Preparation method, quantum random number security chip and quantum key generation method
By adopting a three-dimensional stacking structure and plastic packaging process in the quantum random number security chip, the quantum entropy source chip and the security processing module are effectively combined, and signal transmission is achieved using wafer fan-out technology, which solves the packaging problem and realizes the compactness and efficient packaging of the chip.
Patent Information
- Application Number
- CN202510031152.6
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2025-01-09
- Publication Date
- 2025-05-06
- Estimated Expiration
- 2045-01-09
AI Technical Summary
The prior art is difficult to effectively combine quantum entropy source chips and post-processing units within a finite volume, and the quantum entropy source chips have large volumes and irregular shapes, resulting in packaging difficulties.
Using a three-dimensional stacking structure and plastic sealing process, the quantum entropy source chip and safety processing module are arranged on both sides of the substrate, and the pads and copper column bumps are redirected through wafer fan-out technology to form a signal transmission path across the plastic sealing layer.
The compact and efficient packaging of quantum random number security chips is realized, reducing the horizontal area of the chip, improving space utilization, and reducing the risk of electromagnetic signal leakage.
Smart Images

Figure CN119519969B_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the technical field of quantum random number generation, and more specifically, to a preparation method, a quantum random number security chip and a quantum key generation method. Background Art
[0002] Quantum random number generators need to be small in size, have high random number generation rate, and strong stability. The optical chip solution based on vacuum state fluctuation measurement does not require an optical interferometer, has a simple optical structure and stable light emission, and is easy to achieve smaller single silicon chip integration and plastic packaging. Quantum state measurement can be directly achieved on the chip, so it has the best application prospects.
[0003] Optical chips based on vacuum state fluctuation measurement usually include a quantum entropy source chip and a post-processing unit. However, since the quantum entropy source chip and the post-processing unit are mostly subsystems of two different processes and different raw materials, conventional packaging technology makes it difficult to combine these two process-incompatible devices together in a limited volume; in addition, since the quantum entropy source chip itself contains a variety of active and passive devices and optical waveguide structures, it is large in size and has an irregular three-dimensional shape. Summary of the invention
[0004] In view of this, the present invention provides a preparation method, a quantum random number security chip and a quantum key generation method.
[0005] One aspect of the present invention provides a method for preparing a quantum random number security chip, the preparation method comprising: using a three-dimensional stacking structure, arranging a quantum entropy source chip die and a security processing module on a first surface of a substrate and a second surface of the substrate, respectively, wherein a plurality of copper pillars are arranged on the second surface of the substrate; using a plastic encapsulation process to plastic-encapsulate the first surface of the substrate and the second surface of the substrate to obtain a plastic encapsulation structure wrapping the substrate, wherein the bumps of the plurality of copper pillars are exposed outside the plastic encapsulation structure; using a wafer fan-out method, redirecting the substrate pads arranged on the second surface of the substrate to the fan-out area of the substrate, so as to use the bumps of the plurality of copper pillars exposed outside the plastic encapsulation structure as external pins of the quantum random number security chip, thereby obtaining the quantum random number security chip.
[0006] According to an embodiment of the present invention, the security processing module includes a security processor chip die and a signal amplifier chip die, and the quantum entropy source chip die and the security processing module are arranged on the first surface of the substrate and the second surface of the substrate respectively, including: setting the security processor chip die and the signal amplifier chip die on the second surface of the substrate, and setting the soldering points of the security processor chip die and the soldering points of the signal amplifier chip die to be in the same direction as the substrate pads on the second surface of the substrate.
[0007] According to an embodiment of the present invention, the above-mentioned preparation method also includes: using a bonding process to bond the welding points of the above-mentioned quantum entropy source chip bare die, the welding points of the above-mentioned security processor chip bare die and the welding points of the above-mentioned signal amplifier chip bare die to the above-mentioned multiple copper pillars respectively.
[0008] According to an embodiment of the present invention, the preparation method further includes: when the plastic encapsulation structure is a pinless packaging form, implanting solder balls into the substrate pads disposed on one side of the second surface of the substrate; when the plastic encapsulation structure is a flat pin packaging form, configuring metal pins on the substrate pads disposed on one side of the second surface of the substrate to ensure that the quantum random number security chip is connected to the external circuit.
[0009] According to an embodiment of the present invention, the material of the substrate includes epoxy resin material.
[0010] Another aspect of the present invention provides a quantum random number security chip, which is obtained according to the preparation method described in any one of the above items, wherein the quantum random number security chip includes a quantum entropy source chip and a security processing module, and the quantum entropy source chip is connected to the security processing module; wherein the quantum entropy source chip is configured to convert the optical signal of the continuous light source into an electrical signal, and perform signal processing on the electrical signal based on the homodyne detection method to generate a quantum entropy source analog signal; the security processing module is configured to perform randomness extraction processing on the quantum entropy source analog signal generated by the quantum entropy source chip to obtain a quantum random number, and encrypt and decrypt the quantum random number to obtain a target quantum key.
[0011] According to an embodiment of the present invention, the above-mentioned quantum entropy source chip includes a light source generating unit, an optical beam splitter, a photodetector and a transimpedance amplifier connected in sequence, wherein the above-mentioned light source generating unit is used to generate the above-mentioned continuous light source and input the above-mentioned continuous light source into the above-mentioned optical beam splitter; the above-mentioned optical beam splitter is used to divide the above-mentioned continuous light source into two paths, which are respectively input into the above-mentioned photodetector, wherein the first input end of the above-mentioned optical beam splitter is used to receive the above-mentioned continuous light source, and the second input end of the above-mentioned optical beam splitter is vacant to serve as a vacuum state input end; the above-mentioned photodetector includes a first photodetector and a second photodetector, wherein the first photodetector and the second photodetector are respectively used to convert the optical signal of the above-mentioned continuous light source into a first electrical signal and a second electrical signal, so as to perform zero-difference detection on the above-mentioned first electrical signal and the above-mentioned second electrical signal to obtain the current difference of the output signal; the above-mentioned transimpedance amplifier is used to amplify the current difference of the above-mentioned output signal to obtain the above-mentioned quantum entropy source analog signal.
[0012] According to an embodiment of the present invention, the security processing module includes a signal amplifier chip and a security processor chip, the input end of the signal amplifier chip is connected to the output end of the transimpedance amplifier in the quantum entropy source chip, and the output end of the signal amplifier chip is connected to the input end of the security processor chip; wherein the signal amplifier chip is used to receive the quantum entropy source analog signal, and amplify the quantum entropy source analog signal to obtain a quantum entropy source random signal; the security processor chip includes an analog-to-digital converter, a digital-to-analog converter, a randomness extraction unit and an encryption processing unit, wherein the analog-to-digital converter is used to convert the quantum entropy source random signal into a digital signal, and send the digital signal of the quantum entropy source random signal to the randomness extraction unit; the randomness extraction unit is used to extract randomness from the digital signal of the quantum entropy source random signal to generate a quantum random number; the encryption processing unit is used to encrypt and decrypt the quantum random number to obtain the target quantum key.
