A quantum secure communication system and method
By switching to classical key encryption when the quantum key channel fails, the reliability problem of the quantum secure communication system during failure is solved, and absolute secure communication is achieved by automatically switching back to quantum encryption mode after the failure is recovered.
Patent Information
- Application Number
- CN202411767806.3
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2024-12-04
- Publication Date
- 2026-02-27
- Estimated Expiration
- 2044-12-04
AI Technical Summary
Existing quantum secure communication systems suffer from low communication reliability and risk of interruption when the quantum key channel is damaged or the quantum key transceiver malfunctions.
A quantum-safe communication system is adopted, including a quantum-safe service platform, service terminals, a quantum-safe gateway, and a service server. It uses quantum keys to encrypt service data and switches to classical key encryption when quantum keys cannot be received, ensuring the security and reliability of communication.
Even when the quantum key channel is damaged or the equipment malfunctions, normal communication can still be maintained, achieving absolutely secure confidential communication, improving the security and reliability of communication, and ensuring automatic switching back to quantum encryption mode after the quantum encryption mode is restored.
Smart Images

Figure CN119449306B_ABST
Abstract
Description
Technical Field
[0001] This application relates to the field of information security technology, specifically to a quantum-secure communication system and method. Background Technology
[0002] For industries with high communication security requirements, such as the power industry, there is a security risk of business data being intercepted and compromised when external network business terminals communicate with internal network business servers. Therefore, business terminals need to access the internal network through a secure gateway to establish an encrypted channel and encrypt the transmission of business data. Quantum-secure communication systems can utilize quantum keys to encrypt business data transmission, achieving absolutely secure and confidential communication.
[0003] Existing quantum secure communication systems suffer from low communication reliability when the quantum key channel is destroyed or the quantum key transceiver malfunctions. Summary of the Invention
[0004] This application is proposed based on the aforementioned needs of the prior art. The technical problem to be solved by this application is to provide a quantum-secure communication system and method that can use classical keys to encrypt business data when the quantum key channel is destroyed or the quantum key transceiver device fails, thereby improving the security and reliability of communication.
[0005] To address the aforementioned problems, this application provides the following technical solution.
[0006] This application proposes a quantum-safe communication system, including a quantum-safe service platform, a service terminal, a quantum-safe gateway, and a service server. The quantum-safe service platform is responsible for generating quantum keys and distributing them to the quantum-safe gateway and the service terminal. The service terminal is responsible for collecting service data. The quantum-safe gateway is responsible for negotiating and establishing an encrypted channel with the service terminal. When both the quantum-safe gateway and the service terminal receive the quantum key, the service terminal uses the quantum key to encrypt and transmit the service data, and the quantum-safe gateway uses the quantum key to decrypt the encrypted service data. The quantum-safe gateway is also responsible for generating classical keys. When neither the quantum-safe gateway nor the service terminal receives the quantum key, the service terminal uses the classical key to encrypt and transmit the service data, and the quantum-safe gateway uses the classical key to decrypt the encrypted service data. The service server is responsible for receiving the service data decrypted by the quantum-safe gateway.
[0007] Furthermore, the quantum security gateway includes a main control board, a network port, a power supply, and a cryptographic card. The main control board is responsible for sending, receiving, and processing data; the network port is responsible for communication connections with the quantum security service platform, business terminals, and business servers; the power supply is responsible for providing power; and the cryptographic card is responsible for receiving quantum keys and generating classical keys, as well as calling the corresponding keys to encrypt and decrypt business data.
[0008] Furthermore, the quantum security gateway also includes a quantum key management module, which monitors the quantum security gateway and business terminals in real time or periodically to receive quantum keys, and applies for quantum keys from the quantum security service platform in real time or periodically.
[0009] Furthermore, the main control board includes a detection module, which is communicatively connected to the network port and the quantum key management module to monitor the reception of quantum keys through the network port and to feed back the reception status of quantum keys to the quantum key management module.
[0010] Furthermore, the quantum-safe gateway includes a cryptographic key to verify the identity of the person configuring the quantum-safe gateway.
[0011] Furthermore, there are multiple power sources, with at least one serving as a backup power source.
[0012] Furthermore, the backup power supply is a UPS power supply.
[0013] This application also proposes a communication method using the aforementioned quantum-safe communication system, comprising: establishing an encrypted channel: the service terminal negotiates with the quantum-safe gateway to establish a channel for encrypting and transmitting service data; requesting a quantum key: the service terminal and the quantum-safe gateway send a request to the quantum-safe service platform, enabling the quantum-safe service platform to generate and distribute a quantum key; entering quantum encryption mode: when the quantum-safe gateway and the service terminal receive the quantum key, the service terminal uses the quantum key to encrypt the service data; entering classical encryption mode: when the quantum-safe gateway or the service terminal does not receive the quantum key, the quantum-safe gateway negotiates with the service terminal and generates a classical key, and the service terminal uses the classical key to encrypt the service data; decrypting and sending plaintext: the quantum-safe gateway receives the encrypted service data transmitted through the encrypted channel, uses the corresponding key to decrypt the encrypted service data, and sends the decrypted service data to the service server.
