A method for secure communication and key update based on quantum communication
Through quantum communication technology, efficient distribution of keys and regular/on-demand updates are achieved in the station area, which solves the problems of low key distribution efficiency and insufficient data encryption security in communication in the station area, improves the security and efficiency of data transmission, and ensures the reliability of communication.
Patent Information
- Application Number
- CN202411693842.X
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2024-11-25
- Publication Date
- 2025-08-05
- Estimated Expiration
- 2044-11-25
AI Technical Summary
The existing technology has low key distribution efficiency and insufficient data encryption security, so it is unable to effectively deal with the threat of quantum computers.
The station area secure communication and key update method based on quantum communication is adopted, and the side equipment and end equipment are charged with quantum protection keys and certificates through the quantum key management platform, and the session key is generated after identity authentication, and data encryption and decryption are carried out through the quantum protection key, combining the regular and on-demand update mechanism to ensure the security and effectiveness of the key.
It improves the security and efficiency of data transmission, ensures the reliability of communication, prevents key leakage, promptly detects and replaces communication risks, and realizes efficient management of quantum keys.
Smart Images

Figure CN119449302B_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to communication technology, and more specifically, to a method for secure communication and key updating in a quantum communication-based area, aiming to improve the security, efficiency and reliability of data transmission. Background Art
[0002] With the rapid development of information technology, communication security has become a pressing issue. Traditional encryption methods such as RSA and AES are unable to withstand the potential threat of quantum computers. Quantum communication technology, with its unique properties of unclonability, unpredictability, and high security, offers a new solution for communication security. This is particularly true for regional communications, which place higher demands on key distribution and data encryption. Summary of the Invention
[0003] The present invention aims to solve the problems of low efficiency of regional key distribution and insufficient data encryption security in the prior art, and provides a regional secure communication and key update method based on quantum communication.
[0004] In order to achieve the above objectives, the present invention provides a method for secure communication and key update in a quantum communication-based area, comprising:
[0005] A method for secure communication and key update in a station area based on quantum communication, comprising:
[0006] Step S1: The quantum key management platform injects the quantum protection key Kc and certificate into the main control board of the edge device, and injects the quantum protection key Ks and certificate into the end device. The quantum key management platform generates the quantum key and certificate, transmits the protection key Kc and certificate to the local communication warehouse of the edge device through offline injection, and transmits the protection key Ks and certificate to the end device.
[0007] Step S2: The end device S performs identity authentication on the main control board of the edge device C;
[0008] Step S3: The main control board of the edge device C performs identity authentication on the end device S;
[0009] Step S4: The edge device C generates a session key Kh and sends it to the end device;
[0010] Step S5: encryption and decryption of downlink data;
[0011] Step S6: encryption and decryption of uplink data;
[0012] Step S7: Session key update.
[0013] Preferably, step S2 further includes:
[0014] The end device S sends its network access certificate to the local communication warehouse of the edge device C. The local communication warehouse of the edge device C sends the network access certificate to the main control board of the edge device. The main control board of the edge device C authenticates its certificate and sends the authentication result to the end device S through the local communication warehouse of the edge device.
[0015] Preferably, step S3 further includes:
[0016] The main control board of the edge device C sends its network access certificate to the end device S through the local communication warehouse of the edge device. The end device S authenticates its certificate and sends the authentication result to the main control board of the edge device C through the local communication warehouse of the edge device;
[0017] After the steps S2 and S3, an authenticated communication connection is established between the main control board of the edge device C and the end device S via the local communication compartment of the edge device.
[0018] Preferably, step S4 further includes:
[0019] Step S4.1: The end device S transmits the dispersion factor to the local communication warehouse of the edge device C through the established channel;
[0020] Step S4.2: The local communication compartment of the edge device C sends the dispersion factor to the main control board;
[0021] Step S4.3: The main control board of the edge device C calculates the protection key Ks of the end device using the quantum protection key Kc and the dispersion factor;
[0022] Step S4.4: Randomly generate a set of session keys Kh according to the key composition requirements;
[0023] Step S4.5: Encrypt the session key Kh using the protection key Ks to obtain the encrypted session key Ks(Kh), and send it to the local communication warehouse of the edge device C;
[0024] Step S4.6: The local communication compartment of the edge device C transmits the encrypted session key Ks (Kh) to the end device S through the established channel;
[0025] Step S4.7: The end device S receives the encrypted session key Ks (Kh), decrypts it, and obtains the session key Kh.