[0013] According to an embodiment of the present invention, the target quantum key includes any one of a shared key pair of symmetric encryption, a public-private key pair of asymmetric encryption, and a temporary key of hybrid encryption.
[0014] Another aspect of the present invention provides a quantum key generation method based on quantum random numbers, which is applicable to the quantum random number security chip described in any of the above items. The quantum key generation method based on quantum random numbers includes: in response to receiving a quantum key generation request, converting the optical signal of a continuous light source into an electrical signal; processing the electrical signal of the continuous light source based on a homodyne detection method to generate a quantum entropy source simulation signal; performing randomness extraction processing on the quantum entropy source simulation signal to obtain a quantum random number; and encrypting and decrypting the quantum random number to obtain a target quantum key.
[0015] According to an embodiment of the present invention, by applying wafer fan-out and plastic encapsulation processes to a bare die of optoelectronic hybrid integration, a complete chip of system-level packaging is formed. By integrating the quantum entropy source chip and the security processing module on both sides of the substrate, a three-dimensional stacking structure is formed, which not only reduces the horizontal area of the chip after packaging, but also improves space utilization. In addition, by arranging copper pillars on the bottom surface of the substrate to form bumps, the circuit layer is located on the second surface of the substrate, and then the wafer fan-out process is used to cross the entire plastic encapsulation layer to redirect the pads to the fan-out area around the substrate to achieve the function of transmitting signals across the plastic encapsulation layer. BRIEF DESCRIPTION OF THE DRAWINGS
[0016] The above and other objects, features and advantages of the present invention will become more apparent through the following description of the embodiments of the present invention with reference to the accompanying drawings.
[0017] Figure 1A flow chart of a method for preparing a quantum random number security chip according to an embodiment of the present invention is shown.
[0018] Figure 2 A schematic diagram of a packaged quantum random number security chip according to an embodiment of the present invention is shown.
[0019] Figure 3 A schematic diagram of a quantum random number security chip according to an embodiment of the present invention is shown.
[0020] Figure 4 A schematic diagram of the working process of a quantum random number security chip according to an embodiment of the present invention is shown.
[0021] Figure 5 A schematic diagram of the working process of the encryption processing unit according to an embodiment of the present invention is shown.
[0022] Figure 6 A schematic diagram of a symmetric encryption method according to a specific embodiment of the present invention is shown.
[0023] Figure 7 A schematic diagram of a symmetric decryption method according to a specific embodiment of the present invention is shown.
[0024] Figure 8 A schematic diagram of a method for generating an asymmetric key pair according to a specific embodiment of the present invention is shown.
[0025] Fig. 9 A schematic diagram of a method for generating an asymmetric key pair according to another specific embodiment of the present invention is shown.
[0026] Fig.10 A flow chart of a quantum key generation method based on quantum random numbers according to an embodiment of the present invention is shown.
[0027] Fig.11 A block diagram of a quantum key generation device based on quantum random numbers according to an embodiment of the present invention is shown. DETAILED DESCRIPTION
[0028] Below, embodiments of the present invention will be described with reference to the accompanying drawings. However, it should be understood that these descriptions are exemplary only and are not intended to limit the scope of the present invention. In the following detailed description, for ease of explanation, many specific details are set forth to provide a comprehensive understanding of embodiments of the present invention. However, it is apparent that one or more embodiments may also be implemented without these specific details. In addition, in the following description, descriptions of known structures and technologies are omitted to avoid unnecessary confusion of concepts of the present invention.
[0029] The terms used herein are only for describing specific embodiments and are not intended to limit the present invention. The terms "comprise", "include", etc. used herein indicate the existence of the features, steps, operations and / or components, but do not exclude the existence or addition of one or more other features, steps, operations or components.
[0030] All terms (including technical and scientific terms) used herein have the meanings commonly understood by those skilled in the art unless otherwise defined. It should be noted that the terms used herein should be interpreted as having a meaning consistent with the context of this specification and should not be interpreted in an idealized or overly rigid manner.
[0031] When using expressions such as "at least one of A, B, and C, etc.", they should generally be interpreted according to the meaning of the expression commonly understood by those skilled in the art (for example, "a system having at least one of A, B, and C" should include but is not limited to a system having A alone, B alone, C alone, A and B, A and C, B and C, and / or A, B, C, etc.).
[0032] Random numbers are a widely used basic resource, and have extensive and important applications in many fields such as cryptography, numerical computing, neural network computing, traditional information security, and quantum communication. Quantum random number generators are based on the basic principles of quantum physics. The quantum random numbers they generate are unpredictable and non-repeatable. Compared with traditional pseudo-random number generators and noise source random number generators, their randomness sources are clearer, and their randomness can be strictly proved by the minimum entropy theory. Therefore, they have higher security and are particularly suitable for application scenarios with high requirements for randomness.
[0033] At present, quantum random number generators can be implemented using a variety of schemes, such as photon path selection schemes, photon arrival time schemes, laser phase fluctuation schemes, and vacuum state fluctuation measurement schemes. From a practical point of view, quantum random number generators need to have the characteristics of small size, high random number generation rate, and strong stability. The optical chip solution based on vacuum state fluctuation measurement does not require the use of optical interferometers. The optical structure is simple and the light emission is stable, which facilitates the integration of smaller single silicon chips and plastic packaging. Quantum state measurement can be directly realized on the chip, so it has the best application prospects.
[0034] Optical chips based on vacuum state fluctuation measurement usually include a quantum entropy source chip and a post-processing unit. However, since the quantum entropy source chip and the post-processing unit are mostly subsystems of two different processes and different raw materials, conventional packaging technology makes it difficult to combine these two process-incompatible devices together in a limited volume; in addition, since the quantum entropy source chip itself contains a variety of active and passive devices and optical waveguide structures, it is large in size and has an irregular three-dimensional shape.
[0035] Furthermore, in the post-processing process of quantum random numbers, the security chip can be used to encrypt and decrypt the generated quantum random numbers. In the prior art, the security chip usually has a built-in classical true random number generator (TRNG). This true random number generator based on classical physics usually uses thermal noise or unstable oscillator jitter as the entropy source of true random numbers. After extraction, true random numbers are generated as the random number source of the cryptographic algorithm.
