distinguished based on domain division and access control, allowing users in different domains to access them according to their different needs. This method of accessing services and resources outside the same domain involves cross-domain access.

[0003] To address the cross-domain issue, existing technologies provide a cross-domain authentication method based on a quantum key distribution network (QKDN). This method includes: sending a key negotiation request to the corresponding QKDN management system, which forwards it to a quantum key generation system, enabling the QKDN to establish a relay key negotiation link between quantum key terminals and generate a symmetric authentication key; receiving an authentication request from a corresponding user terminal and allocating an authentication key identifier to the user terminal based on the request; and receiving a login request from the corresponding user terminal and responding with a constructed token ciphertext based on the login request, so that when the user terminal accesses the cross-domain authentication service system, the token ciphertext is forwarded to the cross-domain authentication service system. This solution resolves the centralization problem in cross-domain authentication and improves the confidentiality and integrity of authentication credential data distribution.

[0004] Existing technology also provides a cross-trust domain identity authentication method, including an identity authentication service module and an authentication terminal module. The identity authentication service module provides identity token issuance and authentication services. The identity token issuance service includes accepting identity token applications, encapsulating identity tokens, and issuing identity tokens. The identity token authentication service provides challenge-based authentication of identity tokens and returns user application system information based on valid tokens, while excluding unauthorized users' identity token authentication through LDAP or CRL synchronization. The authentication terminal module includes an identity token application module and a client password module. The identity token application module is responsible for the application and maintenance of identity tokens. The client password module provides client certificates and cryptographic operations. This solution achieves one-stop authentication for network-wide access, resolving the current trust issues.

[0005] Using existing technologies, in cross-trust domain scenarios, each user belongs to a different trust domain, forming a multi-center system. Each center is within a trust domain, and these centers can communicate with each other. When a user logs in, the system can allocate requests to a specific business center according to a certain strategy. However, in some cases, the user's identity information may not be in that center, causing cross-domain login failures. Summary of the Invention

[0006] This application discloses a cross-domain user login system, method, and apparatus based on a quantum key distribution network.

[0007] In a first aspect, this application discloses a cross-domain user login system based on a quantum key distribution network. The system includes: an access routing service, multiple service centers, a quantum cryptography service module corresponding to each service center, a quantum exchange cryptography machine, and a quantum key distribution module; wherein...

[0008] The access routing service is used to route user requests sent by users from the client or the web terminal to the corresponding business center according to a preset algorithm.

[0009] The multiple business centers receive and process the user requests sent by the access routing service, and send key requests and authentication requests to the corresponding quantum cryptography service modules.

[0010] The quantum cryptography service module is connected to the quantum exchange cryptography machine and is used to provide encryption keys for the key request and to perform identity authentication for the identity authentication request.

[0011] The quantum exchange cryptographic machine is used to receive quantum keys issued by the quantum random number generator and to provide key services. The quantum exchange cryptographic machine stores quantum keys pre-generated by the quantum random number generator and these quantum keys are symmetric keys with the quantum security keys stored in the quantum security chip.

[0012] The quantum key distribution module is used to enable both communicating parties to generate and share the same quantum key based on a quantum key distribution protocol, and to encrypt and decrypt user data based on the quantum key.

[0013] Optionally, the quantum-safe chip is specifically used for:

[0014] The quantum key received from the quantum random number generator is used to perform symmetric entity authentication with the quantum security key via the network and the quantum cryptography service module.

[0015] Optionally, the business center is specifically used for:

[0016] Process user requests for system registration, system login, system query, and system logout.

[0017] Optionally, the access routing service is specifically used for:

[0018] Based on a preset algorithm constructed using at least one influencing factor among load pressure, latency, polling, IP address, and user's address, user requests sent from the client or web interface are routed to the corresponding business center.

[0019] Optionally, the system further includes: a quantum key injection machine;

[0020] The quantum key injector is connected to the output of the quantum cryptographic switch and is used to inject quantum keys.

[0021] Optionally, the system further includes: a quantum security shield;

[0022] The quantum security shield is used to handle key reading, data encryption, and data and information interaction with the quantum cryptography service module on the quantum security chip.

[0023] Secondly, this application discloses a cross-domain user login method based on a quantum key distribution network, applied to the aforementioned system, the method comprising:

[0024] The target business center receives system login requests from target users;

[0025] The target business center queries whether it contains the user data of the target user. If it does not contain the user data, it requests the user data from the candidate business centers, which are multiple business centers other than the target business center.

[0026] The original business center containing the user data in the candidate business center requests the quantum key through the corresponding quantum cryptography service module in the domain.

[0027] The quantum cryptography service module corresponding to the original business center domain generates a shared quantum key through the QKD node in the domain, distributes the shared quantum key to the QKD target node in the target business center domain based on the quantum key distribution network, and returns the shared quantum key to the system.