[0026] Preferably, step S5 further includes:
[0027] Step S5.1: The main control board of edge device C sends a downlink plaintext data Data to the local communication compartment of edge device C;
[0028] Step S5.2: The local communication compartment of edge device C encrypts the downlink plaintext data Data using the session key Kh;
[0029] Step S5.3: The terminal device decrypts the encrypted data Kh(Data) to obtain the downlink plaintext data Data.
[0030] Preferably, step S6 further includes:
[0031] Step S6.1: The end device S encrypts the uplink plaintext data Data with the session key Kh and sends it to the local communication warehouse of the edge device C;
[0032] Step S6.2: The local communication compartment of edge device C sends the encrypted data to the main control board;
[0033] Step S6.3: Decrypt the encrypted data Kh(Data) using the session key Kh to obtain the uplink plaintext data Data.
[0034] Preferably, step S7 further includes:
[0035] The end device S requests the edge device C to update the session key. The main control board of the edge device C generates a new set of session keys Kh', encrypts the new session keys Kh' using the session key Kh, and transmits the encrypted data Kh(Kh') to the end device through the local communication warehouse of the edge device. The end device uses the session key Kh to decrypt the encrypted data Kh(Kh') to obtain the new session key Kh'.
[0036] The quantum key management platform generates two sets of associated quantum keys of length N, denoted as U and V. , ;
[0037] Randomly generate a set of keys of length 2N [ r 1 , r 2 , ⋯ , r N , r N + 1 , r N + 2 , ⋯ , r 2 N ] , the first half of the interval is inserted into U, and the second half of the interval is inserted into V, thus obtaining the protection keys Ks and Kc of length 2N;
[0038] Ks = [ u 1 , r 1 , u 2 , r 2 , ⋯ , u N , r N ] , Kc = [ v 1 , r N + 1 , v 2 , r N + 2 , ⋯ , v N , r 2 N ] ;
[0039] The key generated above is distributed to the end device S and the edge device C using an offline charging method.
[0040] Preferably, the method for updating the session key includes:
[0041] The session key Kh is generated by the edge device C, encrypted using the protection Ks and transmitted to the end device, and used as the decryption key of the end device S;
[0042] The session key Kh is a set of encryption keys, consisting of Q strings of length P, denoted as
[0043] ;
[0044] The session key is updated using a periodic update mechanism or an on-demand update mechanism.
[0045] Preferably, the regular update mechanism includes:
[0046] When the amount of encrypted output data reaches the threshold F_data, or the session key usage time reaches T_limit, the end device S sends a key update request to the edge device C. The edge device C uses a quantum random number generation chip to regenerate the session key and encrypts it for transmission to the end device S.
[0047] Preferably, the on-demand update mechanism includes:
[0048] Assume that the transmitted data is Data, the session key is Kh, and the edge device C transmits the encrypted data Kh(Data) to the end device S;
[0049] The end device S calculates the hash value Hd using the unique identifiers of both communicating devices and the transmitted data, where the unique identifiers of both communicating devices are denoted by As for the end device and Ac for the edge device.
[0050] As = [ s 1 , s 2 , ⋯ , s M ] , Ac = [ c 1 , c 2 , ⋯ , c M ] ;
[0051] Hash value , where Calculate the hash value function;
[0052] The edge device C transmits the encrypted hash value Kh(Hd) to the end device S;
[0053] After receiving the encrypted data Kh(Data) and hash value Kh(Hd), the terminal device S decrypts them to obtain the data Data' and hash value Hd';
[0054] According to the unique identification code of the data generator and itself, the hash value calculation function is used Calculate the hash value of the currently received data ,
[0055] if If it is consistent with Hd, it means that the current communication is secure;
[0056] If they are inconsistent, it means that there may be risks in the communication process. A resending signal is sent, and the edge device resends the data Kh(Data) and hash value Kh(Hd). If the hash value of the end device S is verified, communication continues. If the verification fails, a signal for changing the key is sent.
