A network system with global quantum security protection

By introducing a network system with global quantum security protection into the network system and using quantum security servers and key centers for data encryption and decryption, the security risks of data backup and client access in the existing network management system are resolved, achieving the effects of improved security and reduced costs.

CN119449437BActive Publication Date: 2025-09-23MATRICTIME DIGITAL TECH CO LTD
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202411612575.9
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2024-11-13
Publication Date
2025-09-23
Estimated Expiration
2044-11-13

AI Technical Summary

Technical Problem

Existing network management systems have security risks in data backup and client access, especially on multiplexed lines. It is difficult to improve security while maintaining the existing network architecture and user operating habits. Existing security service systems based on quantum principles also face challenges in integration and key management.

Method used

A network system with full-area quantum security protection, including provincial centers, municipal client systems and backup centers, uses quantum security servers, access base stations and key centers to encrypt and decrypt data, ensures data transmission security through quantum encryption technology, and integrates the quantum security service system without changing the original networking relationship and routing configuration.

Benefits of technology

It improves the security of data transmission and business processing efficiency, reduces network construction and operation and maintenance costs, achieves stability and reliability of data backup, and simplifies the key management process.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN119449437B_ABST
    Figure CN119449437B_ABST
Patent Text Reader

Abstract

The present invention relates to the field of information security technology, and specifically to a network system with global quantum security protection. The solution of the present application realizes quantum encryption and decryption processing of business data by adopting a quantum security service system, including a quantum security server, an access base station and a key center, effectively improving the security of data transmission, preventing data leakage and tampering, and ensuring the information security of the network system. As the main computer room, the provincial center is responsible for receiving and managing data reports from gateway network elements in various cities and prefectures, while the backup center receives data backups from the provincial center and uses dedicated data backup lines and multiplexed lines to ensure the stability and reliability of data backups. The client systems in various cities and prefectures can access the network management system of the provincial center through remote browsing, which facilitates business interaction between the client and the provincial center and improves business processing efficiency.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the field of information security technology, and in particular to a network system with global quantum security protection. Background Art

[0002] In today's information age, network security is crucial for protecting sensitive information and maintaining stable system operations. As cyberattacks become increasingly sophisticated and the limitations of traditional encryption technologies become increasingly apparent, the need for more secure communication methods has become urgent. Against this backdrop, encryption technology based on the principles of quantum mechanics has emerged, providing a theoretically unbreakable communication method.

[0003] Existing network management systems generally adopt a centralized architecture, with provincial centers serving as the main server room, responsible for receiving and managing data from gateway network elements in various municipalities. Furthermore, to ensure data integrity and system continuity, backup centers are typically deployed. However, existing data backup transmission lines, whether dedicated or multiplexed, present certain security risks. In particular, on multiplexed lines, the combined use of data backup and client access can increase the risk of data leakage.

[0004] Local client systems typically access the provincial network management system through remote browsing. This access method may not be sufficient to protect against advanced network attacks using traditional encryption technology. Therefore, improving network security while maintaining the existing network architecture and user operating habits has become a technical challenge.

[0005] While some quantum-based security service systems have been proposed, they still face challenges in integrating them into existing network management systems and implementing efficient data encryption and key management. In particular, implementing efficient and secure communication within existing network infrastructure while simplifying key management remains a pressing challenge in network security. Summary of the Invention

[0006] To solve the above problems, this application discloses a network system with global quantum security protection, including a provincial center, a prefecture-level client system, and a backup center;

[0007] The provincial center serves as the main computer room, receiving and managing data reports from gateway network elements in prefectures and cities.

[0008] The backup center is used to receive data backup from the provincial center. The data backup transmission lines include: dedicated data backup lines and multiplexed lines; the multiplexed lines are used for data backup and client access.

[0009] The client systems of various cities access the network management system of the provincial center through remote browsing;

[0010] The network management system of the provincial center includes a network server and a quantum security service system. The quantum security service system includes: a quantum security server, an access base station and a key center. The quantum security server is respectively communicated with the access base station and the key center. The network server is connected to the quantum security server, and business data is transmitted between the client and the network server through the quantum security server. Quantum encryption and decryption processing is provided for business service data, and the quantum keys used for encryption and decryption are managed.

[0011] The quantum security service system is connected to the access switch via a communication agent;

[0012] The quantum security server of the quantum security service system corresponds to multiple network servers; each of the network servers is connected to the quantum security server through an independent network card; and the quantum security server is connected to each network port IP of the corresponding network server to serve as a network server gateway; the communication agent is connected to each network port IP of the access switch as the address of the corresponding network server;

[0013] The quantum security server further includes an isolation module, which is used for data filtering. Non-network management clients, backup data, and municipal gateway network element data are not subject to quantum security protection and are directly released.