[0014] Furthermore, the communication method of the quantum-safe communication system also includes: rapid switching of encryption modes: during the session key update cycle, the quantum-safe gateway monitors the reception of quantum keys in real time or periodically, and requests quantum keys from the quantum-safe service platform in real time or periodically. When the quantum-safe gateway detects that the quantum-safe gateway and the service terminal have received quantum keys, the quantum-safe communication system maintains or immediately switches to quantum encryption mode; when the quantum-safe gateway does not detect that the quantum-safe gateway and the service terminal have received quantum keys, the quantum-safe communication system maintains or immediately switches to classical encryption mode.
[0015] Furthermore, when the quantum-secure communication system is in quantum encryption mode, if the quantum-secure gateway does not detect that the business terminal and the quantum-secure gateway have received the quantum key for three consecutive cycles, the quantum-secure communication system immediately switches to classical encryption mode.
[0016] Furthermore, the communication method of the quantum-safe communication system also includes: alarm for failure to enter quantum encryption mode: when the quantum-safe gateway does not detect that the quantum-safe gateway and the service terminal have received the quantum key, the quantum-safe gateway sends an alarm message to the quantum security service platform.
[0017] Furthermore, the communication method of the quantum-safe communication system also includes: control data generation: the service server generates control data; establishing an encrypted channel: the quantum-safe gateway monitors the control data and negotiates with the service terminal to establish a channel for encrypting and transmitting control data; requesting a quantum key: the service terminal and the quantum-safe gateway send a request to the quantum-safe service platform, enabling the quantum-safe service platform to generate and distribute a quantum key; entering quantum encryption mode: when the quantum-safe gateway and the service terminal receive the quantum key, the quantum-safe gateway receives the control data and uses the quantum key to encrypt the control data; entering classical encryption mode: when the quantum-safe gateway or the service terminal does not receive the quantum key, the quantum-safe gateway negotiates with the service terminal to generate a classical key, the quantum-safe gateway receives the control data, and uses the classical key to encrypt the control data; sending ciphertext and decryption: the service terminal uses the corresponding key to decrypt the received encrypted control data.
[0018] Furthermore, the encrypted channel is an IPSec VPN.
[0019] The beneficial effects of this application include:
[0020] (1) When both the service terminal and the quantum security gateway receive the quantum key, the service terminal calls the quantum key to encrypt the service data in order to achieve absolutely secure confidential communication and improve the security of communication.
[0021] (2) When the business terminal or quantum security gateway does not receive the quantum key, the quantum security gateway can negotiate with the business terminal and generate a classical key. The business terminal calls the classical key to encrypt the business data, so that the quantum security communication system can still work normally in the event that the quantum key channel is destroyed or the quantum key transceiver equipment fails, thereby ensuring uninterrupted secure communication and improving the security and reliability of communication.
[0022] (3) The preferred encryption mode of the quantum secure communication system is the quantum encryption mode. The quantum secure communication system will only enter the classical encryption mode when the business terminal or the quantum secure gateway does not receive the quantum key. After the transmission of the quantum key is restored to normal, the classical encryption mode will automatically switch to the quantum encryption mode.
[0023] (4) During the session key update cycle, the quantum security gateway can monitor the reception of quantum keys in real time or periodically, and apply for quantum keys from the quantum security service platform in real time or periodically. When the quantum security gateway detects that the service terminal and the quantum security gateway have received quantum keys, it maintains or immediately switches to quantum encryption mode; when the quantum security gateway does not detect that the service terminal and the quantum security gateway have received quantum keys, it maintains or immediately switches to classical encryption mode.
[0024] (5) When the business server generates control data, the quantum security gateway uses either a quantum key or a classical key to encrypt the control data, thereby achieving secure communication of the control data. The preferred encryption mode for the control data is also the quantum encryption mode, and it can switch to the classical encryption mode in real time or periodically when the business terminal or the quantum security gateway does not receive the quantum key, thereby improving the security of communication. Attached Figure Description
[0025] To more clearly illustrate the technical solutions in the embodiments of this application, the accompanying drawings used in the description of the embodiments will be briefly introduced below. Obviously, the accompanying drawings described below are only some embodiments of this application. For those skilled in the art, other drawings can be obtained based on these drawings without creative effort.
[0026] Figure 1 This is a schematic diagram of a quantum-safe communication system according to a specific embodiment of this application.
[0027] Figure 2 This is a flowchart illustrating the quantum-safe communication method in a specific embodiment of this application.