[0057] Preferably, the method for generating the update key includes:
[0058] In the station area, each device has a unique identification code, and the terminal device structure dispersion factor is as follows:
[0059] Re-obtain the unique identification codes of the device and the device to communicate in the system, record the end device as As and the edge device as Ac;
[0060] As = [ s 1 , s 2 , ⋯ , s M ] , Ac = [ c 1 , c 2 , ⋯ , c M ] ;
[0061] For the end device As, use the quantum key U to encrypt (As, Ac) to form a new encryption sequence [ s ' 1 , s ' 2 , ⋯ , s ' M , c ' 1 , c ' 2 , ⋯ , c ' M ] ;
[0062] Based on the quantum key U, determine the quantum key V and use the key to parse the random sequence [ r 1 , r 2 , ⋯ , r N ] Encrypt and get [ r ' 1 , r ' 2 , ⋯ , r ' N ] ;
[0063] will sequence [ s ' 1 , s ' 2 , ⋯ , s ' M , c ' 1 , c ' 2 , ⋯ , c ' M , r ' 1 , r ' 2 , ⋯ , r ' N ] The data is transmitted to the edge device C through the established channel, and the edge device C parses the data.
[0064] Preferably, the specific calculation method of the session key Ks further includes:
[0065] The edge device C regenerates a set of session keys ;
[0066] Recombine the Q row keys;
[0067] Kh' is written ,
[0068] In the formula K ' i = [ k ' i 1 k ' i 2 ⋯ k ' iP ] , i = 1 , 2 , ⋯ , Q ;
[0069] Edge device C uses the injected quantum protection key V = [ v 1 , v 2 , ⋯ , v N ] , reorder Kh';
[0070] Select Z groups of data from V in sequence, each group of data has a length of G, Z <Q,
[0071] 、 ,…, ,
[0072] If ZG>N, the value of the protection key is selected cyclically, that is, the selection is complete. Then, select v1;
[0073] by For example, The new location is ,
[0074] In the formula, val() is the calculation sequence The value of mod() is the remainder function, that is, The remainder of the value divided by Q is new location;
[0075] Note that if the remainder is 0, the position is not changed. In addition, if the calculated new position has been used before, the position is not changed. The positions of the other Z-1 keys are calculated in the same way, and we get
[0076] .
[0077] Preferably, the specific calculation method of the session key Ks further includes a decryption and restoration step of the session key Kh', which is as follows:
[0078] Kh ( ) is transmitted to the terminal device, and the terminal device S decrypts it to obtain , according to their own quantum key Calculate the edge device , select group Z data 、 ,…, , by performing the reverse operation according to the steps of recombining the Q row keys, Kh' can be obtained, thereby completing the key update.
[0079] Compared with the prior art, the present invention has the following beneficial effects:
[0080] 1) Key updates are based on periodic and on-demand mechanisms, ensuring the security of data transmission while guaranteeing the cost-effectiveness of communications.
[0081] 2) During the communication transmission process, quantum key sequence changes are used to ensure the security of the key. The quantum key is only stored by the communicating parties, which can effectively prevent leakage.
[0082] 3) By verifying the communication data, risks in communication can be discovered in a timely manner and keys can be replaced in a timely manner. BRIEF DESCRIPTION OF THE DRAWINGS
[0083] Figure 1 This is a security protection solution for low-voltage distribution services based on quantum encryption in the present invention.
[0084] Figure 2 This is a flow chart of the edge-to-end quantum key session key distribution and business data transmission protection of the present invention. DETAILED DESCRIPTION
[0085] The present invention is further described in detail below with reference to the accompanying drawings:
[0086] In order to better understand the present invention, the embodiments of the present invention are explained in detail below with reference to the accompanying drawings.