[0036] Since quantum random numbers have the characteristics of unpredictability, non-repeatability and unbiasedness, compared with classical true random number generators, the vacuum state quantum random number generation method can provide a new solution for the random number source of security chips. It can generate a vacuum state quantum random number source with a sufficiently high entropy value and stability. The randomness of this method comes from the physical random process inherent in the quantum system, which can provide strong security protection for key generation.
[0037] However, there are already some independently working quantum random number generator chips on the market. If you want to use these quantum random numbers to provide security chips, you need to arrange the security chip and the quantum random number generator chip separately on the circuit board, and use board-level wiring to communicate between them. But if the random number generator and the device that executes the cryptographic algorithm are different devices, the board-level connection between them may become an entry point for attackers to steal information. In the long printed circuit board lines, the signal carrying the original random number will inevitably generate electromagnetic radiation, providing an opportunity for side channel attacks.
[0038] In view of this, the embodiment of the present invention forms a complete chip of system-level packaging by applying wafer fan-out and plastic packaging processes to the bare die of optoelectronic hybrid integration. By integrating the quantum entropy source chip and the security processing module on both sides of the substrate, a three-dimensional stacking structure is formed, which not only reduces the horizontal area of the chip after packaging, but also improves the space utilization. In addition, by arranging copper pillars on the bottom surface of the substrate to form bumps, the circuit layer is located on the inner side of the substrate, and then the wafer fan-out process is used to cross the entire plastic packaging layer to redirect the pads to the fan-out area around the substrate to realize the function of transmitting signals across the plastic packaging layer.
[0039] Specifically, an embodiment of the present invention provides a method for preparing a quantum random number security chip, which includes: using a three-dimensional stacking structure to arrange a quantum entropy source chip die and a security processing module on a first surface of a substrate and a second surface of the substrate, respectively, wherein a plurality of copper pillars are configured on the second surface of the substrate; using a plastic encapsulation process to plastic-encapsulate the first surface of the substrate and the second surface of the substrate to obtain a plastic encapsulation structure that wraps the substrate; using a wafer fan-out method to redirect the substrate pads configured on the second surface of the substrate to the fan-out area of the substrate, so as to use the bumps of the plurality of copper pillars exposed outside the plastic encapsulation structure as external pins of the quantum random number security chip, thereby obtaining a quantum random number security chip.
[0040] It should be noted that the preparation method, quantum random number security chip, and quantum key generation method determined in the embodiments of the present invention can be used in the field of quantum random number technology, such as the field of quantum random number generation technology. The preparation method, quantum random number security chip, and quantum key generation method determined in the embodiments of the present invention can also be used in any field other than the field of quantum random number technology, such as the field of quantum computer technology. The application field of the preparation method, quantum random number security chip, and quantum key generation method determined in the embodiments of the present invention is not limited.
[0041] Figure 1 A flow chart of a method for preparing a quantum random number security chip according to an embodiment of the present invention is shown.
[0042] like Figure 1 As shown, the preparation method includes operations S101 to S103.
[0043] In operation S101, a three-dimensional stacking structure is adopted to arrange the quantum entropy source chip die and the security processing module on the first surface and the second surface of the substrate respectively.
[0044] In operation S102 , a plastic packaging process is used to plastic-package the first surface of the substrate and the second surface of the substrate to obtain a plastic packaging structure that wraps the substrate.
[0045] In operation S103, the substrate pads configured on the second surface of the substrate are redirected to the fan-out area of the substrate by using a wafer fan-out method, so that the bumps of the multiple copper pillars exposed outside the plastic packaging structure are used as external pins of the quantum random number security chip to obtain a quantum random number security chip.
[0046] According to an embodiment of the present invention, the substrate can be used as a carrier of the quantum entropy source chip die and the security processing module, combining all components included in the quantum entropy source chip die and the security processing module, and providing circuit interconnection between the chip and the components to achieve optoelectronic hybrid integration. The quantum entropy source chip die and the chip die included in the security processing module can be obtained by wafer cutting and testing.
[0047] The quantum entropy source chip die may include an optoelectronic device required to generate a quantum entropy source analog signal. The security processing module may include a security processor chip die and a signal amplifier chip die.
[0048] According to an embodiment of the present invention, the substrate may include a first surface and a second surface. In a specific embodiment of the present invention, a three-dimensional stacking structure may be used, and the quantum entropy source chip die may be bonded and arranged on the first surface, and the security processor chip die and the signal amplifier chip die included in the security processing module may be bonded and arranged on the second surface to achieve a three-dimensional device layout. Preferably, the substrate material may be an epoxy resin material, and the adhesive material may be a non-conductive epoxy adhesive.
[0049] According to the embodiments of the present invention, using a bare die-sized security processor chip and a signal amplifier chip can reduce chip size, lower costs, and reduce wiring complexity.
[0050] According to an embodiment of the present invention, the pads (PAD) of the quantum entropy source chip die can be configured to be oriented in the same direction as the substrate pads on the first surface of the substrate, and the pads (PADs) of the security processor chip die and the signal amplifier chip die included in the security processing module can be configured to be oriented in the same direction as the substrate pads on the second surface of the substrate.
[0051] According to an embodiment of the present invention, a plurality of copper pillars are arranged on one side of the second surface of the substrate on which the security processor chip die and the signal amplifier chip die are arranged, so that the plurality of copper pillars form bumps for signal extraction.
[0052] According to an embodiment of the present invention, the method for preparing a quantum random number security chip further includes: using a bonding process to bond the bonding points of the quantum entropy source chip die, the bonding points of the security processor chip die, and the bonding points of the signal amplifier chip die to the bumps on the second surface of the substrate, so as to achieve electrical connection between the quantum entropy source chip die, the security processor chip die, and the signal amplifier chip die. The bonding wire can be made of gold wire material.
[0053] According to an embodiment of the present invention, the method for preparing a quantum random number security chip further includes: using a plastic encapsulation process to respectively inject a plastic encapsulation material into the first surface and the second surface of the substrate for plastic encapsulation to obtain a double-sided plastic encapsulation structure wrapping the substrate.
[0054] According to an embodiment of the present invention, the method for preparing a quantum random number security chip further includes: grinding the plastic encapsulation layer on the second surface of the substrate until the copper pillar bumps are exposed from the plastic encapsulation layer.
[0055] According to an embodiment of the present invention, by using a wafer fan-out method, the substrate pads configured on the second surface of the substrate are redirected to the fan-out area around the substrate and the bottom of the substrate, or the signals of the multiple copper pillar bumps configured on the second surface of the substrate are guided to the fan-out area around the substrate to form a redistribution layer, and the external connection pads are rearranged to a suitable position, so that the pads originally covered by the plastic encapsulation layer can be connected to the new pads on the fan-out area around the substrate through the internal circuit layer, so that the copper pillars are used as external pins of the quantum random number security chip. These external pins not only provide physical connection points with external circuits, but also ensure that the signal can be transmitted across the plastic encapsulation layer.