[0028] Figure 3 This is a schematic diagram of the structure and connection relationship of the quantum security gateway in a specific embodiment of this application.
[0029] Figure 4 This is a schematic diagram illustrating the process of maintaining or switching encryption modes in a quantum-secure communication system during the session key update cycle, according to a specific embodiment of this application.
[0030] Figure 5 This is a schematic diagram of the control data encryption transmission process of the quantum-safe communication system in a specific embodiment of this application. Detailed Implementation
[0031] To make the objectives, technical solutions, and advantages of this application clearer, the technical solutions of this application will be clearly and completely described below with reference to the accompanying drawings. Obviously, the described embodiments are only a part of the embodiments of this application, and not all of them. Based on the embodiments in this application, all other embodiments obtained by those skilled in the art without creative effort are within the scope of protection of this application.
[0032] This application proposes a quantum-safe communication system, including a quantum-safe service platform, a service terminal, a quantum-safe gateway, and a service server. The quantum-safe service platform is responsible for generating quantum keys and distributing them to the quantum-safe gateway and the service terminal. The service terminal is responsible for collecting service data. The quantum-safe gateway is responsible for negotiating and establishing an encrypted channel with the service terminal. When both the quantum-safe gateway and the service terminal receive the quantum key, the service terminal uses the quantum key to encrypt and transmit the service data, and the quantum-safe gateway uses the quantum key to decrypt the encrypted service data. The quantum-safe gateway is also responsible for generating classical keys. When neither the quantum-safe gateway nor the service terminal receives the quantum key, the service terminal uses the classical key to encrypt and transmit the service data, and the quantum-safe gateway uses the classical key to decrypt the encrypted service data. The service server is responsible for receiving the service data decrypted by the quantum-safe gateway.
[0033] This application also proposes a communication method using the aforementioned quantum-safe communication system, comprising: establishing an encrypted channel: the service terminal negotiates with the quantum-safe gateway to establish a channel for encrypting and transmitting service data; requesting a quantum key: the service terminal and the quantum-safe gateway send a request to the quantum-safe service platform, enabling the quantum-safe service platform to generate and distribute a quantum key; entering quantum encryption mode: when the quantum-safe gateway and the service terminal receive the quantum key, the service terminal uses the quantum key to encrypt the service data; entering classical encryption mode: when the quantum-safe gateway or the service terminal does not receive the quantum key, the quantum-safe gateway negotiates with the service terminal and generates a classical key, and the service terminal uses the classical key to encrypt the service data; decrypting and sending plaintext: the quantum-safe gateway receives the encrypted service data transmitted through the encrypted channel, uses the corresponding key to decrypt the encrypted service data, and sends the decrypted service data to the service server.
[0034] The quantum-secure communication system in this application includes two encryption modes: quantum encryption mode and classical encryption mode. Quantum encryption mode can guarantee absolute security of communication and is the preferred encryption mode of quantum-secure communication system. When it is unable to enter quantum encryption mode, the quantum-secure communication system can automatically switch to classical encryption mode, thereby ensuring uninterrupted secure communication and improving the security and reliability of communication.
[0035] Furthermore, quantum-secure communication systems can monitor the reception of quantum keys in real time or periodically and apply for quantum keys during the session key update cycle, enabling faster maintenance or switching of encryption modes and further improving the security and reliability of communication.
[0036] This specific implementation method is illustrated using power communication as an example.
[0037] Example 1
[0038] like Figure 1 As shown, the quantum-safe communication system provided in this application includes a quantum-safe gateway 100, a service terminal 200, a quantum-safe service platform 300, and a service server 400.
[0039] The types of business terminals 200 include power station terminals, feeder terminals, etc., which are responsible for collecting business data such as fault inspection and monitoring, and also have functions such as key application, key reception monitoring, and data encryption and decryption.
[0040] The business server 400 is installed in the data center and can receive business data collected by the business terminal 200. It can also analyze the operation of the business terminal 200 based on the business data to generate control data for controlling the business terminal 200.
[0041] The quantum security gateway 100 is installed in the data center. It connects to the business server 400 via the intranet and to the business terminal 200 via the internet. As the entry point for internet data, the quantum security gateway 100 needs to negotiate and establish an encrypted channel with the business terminal 200. Business data is encrypted with a key and transmitted through this encrypted channel, eventually reaching the quantum security gateway 100 via the internet. The quantum security gateway 100 can then use the key to decrypt the encrypted business data and send the decrypted data to the business server 400.
[0042] The quantum security service platform 300 is installed in the data center to generate and distribute quantum keys. The business terminal 200 and the quantum security gateway 100 respectively send requests to the quantum security service platform 300 to obtain quantum keys for encrypting or decrypting business data.