[0028] The original business center encrypts the user data based on the shared quantum key and transmits the ciphertext to the target business center via the network;

[0029] The target business center receives the ciphertext, applies for the shared quantum key from the quantum cryptography service module within the target business center domain, and uses the shared quantum key to decrypt the ciphertext to obtain the decrypted user data.

[0030] The target business center compares the user data carried in the system login request with the decrypted user data. Once authentication is successful, the user logs in successfully.

[0031] Optionally, before the step of the target business center receiving the system login request from the target user, the method further includes:

[0032] The target user requests the registration interface from the client or web interface;

[0033] The access routing service routes the user request of the target user to the original business center;

[0034] The original business center creates users and records user information, which includes at least user passwords, fingerprints, and identity tokens.

[0035] Optionally, the step of the target business center receiving the system login request from the target user includes:

[0036] The access routing service responds to system login requests sent by target users from clients or web terminals, and routes the system login requests to the target business center according to a preset algorithm.

[0037] Thirdly, this application discloses a cross-domain user login device based on a quantum key distribution network, applied to the aforementioned system, the device comprising:

[0038] The user request receiving module is used by the target business center to receive system login requests from target users.

[0039] The user data query module is used for the target business center to query whether it contains the user data of the target user. If it does not contain the user data, it requests the user data from the candidate business centers, which are multiple business centers other than the target business center.

[0040] A quantum key generation module is used by the original business center containing the user data in the candidate business center to request a quantum key through the corresponding quantum cryptography service module in the domain.

[0041] A quantum key distribution module is used by the quantum cryptography service module corresponding to the original business center domain to generate a shared quantum key through the QKD node in the domain, and distribute the shared quantum key to the QKD target node in the target business center domain based on the quantum key distribution network, and return the shared quantum key to the system.

[0042] The user data encryption module is used by the original business center to encrypt the user data based on the shared quantum key, and transmit the ciphertext to the target business center through the network;

[0043] The user data decryption module is used to receive the ciphertext at the target business center, apply for the shared quantum key from the quantum cryptography service module within the target business center domain, and use the shared quantum key to decrypt the ciphertext to obtain the decrypted user data.

[0044] The login authentication module is used by the target business center to compare the user data carried in the system login request with the decrypted user data. If the authentication is successful, the user logs in successfully.

[0045] Optionally, the user request receiving module is specifically used to route the user request of the target user to the original business center when the target user requests the registration interface from the client or the web.

[0046] The device further includes an information registration module, which, upon receiving a user request sent by the user request module, enables the original business center to create a user and record user information, wherein the user information includes at least a user password, fingerprint, and identity token.

[0047] Optionally, the user request receiving module is specifically used to access the routing service to respond to the system login request sent by the target user from the client or the web terminal, and to route the system login request to the target business center according to a preset algorithm.

[0048] Fourthly, this application discloses an electronic device comprising: a processor, a memory, and a computer program stored in the memory and executable on the processor, wherein the computer program, when executed by the processor, implements the above-described method.

[0049] Fifthly, this application discloses a computer-readable storage medium, characterized in that a computer program is stored on the computer-readable storage medium, which, when executed by a processor, implements the above-described method.

[0050] Sixthly, this application discloses a computer program product, characterized in that, when the instructions in the computer program product are executed by a processor of an electronic device, the electronic device is able to perform the above-described method.

[0051] The technical solution provided in this application may include the following beneficial effects:

[0052] The cross-domain user login scheme based on quantum key distribution networks provided in this application, on the one hand, ensures that the two communicating parties can generate and share a secure key known only to them, which is used to encrypt and decrypt communication content, thereby preventing potential eavesdropping and data leakage and improving communication security. On the other hand, through quantum key distribution (QKD) technology, multiple business centers can share a single key, which can then be used by multiple business centers to encrypt and decrypt user authentication information (such as passwords, fingerprints, authentication codes, etc.) for transmission, thus enabling successful cross-trust domain login for users. Attached Figure Description

[0053] Figure 1 An architecture diagram of a cross-domain user login system based on a quantum key distribution network provided in this application;

[0054] Figure 2 A flowchart illustrating a cross-domain user login method based on a quantum key distribution network provided in this application;

[0055] Figure 3 A structural diagram of a cross-domain user login device based on a quantum key distribution network provided in this application;

[0056] Figure 4 A block diagram of an electronic device provided in this application.

[0057] Figure 5 A block diagram of an electronic device provided in this application. Detailed Implementation

[0058] The technical solutions of the embodiments of this application will be clearly and completely described below with reference to the accompanying drawings. Obviously, the described embodiments are only some embodiments of this application, not all embodiments. Based on the embodiments of this application, all other embodiments obtained by those skilled in the art without creative effort are within the scope of protection of this application.

