A multi-device key distribution method, system and device based on quantum random numbers

By constructing quantum random number models and models, and using the amplified spontaneous emission source of erbium-doped optical fiber to register and authenticate IoT devices, the problems of rapid authentication and group key distribution of IoT devices are solved, and efficient, flexible information exchange and rapid response are achieved.

CN119449309BActive Publication Date: 2025-09-09ELECTRIC POWER RES INST OF STATE GRID ZHEJIANG ELECTRIC POWER COMAPNY
View PDF 3 Cites 0 Cited by

Patent Information

Application Number
CN202411798518.4
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2024-12-09
Publication Date
2025-09-09
Estimated Expiration
2044-12-09

AI Technical Summary

Technical Problem

Existing technologies are unable to achieve rapid authentication of IoT devices and rapid distribution of group keys, resulting in low user authentication efficiency and poor flexibility, and are not suitable for scenarios where a large number of requests must be processed quickly.

Method used

By constructing a power Internet of Things control model, an edge key generation model, a device registration model, a device authentication model, and a key distribution model, the device is registered using quantum random numbers from an amplified spontaneous emission source based on erbium-doped fiber, and the key information in the registration phase is used to complete rapid authentication and group key distribution of any IoT device.

Benefits of technology

It realizes the rapid authentication of IoT devices and the rapid distribution of group keys. It is suitable for the fast and secure information exchange between IoT devices connected to the edge gateway in the power IoT, improves the authentication efficiency and flexibility, and can quickly respond to a large number of requests.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN119449309B_ABST
    Figure CN119449309B_ABST
Patent Text Reader

Abstract

The present invention discloses a multi-device key distribution method, system and device based on quantum random numbers, which belongs to the technical field of electric power Internet of Things. The present invention constructs an electric power Internet of Things control model, an edge key generation model, a device registration model, a device authentication model and a key distribution model, and registers the device using the quantum random number of the amplified spontaneous emission source based on the erbium-doped optical fiber, and uses the key information in the registration stage to complete the rapid authentication of any Internet of Things device, and then distributes the group key to the authenticated legal device, thereby realizing the rapid authentication of the Internet of Things device and the rapid distribution of the group key. Therefore, it is suitable for the rapid and secure information exchange between the Internet of Things devices connected to the edge gateway in the electric power Internet of Things, and the scheme is scientific, reasonable and feasible. Furthermore, the method of the present invention can be applied to scenarios where a large number of requests need to be processed quickly, which is conducive to the rapid distribution of the group key.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to a multi-device key distribution method, system and device based on quantum random numbers, and belongs to the technical field of power Internet of Things. Background Art

[0002] Driven by carbon reduction targets, the penetration rate of distributed energy in my country has steadily increased. New power grids, primarily based on distributed renewable energy, have introduced a large number of IoT nodes to collect data on distributed energy access, transmission, distribution, and end-user operations and energy usage. The interactive business instructions and information data generated during this collection process are mostly transmitted over wireless public networks, making this data vulnerable to physical attacks and tampering.

[0003] Furthermore, a Chinese patent application (publication number: CN110620820A) discloses a ubiquitous power Internet of Things (IoT) intelligent management system, comprising a device terminal and a management terminal; the device terminal is provided with an information collection module and an information transmission module; the information collection module is used to collect IoT data from the device terminal; the information transmission module is used to send the IoT data to each node in the blockchain network for legitimacy judgment. If the IoT data is legal, the IoT data is written to the management terminal and the blockchain respectively. By sending the IoT data to each node in the blockchain network for legitimacy judgment, and if the IoT data is legal, the IoT data is written to the management terminal and the blockchain respectively, data loss or change is prevented, and the traditional structured center model is prevented from paralyzing power grid data management and affecting people's normal lives if the terminal fails, thus ensuring the normal operation of the power grid.

[0004] The above method uses each node in the blockchain network to judge the legitimacy of IoT data, but IoT nodes have low processing and storage capabilities and usually have low-bandwidth communication channels. Therefore, the above node processing solution has a large node resource overhead, making it impossible for IoT nodes to respond quickly. Therefore, the above solution cannot be applied to scenarios that require rapid processing of a large number of requests, resulting in low user authentication efficiency and poor flexibility.

[0005] Furthermore, the existing technology cannot achieve rapid authentication of IoT devices, affects information exchange between IoT devices, and is not conducive to the rapid distribution of group keys.