[0043] Specifically, the quantum security service platform 300 includes a key generation module, a key maintenance module, a communication module, and a power supply module. The key generation module is responsible for generating quantum keys; the key maintenance module is responsible for receiving and storing quantum keys, distributing quantum keys according to requests from the service terminal 200 and the quantum security gateway 100, and analyzing the generation and remaining status of quantum keys; the communication module may include wired network interfaces such as RJ-45 interfaces and SC fiber optic interfaces, or it may include wireless network interfaces, and is responsible for establishing communication connections with the service terminal 200 and the quantum security gateway 100; the power supply module is responsible for providing the power required for the quantum security service platform 300 to operate.
[0044] When both the service terminal 200 and the quantum security gateway 100 receive the quantum key, the service terminal 200 uses the quantum key to encrypt the service data to achieve absolutely secure confidential communication and improve the security of the communication.
[0045] When the business terminal 200 or the quantum security gateway 100 does not receive the quantum key, the quantum security gateway 100 can negotiate with the business terminal 200 to generate a classical key. The business terminal 200 then uses the classical key to encrypt the business data, enabling the quantum secure communication system to continue to function normally even if the quantum key channel is damaged or the quantum key transceiver malfunctions. This ensures uninterrupted secure communication and improves the security and reliability of the communication.
[0046] Specifically, the business terminal 200 is connected to the quantum security gateway 100 via the external network. The business terminal 200 and the quantum security gateway 100 negotiate and establish an IPSec VPN. An IPSec VPN is a virtual private network based on internet security protocols, essentially a private network established on the public internet for encrypted communication. It can encrypt business data while simultaneously achieving target address translation and enabling remote access. The quantum security gateway 100 is connected to the quantum security service platform 300 via the internal network, while the business terminal 200 is connected to the quantum security service platform 300 via the external network. Both the business terminal 200 and the quantum security gateway 100 request quantum keys from the quantum security service platform 300. The quantum security gateway 100 can negotiate and generate a classical key with the service terminal 200. Depending on whether both the service terminal 200 and the quantum security gateway 100 receive the quantum key, the IPSec VPN can use either the quantum key or the classical key as the session key, thus establishing two tunnel modes. In each IPSec VPN tunnel mode, the service terminal 200 uses the quantum key and the classical key respectively to encrypt the service data. The encrypted service data is transmitted to the quantum security gateway 100 via the IPSec VPN, and the quantum security gateway 100 decrypts the encrypted service data using the corresponding key. The service server 400 connects to the quantum security gateway 100 via the intranet and receives the decrypted service data from the quantum security gateway 100.
[0047] To ensure communication security, the preferred encryption mode of the quantum-secure communication system is the IPSec VPN tunnel mode based on quantum keys, i.e., the quantum encryption mode. Only when the service terminal 200 or the quantum-secure gateway 100 does not receive the quantum key will the quantum-secure communication system use the IPSec VPN tunnel mode based on classical keys, i.e., the classical encryption mode.
[0048] like Figure 2 As shown, the communication method of a quantum-safe communication system mainly includes the following steps:
[0049] S11: Service terminal 200 negotiates with quantum security gateway 100 and establishes IPSec VPN.
[0050] S12: Business terminal 200 and quantum security gateway 100 apply for quantum keys from quantum security service platform 300.
[0051] S13: When both the service terminal 200 and the quantum security gateway 100 receive the quantum key, the IPSec VPN will use the quantum key as the session key and establish a tunnel mode.
[0052] S14: The service terminal 200 calls the quantum key to encrypt the service data and sends the encrypted service data to the quantum security gateway 100.
[0053] S15: The quantum security gateway 100 calls the quantum key to decrypt the encrypted business data and sends the decrypted business data to the business server 400.
[0054] S16: If the service terminal 200 or the quantum security gateway 100 does not receive the quantum key, the service terminal 200 and the quantum security gateway 100 negotiate to generate a classical key. The IPSec VPN uses the classical key as the session key and establishes a tunnel mode.
[0055] S17: Service terminal 200 calls the classical key to encrypt service data and sends the encrypted service data to quantum security gateway 100.
[0056] S18: The quantum security gateway 100 calls the classical key to decrypt the encrypted business data and sends the decrypted business data to the business server 400.
[0057] like Figure 3 As shown, in this specific embodiment, the quantum security gateway 100 includes a main control board 101, a network port, a power supply, a USB interface 107, a PCIE interface 109, and a password card 110.
[0058] The main control board 101 can be a CPU, responsible for sending, receiving, and processing business data, quantum keys, classical keys, and other data.