[0059] Existing solutions, in cross-trust domain scenarios, involve each user belonging to a different trust domain, forming a multi-center system. Each center operates within a single trust domain, and these centers can communicate with each other. When a user logs in, the system can allocate requests to a specific business center according to a certain strategy. However, in some cases, the user's identity information may not be present in that center, leading to cross-domain login failures.

[0060] To address the aforementioned issues, this application provides a cross-domain user login system, method, and apparatus based on a quantum key distribution network. The following detailed description of the application's solution is provided in conjunction with the accompanying drawings.

[0061] Example 1

[0062] Please see Figure 1 This is an architecture diagram of a cross-domain user login system based on a quantum key distribution network provided in this application. Specifically, the cross-domain user login system based on a quantum key distribution network provided in this application includes: an access routing service, multiple business centers ( Figure 1 The diagram shows two business centers, a quantum cryptography service module corresponding to each business center, a quantum exchange cryptography machine (not shown), and a quantum key distribution module (i.e., Figure 1 (QKD node 1 and QKD node 2 in the data).

[0063] The access routing service is used to route user requests sent from the client or web terminal to the corresponding business center according to a preset algorithm. Specifically, the access routing service routes user requests sent from the client or web terminal to the corresponding business center according to a preset algorithm constructed based on at least one influencing factor among load pressure, latency, round-robin, IP address, and user's address. This preset algorithm includes, but is not limited to, load pressure, latency, round-robin, IP address, and user's address.

[0064] The multiple business centers receive and process the user requests sent by the access routing service, and send key requests and authentication requests to the corresponding quantum cryptography service modules. Specifically, the business centers can process user requests for system registration, system login, system query, and system exit. It should be noted that the user requests here include, but are not limited to, the above four scenarios.

[0065] The quantum cryptography service module, connected to the quantum cryptographic exchange machine, is used to provide encryption keys for key requests and to perform identity authentication for identity authentication requests. Specifically, the quantum cryptography service module interacts with the instant messaging system and the quantum security chip via a network, while the quantum cryptography management service system is directly connected to the quantum cryptographic exchange to provide encryption keys and identity authentication functions.

[0066] The quantum exchange cryptographic machine is used to receive quantum keys issued by a quantum random number generator and to provide key services. The quantum exchange cryptographic machine stores quantum keys pre-generated by the quantum random number generator and these quantum keys are symmetric keys with the quantum security keys stored in the quantum security chip. The quantum random number generator is used to generate quantum keys.

[0067] The quantum key distribution module is used to enable both communicating parties to generate and share the same quantum key based on a quantum key distribution protocol, and to encrypt and decrypt user data based on the quantum key. Specifically, the quantum key distribution module ( Figure 1 The QKD nodes in the system, based on internationally recognized quantum key distribution protocols such as BB84 and BBM92, enable both communicating parties to generate and share a random, secure key for encrypting and decrypting user data.

[0068] In one scenario, the quantum-safe chip stores a quantum-safe key. The quantum-safe key stored in each quantum-safe chip and the key pre-stored in the quantum exchange cryptography machine are symmetric keys. Specifically, this is used to perform symmetric entity authentication between the quantum key received from the quantum random number generator and the quantum-safe key via a network and the quantum cryptography service module.

[0069] Furthermore, the system also includes a quantum key injector, which is connected to the output of the quantum cryptographic switch and is used to inject quantum keys.

[0070] Furthermore, the system also includes a quantum security shield, which is used to handle key reading, data encryption, and data and information interaction with the quantum cryptography service module on the quantum security chip.

[0071] The cross-domain user login system based on quantum key distribution networks provided in this application, on the one hand, ensures that both communicating parties can generate and share a secure key known only to them through quantum key distribution (QKD) technology, which is used to encrypt and decrypt communication content, thereby preventing potential eavesdropping and data leakage and improving communication security; on the other hand, through quantum key distribution (QKD) technology, multiple business centers can share a single key, which can then be used by multiple business centers to encrypt and decrypt user authentication information (such as passwords, fingerprints, authentication codes, etc.) for transmission, thus enabling successful cross-trust domain login for users.

[0072] Example 2

[0073] Please see Figure 2 This is a flowchart of a cross-domain user login method based on a quantum key distribution network provided in this application, applied to the system described in Embodiment 1. The method may include the following steps:

[0074] Step S101: The target business center receives the system login request from the target user.

[0075] Specifically, the access routing service responds to system login requests sent by target users from clients or web terminals, and routes the system login requests to the target business center according to a preset algorithm.

[0076] Step S102: The target business center queries whether it contains the user data of the target user. If it does not contain the user data, it requests the user data from the candidate business centers, which are multiple business centers other than the target business center.

[0077] Step S103: The original business center containing the user data in the candidate business center requests the quantum key through the corresponding quantum cryptography service module within the domain.