[0087] The present invention provides embodiment 1 which discloses the relevant structure of the quantum encryption device of the present invention.
[0088] The first embodiment discloses a quantum encryption communication system structure.
[0089] This invention leverages quantum key technology to build an edge-to-end quantum-secure encryption channel by integrating quantum security chips into the main control boards of edge devices such as distribution terminals and converged terminals. Furthermore, security chips (for internal assets) or external security modules (for external assets) are integrated into end devices such as smart circuit breakers, photovoltaic grid-connected circuit breakers, and LTUs. The specific implementation strategy is as follows.
[0090] The structure of the security protection scheme for low-voltage distribution business based on quantum encryption is as follows: Figure 1 As shown:
[0091] The encrypted communication system includes edge nodes and end nodes, and realizes encrypted communication between the edge nodes and the end nodes by adding a security chip in an embedded or external security module manner.
[0092] The edge of the substation distribution network is generally a distribution terminal. A security chip with a built-in quantum random number generator is deployed in the local communication warehouse of the edge device, and the quantum session key is encrypted and issued using a quantum protection key.
[0093] In particular, the security chip of the quantum random number generator can be a quantum random number generator or a quantum random number chip or other devices or means that can generate true random numbers.
[0094] The end side of the substation distribution network is mainly composed of power consumption (generation) node equipment in the power grid, and a security chip is embedded in the end device or a security module with an external integrated security chip is connected.
[0095] The security chip on the terminal side is mainly embedded in the terminal device and integrated with the device, which is called the embedded mode of secure communication; it can also be used for external terminal devices; the security module provides security services to the terminal device through hardware modification, such as embedding in the tail module, external security isolation device, etc., which is called the external mode of secure communication.
[0096] The edge-side device uses quantum key encryption to protect the transmission of edge-to-end business data.
[0097] Another aspect of the present invention discloses the composition of encrypted communication system equipment.
[0098] In the process of implementing quantum encryption communication in the distribution network of the substation, the following equipment is involved:
[0099] (1) The key management platform is used to generate and issue the initial protection keys and certificates for edge-to-end communication. It is the basic platform for key management of distribution network communication in the substation area. In quantum cryptographic secure communication, the protection keys and certificates are generally injected offline.
[0100] (2) Edge devices mainly include a security chip and a local communication pod. The device's main control board is the device for generating, processing, and executing information, and the local communication pod is an encrypted secure communication device. The main control board and the local communication pod constitute the secure communication and information processing control node of the edge device. The security chip is integrated into the main control board.
[0101] (3) End devices, including the end device functional system and the encryption and security communication module. The end device functional system mainly refers to the corresponding facilities and equipment of the distribution network terminal, such as various types of power consumption devices, power grid security protection devices, etc. The security communication module is the main carrier for realizing quantum encryption and security communication.
[0102] The protection keys between edge and end are uniformly generated and distributed by the key management platform. The session keys between edge and end are generated by the quantum random numbers built into the edge security chip and distributed to the end device. The edge device is responsible for maintaining and managing the session keys of the end device.
[0103] The second embodiment of the present invention discloses the implementation process of encrypted communication of the present invention, as shown in the attached Figure 2 shown.
[0104] The edge device is denoted as C and the end device is denoted as S. The method for implementing quantum encryption secure communication between devices C and S is described as follows:
[0105] It can be understood that the edge device includes a main control board, a local communication compartment and a security chip.
[0106] Step S1: The quantum key management platform injects the quantum protection key Kc and certificate into the main control board of the edge device, and the quantum key management platform injects the quantum protection key Ks and certificate into the end device;
[0107] The key management platform generates quantum keys and certificates, transfers the protection key Kc and certificate to the local communication vault of the edge device through offline charging, and transfers the protection key Ks and certificate to the end device. The function of charging the protection key Kc is placed on the edge device's main control board.
[0108] Step S2: The end device S performs identity authentication on the main control board in the edge device C.