[0056] According to an embodiment of the present invention, the wafer fan-out technology increases the number of I / O contacts and fully utilizes the effective area of the chip by designing the wiring of I / O contacts in an area outside the chip size. This technology can shorten the signal transmission distance, improve electrical performance, and allow more complex system integration.
[0057] According to an embodiment of the present invention, the method for preparing a quantum random number security chip further includes: when the double-sided plastic packaging structure is a pinless packaging form, implanting solder balls into the substrate pads disposed on the redistribution layer side. When the double-sided packaging structure is a flat pin packaging form, metal pins are configured on the substrate pads disposed on the redistribution layer side to ensure that the quantum random number security chip is connected to an external circuit, thereby obtaining a quantum random number security chip based on wafer fan-out packaging technology.
[0058] Figure 2 A schematic diagram of a packaged quantum random number security chip according to an embodiment of the present invention is shown.
[0059] like Figure 2 As shown, the quantum random number security chip packaged based on the wafer fan-out packaging technology includes a quantum entropy source chip 1, a security processing module 2, a substrate 3, a redistribution layer 4, and a plastic packaging layer 5. Among them, the quantum entropy source chip 1 and the security processing module 2 connected in sequence are respectively integrated on the first surface and the second surface of the substrate 3. In a specific embodiment, the horizontal area of the quantum random number security chip obtained by the preparation method is reduced to 50% of the tiling scheme.
[0060] like Figure 2 As shown, the redistribution layer 4 includes metal wiring 41 and metal pads 42, wherein the redistribution layer is used to connect all signal networks in the substrate 3 that need to be interconnected with the outside world. Specifically, the wafer fan-out technology is used to redirect multiple copper pillar bumps on the substrate 3 that need to be interconnected with the outside world to the fan-out area, and finally connected to the metal pads 42, and the multiple copper pillar bumps across the plastic encapsulation layer 5 are exposed outside the plastic encapsulation layer 5 to serve as external pins of the quantum random number security chip.
[0061] like Figure 2 As shown, a plastic encapsulation process is used to encapsulate the first surface and the second surface of the substrate 3 with epoxy resin plastic encapsulation material to form a plastic encapsulation layer 5, thereby providing a packaging shell for the chip. The plastic encapsulation layer 5 also provides physical support and mechanical protection for the quantum entropy source chip 1 and the security processing module 2, achieving high stability, small size, and low noise optoelectronic integration. In a specific embodiment, the quantum random number security chip obtained by the preparation method greatly reduces the volume while reducing the cost. Compared with the solution of combining a PCB board with a ceramic shell using a welding process under the prior art, the overall volume of the system is reduced by 20%.
[0062] In addition, since the plastic encapsulation layer 5 has good thermal contact and thermal conductivity properties, it can improve the heat dissipation performance of the chip and widen its operating temperature range. At the same time, the epoxy resin used for plastic encapsulation will also form a compact three-dimensional microstructure after curing, so that the plastic encapsulation layer 5 also provides good physical isolation for the substrate 3 and the bare chip, reducing their erosion by water vapor and widening their operating humidity range.
[0063] Based on this, the embodiment of the present invention forms a complete chip of System-in-Package (SiP) by applying wafer fan-out and plastic packaging processes to the optoelectronic hybrid integrated bare chip. By integrating the quantum entropy source chip and the security processing module on both sides of the substrate, a three-dimensional stacking structure is formed, which not only reduces the horizontal area of the chip after packaging, but also improves the space utilization. In addition, by arranging copper pillars on the bottom surface of the substrate to form bumps, the circuit layer is located on the second surface of the substrate, and then the wafer fan-out process is used to cross the entire plastic packaging layer to redirect the pads to the fan-out area around the substrate to realize the function of transmitting signals across the plastic packaging layer.
[0064] According to an embodiment of the present invention, a quantum random number security chip includes a quantum entropy source chip and a security processing module, and the quantum entropy source chip is connected to the security processing module; wherein the quantum entropy source chip is configured to convert the optical signal of a continuous light source into an electrical signal, and perform signal processing on the electrical signal based on a homodyne detection method to generate a quantum entropy source analog signal; the security processing module is configured to perform randomness extraction processing on the quantum entropy source analog signal generated by the quantum entropy source chip to obtain a quantum random number, and encrypt and decrypt the quantum random number to obtain a target quantum key.
[0065] Figure 3 A schematic diagram of a quantum random number security chip according to an embodiment of the present invention is shown.
[0066] like Figure 3As shown, there is a signal connection between the quantum entropy source chip 1 and the security processing module 2, wherein the quantum entropy source chip 1 includes a light source generating unit 11, an optical beam splitter 13, a first photodetector 14, a second photodetector 15 and a transimpedance amplifier 16 connected in sequence.
[0067] The output end of the light source generating unit 11 is connected to the first input end of the beam splitter 13. The light source generating unit 11 is used to generate a continuous light source and input the continuous light source to the beam splitter 13. Preferably, the light source generating unit 11 can use a laser chip as an intrinsic light source.
[0068] The first input end of the beam splitter 13 is used to receive the continuous light source, and the second input end of the beam splitter 13 is left vacant to serve as a vacuum state input end to receive the vacuum state light 12. The beam splitter 13 is used to split the continuous light source into two paths, which are output to the first photodetector 14 and the second photodetector 15 respectively.
[0069] The output end of the first photodetector 14 and the output end of the second photodetector 15 are both connected to the input end of the transimpedance amplifier 16. The first photodetector 14 and the second photodetector 15 are respectively used to convert the optical signal of the continuous light source into a first electrical signal and a second electrical signal, so as to perform zero-difference detection on the first electrical signal and the second electrical signal to obtain the current difference of the output signal.
[0070] The transimpedance amplifier 16 is used to amplify the current difference of the output signal to obtain a quantum entropy source analog signal, and transmit the quantum entropy source analog signal to the security processing module 2.
[0071] Based on this, the embodiments of the present invention integrate all the above components on a single quantum entropy source chip by adopting hybrid integration technology to form a compact light source, optical path structure and detector integration.
[0072] like Figure 3 As shown, the security processing module 2 includes a signal amplifier chip 21 and a security processor chip 22. The input end of the signal amplifier chip 21 is connected to the output end of the transimpedance amplifier 16 in the quantum entropy source chip 1, and the output end of the signal amplifier chip 21 is connected to the input end of the security processor chip 22. The signal amplifier chip 21 is used to receive the quantum entropy source analog signal and amplify the quantum entropy source analog signal to obtain a quantum entropy source random signal.