[0006] The information disclosed in this Background Art is only for understanding the background of the present inventive concept and therefore it may include information that does not constitute prior art. Summary of the Invention

[0007] In response to the above problem or one of the above problems, the first purpose of the present invention is to provide a multi-device key distribution method based on quantum random numbers. By constructing a power Internet of Things control model, an edge key generation model, a device registration model, a device authentication model, and a key distribution model, the quantum random numbers of the amplified spontaneous emission source based on erbium-doped optical fiber are used to register the devices, and the key information in the registration stage is used to complete the rapid authentication of any Internet of Things device, and then group keys are distributed to the authenticated legitimate devices, thereby realizing rapid authentication of Internet of Things devices and rapid distribution of group keys. Therefore, it is suitable for fast and secure information exchange between Internet of Things devices connected to the edge gateway in the power Internet of Things. The solution is scientific, reasonable, and feasible.

[0008] In response to the above problem or one of the above problems, the second object of the present invention is to provide a multi-device key distribution method, system and device based on quantum random numbers, which makes the authentication of IoT devices efficient and flexible, and enables IoT nodes to respond quickly, and can be suitable for scenarios that need to quickly process a large number of requests; at the same time, it facilitates information exchange between IoT devices and is conducive to the rapid distribution of group keys.

[0009] To achieve one of the above purposes, the first technical solution of the present invention is:

[0010] A multi-device key distribution method based on quantum random numbers, comprising the following steps:

[0011] Step 1: Use the pre-built power IoT control model and the bilinear pairing mechanism to generate the edge key center KGC. i Configure the identity ID i ;

[0012] Step 2: After the identity configuration is completed, the pre-built edge key generation model is used to obtain the quantum random number of the erbium-doped fiber amplified spontaneous emission source based on the standard small form-factor pluggable field programmable gate array. The quantum random number is used as the private key, and the master public key is calculated based on the quantum random number.

[0013] Step 3: Use the pre-built device registration model and give a time limit T i , and according to the master public key, limit T i Complete one or more IoT devices D i At the edge key generation center KGC i registration;

[0014] Step 4: Use the pre-built device authentication model to authenticate the registered IoT device D i Conduct certification;

[0015] Step 5: Based on the pre-built key distribution model, the group key obtained based on the quantum random number is distributed to one or more IoT devices D that have successfully authenticated. i , realizing multi-device key generation based on quantum random numbers.

[0016] After continuous exploration and experimentation, the present invention constructs an electric power Internet of Things control model, an edge key generation model, a device registration model, a device authentication model, and a key distribution model. It uses quantum random numbers based on an amplified spontaneous emission source of erbium-doped optical fiber to register devices, and uses the key information in the registration stage to complete the rapid authentication of any Internet of Things device, and then distributes group keys to the authenticated legitimate devices, thereby realizing rapid authentication of Internet of Things devices and rapid distribution of group keys. Therefore, the present invention is suitable for rapid and secure information exchange between Internet of Things devices connected to the edge gateway in the electric power Internet of Things. The solution is scientific, reasonable, and feasible.

[0017] Furthermore, the method of the present invention can make IoT device authentication efficient and flexible, enable IoT nodes to respond quickly, and be applicable to scenarios that require rapid processing of a large number of requests; at the same time, it facilitates information exchange between IoT devices and is conducive to the rapid distribution of group keys.

[0018] As preferred technical measures:

[0019] Step 1: Use the pre-built power IoT control model and the bilinear pairing mechanism to generate the edge key center KGC. i Configure the identity ID i The method is as follows:

[0020] Step 11: Based on the bilinear pairing mechanism, select the bilinear pairing group (G1, G2, G T ), the expression of bilinear pairing is as follows:

[0021] G i ×G2→G1

[0022] Among them, G i , G2, G1 are three cyclic groups of order prime number N, G1 and G2 are additive groups, G T is a multiplicative group; the generator of G1 is P1, the generator of G2 is P2, and there exists a homomorphism ψ from G2 to G1 such that ψ(P2)=P1;

[0023] Step 12: Generate the center KGC for the edge key according to the expression of bilinear pairing i Configure the identity ID i ;

[0024] Step 13: Edge Key Generation Center KGC iGet the identity ID i After that, register your own ID with the power Internet of Things control center i .