[0059] The network ports are located on the main control board 101. These ports can be multiple wired or wireless network interfaces, including a first network port 102, a second network port 103, and a third network port 104. The first network port 102 is connected to the quantum security service platform 300 via an internal network. The quantum security gateway 100 sends key requests to the quantum security service platform 300 through the first network port 102 and receives quantum keys through the same port. The second network port 103 is connected to multiple service terminals 200 via an external network. The quantum security gateway 100 connects to these service terminals 200 through the second network port 103 and establishes encrypted channels to encrypt and transmit service data. The third network port 104 is connected to the service server 400 via an internal network. The quantum security gateway 100 connects to the service server 400 through the third network port 104 to transmit decrypted service data or control data.
[0060] It should be noted that the quantum security gateway 100 can establish encrypted channels using a multi-process, multi-threaded concurrent processing method. This allows for the rapid establishment of a large number of encrypted channels while increasing the number of service terminals 200 that a single quantum security gateway 100 can connect to. For example, in this embodiment, each quantum security gateway 100 can connect to three thousand service terminals 200 through the second network port 103. Therefore, the data center only needs to set up one quantum security gateway 100, or only two quantum security gateways 100 (one primary and one backup), to achieve encrypted communication with a large number of service terminals 200. This reduces the number of quantum security gateways 100 required in the data center and simplifies the network and security configuration between the quantum security gateway 100, the quantum security service platform 300, and the service server 400, further improving the security and reliability of communication.
[0061] PCIe interface 109 is located on the main control board 101. PCIe interface 109 includes PCIe x8 and PCIe x16 types. The cryptographic card 110 has a connector that matches the PCIe interface 109. The cryptographic card 110 is inserted into the PCIe interface 109 and communicates with the main control board 101. The cryptographic card 110 is compatible with the national cryptographic algorithms SM2, SM3, and SM4 and can generate classical keys. The cryptographic card 110 can store both quantum keys and classical keys, allowing the use of either quantum key or classical key to encrypt or decrypt business data.
[0062] The specific working steps of a quantum-safe communication system are as follows:
[0063] Establishing an IPSec VPN: The service terminal 200 and the second network port 103 of the quantum security gateway 100 are connected via a 4G or 5G network. The service terminal 200 initiates a network key exchange protocol (IKE) to establish a security association (SA) with the quantum security gateway 100, enabling the service terminal 200 and the quantum security gateway 100 to authenticate each other and negotiate encryption algorithms, hash algorithms, and authentication methods.
[0064] Applying for quantum keys: The quantum security service platform 300 and the first network port 102 of the quantum security gateway 100 are connected through intranet communication. The quantum security service platform 300 and the business terminal 200 are connected through 4G or 5G network communication. The business terminal 200 and the quantum security gateway 100 apply for quantum keys from the quantum security service platform 300 respectively.
[0065] Key generation and distribution: In response to requests from the business terminal 200 and the quantum security gateway 100, the quantum security service platform 300 generates a pair of quantum keys and sends the quantum keys to the business terminal 200 and the quantum security gateway 100.
[0066] Key reception: The quantum key is transmitted to the cryptographic card 110 via the intranet and through the first network port 102, the main control board 101 and the PCIE interface 109. The cryptographic card 110 receives and stores the quantum key. The quantum key is also transmitted to the business terminal 200 via the external network. The business terminal 200 receives and stores the quantum key.
[0067] Entering quantum encryption mode: The quantum security gateway 100 monitors whether it has received the quantum key through its first network port 102; the service terminal 200 can also monitor whether it has received the quantum key and reports the quantum key reception status to the quantum security gateway 100 through its second network port 103. When both the service terminal 200 and the quantum security gateway 100 have received the quantum key, the IPSec VPN uses the quantum key as the session key and establishes a tunnel mode based on the quantum key. The service terminal 200 then uses its stored quantum key to encrypt service data.
[0068] Entering Classic Encryption Mode: If the service terminal 200 or the quantum security gateway 100 does not receive the quantum key, the service terminal 200 negotiates with the quantum security gateway 100 to generate a classic key through the cryptographic card 110 of the quantum security gateway 100. The classic key enters the IPSec VPN through the PCIE interface 109, the main control board 101, and the second network port 103. The IPSec VPN uses the classic key as the session key and establishes a tunnel mode based on the classic key. The service terminal 200 receives the classic key through the IPSec VPN and uses the classic key to encrypt the service data.
[0069] Encrypted business data transmission: Encrypted business data enters the IPSec VPN from the business terminal 200, and is transmitted sequentially through the second network port 103, the main control board 101 and the PCIE interface 109 to the cryptographic card 110 of the quantum security gateway 100.
[0070] Decryption and plaintext transmission: The cryptographic card 110 of the quantum security gateway 100 calls the corresponding quantum key or classical key to decrypt the encrypted business data. The decrypted business data is then sent to the business server 400 via the PCIE interface 109, the main control board 101, and the third network port 104.