[0078] Step S104: The quantum cryptography service module corresponding to the original business center domain generates a shared quantum key through the QKD node in the domain, distributes the shared quantum key to the QKD target node in the target business center domain based on the quantum key distribution network, and returns the shared quantum key to the system.

[0079] Step S105: The original business center encrypts the user data based on the shared quantum key and transmits the ciphertext to the target business center via the network.

[0080] Step S106: The target business center receives the ciphertext, applies for the shared quantum key from the quantum cryptography service module within the target business center domain, and uses the shared quantum key to decrypt the ciphertext to obtain the decrypted user data.

[0081] Step S107: The target business center compares the user data carried in the system login request with the decrypted user data. After successful authentication, the user logs in successfully.

[0082] In one scenario, prior to the step of the target business center receiving the system login request from the target user, the method may further include the following steps:

[0083] (1) The target user requests the registration interface from the client or the web;

[0084] (2) The access routing service routes the user request of the target user to the original business center;

[0085] (3) The original business center creates users and records user information, which includes at least user password, fingerprint, and identity token.

[0086] The cross-domain user login method based on quantum key distribution networks provided in this application, on the one hand, ensures that the two communicating parties can generate and share a secure key known only to them through quantum key distribution (QKD) technology, which is used to encrypt and decrypt communication content, thereby preventing potential eavesdropping and data leakage and improving communication security; on the other hand, through quantum key distribution (QKD) technology, multiple business centers can share a key, so that multiple business centers can use this key to encrypt and decrypt user authentication information (such as passwords, fingerprints, authentication codes, etc.) for transmission, thereby enabling users to successfully log in across trusted domains.

[0087] The cross-domain user login method based on quantum key distribution networks provided in this application is illustrated below with a specific example. Please refer to [link to relevant documentation]. Figure 1 and Figure 2 Business Center 1 is the original business center for protecting user data, and Business Center 2 is the target business center to be logged in.

[0088] S1. Users request the registration interface from the client or web terminal, and the routing service routes the user request to business center 1;

[0089] S2. Business Center 1 creates users and records user information, such as user passwords, fingerprints, identity tokens, and other data;

[0090] S3. The user requests the login interface again through the client or web interface. The routing service routes the user request to business center 2 according to the routing algorithm.

[0091] S4. Business Center 2 checks if it has stored the user information. If it finds that this business center does not contain user data, Business Center 2 then requests information from other business centers. Figure 1 The business center in the middle 1) requests user data;

[0092] S5. Since user data is private data and needs to be transmitted in encrypted form, after receiving the user data request, Business Center 1 requests a quantum random number key through the quantum cryptography service module corresponding to Business Center 1.

[0093] S6. The quantum cryptography service module corresponding to Business Center 1 generates a shared quantum key through QKD node 1;

[0094] S7. The quantum cryptography service module corresponding to Business Center 1 distributes the shared quantum key to the QKD target node through the quantum network;

[0095] S8. The quantum cryptography service module corresponding to Business Center 1 returns the generated shared key to the business system;

[0096] S9. Business Center 1 uses the shared quantum key to encrypt user privacy data and transmits the ciphertext to Business Center 2 via a classical network;

[0097] S10. Business Center 2 receives the ciphertext and applies for the corresponding shared quantum key from the corresponding quantum cryptography service module;

[0098] S11. Business Center 2 obtains the shared quantum key distributed through the quantum network and decrypts the ciphertext;

[0099] S12. Business Center 2 compares the user data carried in the login request with the decrypted user data. If the verification is successful, the user logs in successfully.

[0100] It should be noted that, for the sake of simplicity, the method embodiments are all described as a series of actions. However, those skilled in the art should understand that this application is not limited to the described order of actions, because according to this application, some steps can be performed in other orders or simultaneously. Secondly, those skilled in the art should also understand that the embodiments described in the specification are all optional embodiments, and the actions involved are not necessarily required by this application.

[0101] Example 3

[0102] Please see Figure 3This is a structural diagram of a cross-domain user login device based on a quantum key distribution network provided in this application. It is applied to a system containing multiple service centers located in different domains. The device may include the following modules:

[0103] User request receiving module 21 is used by the target business center to receive system login requests from target users;

[0104] User data query module 22 is used for the target business center to query whether it contains user data of the target user. If it does not contain user data, it requests user data from candidate business centers. The candidate business centers are multiple business centers other than the target business center.

[0105] Quantum key generation module 23 is used by the original business center containing the user data in the candidate business center to request a quantum key through the corresponding quantum cryptography service module in the domain;

[0106] The quantum key distribution module 24 is used by the quantum cryptography service module corresponding to the original business center domain to generate a shared quantum key through the QKD node in the domain, and distribute the shared quantum key to the QKD target node in the target business center domain based on the quantum key distribution network, and return the shared quantum key to the system.