[0025] As preferred technical measures:

[0026] Step 2: After the identity configuration is completed, the pre-built edge key generation model is used to obtain the quantum random number s from the erbium-doped fiber amplified spontaneous emission source based on a standard small form-factor pluggable field programmable gate array. The quantum random number s is used as the private key. The master public key is calculated based on the quantum random number s as follows:

[0027] Step 21: After the identity configuration is completed, the edge key generation center KGC i Receive feedback from the power Internet of Things control center;

[0028] Step 22: After receiving the information, the edge key generation center KGC i Using a standard small form-factor pluggable field programmable gate array, we can obtain the quantum random number s from an amplified spontaneous emission source based on an erbium-doped fiber.

[0029] Step 23: Use the quantum random number s as the private key; calculate the element P in the generator G2 based on the quantum random number s pub =[s]P1, and the element P pub As the master public key;

[0030] Step 24: Edge Key Generation Center KGC i Save the private key and public element P pub , that is, the master public key;

[0031] Step 25: Edge Key Generation Center KGC i Transmit the private key and master public key to the power Internet of Things control center.

[0032] As preferred technical measures:

[0033] In the third step, the method for obtaining the quantum random number of the amplified spontaneous emission source based on the erbium-doped fiber by using the standard small form-factor pluggable field programmable gate array (FPGA) using KGCi is as follows:

[0034] Step 31: Construct a randomness source based on a filtered amplified spontaneous emission source;

[0035] Step 32: The randomness source is connected to a small modular plug of the FPGA to form a standard small form-factor pluggable field programmable gate array.

[0036] Step 33: Using a field programmable gate array, obtain the quantum random number of the amplified spontaneous emission source based on the erbium-doped fiber.

[0037] As preferred technical measures:

[0038] Step 3: Use the pre-built device registration model and give a time limit T i , and according to the master public key, limit T i Complete one or more IoT devices D i At the edge key generation center KGC i The registration method is as follows:

[0039] Step 31: Give a time limit T i , IoT device D i To the edge key generation center KGC i Submit a registration request to the edge key generation center KGC i Choose a random number x and a hash function h1:{0,1} * , and based on IoT devices D i Address Calculate the public key The calculation formula is as follows:

[0040]

[0041] Among them, hid is the encryption private key generation function identifier;

[0042] Step 32, IoT device D i Register information Sent to the edge key generation center KGC through a secure channel i , Edge Key Generation Center KGC i Check the IoT device D i Is it within the time limit T i Already registered;

[0043] Step 33: If the device has been registered, ignore the information;

[0044] Step 34: If not registered, the edge key generation center KGC i For IoT devices i Calculate the private key The calculation formula is as follows:

[0045]

[0046] Then the private key And the time limit T i Send to IoT device D i ;

[0047] Step 35, IoT device Di receive The information is then fed back to the edge key generation center KGC i , complete IoT device D i register;

[0048] Step 36: For all key generation centers KGC at the edge i IoT terminals within the coverage area complete registration.

[0049] As preferred technical measures:

[0050] Step 4: Use the pre-built device authentication model to authenticate the registered IoT device D i Conduct certification;

[0051] Step 41: IoT Device D i Generate a random number y, based on the current time T1, calculate the key β i and key 2γ i , which is expressed as follows:

[0052]

[0053] Then the key β i and key 2γ i Sent to the edge key generation center KGC i ;

[0054] Step 42: Receive key β i and key 2γ i Then, the edge key generation center KGC i Based on the receiving time T2, the time difference ΔT is calculated, and the calculation formula is as follows:

[0055] ΔT=|T2-T1|

[0056] If ΔT is not within the permitted time, the IoT device cannot be authenticated and is an illegal node even if it has completed registration;

[0057] If ΔT is within the permitted time, the edge key generation center KGC i Calculate the new key 2 The calculation formula is as follows:

[0058]

[0059] Step 43: Verify the new key 2 With key 2 i Are they equal?

[0060] If they are equal, it means that the IoT device is a legitimate node, and the IoT device D is completed. i Certification;

[0061] If they are not equal, it means that the IoT device is an illegal node, and the IoT device D is terminated. i certification.

[0062] As preferred technical measures:

[0063] Step 5: Based on the pre-built key distribution model, the group key obtained based on the quantum random number is distributed to one or more IoT devices D that have successfully authenticated. i The method is as follows:

[0064] Step 51: Edge Key Generation Center KGC i At the current time T3, a quantum random number z is generated;

[0065] Step 52: Calculate the group key λ based on the quantum random number z i , which is calculated as follows:

[0066]

[0067] Step 53: Set the group key λ i Distributed to authenticated and legitimate IoT devices.