[0071] The power supply includes a first power supply 105, which is connected to a power supply interface to power the quantum security gateway 100. To improve the reliability of the quantum secure communication system, the quantum security gateway 100 may include a second power supply 106 as a backup power supply to achieve dual power supply. For example, the first power supply 105 and the second power supply 106 can be connected to the power supply interface simultaneously. When one power supply fails to provide power due to voltage instability or other reasons, the quantum security gateway 100 can continue to operate by being powered by the other power supply. Alternatively, the second power supply 106 can be a UPS power supply, using the first power supply 105 connected to the power supply interface as the main power supply and the second power supply 106 as a backup power supply. When the first power supply 105 fails to provide power, the quantum security gateway 100 can automatically switch to the second power supply 106 to provide the time needed to save data or restore power.
[0072] USB interface 107 is located on the main control board 101. USB interface 107 can be USB 2.0 or USB 3.0. Password key 108 has a USB plug that matches USB interface 107. When configuring the quantum security gateway 100, password key 108 needs to be inserted into USB interface 107 to complete the authentication of system administrator, security administrator or audit administrator, thereby improving the security of communication.
[0073] Example 2
[0074] Example 2 provides another quantum-safe communication system and method. The difference from Example 1 is that, in order for the quantum-safe communication system to switch encryption modes during the session key update cycle, the quantum-safe gateway 100 may further include a quantum key management module 111.
[0075] like Figure 3 As shown, the quantum key management module 111 is a functional module of the main control board 101 used to monitor key status. The quantum key management module 111 can monitor the key types received by the quantum security gateway 100 and the service terminal 200 in real time or periodically, as well as information such as the key type, key usage, key remaining quantity, and timestamps in the cryptographic card 110. The quantum key management module 111 also has the function of periodically executing tasks, triggering key monitoring tasks, key application tasks, and key status reporting tasks in real time or at predetermined time intervals, and controlling the execution of these tasks through the main control board 101.
[0076] Based on the above functions, the quantum key management module 111 can monitor the quantum security gateway 100 and the service terminal 200 for receiving quantum keys in real time or periodically during the session key update cycle. It can also request quantum keys from the quantum security service platform 300 in real time or periodically. If the quantum key management module 111 does not detect that both the service terminal 200 and the quantum security gateway 100 have received quantum keys, the quantum secure communication system maintains or immediately switches to classical encryption mode and sends an alarm message to the quantum security service platform 300. The quantum security service platform 300 analyzes the generation and transmission of quantum keys based on the alarm message and reminds the user via SMS or pop-up windows, informing the user that the quantum secure communication system cannot enter quantum encryption mode and that there is a risk of encrypted business data being cracked. If the quantum key management module 111 detects that both the service terminal 200 and the quantum security gateway 100 have received quantum keys, the quantum secure communication system maintains or immediately switches to quantum encryption mode to avoid the risk of data being cracked due to the quantum secure communication system remaining in classical encryption mode for an extended period, thereby improving communication security.
[0077] It should be noted that the time interval predetermined by the quantum key management module 111 is shorter than the session key update cycle time interval. This means that in this embodiment, quantum key monitoring, application, and status reporting are more frequent to meet the requirements of the quantum-secure communication system for rapid switching of encryption modes. When the time interval predetermined by the quantum key management module 111 reaches the second level, for example, a predetermined time interval of 10 seconds, it can be considered that the quantum key management module 111 can monitor quantum key reception and apply for quantum keys in real time.
[0078] The quantum security gateway 100 can monitor the reception of quantum keys through the first network port 102 and feed back the reception status of quantum keys to the quantum key management module 111 through the main control board 101; the service terminal 200 can monitor the reception status of quantum keys and feed back the reception status of quantum keys to the quantum key management module 111 through IPSec VPN, the second network port 103 and the main control board 101.
[0079] Since network ports come in various types, in some embodiments, the first network port 102 and the second network port 103 do not have the function of monitoring the quantum key reception. Therefore, the main control board 101 may also include a detection module. The detection module is communicatively connected to the network port and the quantum key management module 111 to monitor the reception of quantum keys by the network port. In this embodiment, the detection module includes a first detection module and a second detection module. The first detection module is communicatively connected to the first network port 102 and the quantum key management module 111 to monitor the reception of quantum keys by the quantum security gateway 100 and provide feedback to the quantum key management module 111. The second detection module is communicatively connected to the second network port 103 and the quantum key management module 111 to monitor the reception of quantum keys by the service terminal 200 and provide feedback to the quantum key management module 111.
[0080] like Figure 4 As shown, the main steps for a quantum-secure communication system to maintain or switch encryption modes during the session key update cycle include:
[0081] S21: Service terminal 200 negotiates with quantum security gateway 100 and establishes IPSec VPN.
[0082] S22: During the session key update cycle, the quantum key management module 111 monitors the quantum key reception status in real time or periodically, and the quantum key management module 111 requests quantum keys from the quantum security service platform 300 in real time or periodically.