[0109] The end device S sends its network access certificate to the local communication warehouse of the edge device C. The local communication warehouse of the edge device C sends the network access certificate to the main control board of the edge device. The main control board of the edge device C authenticates its certificate and sends the authentication result to the end device S through the local communication warehouse of the edge device.
[0110] Step S3: The main control board of the edge device C performs identity authentication on the end device S.
[0111] The main control board of edge device C sends its network access certificate to end device S through the local communication warehouse of the edge device. End device S authenticates its certificate and sends the authentication result to the main control board of edge device C through the local communication warehouse of the edge device.
[0112] After steps S2 and S3, an authenticated communication connection is established between the main control board of the edge device C and the end device S.
[0113] Step S4: The edge device C generates a session key Kh and sends it to the end device.
[0114] Step S4.1: The end device S transmits the dispersion factor to the local communication warehouse of the edge device C through the established channel.
[0115] Step S4.2: The local communication compartment of edge device C sends the dispersion factor to the main control board.
[0116] Step S4.3: The main control board of edge device C uses the quantum protection key Kc and the dispersion factor to calculate the protection key Ks of the end device.
[0117] Step S4.3: Randomly generate a set of session keys Kh according to the key composition requirements.
[0118] Step S4.4: Use the protection key Ks to encrypt the session key Kh, obtain the encrypted session key Ks (Kh), and send it to the local communication warehouse.
[0119] Step S4.5: Through the established channel, the local communication warehouse of the edge device C transmits the encrypted session key Ks (Kh) to the end device S.
[0120] Step S4.6: The end device S receives the encrypted session key Ks (Kh) and decrypts it to obtain the session key Kh.
[0121] Step S5: Encryption and decryption of downlink data.
[0122] Step S5.1: The main control board of edge device C sends a downlink plaintext data to the local communication warehouse;
[0123] Step S5.2: The local communication compartment of edge device C encrypts the downlink plaintext data Data using the session key Kh;
[0124] Step S5.3: The terminal device S decrypts the encrypted data Kh(Data) to obtain the downlink plaintext data Data.
[0125] Step S6: Encryption and decryption of uplink data.
[0126] Step S6.1: The end device S encrypts the uplink plaintext data Data with the session key Kh and sends it to the local communication warehouse of the edge device C;
[0127] Step S6.2: The local communication compartment of edge device C sends the encrypted data to the main control board;
[0128] Step S6.3: Use the session key Kh to decrypt the encrypted data Kh(Data) to obtain the uplink plaintext data Data.
[0129] Step S7: Key update.
[0130] To ensure communication security, session keys must be updated regularly. End device S requests an update from edge device C. Edge device C's main control board generates a new session key, Kh', encrypts it with the current session key, Kh, and transmits it to end device S via the edge device's local communication repository. End device S then decrypts the encrypted data, Kh(Kh'), using the current session key, Kh, to obtain the new session key, Kh'.
[0131] Specifically, embodiment three of the present invention further provides a method for calculating a session key Ks.
[0132] The quantum key management platform generates two sets of associated quantum keys of length N, denoted as U and V. , To ensure key security, improve the efficiency of quantum key usage, and enhance economic efficiency, the following methods are used:
[0133] Randomly generate a set of keys of length 2N [ r 1 , r 2 , ⋯ , r N , r N + 1 , r N + 2 , ⋯ , r 2 N ] , the first half of the interval is inserted into U, and the second half of the interval is inserted into V, thus obtaining the protection keys KS and Kc of length 2N.
[0134] Ks = [ u 1 , r 1 , u 2 , r 2 , ⋯ , u N , r N ] , Kc = [ v 1 , r N + 1 , v 2 , r N + 2 , ⋯ , v N , r 2 N ]
[0135] The key generated above is distributed to the end device S and the variable device C in an offline charging manner.
[0136] Specifically, the present invention also provides a session key updating method.
[0137] The session key Kh is generated by the edge device C, encrypted using the protection Ks and transmitted to the end device, and used as the decryption key of the end device S.