[0107] User data encryption module 25 is used by the original business center to encrypt the user data based on the shared quantum key, and transmit the ciphertext to the target business center through the network;

[0108] User data decryption module 26 is used for the target business center to receive the ciphertext, apply for the shared quantum key from the quantum cryptography service module in the target business center domain, and use the shared quantum key to decrypt the ciphertext to obtain the decrypted user data;

[0109] The login authentication module 27 is used by the target business center to compare the user data carried in the system login request with the decrypted user data. After successful authentication, the user logs in successfully.

[0110] In one scenario, the user request receiving module 21 is specifically used to route the user request of the target user to the original business center when the target user requests the registration interface from the client or the web.

[0111] Furthermore, the device also includes: an information registration module, used to create a user and record user information in the original business center when a user request is received from the user request module, the user information including at least a user password, fingerprint, and identity token. Correspondingly, the user request receiving module 21 is specifically used to access the routing service to respond to a system login request sent by a target user from a client or web application, and to route the system login request to the target business center according to a preset algorithm.

[0112] The cross-domain user login device based on quantum key distribution network provided in this application, on the one hand, ensures that the two communicating parties can generate and share a secure key known only to them through quantum key distribution (QKD) technology, which is used to encrypt and decrypt communication content, thereby preventing potential eavesdropping and data leakage and improving communication security; on the other hand, through quantum key distribution (QKD) technology, multiple business centers can share a key, so that multiple business centers can use this key to encrypt and decrypt user authentication information (such as passwords, fingerprints, authentication codes, etc.) for transmission, thereby enabling users to successfully log in across trusted domains.

[0113] As the device embodiment is basically similar to the method embodiment, the description is relatively simple, and relevant parts can be found in the description of the method embodiment.

[0114] Example 4

[0115] Optionally, this application also provides an electronic device, including: a processor, a memory, and a computer program stored in the memory and executable on the processor. When the computer program is executed by the processor, it implements the various processes of the above method embodiments and achieves the same technical effect. To avoid repetition, it will not be described again here.

[0116] Example 5

[0117] This application also provides a computer-readable storage medium storing a computer program. When the computer program is executed by a processor, it implements the various processes of the above-described method embodiments and achieves the same technical effects. To avoid repetition, it will not be described again here. The computer-readable storage medium may be a read-only memory (ROM), a random access memory (RAM), a magnetic disk, or an optical disk, etc.

[0118] Example 6

[0119] Sixthly, this application discloses a computer program product in which, when the instructions in the computer program product are executed by a processor of an electronic device, the electronic device is enabled to perform the method as described in any of the preceding aspects.

[0120] The figure is a block diagram of an electronic device 800 shown in the four applications. For example, the electronic device 800 can be a mobile phone, computer, digital broadcasting terminal, messaging device, game console, tablet device, medical device, fitness equipment, personal digital assistant, etc.

[0121] Reference Figure 4 The electronic device 800 may include one or more of the following components: a processing component 802, a memory 804, a power supply component 806, a multimedia component 808, an audio component 810, an input / output (I / O) interface 812, a sensor component 814, and a communication component 816.

[0122] Processing component 802 typically controls the overall operation of electronic device 800, such as operations associated with display, telephone calls, data communication, camera operation, and recording operations. Processing component 802 may include one or more processors 820 to execute instructions to complete all or part of the steps of the methods described above. Furthermore, processing component 802 may include one or more modules to facilitate interaction between processing component 802 and other components. For example, processing component 802 may include a multimedia module to facilitate interaction between multimedia component 808 and processing component 802.

[0123] Memory 804 is configured to store various types of data to support the operation of device 800. Examples of this data include instructions for any application or method operating on electronic device 800, contact data, phonebook data, messages, images, videos, etc. Memory 804 can be implemented by any type of volatile or non-volatile storage device or a combination thereof, such as static random access memory (SRAM), electrically erasable programmable read-only memory (EEPROM), erasable programmable read-only memory (EPROM), programmable read-only memory (PROM), read-only memory (ROM), magnetic storage, flash memory, magnetic disk, or optical disk.

[0124] Power supply component 806 provides power to various components of electronic device 800. Power supply component 806 may include a power management system, one or more power supplies, and other components associated with generating, managing, and distributing power to electronic device 800.

[0125] Multimedia component 808 includes a screen that provides an output interface between the electronic device 800 and the user. In some embodiments, the screen may include a liquid crystal display (LCD) and a touch panel (TP). If the screen includes a touch panel, the screen may be implemented as a touchscreen to receive input signals from the user. The touch panel includes one or more touch sensors to sense touches, swipes, and gestures on the touch panel. The touch sensors may sense not only the boundaries of the touch or swipe action but also the duration and pressure associated with the touch or swipe operation. In some embodiments, multimedia component 808 includes a front-facing camera and / or a rear-facing camera. When the device 800 is in an operating mode, such as a shooting mode or a video mode, the front-facing camera and / or the rear-facing camera may receive external multimedia data. Each front-facing camera and rear-facing camera may be a fixed optical lens system or have focal length and optical zoom capabilities.