[0068] To achieve one of the above purposes, the second technical solution of the present invention is:

[0069] A multi-device key distribution method based on quantum random numbers, comprising the following steps:

[0070] The first step is to configure the identity IDs of multiple edge key generation centers (KGCs) in the power Internet of Things control center.

[0071] The edge key generation center KGCi uses a standard small form-factor pluggable field programmable gate array to obtain quantum random numbers from an amplified spontaneous emission source based on erbium-doped fiber;

[0072] The second step is that each edge key generation center KGC i Generate private keys and publish master public keys;

[0073] Step 3: IoT Terminal D i Based on quantum random numbers and its own properties, it completes the communication with the edge key generation center KGC i registration;

[0074] The fourth step is that any IoT device completes the key generation center KGC i Certification;

[0075] Step 5: Edge Key Generation Center KGC i Distribute group keys to authenticated legitimate IoT devices.

[0076] To achieve one of the above purposes, the third technical solution of the present invention is:

[0077] A multi-device key generation system based on quantum random numbers, which includes at least one power Internet of Things control center, one or more edge key centers and several Internet of Things devices;

[0078] The power Internet of Things control center is used to configure identity IDs for one or more edge key generation centers (KGCs);

[0079] The edge key center is used to obtain quantum random numbers, store its own private keys, complete the registration of IoT devices, and verify whether the IoT devices are legitimate nodes;

[0080] IoT devices complete registration and authentication based on the quantum random number generator and its own properties, and according to the public key of the edge key center, and then obtain the group key and communicate securely between multiple IoT devices.

[0081] To achieve one of the above purposes, the fourth technical solution of the present invention is:

[0082] An electronic device comprising:

[0083] one or more processors;

[0084] a storage device for storing one or more programs;

[0085] When the one or more programs are executed by the one or more processors, the one or more processors implement the above-mentioned multi-device key distribution method based on quantum random numbers.

[0086] Compared with the existing technical solutions, the present invention has the following beneficial effects:

[0087] After continuous exploration and experimentation, the present invention constructs an electric power Internet of Things control model, an edge key generation model, a device registration model, a device authentication model, and a key distribution model. It uses quantum random numbers based on an amplified spontaneous emission source of erbium-doped optical fiber to register devices, and uses the key information in the registration stage to complete the rapid authentication of any Internet of Things device, and then distributes group keys to the authenticated legitimate devices, thereby realizing rapid authentication of Internet of Things devices and rapid distribution of group keys. Therefore, the present invention is suitable for rapid and secure information exchange between Internet of Things devices connected to the edge gateway in the electric power Internet of Things. The solution is scientific, reasonable, and feasible.

[0088] Furthermore, the method of the present invention can make IoT device authentication efficient and flexible, enable IoT nodes to respond quickly, and be applicable to scenarios that require rapid processing of a large number of requests; at the same time, it facilitates information exchange between IoT devices and is conducive to the rapid distribution of group keys. BRIEF DESCRIPTION OF THE DRAWINGS

[0089] Figure 1 This is a first schematic diagram of the multi-device key distribution method of the present invention;

[0090] Figure 2 This is a second schematic diagram of the multi-device key distribution method of the present invention. DETAILED DESCRIPTION

[0091] In order to make the purpose, technical solutions and advantages of the present invention more clearly understood, the present invention will be further described in detail below with reference to the accompanying drawings and embodiments. It should be understood that the specific embodiments described herein are only used to explain the present invention and are not intended to limit the present invention.

[0092] Rather, the present invention encompasses any alternatives, modifications, equivalents, and solutions that fall within the spirit and scope of the present invention as defined by the claims. Furthermore, to facilitate a better understanding of the present invention, certain specific details are described in detail below in the detailed description of the present invention. Those skilled in the art will be able to fully understand the present invention without these details.

[0093] Unless otherwise defined, all technical and scientific terms used herein have the same meaning as commonly understood by one skilled in the art to which this invention pertains. The terms used herein are for the purpose of describing specific embodiments only and are not intended to limit the present invention. As used herein, the term "or / and" includes any and all combinations of one or more of the associated listed items.