[0138] Usually the session key Kh is a set of encryption keys, including Q strings of length P, denoted as
[0139]
[0140] There are two mechanisms for updating session keys. One is a periodic update mechanism, where the edge device C regenerates a new key after the current key Kh has been used for a certain period of time. The other is that during the communication process, if information verification fails, data is lost, or tampered with, the end device requests to regenerate the session key Kh'. The specific method is as follows:
[0141] Mechanism 1: Regular updates
[0142] When the amount of encrypted output data reaches the threshold F_data, or the session key usage time reaches T_limit, the end device S sends a key update request to the edge device C. The edge device uses the quantum random number generation chip to regenerate the session key and encrypts it for transmission to the end device S.
[0143] Mechanism 2: Update on demand.
[0144] Assume that the transmitted data is Data and the session key is Kh. The edge device C transmits the encrypted data Kh(Data) to the end device S. The end device calculates the hash value Hd by combining the unique identifiers of both communicating devices and the transmitted data. The unique identifiers of both communicating devices are denoted by As for the end device and Ac for the edge device. As = [ s 1 , s 2 , ⋯ , s M ] , Ac = [ c 1 , c 2 , ⋯ , c M ] The hash value Hd is calculated as follows:
[0145]
[0146] In the formula Hash value calculation function.
[0147] Then, the edge device C transmits the encrypted hash value Kh(Hd) to the end device S.
[0148] After receiving the encrypted data Kh (Data) and hash value Kh (Hd), the terminal device S decrypts the data to obtain the data Data' and hash value Hd'. Then, according to the unique identifier of the data generator and its own, the hash value calculation function is used. Calculate the hash value of the currently received data
[0149] ,
[0150] if If it is consistent with Hd, the current communication is secure. If it is inconsistent, it means that there may be risks in the communication process. A resend signal is sent, and the edge device resends the data Kh(Data) and hash value Kh(Hd). If the hash value of the end device S is verified, communication continues. If the verification fails, a signal to change the key is sent.
[0151] The above process also applies to the case where the end device S sends data to the edge device C. If the edge device finds that the obtained data is inconsistent with the hash value verification, it sends a retransmission signal message. If the verification still fails, the key is replaced.
[0152] The present invention also provides a method for generating an update key.
[0153] Edge device C regenerates a set of session keys ,Since the early session secret Kh is used for encrypted ,transmission, the following method is adopted to improve data security.
[0154] Reassemble the Q row keys.
[0155] Kh' can be written as
[0156] ;
[0157] In the formula K ' i = [ k ' i 1 k ' i 2 ⋯ k ' iP ] , i = 1 , 2 , ⋯ , Q .
[0158] Edge device C uses the injected quantum protection key , reorder Kh'. Select Z groups of data from V in order, each group of data has a length of G, Z <Q。 、 ,…, If ZG>N, the value of the protection key is selected cyclically, that is, the selection is complete. Then, select v1.
[0159] by For example, The new location is:
[0160] ,
[0161] In the formula, val() is the calculation sequence The value of mod() is the remainder function, that is, The remainder of the value divided by Q. The remainder is to the new location.
[0162] Note that if the remainder is 0, the position is not changed. In addition, if the calculated new position has been used before, the position is not changed. The positions of the other Z-1 keys are calculated in the same way, and we get
[0163]
[0164] The session key Kh' is decrypted and restored.
[0165] Kh ( ) is transmitted to the end device, which decrypts it to obtain , according to their own quantum key Calculate the edge device , then select group Z data 、 ,…, , according to the reverse operation of the above steps, Kh' can be obtained, thereby completing the key update.
[0166] In the description of the present invention, it should be noted that, unless otherwise specified or limited, the terms "connected" and "connection" should be understood in a broad sense. For example, they can refer to fixed connection, detachable connection, or integral connection; mechanical connection, electrical connection; direct connection, or indirect connection through an intermediary. Those skilled in the art will understand the specific meanings of the above terms in the present invention based on specific circumstances.