[0073] like Figure 3 As shown, the security processor chip 22 includes a digital-to-analog converter 23, an analog-to-digital converter 24, and a security kernel 25, wherein the security kernel 25 includes a randomness extraction unit and an encryption processing unit.
[0074] The input end of the analog-to-digital converter 24 is connected to the output end of the signal amplifier chip 21, and the output end of the analog-to-digital converter 24 is connected to the input end of the security core 25. The analog-to-digital converter 24 is used to quantize the amplified quantum entropy source random signal, convert it into a digital signal, and send the digital signal of the quantum entropy source random signal to the security core 25.
[0075] The security kernel 25 is used to perform the regulation and control of the entire quantum random number security chip, and at the same time process the quantized quantum entropy source random signal in real time, perform various encryption and decryption workflows according to the user's instructions and programs, and perform data encryption and decryption and information exchange. Preferably, the security kernel 25 can use a security processor with its own randomness extraction program and general cryptographic algorithm to achieve an integrated process from random number generation to encryption and decryption, thereby increasing security.
[0076] The input end of the randomness extraction unit is connected to the output end of the analog-to-digital converter 24, and the randomness extraction unit is used to extract randomness from the digital signal of the quantum entropy source random signal to generate a quantum random number.
[0077] The input end of the encryption processing unit is connected to the output end of the randomness extraction unit. The encryption processing unit can be used to encrypt, decrypt, and sign the quantum random number to obtain the target quantum key.
[0078] The input end of the digital-to-analog converter 23 is connected to the output end of the security kernel 25 to receive a digital signal from the security kernel 25 and convert the digital signal into an analog signal for driving the light source generating unit 11 and adjusting the power of the light source generating unit 11 .
[0079] Based on this, the embodiment of the present invention directly embeds the general cryptographic algorithm and randomness extraction program into the main control chip of the vacuum state quantum random number generator, reducing the risk of data exposure during transmission and processing, helping to achieve more efficient encryption operations and improve the overall performance of the system. At the same time, by reducing the connection distance between the quantum entropy source and the security chip from the board level to the chip level, the line length is significantly reduced, the leakage amplitude of the electromagnetic signal during transmission is reduced, and the difficulty of side channel attacks is increased. In addition, chip-level integration reduces external interfaces and connecting wires, thereby reducing potential electromagnetic leakage points.
[0080] Combine the following Figure 4 The working process diagram of the quantum random number security chip based on wafer fan-out packaging technology shown in the figure further explains its working principle.
[0081] Figure 4 A schematic diagram of the working process of a quantum random number security chip according to an embodiment of the present invention is shown.
[0082] like Figure 4 As shown, in the quantum entropy source chip, one of the input signals is the continuous laser provided by the laser chip, that is, the coherent state intrinsic light signal , the other input signal is a vacuum state optical signal The two input signals are input to the optical beam splitter respectively. After being processed by the on-chip integrated optical beam splitter, two different quantum state optical signals are output, namely the first quantum state optical signal and the second quantum state light signal The first quantum state light signal and the second quantum state light signal Photoelectric conversion is performed through the first photodetector and the second photodetector respectively, and two photocurrent signals are obtained, which are the first electrical signal i1 and the second electrical signal i2 respectively. The first electrical signal i1 and the second electrical signal i2 are input into the transimpedance amplifier to amplify the weak high-frequency current signal and convert it into a voltage signal; the voltage signal is the quantum entropy source simulation signal generated by quantum fluctuations.
[0083] like Figure 4 As shown, the quantum entropy source analog signal is input into the signal amplifier chip in the security processing module for signal amplification to obtain the quantum entropy source random signal. The quantum entropy source random signal enters the analog-to-digital converter in the security processor chip, generates raw data after conversion, and after post-processing by the randomness extraction unit in the security processor chip, the real-time generated quantum random number can be obtained. The output quantum random number can be encrypted, decrypted, signed and other cryptographic processing by the security processing unit to obtain the target quantum key.
[0084] The above working principle is described in detail below. Quantum fluctuations exist in the coherent state light field, which satisfies the principle of minimum uncertainty in amplitude and phase. The essence of random number generation is to quantize and extract coherent state quantum fluctuations. In the embodiment of the present invention, two photodetector chips are used to generate random signals by measuring quantum fluctuations.
[0085] Specifically, one path of the laser chip is the local oscillator light source (i.e. continuous laser) input, and the other path is empty (i.e. vacuum state light). If we assume that the two input quantum states are recorded as , ,remember , , after being processed by the optical beam splitter, the quantum states of the two output lights are recorded as , , and the following relationship exists:
[0086] (1);
[0087] (2);
[0088] In the formula, represents the first quantum state light signal, represents the second quantum state light signal, represents the coherent state intrinsic light signal, represents the vacuum state optical signal, represents the quantum state of the coherent state intrinsic light signal, represents the quantum state of the vacuum state light signal. .
[0089] The first quantum state light signal and the second quantum state light signal After the photoelectric conversion is performed by the first photodetector and the second photodetector, two photocurrent signals are obtained respectively. The current passing through the first photodetector and the second photodetector is:
[0090] (3);
[0091] (4);
[0092] Wherein, i1 represents the first electrical signal, i2 represents the second electrical signal, represents the quantum efficiency of the photodetector, , respectively corresponding to the light intensity of the two input photodetectors; the superscript " "express , Hermitian conjugation of quantum states.
[0093] Since the current value should be equal to the product of quantum efficiency and light intensity, the current difference between the two photocurrents can be expressed as:
[0094] (5);
[0095] In the formula, Represents the current difference between the two photocurrents.
[0096] Therefore, it can be proved that:
[0097] (6);
[0098] In the formula, Corresponding quantum noise . Quantum noise is reflected in the results of equilibrium detection.
[0099] In a specific embodiment of the present invention, the noise distribution obtained by the data acquisition and post-processing circuit is divided into two parts, namely quantum noise and classic noise ,Right now:
[0100] (7);
[0101] In the formula, Represents the noise obtained by the data acquisition and post-processing circuits.
[0102] Since the continuous laser generated by the laser is a coherent light source, its average photon number can be expressed as For coherent light sources, the number of photons It follows a Poisson distribution, and its distribution is given by:
[0103] (8);
[0104] In the formula, represents a Poisson distribution.
[0105] The detection results of the first photodetector and the second photodetector are subjected to homodyne detection, and the number of photons obtained is It obeys the Skellam distribution, and its distribution is given by the following formula:
[0106] (9);
[0107] in, represents the Skellam distribution, represents the modified Bessel function; , The two parameters corresponding to the average number of photons in the two light paths are also the two parameters of the Skellam distribution, which determine the shape of this distribution.
[0108] In a specific embodiment of the present invention, the quantum noise distribution can be obtained through the above calculation. Since the classical noise in the system obeys the Gaussian distribution, it is only necessary to measure the classical noise when there is no light input. , we can calculate the proportion of quantum noise.