[0126] Audio component 810 is configured to output and / or input audio signals. For example, audio component 810 includes a microphone (MIC) configured to receive external audio signals when electronic device 800 is in an operating mode, such as call mode, recording mode, and voice recognition mode. The received audio signals may be further stored in memory 804 or transmitted via communication component 816. In some embodiments, audio component 810 also includes a speaker for outputting audio signals.

[0127] I / O interface 812 provides an interface between processing component 802 and peripheral interface modules, such as keyboards, click wheels, buttons, etc. These buttons may include, but are not limited to, home buttons, volume buttons, power buttons, and lock buttons.

[0128] Sensor assembly 814 includes one or more sensors for providing state assessments of various aspects of electronic device 800. For example, sensor assembly 814 may detect the on / off state of device 800, the relative positioning of components such as the display and keypad of electronic device 800, changes in position of electronic device 800 or a component of electronic device 800, the presence or absence of user contact with electronic device 800, orientation or acceleration / deceleration of electronic device 800, and temperature changes of electronic device 800. Sensor assembly 814 may include a proximity sensor configured to detect the presence of nearby objects without any physical contact. Sensor assembly 814 may also include a light sensor, such as a CMOS or CCD image sensor, for use in imaging applications. In some embodiments, sensor assembly 814 may also include an accelerometer, gyroscope, magnetometer, pressure sensor, or temperature sensor.

[0129] Communication component 816 is configured to facilitate wired or wireless communication between electronic device 800 and other devices. Electronic device 800 can access wireless networks based on communication standards, such as WiFi, carrier networks (such as 2G, 3G, 4G, or 5G), or combinations thereof. In one exemplary embodiment, communication component 816 receives broadcast signals or broadcast operation information from an external broadcast management system via a broadcast channel. In one exemplary embodiment, communication component 816 also includes a near-field communication (NFC) module to facilitate short-range communication. For example, the NFC module may be implemented based on radio frequency identification (RFID) technology, Infrared Data Association (IrDA) technology, ultra-wideband (UWB) technology, Bluetooth (BT) technology, and other technologies.

[0130] In an exemplary embodiment, the electronic device 800 may be implemented by one or more application-specific integrated circuits (ASICs), digital signal processors (DSPs), digital signal processing devices (DSPDs), programmable logic devices (PLDs), field-programmable gate arrays (FPGAs), controllers, microcontrollers, microprocessors, or other electronic components to perform the methods described above.

[0131] In an exemplary embodiment, a non-transitory computer-readable storage medium including instructions is also provided, such as a memory 804 including instructions, which can be executed by a processor 820 of an electronic device 800 to perform the above-described method. For example, the non-transitory computer-readable storage medium may be a ROM, random access memory (RAM), CD-ROM, magnetic tape, floppy disk, and optical data storage device, etc.

[0132] Figure 5 This is a block diagram of an electronic device 1900 shown in this application. For example, the electronic device 1900 can be provided as a server.

[0133] Reference Figure 5 The electronic device 1900 includes a processing component 1922, which further includes one or more processors, and memory resources represented by memory 1932 for storing instructions, such as application programs, that can be executed by the processing component 1922. The application programs stored in memory 1932 may include one or more modules, each corresponding to a set of instructions. Furthermore, the processing component 1922 is configured to execute instructions to perform the methods described above.

[0134] Electronic device 1900 may also include a power supply component 1926 configured to perform power management of electronic device 1900, a wired or wireless network interface 1950 configured to connect electronic device 1900 to a network, and an input / output (I / O) interface 1958. Electronic device 1900 can operate on an operating system stored in memory 1932, such as Windows Server™, Mac OS X™, Unix™, Linux™, FreeBSD™, or similar.

[0135] It should be noted that, in this document, the terms "comprising," "including," or any other variations thereof are intended to cover non-exclusive inclusion, such that a process, method, article, or apparatus that comprises a list of elements includes not only those elements but also other elements not expressly listed, or elements inherent to such a process, method, article, or apparatus. Unless otherwise specified, an element defined by the phrase "comprising one..." does not exclude the presence of other identical elements in the process, method, article, or apparatus that includes that element.

[0136] Through the above description of the embodiments, those skilled in the art can clearly understand that the methods of the above embodiments can be implemented by means of software plus necessary general-purpose hardware platforms. Of course, they can also be implemented by hardware, but in many cases the former is a better implementation method. Based on this understanding, the technical solution of this application, in essence, or the part that contributes to the prior art, can be embodied in the form of a software product. This computer software product is stored in a storage medium (such as ROM / RAM, magnetic disk, optical disk) and includes several instructions to cause a terminal (which may be a mobile phone, computer, server, air conditioner, or network device, etc.) to execute the methods described in the various embodiments of this application.