[0167] In the description of the present invention, unless otherwise specified, the terms "upper", "lower", "left", "right", "inside", "outside", etc., indicating directions or positional relationships, are based on the directions or positional relationships shown in the accompanying drawings. They are only for the convenience of describing the present invention and simplifying the description, and do not indicate or imply that the device or element referred to must have a specific direction, be constructed and operate in a specific direction. Therefore, they cannot be understood as limiting the present invention.
[0168] Finally, it should be noted that the above technical solution is only one embodiment of the present invention. For those skilled in the art, it is easy to make various types of improvements or modifications based on the application methods and principles disclosed in the present invention, and it is not limited to the method described in the above specific embodiment of the present invention. Therefore, the method described above is only preferred and does not have a restrictive meaning.
Claims
1. A method for secure communication and key update in a quantum communication-based area, characterized by: Step S1: The quantum key management platform injects the quantum protection key Kc and certificate into the main control board of the edge device, and the quantum key management platform injects the quantum protection key Ks and certificate into the end device; The quantum key management platform generates quantum keys and certificates, transmits the protection key Kc and certificate to the local communication warehouse of the edge device through offline filling, and transmits the protection key Ks and certificate to the end device; Step S2: The end device S performs identity authentication on the main control board of the edge device C; Step S3: The main control board of the edge device C performs identity authentication on the end device S; Step S4: The edge device C generates a session key Kh and sends it to the end device; Step S5: encryption and decryption of downlink data; Step S6: encryption and decryption of uplink data; Step S7: Session key update; The step S7 further comprises: The end device S submits a request to the edge device C to update the session key. The main control board of the edge device C regenerates a new set of session keys Kh', encrypts the new session keys Kh' using the session key Kh, and transmits the encrypted data Kh(Kh') to the end device via the local communication warehouse of the edge device. The end device uses the session key Kh to decrypt the encrypted data Kh(Kh') to obtain the new session key Kh'. The quantum key management platform generates two sets of associated quantum keys of length N, denoted as U and V. , ; Randomly generate a set of keys of length 2N , the first half of the interval is inserted into U, and the second half of the interval is inserted into V, so that the protection keys Ks and Kc of length 2N are obtained; , ; The key generated above is distributed to the end device S and the edge device C by offline charging; The method for updating the session key includes: The session key Kh is generated by the edge device C, encrypted using the protection Ks and transmitted to the end device, and used as the decryption key of the end device S; The session key Kh is a set of encryption keys, including Q strings of length P, denoted as ; Session key updates adopt a periodic update mechanism or an on-demand update mechanism; The periodic update mechanism includes: When the amount of encrypted output data reaches the threshold F_data, or the session key usage time reaches T_limit, the end device S sends a key update request to the edge device C. The edge device C uses a quantum random number generation chip to regenerate the session key and encrypts it for transmission to the end device S.
2. The method according to claim 1, characterized in that The step S2 further comprises: The end device S sends its network access certificate to the local communication warehouse of the edge device C. The local communication warehouse of the edge device C sends the network access certificate to the main control board of the edge device. The main control board of the edge device C authenticates its certificate and sends the authentication result to the end device S through the local communication warehouse of the edge device.
3. The method according to claim 2, characterized in that The step S3 further comprises: The main control board of the edge device C sends its network access certificate to the end device S through the local communication warehouse of the edge device. The end device S authenticates its certificate and sends the authentication result to the main control board of the edge device C through the local communication warehouse of the edge device; After the steps S2 and S3, an authenticated communication connection is established between the main control board of the edge device C and the end device S via the local communication compartment of the edge device.
4. The method according to claim 3, characterized in that The step S4 further comprises: Step S4.1: The end device S transmits the dispersion factor to the local communication warehouse of the edge device C through the established channel; Step S4.2: The local communication compartment of the edge device C sends the dispersion factor to the main control board; Step S4.3: The main control board of the edge device C calculates the protection key Ks of the end device using the quantum protection key Kc and the dispersion factor; Step S4.4: Randomly generate a set of session keys Kh according to the key composition requirements; Step S4.5: Encrypt the session key Kh using the protection key Ks to obtain the encrypted session key Ks(Kh), and send it to the local communication warehouse of the edge device C; Step S4.6: The local communication compartment of the edge device C transmits the encrypted session key Ks (Kh) to the end device S through the established channel; Step S4.7: The end device S receives the encrypted session key Ks (Kh), decrypts it, and obtains the session key Kh.