[0094] like Figure 1 As shown, the first specific embodiment of the multi-device key distribution method based on quantum random numbers of the present invention is as follows:

[0095] A multi-device key distribution method based on quantum random numbers, comprising the following steps:

[0096] Step 1: Use the pre-built power IoT control model and the bilinear pairing mechanism to generate the edge key center KGC. i Configure the identity ID i ;

[0097] Step 2: After the identity configuration is completed, the pre-built edge key generation model is used to obtain the quantum random number of the erbium-doped fiber amplified spontaneous emission source based on the standard small form-factor pluggable field programmable gate array. The quantum random number is used as the private key, and the master public key is calculated based on the quantum random number.

[0098] Step 3: Use the pre-built device registration model and give a time limit T i , and according to the master public key, limit T i Complete one or more IoT devices D i At the edge key generation center KGC i registration;

[0099] Step 4: Use the pre-built device authentication model to authenticate the registered IoT device D i Conduct certification;

[0100] Step 5: Based on the pre-built key distribution model, the group key obtained based on the quantum random number is distributed to one or more IoT devices D that have successfully authenticated. i , realizing multi-device key generation based on quantum random numbers.

[0101] like Figure 2 As shown, the second specific embodiment of the multi-device key distribution method based on quantum random numbers of the present invention is as follows:

[0102] A multi-device key distribution method based on quantum random numbers, comprising the following steps:

[0103] The first step is to configure the respective IDs for multiple edge key generation centers (KGC) in the power Internet of Things control center. i Using a standard small form-factor pluggable field programmable gate array to obtain quantum random numbers from an erbium-doped fiber-based amplified spontaneous emission source;

[0104] The second step is that each KGC i Generate private keys and publish master public keys;

[0105] Step 3: IoT Terminal D i Based on quantum random numbers and its own properties, it completes the communication with the KGC to which it belongs. i registration;

[0106] Step 4: Any IoT device completes the communication with KGC i Certification;

[0107] Step 5, KGC i Distribute group keys to authenticated legitimate IoT devices.

[0108] The present invention constructs an edge key generation center model for IoT devices, a quantum random number generation model, a device registration process, a device authentication process, and an edge group key generation algorithm. IoT devices are connected to an edge key generation center based on their geographic locations. A standard small form-factor pluggable field programmable gate array is used to obtain quantum random numbers from an amplified spontaneous emission source based on an erbium-doped fiber to complete IoT device registration. The edge key center authenticates the IoT devices, and group keys are distributed to devices after identity authentication. Devices are registered using random numbers generated by the quantum random number generation model, and key information from the registration phase is used to authenticate any IoT device. Group keys are distributed to authenticated legitimate devices. IoT devices can quickly authenticate and obtain group keys. The present invention is suitable for fast and secure information exchange between authenticated IoT devices connected to edge gateways in the power IoT. The solution is scientific, reasonable, and feasible.

[0109] In this embodiment: In the first step, the power Internet of Things control center configures multiple edge key generation centers (KGC) with their own IDs. Each KGC i The method for publishing the master public key and sending registration information to the control center is as follows:

[0110] Step 11: Select the bilinear pairing group (G1, G2, G T ), P1, P2 are the generators of the first two groups, and the bilinear pairing is expressed as e:G1×G2→G T , and generate a key generation center (KGC) for each edge i Configure their respective IDs i .

[0111] Step 12: The randomness source is based on a filtered amplified spontaneous emission source followed by a small modular plug connected to the FPGA;

[0112] Step 13: Using a standard small form-factor pluggable field programmable gate array (FPGA), obtain the quantum random number of the erbium-doped fiber-based amplified spontaneous emission source;

[0113] In this embodiment: In the second step, each KGC i Generate a private key and publish the master public key as follows:

[0114] Step 21: KGC i After receiving the information from the control center, a standard small form-factor pluggable field programmable gate array is used to obtain the quantum random number s of the amplified spontaneous emission source based on the erbium-doped fiber as the private key;

[0115] Step 22: Calculate the element P in G2 pub =[s]P1 as the master public key, and publish its own master public key P pub .