[0014] The provincial center includes at least two quantum security service systems, and the quantum security servers in each quantum security service system are connected to the core switch through a communication proxy and a firewall. The quantum security servers in the two quantum security service systems have a master-slave relationship with each other, and the quantum security servers in the two quantum security service systems synchronize quantum keys in real time.

[0015] The network port of the access switch connected to the quantum security server serves as the gateway of the access switch, and the network port of the core switch connected to the communication agent serves as the gateway of the core switch, so as not to change the original networking relationship, routing configuration and firewall policy.

[0016] The backup center includes a first computer room and a second computer room, wherein the first computer room is connected to the main computer room of the provincial center through a dedicated communication line; the second computer room is connected to the client system of the prefecture-level city through a multiplex line;

[0017] The backup network servers in the first and second computer rooms are connected to the quantum security server in the backup center, and the quantum security server is connected to the access switch between the main computer rooms through a communication proxy;

[0018] The quantum security server of the backup center, the key center of the main computer room, and the access base station constitute a quantum security service system; the supplementary quantum key is obtained through the key center of the provincial center, and the quantum key is relayed through the access base station of the provincial center.

[0019] The backup center includes a first computer room and a second computer room, wherein the first computer room is connected to the main computer room of the provincial center through a dedicated communication line; the second computer room is connected to the client system of the prefecture-level city through a multiplex line;

[0020] The backup network servers in the first and second computer rooms are connected to the quantum security server in the backup center. The quantum security server is connected to the core switch through a communication proxy and a firewall. The backup management server is connected to the quantum security server via an access switch.

[0021] The quantum security server of the backup center, the key center of the main computer room, and the access base station constitute a quantum security service system; the supplementary quantum key is obtained through the key center of the provincial center, and the quantum key is relayed through the access base station of the provincial center;

[0022] The access switch network port connected to the quantum security server serves as the gateway of the access switch, and the network port connected to the core switch by the communication agent serves as the gateway of the core switch, thereby ensuring that the original networking relationship, routing configuration and firewall policy are not changed.

[0023] The local client system includes a quantum security all-in-one machine, a quantum security encryption box or a quantum security server.

[0024] The quantum-safe all-in-one machine, also known as the quantum-safe privacy computer, directly provides users with a quantum-encrypted privacy environment, where they can directly access the network management system via quantum-safe encryption. Access to the privacy computer via an existing computer allows for non-secure network access. The privacy computer also comes with a built-in KVM switching function, allowing users to freely switch between the privacy environment and their existing computer.

[0025] The quantum-safe encryption box is connected to the existing terminal in an external manner. All data accessed by the user terminal through the encryption box will be quantum-safely encrypted before being sent out. The user's office environment is still the same terminal device, and the data communicated by the existing network management client is encrypted and protected by the quantum-safe encryption box.

[0026] Quantum security servers can be used to provide quantum security encryption protection for high-volume secure access requirements. Their functions are similar to those of quantum security boxes when used on terminals.

[0027] The solution of this application realizes quantum encryption and decryption processing of business data by adopting a quantum security service system, including a quantum security server, an access base station and a key center, effectively improving the security of data transmission, preventing data leakage and tampering, and ensuring the information security of the network system. The provincial center serves as the main computer room, responsible for receiving and managing data reports from gateway network elements in various cities and prefectures, while the backup center receives data backups from the provincial center and uses dedicated data backup lines and multiplexed lines to ensure the stability and reliability of data backups. Client systems in various cities can access the network management system of the provincial center through remote browsing, which facilitates business interaction between the client and the provincial center and improves business processing efficiency. The multiplexed line is used for both data backup and client access, realizing the rational use of line resources and reducing network construction and operation and maintenance costs. BRIEF DESCRIPTION OF THE DRAWINGS

[0028] Figure 1 This is a schematic diagram of the structure of a provincial center in an embodiment of the present application;

[0029] Figure 2 This is a schematic diagram of the structure of another provincial center in the embodiment of this application;

[0030] Figure 3 This is a schematic diagram of the structure of a backup center in an embodiment of the present application;

[0031] Figure 4 This is a structural diagram of another backup center in an embodiment of the present application. DETAILED DESCRIPTION

[0032] To make the objectives, technical solutions, and advantages of this application more clear, this application will be further described in detail below with reference to the accompanying drawings. Obviously, the embodiments described are only part of the embodiments of this application, not all of them. All other embodiments obtained by ordinary technicians in this field based on the embodiments of this application without making any creative efforts are within the scope of protection of this application.