[0137] The embodiments of this application have been described above with reference to the accompanying drawings. However, this application is not limited to the specific embodiments described above. The specific embodiments described above are merely illustrative and not restrictive. Those skilled in the art can make many other forms under the guidance of this application without departing from the spirit and scope of the claims, and all of these forms are within the protection scope of this application.

[0138] Those skilled in the art will recognize that the units and algorithm steps of the various examples described in conjunction with the embodiments disclosed in this application can be implemented in electronic hardware, or a combination of computer software and electronic hardware. Whether these functions are implemented in hardware or software depends on the specific application and design constraints of the technical solution. Those skilled in the art can use different methods to implement the described functions for each specific application, but such implementation should not be considered beyond the scope of this application.

[0139] Those skilled in the art will understand that, for the sake of convenience and brevity, the specific working processes of the systems, devices, and units described above can be referred to the corresponding processes in the foregoing method embodiments, and will not be repeated here.

[0140] In the embodiments provided in this application, it should be understood that the disclosed apparatus and methods can be implemented in other ways. For example, the apparatus embodiments described above are merely illustrative. For instance, the division of units is only a logical functional division, and in actual implementation, there may be other division methods. For example, multiple units or components may be combined or integrated into another system, or some features may be ignored or not executed. Furthermore, the coupling or direct coupling or communication connection shown or discussed may be through some interfaces; the indirect coupling or communication connection between apparatuses or units may be electrical, mechanical, or other forms.

[0141] The units described as separate components may or may not be physically separate. The components shown as units may or may not be physical units; that is, they may be located in one place or distributed across multiple network units. Some or all of the units can be selected to achieve the purpose of this embodiment according to actual needs.

[0142] In addition, the functional units in the various embodiments of this application can be integrated into one processing unit, or each unit can exist physically separately, or two or more units can be integrated into one unit.

[0143] If the aforementioned functions are implemented as software functional units and sold or used as independent products, they can be stored in a computer-readable storage medium. Based on this understanding, the technical solution of this application, in essence, or the part that contributes to the prior art, or a portion of the technical solution, can be embodied in the form of a software product. This computer software product is stored in a storage medium and includes several instructions to cause a computer device (which may be a personal computer, server, or network device, etc.) to execute all or part of the steps of the methods described in the various embodiments of this application. The aforementioned storage medium includes various media capable of storing program code, such as USB flash drives, portable hard drives, ROM, RAM, magnetic disks, or optical disks.

[0144] The above description is merely a specific embodiment of this application, but the scope of protection of this application is not limited thereto. Any variations or substitutions that can be easily conceived by those skilled in the art within the technical scope disclosed in this application should be included within the scope of protection of this application. Therefore, the scope of protection of this application should be determined by the scope of the claims.

Claims

1. A cross-domain user login system based on a quantum key distribution network, characterized in that, The system includes: an access routing service, multiple business centers, a quantum cryptography service module corresponding to each business center, a quantum exchange cryptography machine, and a quantum key distribution module; wherein... The access routing service is used to route user requests sent by users from the client or the web terminal to the corresponding business center according to a preset algorithm. The multiple business centers receive and process the user requests sent by the access routing service, and send key requests and authentication requests to the corresponding quantum cryptography service modules. The quantum cryptography service module is connected to the quantum exchange cryptography machine and is used to provide encryption keys for the key request and to perform identity authentication for the identity authentication request. The quantum exchange cryptographic machine is used to receive quantum keys issued by the quantum random number generator and to provide key services. The quantum exchange cryptographic machine stores quantum keys pre-generated by the quantum random number generator and these quantum keys are symmetric keys with the quantum security keys stored in the quantum security chip. The quantum key distribution module is used to enable both communicating parties to generate and share the same quantum key based on the quantum key distribution protocol, and to encrypt and decrypt user data based on the quantum key. The communication parties include a target service center and an original service center. The target service center is the service center to which the access routing service routes, and the original service center is the service center containing the user data. If the target service center does not contain the user data, the original service center encrypts the user data based on the quantum key and transmits the ciphertext to the target service center via the network. The target service center decrypts the ciphertext using the quantum key to obtain the decrypted user data. The target service center compares the user data carried in the user request with the decrypted user data. If the authentication is successful, the user logs in successfully.

2. The cross-domain user login system based on a quantum key distribution network according to claim 1, characterized in that, The quantum-safe chip is specifically used for: The quantum key received from the quantum random number generator is used to perform symmetric entity authentication with the quantum security key via the network and the quantum cryptography service module.

3. The cross-domain user login system based on a quantum key distribution network according to claim 1, characterized in that, The business center is specifically used for: Process user requests for system registration, system login, system query, and system logout.