[0083] S23: When the quantum key management module 111 detects that both the service terminal 200 and the quantum security gateway 100 have received the quantum key, the IPSec VPN will use the quantum key as the session key and establish a tunnel mode, so that the quantum secure communication system can maintain or immediately switch to quantum encryption mode.
[0084] S24: When the quantum key management module 111 does not detect that the service terminal 200 and the quantum security gateway 100 have received the quantum key, the IPSec VPN will use the classical key as the session key and establish a tunnel mode, so that the quantum security communication system can maintain or immediately switch to the classical encryption mode.
[0085] Through the above steps, the quantum security gateway 100 can monitor the reception of quantum keys in real time or periodically during the session key update cycle, and apply for quantum keys from the quantum security service platform 300 in real time or periodically, thereby enabling rapid switching of encryption modes during the session key update cycle.
[0086] In this embodiment, when the quantum-secure communication system is in quantum encryption mode, it is only determined that the service terminal 200 or the quantum security gateway 100 cannot receive the quantum key if the condition "the quantum key management module 111 of the quantum security gateway 100 monitors the reception of the quantum key three times consecutively, and fails to detect that the service terminal 200 and the quantum security gateway 100 have received the quantum key in all three monitoring sessions" is met. Only then will the quantum-secure communication system switch from quantum encryption mode to classical encryption mode. This method improves the accuracy of quantum key monitoring, avoids frequent switching of encryption modes due to quantum key reception failures in a short period, and prevents prolonged periods in classical encryption mode, thereby improving the security and reliability of communication.
[0087] In step S24, when the quantum key management module 111 does not detect that the service terminal 200 and the quantum security gateway 100 have received a quantum key, the quantum key management module 111 sends an alarm message to the key operation and maintenance module of the quantum security service platform 300 through the main control board 101. The alarm message includes the device identifier and key status, etc. The quantum security service platform 300 notifies relevant personnel through pop-up windows, SMS, email, etc., so that relevant personnel can be informed in a timely manner that the quantum security communication system is currently in a classical encryption mode with security risks. The quantum security service platform 300 can also store the alarm record in the key operation and maintenance module of the quantum security service platform 300 for subsequent query and auditing.
[0088] Example 3
[0089] Example 3 provides another quantum-secure communication method. Unlike Examples 1 and 2, this example further includes a step of encrypting and transmitting control data generated by the service server 400.
[0090] like Figure 5 As shown, the encrypted transmission of control data includes the following steps:
[0091] S31: Business server 400 generates control data.
[0092] S32: The quantum security gateway 100 monitors the control data generated by the service server 400 through the third network port 104. The quantum security gateway 100 and the service terminal 200 negotiate to establish a channel for encrypting and transmitting control data.
[0093] S33: The quantum security gateway 100 and the business terminal 200 send a request to the quantum security service platform 300, so that the quantum security service platform 300 generates and distributes quantum keys.
[0094] S34: When both the service terminal 200 and the quantum security gateway 100 receive the quantum key, the quantum security gateway 100 receives the control data and uses the quantum key to encrypt the control data.
[0095] S35: If the service terminal 200 or the quantum security gateway 100 does not receive the quantum key, the quantum security gateway 100 negotiates with the service terminal 200 to generate a classical key. The quantum security gateway 100 receives the control data and calls the classical key to encrypt the control data.
[0096] S36: The service terminal 200 calls the corresponding key to decrypt the encrypted control data it receives.
[0097] In this embodiment, the quantum-secure communication system can encrypt and transmit the control data generated by the service server 400, and the encryption mode of the control data can be switched according to the reception of the quantum key, and the encryption mode of the control data can be switched in real time or periodically during the session key update cycle.
[0098] The above description is only a preferred embodiment of this application and is not intended to limit this application. Any modifications, equivalent substitutions, improvements, etc., made within the spirit and principles of this application should be included within the protection scope of this application.