[0033] Example: Figure 1-4 As shown, a network system with global quantum security protection includes a provincial center, a prefecture-level client system, and a backup center.

[0034] The provincial center serves as the main computer room, receiving and managing data reports from gateway network elements in cities and prefectures. Specifically, it serves as the core management node, responsible for collecting, processing, and storing data from gateway network elements in cities and prefectures, and conducting centralized monitoring and management.

[0035] The backup center receives data backups from provincial centers. Data backup transmission lines include dedicated data backup lines and multiplexed lines; the multiplexed lines are used for data backup and client access. The backup center ensures data security and receives data backups from provincial centers, enabling rapid recovery in the event of a provincial center failure.

[0036] Composition: includes backup servers, storage devices, backup lines, etc.

[0037] The client systems of various cities access the network management system of the provincial center through remote browsing;

[0038] The municipal client system is responsible for reporting data to the local gateway network element and accessing the provincial center's network management system through remote browsing to perform data query and operation. Specifically, it includes client computers, gateway devices, local databases, etc.

[0039] The network management system of the provincial center includes a network server and a quantum security service system. The quantum security service system includes: a quantum security server, an access base station and a key center. The quantum security server is respectively communicated with the access base station and the key center. The network server is connected to the quantum security server, and business data is transmitted between the client and the network server through the quantum security server. Quantum encryption and decryption processing is provided for business service data, and the quantum keys used for encryption and decryption are managed.

[0040] Among them, the dedicated data backup line is used to transmit data backup from the provincial center to the backup center to ensure the real-time and security of data transmission.

[0041] Multiplexing lines: Used for both data backup and client access. They can be used for client access outside of the backup period, improving line utilization.

[0042] In this embodiment, the key center generates a quantum random number key through a quantum true random number generator; when encrypting, data can be encrypted using methods such as XOR or AES.

[0043] The specific process includes:

[0044] The municipal gateway network element reports the data to the provincial central network server;

[0045] The provincial central network server transmits the data to the quantum security server;

[0046] The quantum security server performs quantum encryption on the data and transmits it to the client;

[0047] The client uses the quantum key to decrypt the encrypted data and obtain the original data.

[0048] By leveraging quantum encryption technology, data transmission security can be ensured. Provincial centers are responsible for data management of gateway network elements in prefectures and cities, improving operational efficiency. Backup centers utilize dedicated and multiplexed lines to ensure real-time data backup and high line utilization. Prefectural and city client systems can easily access the quantum security service system, enabling quantum encrypted communication.

[0049] In one possible implementation, the quantum security service system is connected to an access switch via a communication agent;

[0050] The quantum security server of the quantum security service system corresponds to multiple network servers; each of the network servers is connected to the quantum security server through an independent network card; and the quantum security server is connected to each network port IP of the corresponding network server to serve as a network server gateway; the communication agent is connected to each network port IP of the access switch as the address of the corresponding network server;

[0051] The quantum security server further includes an isolation module, which is used for data filtering. Non-network management clients, backup data, and municipal gateway network element data are not subject to quantum security protection and are directly released.

[0052] The communication proxy acts as a bridge between the quantum security server and the access switch, responsible for forwarding and receiving data packets. The communication proxy connects to each network port on the access switch, which uses the IP address of the corresponding network server. The access switch can then correctly forward data to the corresponding network server.

[0053] The quantum security service system is connected to the access switch through a communication agent, which can realize data exchange between the quantum security server and the network server.

[0054] The access switch is responsible for forwarding data from the network server to the quantum security server, and forwarding data from the quantum security server to the network server.

[0055] A quantum secure server corresponds to multiple network servers, meaning one quantum secure server can serve multiple network servers. Each network server connects to the quantum secure server via a separate network card, ensuring the independence and security of data transmission. The quantum secure server connects to the network IP address of each network server and acts as the gateway for the network servers. All data entering and leaving the network servers must be routed through the quantum secure server.

[0056] The isolation module filters data and determines whether to apply quantum security protection based on its source and type. For data from non-network management clients, backup data, and network element data from prefecture-level gateways, the isolation module bypasses quantum security protection and allows it to pass directly. This data may not require quantum-level security, so allowing it directly saves resources and improves data processing efficiency. Some data may need to be transmitted in plaintext or use traditional encryption methods; the isolation module allows this data to be processed in its original form.