[0109] In a specific embodiment of the present invention, the minimum entropy is calculated by calculating the quantum noise distribution. Since randomness is quantified by the minimum entropy and the random numbers of vacuum state fluctuations obey the Skellam distribution, the quantum noise variance is calculated by the above , you can get , and thus calculate the minimum entropy. The minimum entropy can be defined as:
[0110] (10);
[0111] In the formula, represents the minimum entropy, Indicates the probability of the most likely outcome.
[0112] According to an embodiment of the present invention, the minimum entropy of the original random number is calculated based on the measurement result, and the measurement result can be obtained in real time inside the randomness extraction unit, thereby achieving accurate estimation of the minimum entropy.
[0113] The following is a detailed description of the specific operation of the randomness extraction program:
[0114] The randomness extraction program included in the randomness extraction unit is a method for extracting a high-quality random bit sequence from an original random bit sequence through a specific matrix operation. In a specific embodiment of the present invention, a Toeplitz matrix can be used to process the original random number, that is, the quantum entropy source random signal after analog-to-digital conversion. In the final randomness extraction process, a Toeplitz matrix algorithm based on fast Fourier transform can be used, and the matrix size is , that is, from The original quantum random number data can be extracted The final random number of bits satisfies the following relationship: .
[0115] Among them, the Toeplitz matrix is a universal hash function. The matrix elements are composed of binary random bits. Its structure is shown in the figure below:
[0116] (11);
[0117] Where T represents the Toeplitz matrix, t n Represents the nth binary random bit.
[0118] In a specific embodiment of the present invention, for an original random number sequence of length n, it is only necessary to The Toeplitz matrix of the extracted random sequence with a length of m can be multiplied by the Toeplitz matrix, as shown in the following formula:
[0119] (12);
[0120] The above formula can be simplified as:
[0121] (13);
[0122] in, Represents a random bit sequence of m bits: , express The Toeplitz matrix, Represents an n-bit original random sequence: .
[0123] As shown in formula (13), the Toeplitz matrix T is combined with the original random bit sequence D d Performing matrix multiplication operation, we can get the extracted random bit sequence D r Specifically, each row of the Toeplitz matrix is dot-producted with the original random bit sequence (i.e., summed after bitwise AND operation, and then modulo 2 to obtain the final binary bit) to obtain an element of the extracted random bit sequence. After the above processing, the final quantum random number of vacuum state fluctuations can be obtained in real time, that is, the extracted random bit sequence D r Its randomness comes from the basic principles of quantum physics and can be verified by information theory.
[0124] Based on this, the quantum random number generator scheme based on vacuum state fluctuations provides a relatively simple optical structure and stable entropy production performance. On this basis, the wafer fan-out and plastic sealing process are used for packaging, which can further reduce the volume and reduce the cost.
[0125] According to an embodiment of the present invention, the randomness extraction unit can also be executed by the operation unit of the security processor chip. During the randomness extraction process, the operation unit of the security processor can be used to perform the multiplication operation of the Toeplitz matrix and the original random bit sequence, and output the extracted quantum random number.
[0126] According to an embodiment of the present invention, a vacuum state quantum random number source with sufficiently high entropy value and stability can provide strong security for key generation. The extracted quantum random number can be encrypted, decrypted and signed by the encryption processing unit in the security processor chip to generate different types of target quantum keys. Among them, the target quantum key can include any one of a shared key pair of symmetric cryptography, a public-private key pair of asymmetric cryptography, and a temporary key of a hybrid cryptography.
[0127] The specific operation of the encryption processing unit is described in detail below.
[0128] Figure 5 A schematic diagram of the working process of the encryption processing unit according to an embodiment of the present invention is shown.
[0129] like Figure 5 As shown, in a specific embodiment of the present invention, the work flow of the encryption processing unit includes: using a symmetric key generation algorithm, such as an AES key generation algorithm, to perform key generation processing on quantum random numbers to obtain a shared key pair, and using the generated shared key pair and a symmetric encryption algorithm (such as an AES encryption algorithm) to encrypt a message to obtain an encrypted message, namely a symmetric cipher.
[0130] like Figure 5As shown, in another specific embodiment of the present invention, the work flow of the encryption processing unit may further include: performing key generation processing on the quantum random number to obtain a temporary key, which may be a part of a symmetric key or an asymmetric key. The temporary key is then used in combination with other encryption mechanisms (such as symmetric encryption or asymmetric encryption) to encrypt the message to obtain a hybrid password.
[0131] like Figure 5 As shown, in another specific embodiment of the present invention, the workflow of the encryption processing unit may also include: performing key generation processing on the quantum random number using an asymmetric key generation algorithm such as an RSA or ECC key generation algorithm to obtain a public key and a private key pair, and encrypting the message using the generated public key and private key pair and an asymmetric encryption algorithm to obtain the encrypted message, i.e., an asymmetric password.
[0132] In another specific embodiment of the above, the workflow of the encryption processing unit may further include: performing encrypted message hashing based on asymmetric cryptography to obtain a digital signature. For example, a one-way hash function (such as SHA-256) may be used to hash the message to obtain a hash value of the message. The hash value of the message is encrypted using a private key and an asymmetric encryption algorithm (such as a digital signature algorithm of RSA or ECC) to obtain a digital signature.
[0133] Figure 6 A schematic diagram of a symmetric encryption method according to a specific embodiment of the present invention is shown.
[0134] like Figure 6 As shown, the CBC grouping mode is taken as an example. The secure storage area can be used to store the quantum random numbers generated by the quantum random number generator. Group the data according to the encryption block size (such as 128 bits, i.e. 16 bytes for AES; 64 bits, i.e. 8 bytes for DES). If the data length is not an integer multiple of the block size, padding is required to ensure that the size of each block is the same. Secondly, generate a random initialization vector (IV) of the same size as the block. IV is required for both encryption and decryption and must be kept confidential. The role of IV is to make the encryption process of each message different, even for the same plaintext block. Perform an XOR operation on the first set of data (plaintext block) and IV. Encrypt the XOR result using an encryption algorithm (such as AES or DES) to obtain the first set of ciphertext. For each subsequent plaintext block, perform an XOR operation on it and the previous ciphertext block, and then encrypt the result using the encryption algorithm to obtain the ciphertext of the current plaintext block. Connect all encrypted blocks in their order to form the final ciphertext.
[0135] Figure 7 A schematic diagram of a symmetric decryption method according to a specific embodiment of the present invention is shown.