5. The method according to claim 4, characterized in that The step S5 further comprises: Step S5.1: The main control board of the edge device C sends a downlink plaintext data Data to the local communication compartment of the edge device C; Step S5.2: The local communication compartment of the edge device C encrypts the downlink plaintext data Data using the session key Kh; Step S5.3: The terminal device decrypts the encrypted data Kh(Data) to obtain the downlink plaintext data Data.
6. The method according to claim 5, characterized in that The step S6 further comprises: Step S6.1: The end device S encrypts the uplink plaintext data Data with the session key Kh and sends it to the local communication warehouse of the edge device C; Step S6.2: The local communication unit of the edge device C sends the encrypted data to the main control board; Step S6.3: Decrypt the encrypted data Kh(Data) using the session key Kh to obtain the uplink plaintext data Data.
7. The method according to claim 6, characterized in that The on-demand update mechanism includes: Assume that the transmitted data is Data and the session key is Kh. The edge device C transmits the encrypted data Kh (Data) to the end device S. The end device S calculates the hash value Hd of the unique identification codes of the communicating devices and the transmitted data, where the unique identification codes of the communicating devices are denoted as As for the end device and Ac for the edge device; , ; Hash value , where Calculate the hash value function; The edge device C transmits the encrypted hash value Kh(Hd) to the end device S; After receiving the encrypted data Kh(Data) and the hash value Kh(Hd), the terminal device S decrypts them to obtain the data Data' and the hash value Hd'; According to the unique identification code of the data generator and itself, the hash value calculation function is used Calculate the hash value of the currently received data , if If it is consistent with Hd, it means that the current communication is secure; If they are inconsistent, it means that there may be risks in the communication process. A resending signal is sent, and the edge device resends the data Kh(Data) and hash value Kh(Hd). If the hash value of the end device S is verified, communication continues. If the verification fails, a signal for changing the key is sent.
8. The method according to claim 6 or 7, characterized in that Methods for generating update keys include: In the station area, each device has a unique identification code, and the terminal device structure dispersion factor is as follows: Re-obtain the unique identification codes of the device and the device to communicate in the system, record the end device as As and the edge device as Ac; , ; For the end device As, use the quantum key U to encrypt (As, Ac) to form a new encryption sequence ; Based on the quantum key U, determine the quantum key V and use the key to parse the random sequence Encrypt and get ; will sequence The data is transmitted to the edge device C through the established channel, and the edge device C parses the data.
9. The method according to claim 8, characterized in that The specific calculation method of the session key Kh further includes: The edge device C regenerates a set of session keys ; Recombine the Q row keys; Kh' is written , In the formula ; The edge device C is based on the injected quantum protection key , reorder Kh'; Select Z groups of data from V in sequence, each group of data has a length of G, Z <Q, 、 ,…, , If ZG>N, the value of the protection key is selected cyclically, that is, the selection is complete. Then, select v1; by For example, The new location is , In the formula, val() is the calculation sequence The value of mod() is the remainder function, that is, The remainder of the value divided by Q is new location; Note that if the remainder is 0, the position will not be changed; In addition, if the calculated new position has been used before, the position will not be changed; The positions of the other Z-1 keys are calculated in this way, and we get 。 10. The method according to claim 9, characterized in that The specific calculation method of the session key Kh further includes the step of decrypting and restoring the session key Kh', which is as follows: Kh ( ) is transmitted to the terminal device, and the terminal device S decrypts it to obtain , according to their own quantum key Calculate the edge device , select group Z data 、 ,…, , by performing the reverse operation according to the steps of recombining the Q row keys, Kh' can be obtained, thereby completing the key update.
Citation Information
Patent Citations
5G virtual quotient key library distribution method based on quantum security
CN114040390A
Quantum encryption communication method and system applied to low-voltage transformer area
CN117353905A