[0057] Through the above solution, the quantum security service system achieves the following advantages:

[0058] Through communication proxies and access switches, efficient communication between the quantum security server and multiple network servers is achieved. The quantum security server acts as a gateway for the network servers, ensuring the security of data transmission. The isolation module allows the system to select appropriate security policies based on data type and source, ensuring both security and flexibility.

[0059] Correspondingly, the backup center includes a first computer room and a second computer room, wherein the first computer room is connected to the main computer room of the provincial center via a dedicated communication line; the second computer room is connected to the prefecture-level client system via a multiplex line;

[0060] The backup network servers in the first and second computer rooms are connected to the quantum security server in the backup center, and the quantum security server is connected to the access switch between the main computer rooms through a communication proxy;

[0061] The quantum security server of the backup center, the key center of the main computer room, and the access base station constitute a quantum security service system; the supplementary quantum key is obtained through the key center of the provincial center, and the quantum key is relayed through the access base station of the provincial center.

[0062] In another possible implementation, the provincial center includes at least two quantum security service systems, wherein the quantum security server in each quantum security service system is connected to the core switch via a communication proxy and a firewall; the quantum security servers in the two quantum security service systems have a master-slave relationship with each other, and the quantum security servers in the two quantum security service systems synchronize quantum keys in real time;

[0063] The network port of the access switch connected to the quantum security server serves as the gateway of the access switch, and the network port of the core switch connected to the communication agent serves as the gateway of the core switch, so as not to change the original networking relationship, routing configuration and firewall policy.

[0064] The provincial centers will include at least two quantum security service systems to improve system reliability and availability. The quantum security servers are connected to the core switch via a communication proxy and firewall. This connection ensures the security and stability of data during transmission.

[0065] The communication agent is responsible for forwarding data packets between the quantum security server and the core switch.

[0066] Firewalls are used to protect quantum secure servers from unauthorized access and attacks.

[0067] The quantum security servers in the two quantum security service systems are in a master-backup relationship with each other, that is, one server runs as the main server and the other as the backup server.

[0068] The quantum keys are synchronized in real time between the two sets of quantum security servers to ensure that when the main server fails, the backup server can take over immediately without affecting the continuity and security of encrypted communications.

[0069] The network port of the access switch connected to the quantum security server acts as the gateway of the access switch. All data entering and leaving the access switch must pass through the quantum security server. The network port of the communication proxy connected to the core switch acts as the gateway of the core switch, so that the core switch can correctly forward data to the quantum security server.

[0070] Through this gateway setup, the system seamlessly integrates quantum security services without changing existing network relationships, routing configurations, and firewall policies. This helps reduce deployment complexity and potential risks while ensuring stable network operation.

[0071] The backup center includes a first computer room and a second computer room, wherein the first computer room is connected to the main computer room of the provincial center through a dedicated communication line; the second computer room is connected to the client system of the prefecture-level city through a multiplex line;

[0072] The backup network servers in the first and second computer rooms are connected to the quantum security server in the backup center. The quantum security server is connected to the core switch through a communication proxy and a firewall. The backup management server is connected to the quantum security server via an access switch.

[0073] The quantum security server of the backup center, the key center of the main computer room, and the access base station constitute a quantum security service system; the supplementary quantum key is obtained through the key center of the provincial center, and the quantum key is relayed through the access base station of the provincial center;

[0074] The access switch network port connected to the quantum security server serves as the gateway of the access switch, and the network port connected to the core switch by the communication agent serves as the gateway of the core switch, thereby ensuring that the original networking relationship, routing configuration and firewall policy are not changed.

[0075] The local client system includes a quantum security all-in-one machine, a quantum security encryption box or a quantum security server.

[0076] The quantum-safe all-in-one machine, also known as the quantum-safe privacy computer, directly provides users with a quantum-encrypted privacy environment, where they can directly access the network management system via quantum-safe encryption. Access to the privacy computer via an existing computer allows for non-secure network access. The privacy computer also comes with a built-in KVM switching function, allowing users to freely switch between the privacy environment and their existing computer.

[0077] The quantum-safe encryption box is connected to the existing terminal in an external manner. All data accessed by the user terminal through the encryption box will be quantum-safely encrypted before being sent out. The user's office environment is still the same terminal device, and the data communicated by the existing network management client is encrypted and protected by the quantum-safe encryption box.

[0078] Quantum security servers can be used to provide quantum security encryption protection for high-volume secure access requirements. Their functions are similar to those of quantum security boxes when used on terminals.

[0079] Obviously, those skilled in the art may make various changes and modifications to this application without departing from the spirit and scope of this application. Thus, if these modifications and variations of this application fall within the scope of the claims of this application and their equivalents, this application is intended to include these modifications and variations.