[0136] like Figure 7 As shown, take CBC grouping mode as an example. As in the encryption process, group the data (ciphertext) according to the encryption block size. Use the same IV as in the encryption process. Decrypt the first group of ciphertexts, and then perform an XOR operation with the IV to obtain the first group of plaintexts. For each subsequent ciphertext block, decrypt it first, and then perform an XOR operation with the previous ciphertext block (the previous plaintext block in the decrypted plaintext sequence) to obtain the plaintext corresponding to the current ciphertext block. After decryption, the padding needs to be removed to obtain the original plaintext data. Connect all the decrypted blocks in their order to obtain the final plaintext.
[0137] Figure 8 A schematic diagram of a method for generating an asymmetric key pair according to a specific embodiment of the present invention is shown.
[0138] like Figure 8 As shown, take the RSA algorithm as an example. Randomly select two large random numbers P and Q. These two random numbers are usually randomly generated and large enough to ensure that they are difficult to factorize. Determine whether the random numbers P and Q are prime numbers. If both are prime numbers, use the RSA algorithm to generate a key pair. If the judgment result is no, regenerate the random number.
[0139] Specifically, the process of generating the key pair may include: calculating the product n of the two prime numbers, that is, The modulus n is invented and will become part of the public key. Using the Euler function Calculate a value t, which represents the number of positive integers less than or equal to n that are relatively prime to n. Choose a smaller integer e as the public key exponent. This integer e is are relatively prime (i.e. their greatest common divisor is 1), and e is less than and is greater than 1. In practical applications, e is usually chosen to be 65537 because it is a safe prime number with good performance characteristics. Calculate an integer d such that This d is the private key exponent, which should satisfy the above congruence equation. The process of calculating d usually uses the extended Euclidean algorithm. The public key consists of the modulus n and the public key exponent e, that is, The private key consists of the modulus n and the private key exponent d, that is .
[0140] Fig. 9 A schematic diagram of a method for generating an asymmetric key pair according to another specific embodiment of the present invention is shown.
[0141] like Fig. 9As shown, take the SM2 algorithm as an example. Select an elliptic curve equation and a base point G, which is a point on the elliptic curve with known coordinates. Select the order n of the elliptic curve, which is a large prime number used to ensure the difficulty of the elliptic curve discrete logarithm problem. Randomly select an integer d as the private key. This integer d must be less than n and greater than 1, and needs to be kept secret. Use the private key d and the base point G to calculate the public key P. The calculation formula is Here, " " represents the point multiplication operation on the elliptic curve, that is, the base point G is multiplied d times using the private key d to obtain the public key P. The public key P consists of the coordinates of the point on the elliptic curve and can be invented. The private key d is an integer and needs to be kept secret.
[0142] In the present invention, the initialization of the quantum random number generator and the entire process of obtaining quantum random numbers can be encapsulated into simple commands in the security processor chip, which can be easily integrated with the cryptographic algorithm. Based on this, users can develop functions that meet their own application scenarios.
[0143] Based on this, the embodiment of the present invention applies the cryptographic algorithm to the main control chip of the vacuum state quantum random number generator, thereby realizing the integration of the quantum entropy source chip and the security processor chip. In this method, the connection between the quantum entropy source chip and the security processor chip is reduced from the board level to the chip level. The reduction in the order of magnitude of the line length can greatly reduce the amplitude of electromagnetic leakage and increase the difficulty of side channel attacks.
[0144] Fig.10 A flow chart of a quantum key generation method based on quantum random numbers according to an embodiment of the present invention is shown.
[0145] like Fig.10 As shown, the method includes operations S1001 to S1004.
[0146] In operation S1001, in response to receiving a quantum key generation request, an optical signal of a continuous light source is converted into an electrical signal.
[0147] In operation S1002, the electrical signal of the continuous light source is processed based on a homodyne detection method to generate a quantum entropy source analog signal.
[0148] In operation S1003, randomness extraction processing is performed on the quantum entropy source analog signal to obtain a quantum random number.
[0149] In operation S1004, the quantum random number is encrypted and decrypted to obtain a target quantum key.
[0150] Fig.11 A block diagram of a quantum key generation device based on quantum random numbers according to an embodiment of the present invention is shown.
[0151] like Fig.11 As shown, the quantum key generation device based on quantum random numbers includes a conversion module 1110, a processing module 1120, an extraction module 1130 and a cryptographic processing module 1140.
[0152] The conversion module 1110 is used to convert the optical signal of the continuous light source into an electrical signal in response to receiving a quantum key generation request.
[0153] The processing module 1120 is used to process the electrical signal of the continuous light source based on the homodyne detection method to generate a quantum entropy source simulation signal.
[0154] The extraction module 1130 is used to perform randomness extraction processing on the quantum entropy source analog signal to obtain quantum random numbers.
[0155] The cryptographic processing module 1140 is used to encrypt and decrypt the quantum random number to obtain the target quantum key.
[0156] According to the embodiments of the present invention, any one or more of the modules, submodules, units, and subunits, or at least part of the functions of any one of them can be implemented in one module. According to the embodiments of the present invention, any one or more of the modules, submodules, units, and subunits can be split into multiple modules for implementation. According to the embodiments of the present invention, any one or more of the modules, submodules, units, and subunits can be at least partially implemented as hardware circuits, such as field programmable gate arrays (FPGAs), programmable logic arrays (PLAs), systems on chips, systems on substrates, systems on packages, application specific integrated circuits (ASICs), or can be implemented by hardware or firmware in any other reasonable way of integrating or packaging the circuit, or by any one of the three implementation methods of software, hardware, and firmware, or by a proper combination of any of them. Alternatively, according to the embodiments of the present invention, one or more of the modules, submodules, units, and subunits can be at least partially implemented as computer program modules, and when the computer program modules are run, the corresponding functions can be executed.
[0157] For example, any of the conversion module 1110, the processing module 1120, the extraction module 1130, and the password processing module 1140 can be combined in one module / unit / sub-unit for implementation, or any of the modules / units / sub-units can be split into multiple modules / units / sub-units. Alternatively, at least part of the functions of one or more of these modules / units / sub-units can be combined with at least part of the functions of other modules / units / sub-units and implemented in one module / unit / sub-unit. According to an embodiment of the present invention, at least one of the conversion module 1110, the processing module 1120, the extraction module 1130, and the password processing module 1140 can be at least partially implemented as a hardware circuit, such as a field programmable gate array (FPGA), a programmable logic array (PLA), a system on a chip, a system on a substrate, a system on a package, an application specific integrated circuit (ASIC), or can be implemented by hardware or firmware such as any other reasonable way of integrating or packaging the circuit, or by any one of the three implementation methods of software, hardware, and firmware, or by a suitable combination of any of them. Alternatively, at least one of the conversion module 1110, the processing module 1120, the extraction module 1130 and the password processing module 1140 can be at least partially implemented as a computer program module, and when the computer program module is executed, the corresponding function can be performed.