[0116] In this embodiment: in the third step, the Internet of Things terminal D i Based on quantum random numbers and its own properties, it completes the communication with the KGC to which it belongs. i The registration method is as follows:

[0117] Step 31: Given a time limit T i , within a limited time, any IoT device D i KGC i D i To KGC i Submit a registration request;

[0118] Step 32: KGC i Choose a random number x and a hash function h1:{0,1} * , based on D i Address Calculate the public key

[0119] Step 33: D i Register information Send to KGC via secure channel i , KGC i Check if the device is in T i Registered within the time period;

[0120] Step 34: If the device has already been registered, ignore this information;

[0121] Step 35: If not registered, KGC i D i Calculate the private key Then the private key information and T i Send to D i ;

[0122] Step 36: D i receive Feedback to KGC after the information i , complete D i register;

[0123] Step 37: For all in KGC i IoT terminals within the coverage area complete registration.

[0124] In this embodiment: In the fourth step, any IoT device D i Completed with KGC i The authentication method is as follows:

[0125] Step 41: D i Generate a random number y, based on the current time T1, calculate Then send this information to KGC i ;

[0126] Step 42: After receiving the information, KGC i At its receiving time T2, if |T2-T1| is not within the permitted time, the device cannot be authenticated and is an illegal node even if it has completed registration;

[0127] Step 43: If |T2-T1| is within the permitted time, KGC i calculate verify If they are equal, the verification device is a legitimate node;

[0128] Step 44: Otherwise, the device is an illegal node.

[0129] In this embodiment: in the fifth step, KGC i The method for distributing group keys to authenticated legitimate IoT devices is as follows:

[0130] Step 51: KGC i At the current time T3, a random number z is generated;

[0131] Step 52: Calculate the group key Distributed to authenticated legitimate devices.

[0132] A system embodiment of the multi-device key distribution method based on quantum random numbers of the present invention is applied:

[0133] A multi-device key distribution system based on quantum random numbers includes Internet of Things devices, an edge key center, and an electric power Internet of Things control center.

[0134] IoT devices complete registration based on the public key of the edge key center, using a quantum random number generator and their own properties. The edge key center is responsible for storing its own private key, completing IoT device registration, and verifying whether the IoT device is a legitimate node. The random numbers generated by the edge key center are truly random and tamper-resistant. IoT devices can quickly authenticate, obtain group keys, and communicate securely across multiple devices.

[0135] An embodiment of a device applying the method of the present invention:

[0136] An electronic device comprising:

[0137] one or more processors;

[0138] a storage device for storing one or more programs;

[0139] When the one or more programs are executed by the one or more processors, the one or more processors implement the above-mentioned multi-device key distribution method based on quantum random numbers.

[0140] A computer medium embodiment of the method of the present invention:

[0141] A computer-readable storage medium stores a computer program, which, when executed by a processor, implements the above-mentioned multi-device key distribution method based on quantum random numbers.

[0142] Those skilled in the art will appreciate that the embodiments of the present application may be provided as methods, systems, and computer program products. Therefore, the present application may take the form of a complete hardware embodiment, a complete software embodiment, or an embodiment combining software and hardware. Furthermore, the present application may take the form of a computer program product implemented on one or more computer-usable storage media (including but not limited to magnetic disk storage, optical storage, etc.) containing computer-usable program code.

[0143] The present application is described in terms of flowcharts or / and block diagrams of the methods, devices (systems), and computer program products according to the embodiments of the present application. It should be understood that each process or / and block in the flowchart or / and block diagram and the combination of the processes or / and blocks in the flowchart or / and block diagram can be implemented by computer program instructions. These computer program instructions can be provided to a processor of a general-purpose computer, a special-purpose computer, an embedded processor, or other programmable data processing device to generate a machine, so that the instructions executed by the processor of the computer or other programmable data processing device generate instructions for implementing the steps in the process. Figure 1 a process or multiple processes and / or boxes Figure 1 A device that provides the functions specified in a block or multiple blocks.

[0144] These computer program instructions may also be stored in a computer readable memory that can direct a computer or other programmable data processing device to work in a specific manner, so that the instructions stored in the computer readable memory produce an article of manufacture comprising an instruction device, which implements the process Figure 1 a process or multiple processes and / or boxes Figure 1 The function specified in one or more boxes.

[0145] These computer program instructions can also be loaded onto a computer or other programmable data processing device so that a series of operational steps are executed on the computer or other programmable device to produce a computer-implemented process, thereby providing the instructions executed on the computer or other programmable device for implementing the process. Figure 1a process or multiple processes and / or boxes Figure 1 A step that specifies a function in one or more boxes.