Claims

1. A network system with global quantum security protection, characterized in that: Including provincial centers, municipal client systems and backup centers; The provincial center serves as the main computer room, receiving and managing data reports from gateway network elements in prefectures and cities. The backup center is used to receive data backup from the provincial center. The data backup transmission lines include: a dedicated data backup line and a multiplexed line; the multiplexed line is used for data backup and client access; The client systems of various cities access the network management system of the provincial center through remote browsing; The network management system of the provincial center includes a network server and a quantum security service system; the quantum security service system includes: a quantum security server, an access base station and a key center. The quantum security server is respectively connected to the access base station and the key center. The network server is connected to the quantum security server, and business data is transmitted between the client and the network server through the quantum security server. The service data is provided with quantum encryption and decryption processing, and the quantum key used for encryption and decryption is managed. Wherein, the quantum security service system is connected to the access switch via a communication agent; The quantum security server of the quantum security service system corresponds to multiple network servers; Each network server is connected to the quantum security server through an independent network card; and the quantum security server is connected to each network port IP of the corresponding network server as a network server gateway; the communication proxy is connected to each network port IP of the access switch as the corresponding network server address; The quantum security server further includes an isolation module, which is used for data filtering and directly allows non-network management clients, backup data, and municipal gateway network element data to pass without quantum security protection; The backup center includes a first computer room and a second computer room, wherein the first computer room is connected to the main computer room of the provincial center through a dedicated communication line; the second computer room is connected to the client system of the prefecture-level city through a multiplex line; The backup network servers in the first and second computer rooms are connected to the quantum security server in the backup center, and the quantum security server is connected to the access switch between the main computer rooms through a communication proxy; The quantum security server of the backup center, the key center of the provincial center, and the access base station constitute a quantum security service system; the supplementary quantum key is obtained through the key center of the provincial center, and the quantum key is relayed through the access base station of the provincial center.

2. The system according to claim 1, wherein: The provincial center includes at least two quantum security service systems, and the quantum security servers in each quantum security service system are connected to the core switch through a communication agent and a firewall. The quantum security servers in the two quantum security service systems have a master-slave relationship with each other, and the quantum security servers in the two quantum security service systems synchronize quantum keys in real time. The network port of the access switch connected to the quantum security server serves as the gateway of the access switch, and the network port of the core switch connected to the communication agent serves as the gateway of the core switch, so as not to change the original networking relationship, routing configuration and firewall policy.

3. The system according to claim 1, wherein: The backup center includes a first computer room and a second computer room, wherein the first computer room is connected to the main computer room of the provincial center through a dedicated communication line; the second computer room is connected to the client system of the prefecture-level city through a multiplex line; The backup network servers in the first and second computer rooms are connected to the quantum security server in the backup center. The quantum security server is connected to the core switch through a communication proxy and a firewall. The backup network servers are connected to the quantum security server via an access switch. The quantum security server of the backup center, the key center of the provincial center, and the access base station constitute a quantum security service system; the supplementary quantum key is obtained through the key center of the provincial center, and the quantum key is relayed through the access base station of the provincial center; The access switch network port connected to the quantum security server serves as the gateway of the access switch, and the network port connected to the core switch by the communication agent serves as the gateway of the core switch, thereby ensuring that the original networking relationship, routing configuration and firewall policy are not changed.

4. The system according to claim 1, wherein: The local client system includes a quantum security all-in-one machine, a quantum security encryption box or a quantum security server.

5. The system according to claim 4, characterized in that The quantum-safe all-in-one machine, also known as the quantum-safe privacy computer, directly provides users with a quantum-encrypted privacy environment. Users can directly access the network management system in the privacy environment through quantum-safe encryption. Users can connect to the privacy computer through existing computers to achieve non-secure network access. The privacy computer has a built-in KVM switching function, allowing users to freely switch between the privacy environment and existing computers. The quantum-safe encryption box is connected to the existing terminal in an external way. All data accessed by the user terminal through the encryption box will be sent after quantum-safe encryption. The user's office environment is still the original terminal equipment, and the data communicated externally by the existing network management client is encrypted and protected by the quantum-safe encryption box. Quantum security server, which is used to meet the security access requirements of large traffic, is used as quantum security encryption protection. It is used in terminals and its functions are the same as those of quantum security encryption boxes.

Citation Information

Patent Citations

  • System and method for remote data secure backup

    CN108965344A

  • Multi-data-center secure data transmission method based on quantum QKD technology

    CN110708159A