[0158] It should be noted that the part of the quantum key generation device based on quantum random numbers in the embodiments of the present invention corresponds to the part of the quantum key generation method based on quantum random numbers in the embodiments of the present invention. The description of the part of the quantum key generation device based on quantum random numbers specifically refers to the part of the quantum key generation method based on quantum random numbers, which will not be repeated here.
[0159] It will be appreciated by those skilled in the art that the features described in the various embodiments of the present invention may be combined and / or combined in various ways, even if such combinations or combinations are not explicitly described in the present invention. In particular, without departing from the spirit and teachings of the present invention, the features described in the various embodiments of the present invention may be combined and / or combined in various ways. All of these combinations and / or combinations fall within the scope of the present invention.
[0160] The embodiments of the present invention are described above. However, these embodiments are only for the purpose of illustration, and are not intended to limit the scope of the present invention. Although each embodiment is described above, it does not mean that the measures in each embodiment cannot be used in combination advantageously. Without departing from the scope of the present invention, those skilled in the art may make various substitutions and modifications, which should all fall within the scope of the present invention.
Claims
1. A method for preparing a quantum random number security chip, characterized in that: The preparation method comprises: A three-dimensional stacking structure is adopted, and the quantum entropy source chip die and the security processing module are arranged on the first surface of the substrate and the second surface of the substrate respectively, wherein a plurality of copper pillars are arranged on the second surface of the substrate; The first surface of the substrate and the second surface of the substrate are respectively filled with a plastic sealing material by a plastic sealing process to obtain a double-sided plastic sealing structure wrapping the substrate; Grinding the plastic packaging layer on the second surface of the substrate until the bumps of the plurality of copper pillars are exposed outside the plastic packaging structure; By using a wafer fan-out method, the substrate pads configured on the second surface of the substrate are redirected to the fan-out area of the substrate to form a redistribution layer located on the surface of the plastic packaging structure, and the new pads included in the redistribution layer are rearranged so that the substrate pads covered by the plastic packaging structure are connected to the new pads on the fan-out area around the substrate through the redistribution layer, so that the bumps of the multiple copper pillars exposed outside the plastic packaging structure are used as external pins of the quantum random number security chip to obtain the quantum random number security chip.
2. The preparation method according to claim 1, characterized in that: The security processing module includes a security processor chip die and a signal amplifier chip die, and the quantum entropy source chip die and the security processing module are arranged on the first surface of the substrate and the second surface of the substrate respectively, including: The security processor chip die and the signal amplifier chip die are arranged on the second surface of the substrate, and the bonding points of the security processor chip die and the signal amplifier chip die are arranged to be in the same direction as the substrate pads on the second surface of the substrate.
3. The preparation method according to claim 2, characterized in that: The preparation method further comprises: The bonding process is used to bond the bonding points of the quantum entropy source chip die, the bonding points of the security processor chip die, and the bonding points of the signal amplifier chip die to the multiple copper pillars respectively.
4. The preparation method according to claim 1, characterized in that: The preparation method further comprises: When the plastic package structure is a pinless package, a solder ball is implanted into a substrate pad disposed on one side of the second surface of the substrate; When the plastic package structure is in the form of a flat pin package, a metal pin is arranged on a substrate pad disposed on one side of the second surface of the substrate to ensure that the quantum random number security chip is connected to an external circuit.
5. The preparation method according to claim 1, characterized in that: The material of the substrate includes epoxy resin material.
6. A quantum random number security chip, characterized in that: The quantum random number security chip is obtained according to the preparation method according to any one of claims 1 to 5, wherein the quantum random number security chip comprises a quantum entropy source chip and a security processing module, and the quantum entropy source chip is connected to the security processing module; Wherein, the quantum entropy source chip is configured to convert the optical signal of the continuous light source into an electrical signal, and perform signal processing on the electrical signal based on the homodyne detection method to generate a quantum entropy source analog signal; The security processing module is configured to perform randomness extraction processing on the quantum entropy source analog signal generated by the quantum entropy source chip to obtain a quantum random number, and encrypt and decrypt the quantum random number to obtain a target quantum key.
7. The quantum random number security chip according to claim 6, characterized in that: The quantum entropy source chip includes a light source generating unit, an optical beam splitter, a photodetector and a transimpedance amplifier connected in sequence. Wherein, the light source generating unit is used to generate the continuous light source and input the continuous light source into the light beam splitter; The optical beam splitter is used to split the continuous light source into two paths, which are respectively input to the photodetector, wherein the first input end of the optical beam splitter is used to receive the continuous light source, and the second input end of the optical beam splitter is vacant to serve as a vacuum state input end; The photodetector comprises a first photodetector and a second photodetector, wherein the first photodetector and the second photodetector are used to convert the optical signal of the continuous light source into a first electrical signal and a second electrical signal, respectively, so as to perform homodyne detection on the first electrical signal and the second electrical signal to obtain a current difference of an output signal; The transimpedance amplifier is used to amplify the current difference of the output signal to obtain the quantum entropy source analog signal.
8. The quantum random number security chip according to claim 7, characterized in that: The security processing module includes a signal amplifier chip and a security processor chip, the input end of the signal amplifier chip is connected to the output end of the transimpedance amplifier in the quantum entropy source chip, and the output end of the signal amplifier chip is connected to the input end of the security processor chip; The signal amplifier chip is used to receive the quantum entropy source analog signal and amplify the quantum entropy source analog signal to obtain a quantum entropy source random signal. The security processor chip includes an analog-to-digital converter, a digital-to-analog converter, a randomness extraction unit and an encryption processing unit, wherein the analog-to-digital converter is used to convert the quantum entropy source random signal into a digital signal, and send the digital signal of the quantum entropy source random signal to the randomness extraction unit; the randomness extraction unit is used to extract randomness from the digital signal of the quantum entropy source random signal to generate a quantum random number; the encryption processing unit is used to encrypt and decrypt the quantum random number to obtain the target quantum key.
9. The quantum random number security chip according to claim 8, characterized in that: The target quantum key includes any one of a shared key pair of symmetric encryption, a public-private key pair of asymmetric encryption, and a temporary key of hybrid encryption.
10. A quantum key generation method based on quantum random numbers, applicable to the quantum random number security chip as claimed in any one of claims 6 to 9, characterized in that: The quantum key generation method based on quantum random numbers includes: In response to receiving a quantum key generation request, converting an optical signal of a continuous light source into an electrical signal; Processing the electrical signal of the continuous light source based on a homodyne detection method to generate a quantum entropy source analog signal; Performing randomness extraction processing on the quantum entropy source analog signal to obtain a quantum random number; The quantum random number is encrypted and decrypted to obtain a target quantum key.