[0146] The model in this application is an object that objectively describes the morphological structure with the help of physical or virtual representation. The object is not equal to the physical body and is not limited to physical and virtual. It can be a data processing function, software program, processing mode, usage method, operation method, workflow, application process, electronic hardware, circuit module, processing system, system imitation or simulation object.

[0147] Finally, it should be noted that the above embodiments are only used to illustrate the technical solutions of the present invention rather than to limit it. Although the present invention has been described in detail with reference to the above embodiments, ordinary technicians in the field can still modify or replace the specific implementation methods of the present invention. Any modification or equivalent replacement that does not depart from the spirit and scope of the present invention should be included in the scope of protection of the claims of the present invention.

Claims

1. A multi-device key distribution method based on quantum random numbers, characterized by: The following steps are involved: Step 1: Use the pre-built power IoT control model and the bilinear pairing mechanism to generate the edge key center KGC. i Configure the identity ID i ; Step 2: After the identity configuration is completed, the pre-built edge key generation model is used to obtain the quantum random number of the erbium-doped fiber amplified spontaneous emission source based on the standard small form-factor pluggable field programmable gate array. The quantum random number is used as the private key, and the master public key is calculated based on the quantum random number. Step 3: Use the pre-built device registration model and give a time limit T i , and according to the master public key, limit T i Complete one or more IoT devices within D i At the edge key generation center KGC i registration; Step 4: Use the pre-built device authentication model to authenticate the registered IoT device D i Conduct certification; Step 5: Based on the pre-built key distribution model, the group key obtained based on the quantum random number is distributed to one or more IoT devices D that have successfully authenticated. i , realizing multi-device key generation based on quantum random numbers.

2. A multi-device key distribution method based on quantum random numbers according to claim 1, characterized in that: Step 1: Use the pre-built power IoT control model and the bilinear pairing mechanism to generate the edge key center KGC. i Configure the identity ID i The method is as follows: Step 11: Based on the bilinear pairing mechanism, select the bilinear pairing group (G1, G2, G T ), the expression of bilinear pairing is as follows: G1×G2→G T Among them, G1, G2, G T There are three cyclic groups of order N, G1 and G2 are additive groups, G T is a multiplicative group; the generator of G1 is P1, the generator of G2 is P2, and there exists a homomorphism ψ from G2 to G1 such that ψ(P2)=P1; Step 12: Generate the center KGC for the edge key according to the expression of bilinear pairing i Configure the identity ID i ; Step 13: Edge Key Generation Center KGC i Get the identity ID i After that, register your own ID with the power Internet of Things control center i .

3. The multi-device key distribution method based on quantum random numbers according to claim 2, characterized in that: Step 2: After the identity configuration is completed, the pre-built edge key generation model is used to obtain the quantum random number s from the erbium-doped fiber amplified spontaneous emission source based on a standard small form-factor pluggable field programmable gate array. The quantum random number s is used as the private key. The master public key is calculated based on the quantum random number s as follows: Step 21: After the identity configuration is completed, the edge key generation center KGC i Receive feedback from the power Internet of Things control center; Step 22: After receiving the information, the edge key generation center KGC i Using a standard small form-factor pluggable field programmable gate array, we can obtain the quantum random number s from an amplified spontaneous emission source based on an erbium-doped fiber. Step 23: Use the quantum random number s as the private key; calculate the element P in the generator G2 based on the quantum random number s pub =[s]P1, and the element P pub As the master public key; Step 24: Edge Key Generation Center KGC i Save the private key and public element P pub , that is, the master public key; Step 25: Edge Key Generation Center KGC i Transmit the private key and master public key to the power Internet of Things control center.

4. A multi-device key distribution method based on quantum random numbers according to claim 3, characterized in that: In the third step, the method for obtaining the quantum random number of the amplified spontaneous emission source based on the erbium-doped fiber by using the standard small form-factor pluggable field programmable gate array (FPGA) using KGCi is as follows: Step 31: Construct a randomness source based on a filtered amplified spontaneous emission source; Step 32: The randomness source is connected to a small modular plug of the FPGA to form a standard small form-factor pluggable field programmable gate array. Step 33: Using a field programmable gate array, obtain the quantum random number of the amplified spontaneous emission source based on the erbium-doped fiber.