4. The cross-domain user login system based on a quantum key distribution network according to claim 1, characterized in that, The access routing service is specifically used for: Based on a preset algorithm constructed using at least one influencing factor among load pressure, latency, polling, IP address, and user's address, user requests sent from the client or web interface are routed to the corresponding business center.

5. The cross-domain user login system based on a quantum key distribution network according to claim 1, characterized in that, The system also includes: a quantum key injection machine; The quantum key injector is connected to the output of the quantum cryptographic switch and is used to inject quantum keys.

6. The cross-domain user login system based on a quantum key distribution network according to claim 1, characterized in that, The system also includes: a quantum security shield; The quantum security shield is used to handle key reading, data encryption, and data and information interaction with the quantum cryptography service module on the quantum security chip.

7. A cross-domain user login method based on a quantum key distribution network, characterized in that, The method, applied to the system as described in any one of claims 1 to 6, comprises: The target business center receives system login requests from target users; The target business center queries whether it contains the user data of the target user. If it does not contain the user data, it requests the user data from the candidate business centers, which are multiple business centers other than the target business center. The original business center containing the user data in the candidate business center requests the quantum key through the corresponding quantum cryptography service module in the domain. The quantum cryptography service module corresponding to the original business center domain generates a shared quantum key through the QKD node in the domain, distributes the shared quantum key to the QKD target node in the target business center domain based on the quantum key distribution network, and returns the shared quantum key to the system. The original business center encrypts the user data based on the shared quantum key and transmits the ciphertext to the target business center via the network; The target business center receives the ciphertext, applies for the shared quantum key from the quantum cryptography service module within the target business center domain, and uses the shared quantum key to decrypt the ciphertext to obtain the decrypted user data. The target business center compares the user data carried in the system login request with the decrypted user data. Once authentication is successful, the user logs in successfully.

8. The cross-domain user login method based on a quantum key distribution network according to claim 7, characterized in that, Before the step of the target business center receiving the system login request from the target user, the method further includes: The target user requests the registration interface from the client or web interface; The access routing service routes the user request of the target user to the original business center; The original business center creates users and records user information, which includes at least user passwords, fingerprints, and identity tokens.

9. The cross-domain user login method based on a quantum key distribution network according to claim 7, characterized in that, The steps for the target business center to receive the system login request from the target user include: The access routing service responds to system login requests sent by target users from clients or web terminals, and routes the system login requests to the target business center according to a preset algorithm.

10. A cross-domain user login device based on a quantum key distribution network, characterized in that, The device, used in any one of claims 1 to 6, comprises: The user request receiving module is used by the target business center to receive system login requests from target users. The user data query module is used for the target business center to query whether it contains the user data of the target user. If it does not contain the user data, it requests the user data from the candidate business centers, which are multiple business centers other than the target business center. A quantum key generation module is used by the original business center containing the user data in the candidate business center to request a quantum key through the corresponding quantum cryptography service module in the domain. A quantum key distribution module is used by the quantum cryptography service module corresponding to the original business center domain to generate a shared quantum key through the QKD node in the domain, and distribute the shared quantum key to the QKD target node in the target business center domain based on the quantum key distribution network, and return the shared quantum key to the system. The user data encryption module is used by the original business center to encrypt the user data based on the shared quantum key, and transmit the ciphertext to the target business center through the network; The user data decryption module is used to receive the ciphertext at the target business center, apply for the shared quantum key from the quantum cryptography service module within the target business center domain, and use the shared quantum key to decrypt the ciphertext to obtain the decrypted user data. The login authentication module is used by the target business center to compare the user data carried in the system login request with the decrypted user data. If the authentication is successful, the user logs in successfully.

11. The cross-domain user login device based on a quantum key distribution network according to claim 10, characterized in that: The user request receiving module is specifically used to access the routing service to route the user request of the target user to the original business center when the target user requests the registration interface from the client or the web. The device further includes an information registration module, which, upon receiving a user request sent by the user request module, enables the original business center to create a user and record user information, wherein the user information includes at least a user password, fingerprint, and identity token.

12. The cross-domain user login device based on a quantum key distribution network according to claim 11, characterized in that, The user request receiving module is specifically used for: The access routing service responds to system login requests sent by target users from clients or web terminals, and routes the system login requests to the target business center according to a preset algorithm.

13. An electronic device, characterized in that, include: A processor, a memory, and a computer program stored in the memory and executable on the processor, wherein the computer program, when executed by the processor, implements the method as described in any one of claims 7 to 9.

14. A computer-readable storage medium, characterized in that, The computer-readable storage medium stores a computer program that, when executed by a processor, implements the method as described in any one of claims 7 to 9.

15. A computer program product, characterized in that, When the instructions in the computer program product are executed by the processor of the electronic device, the electronic device is able to perform the method as described in any one of claims 7 to 9.

Citation Information

Patent Citations

  • Cross-domain identity authentication method and system based on quantum key distribution network

    CN116527259A