Claims
1. A quantum secure communication system, characterized by, The quantum security service platform, the business terminal, the quantum security gateway and the business server are included, wherein the quantum security service platform is responsible for generating quantum keys and distributing the quantum keys to the quantum security gateway and the business terminal; the business terminal is responsible for collecting business data; the quantum security gateway is responsible for negotiating with the business terminal and establishing an encrypted channel; when the quantum security gateway and the business terminal both receive the quantum keys, the business terminal calls the quantum keys to encrypt and transmit the business data, and the quantum security gateway calls the quantum keys to decrypt the encrypted business data; the quantum security gateway is also responsible for generating classical keys; when the quantum security gateway or the business terminal does not receive the quantum keys, the business terminal calls the classical keys to encrypt and transmit the business data, and the quantum security gateway calls the classical keys to decrypt the encrypted business data; the business server is responsible for receiving the business data decrypted by the quantum security gateway; the quantum security gateway includes a main control board, a network port, a power supply and a password card and a quantum key management module. The main control board includes a detection module, which is in communication connection with the network port and the quantum key management module, to monitor the reception of the quantum keys by the network port and feed back the reception of the quantum keys to the quantum key management module; the quantum security gateway uses a multi-process, multi-thread concurrent processing mode to establish an encrypted channel, which meets the requirement of quickly establishing a large number of encrypted channels while improving the number of business terminals connected to a single quantum security gateway; the quantum key management module monitors the reception of the quantum keys by the quantum security gateway and the business terminal in real time or periodically, and applies for quantum keys from the quantum security service platform in real time or periodically; and when the quantum security communication system is in quantum encryption mode, only when the quantum key management module of the quantum security gateway monitors the reception of the quantum keys for three consecutive times and does not monitor the reception of the quantum keys by the business terminal and the quantum security gateway for three times, it is determined that the business terminal or the quantum security gateway cannot receive the quantum keys, and the quantum security communication system switches from the quantum encryption mode to the classical encryption mode.
2. The quantum secure communication system of claim 1, wherein, The main control board is responsible for receiving and processing data; the network port is responsible for communication connection with the quantum security service platform, the business terminal and the business server; and the power supply is responsible for power supply. The password card is responsible for receiving quantum keys and generating classical keys, and calling the corresponding keys to encrypt and decrypt the business data.
3. The quantum secure communication system of claim 2, wherein, The quantum security gateway includes a password key to verify the identity of the person configuring the quantum security gateway.
4. The quantum secure communication system of claim 1, wherein, The number of power supplies is multiple, and at least one of the power supplies is a backup power supply.
5. The quantum secure communication system of claim 4, wherein, The backup power supply is an ups power supply.
6. A communication method using the quantum secure communication system according to any one of claims 1 to 5, characterized by, It includes: Establishing an encrypted channel: the business terminal negotiates with the quantum security gateway to establish a channel for encrypting and transmitting the business data; Applying for quantum keys: the business terminal and the quantum security gateway send an application to the quantum security service platform, so that the quantum security service platform generates and distributes quantum keys; Enter quantum encryption mode: when the quantum security gateway and the service terminal receive quantum keys, the service terminal encrypts the service data using quantum keys; enter classical encryption mode: when the quantum security gateway or the service terminal does not receive quantum keys, the quantum security gateway and the service terminal negotiate and generate classical keys, and the service terminal encrypts the service data using classical keys; Decrypt and send plaintext: the quantum security gateway receives encrypted service data transmitted through the encrypted channel, decrypts the encrypted service data using corresponding keys, and sends the decrypted service data to the service server; Further comprising: fast switching encryption mode: during the update period of the session key, the quantum security gateway monitors the reception of quantum keys in real time or periodically, and applies for quantum keys from the quantum security service platform in real time or periodically; when the quantum security gateway monitors that the quantum security gateway and the service terminal receive quantum keys, the quantum security communication system maintains or immediately switches to the quantum encryption mode; when the quantum security gateway does not monitor that the quantum security gateway and the service terminal receive quantum keys, the quantum security communication system maintains or immediately switches to the classical encryption mode; When the quantum security communication system is in quantum encryption mode, if the quantum security gateway does not monitor that the service terminal and the quantum security gateway receive quantum keys for three consecutive periods, the quantum security communication system immediately switches to the classical encryption mode.
7. The communication method of the quantum secure communication system according to claim 6, wherein Further comprising: Alarm for failure to enter quantum encryption mode: when the quantum security gateway does not monitor that the quantum security gateway and the service terminal receive quantum keys, the quantum security gateway sends alarm information to the quantum security service platform.
8. The communication method of the quantum secure communication system according to claim 6, wherein Further comprising: Control data generation: the service server generates control data; establishment of an encrypted channel: the quantum security gateway monitors the control data and negotiates with the service terminal to establish a channel for encrypting and transmitting the control data; application for quantum keys: the service terminal and the quantum security gateway send an application to the quantum security service platform, so that the quantum security service platform generates and distributes quantum keys; Enter quantum encryption mode: when the quantum security gateway and the service terminal receive quantum keys, the quantum security gateway receives the control data and encrypts the control data using quantum keys; enter classical encryption mode: when the quantum security gateway or the service terminal does not receive quantum keys, the quantum security gateway and the service terminal negotiate and generate classical keys, the quantum security gateway receives the control data and encrypts the control data using classical keys; send ciphertext and decrypt: the service terminal decrypts the encrypted control data received by it using corresponding keys.
9. The communication method of the quantum secure communication system according to claim 6, wherein, The encrypted channel is an IPSec VPN.
Citation Information
Patent Citations
Collaborative encryption method and device, and optical network system
CN109428652A