5. The multi-device key distribution method based on quantum random numbers according to claim 4, characterized in that: Step 3: Use the pre-built device registration model and give a time limit T i , and according to the master public key, limit T i Complete one or more IoT devices within D i At the edge key generation center KGC i The registration method is as follows: Step 31: Give a time limit T i , IoT device D i To the edge key generation center KGC i Submit a registration request to the edge key generation center KGC i Choose a random number x and a hash function h1:{0,1} * , and based on IoT devices D i Address Calculate the public key The calculation formula is as follows: Among them, hid is the encryption private key generation function identifier; Step 32, IoT device D i Register information Sent to the edge key generation center KGC through a secure channel i , Edge Key Generation Center KGC i Check the IoT device D i Is it within the time limit T i Already registered; Step 33: If the device has been registered, ignore the information; Step 34: If not registered, the edge key generation center KGC i For IoT devices i Calculate the private key The calculation formula is as follows: Then the private key And the time limit T i Send to IoT device D i ; Step 35, IoT device D i receive The information is then fed back to the edge key generation center KGC i , complete IoT device D i register; Step 36: For all key generation centers KGC at the edge i IoT terminals within the coverage area complete registration.

6. A multi-device key distribution method based on quantum random numbers according to claim 5, characterized in that: Step 4: Use the pre-built device authentication model to authenticate the registered IoT device D i Conduct certification; Step 41: IoT Device D i Generate a random number y, based on the current time T1, calculate the key β i and key 2γ i , which is expressed as follows: Then the key β i and key 2γ i Sent to the edge key generation center KGC i ; Step 42: Receive key β i and key 2γ i Then, the edge key generation center KGC i Based on the receiving time T2, the time difference ΔT is calculated, and the calculation formula is as follows: ΔT=|T2-T1| If ΔT is not within the permitted time, the IoT device cannot be authenticated and is an illegal node even if it has completed registration; If ΔT is within the permitted time, the edge key generation center KGC i Calculate the new key 2 The calculation formula is as follows: Step 43: Verify the new key 2 With key 2 i Are they equal? If they are equal, it means that the IoT device is a legitimate node, and the IoT device D is completed. i Certification; If they are not equal, it means that the IoT device is an illegal node, and the IoT device D is terminated. i certification.

7. The multi-device key distribution method based on quantum random numbers according to claim 6, characterized in that: Step 5: Based on the pre-built key distribution model, the group key obtained based on the quantum random number is distributed to one or more IoT devices D that have successfully authenticated. i The method is as follows: Step 51: Edge Key Generation Center KGC i At the current time T3, a quantum random number z is generated; Step 52: Calculate the group key λ based on the quantum random number z i , which is calculated as follows: Step 53: Set the group key λ i Distributed to authenticated and legitimate IoT devices.

8. A multi-device key distribution method based on quantum random numbers, characterized by: The following steps are involved: The first step is to configure the identity IDs of multiple edge key generation centers (KGCs) in the power Internet of Things control center. The edge key generation center KGCi uses a standard small form-factor pluggable field programmable gate array to obtain quantum random numbers from an amplified spontaneous emission source based on erbium-doped fiber; The second step is that each edge key generation center KGC i Generate private keys and publish master public keys; Step 3: IoT Terminal D i Based on quantum random numbers and its own properties, it completes the communication with the edge key generation center KGC i registration; The fourth step is that any IoT device completes the key generation center KGC i Certification; Step 5: Edge Key Generation Center KGC i Distribute group keys to authenticated legitimate IoT devices.

9. A multi-device key generation system based on quantum random numbers, characterized by: It includes at least one power Internet of Things control center, one or more edge key centers and several Internet of Things devices; The power Internet of Things control center is used to configure identity IDs for one or more edge key generation centers (KGCs); The edge key center is used to obtain quantum random numbers, store its own private keys, complete the registration of IoT devices, and verify whether the IoT devices are legitimate nodes; IoT devices complete registration and authentication based on the quantum random number generator and its own properties, and according to the public key of the edge key center, and then obtain the group key and communicate securely between multiple IoT devices.

10. An electronic device, characterized in that: It includes: one or more processors; a storage device for storing one or more programs; When the one or more programs are executed by the one or more processors, the one or more processors implement the multi-device key distribution method based on quantum random numbers as described in any one of claims 1 to 8.

Citation Information

Patent Citations

  • Ubiquitous power Internet of Things intelligent management system

    CN110620820A

  • Data judgment method and device and storage medium

    CN114785501A

  • Lightweight authentication method supporting anonymous access of heterogeneous terminal in edge computing scenario

    WO2020133655A1