A method and device for preventing ciphertext replay during quantum secure key relay encryption

By setting a reordered packet sequence number window and encryption header legitimacy check at the receiving end, the replayed ciphertext is identified and excluded, solving the ciphertext replay attack problem in quantum secure key relay encryption communication and ensuring the security and integrity of data transmission.

CN119544269BActive Publication Date: 2025-10-24MATRICTIME DIGITAL TECH CO LTD
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202411555200.3
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2024-11-04
Publication Date
2025-10-24
Estimated Expiration
2044-11-04

AI Technical Summary

Technical Problem

The existing quantum secure key relay encryption communication method cannot effectively resist ciphertext replay attacks, which threatens the security and stability of the communication process.

Method used

By setting a window for random packet sequence numbers at the receiving end, determining the positional relationship of packet sequence numbers, and combining the legitimacy check of the encryption header and the hash algorithm, replayed ciphertext can be identified and excluded to ensure the legitimacy and integrity of the ciphertext data.

Benefits of technology

Effectively identify and eliminate replayed ciphertext, maintain the security and integrity of data transmission, and improve the reliability and flexibility of communications.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN119544269B_ABST
    Figure CN119544269B_ABST
Patent Text Reader

Abstract

The application discloses a method and device for preventing ciphertext replay in quantum secure key relay encryption. When receiving ciphertext data, the legality of the ciphertext data is verified first to ensure the integrity and reliability of the data carried in the ciphertext data, which is a basic step for determining whether the ciphertext data is replayed ciphertext. In the case of determining that the received ciphertext data is legal, if the packet sequence number is located in the saved out-of-order packet sequence number window and the ciphertext data carrying the packet sequence number has been successfully processed, the ciphertext data is determined to be replayed ciphertext; if the packet sequence number is located before the out-of-order packet sequence number window, the ciphertext data is determined to be replayed ciphertext. Through the mechanism, the receiving end can accurately identify and exclude the replayed ciphertext data, thereby effectively maintaining the security and integrity of data transmission. The preset out-of-order packet sequence number window provides a reasonable range, allowing the receiving end to flexibly process out-of-order data packets without affecting the integrity of the data.
Need to check novelty before this filing date? Find Prior Art

Description

TECHNICAL FIELD

[0001] The present application relates to the field of information security and quantum encryption technology, and particularly relates to a method and device for preventing ciphertext replay in quantum secure key relay encryption. BACKGROUND

[0002] With the rapid progress of information technology, network communication security has become a global focus. In this context, the global quantum secure network, as an innovative network architecture, aims to use the unique advantages of quantum technology to provide unprecedented security for network communication. Among them, quantum secure key relay encryption communication plays a crucial role as the core communication mode of the global quantum secure network.

[0003] Quantum secure key relay encryption communication, through the access base station and the relay function of the quantum secure network, skillfully realizes the key sharing and encryption communication between any two quantum secure terminals without direct symmetric keys. This communication mode not only greatly improves the security of the communication process, but also significantly enhances the flexibility and scalability of the network. Through quantum secure key relay encryption communication, even if two quantum secure terminals in the global quantum secure network do not have pre-shared keys, they can quickly and securely perform quantum secure encryption communication when needed, thereby ensuring the confidentiality and integrity of information.

[0004] However, although quantum secure key relay encryption communication has many advantages, it still faces serious security threats in practical application, especially replay attacks. Replay attack is a malicious behavior, attackers capture and resend legitimate ciphertext data, use these data packets that have been normally encrypted to make them pass through the encryption layer verification and be decrypted smoothly. Once these replayed data packets are mistakenly delivered to the business layer, it may cause confusion of business logic, incorrect interpretation of data, and even cause the entire system to crash, thereby posing a serious threat to the security and stability of network communication.

[0005] In order to effectively deal with replay attacks, although a unique key can be allocated and used for each data to be encrypted in the encryption process, i.e. the so-called "one-time key" strategy, the decryption end needs to be able to reliably identify and decrypt these messages encrypted using different keys, while ensuring that each key is only used once in the decryption process. This not only increases the complexity and difficulty of communication, but also puts higher requirements on key management.

[0006] Therefore, how to prevent ciphertext replay attacks in quantum secure key relay encryption has become a key technical problem that needs to be solved in the construction of the global quantum secure network. SUMMARY

[0007] The application provides a method and device for preventing ciphertext replay during quantum secure key relay encryption, to solve the problem that the existing quantum secure key relay encryption communication mode cannot effectively resist ciphertext replay attacks.

[0008] In a first aspect, the application provides a method for preventing ciphertext replay during quantum secure key relay encryption, which is applied to any quantum secure terminal that is connected to a global quantum secure network, and the method comprises the following steps:

[0009] If the received ciphertext data is determined to be legitimate, a saved out-of-order packet sequence number window is obtained, wherein the range of the out-of-order packet sequence number window is [q-m, q], q is the maximum packet sequence number successfully processed from the ciphertext data carried by the sending end, m is a preset window length, and q and m are both integers greater than 0;

[0010] If the packet sequence number is located in the out-of-order packet sequence number window and the ciphertext data carrying the packet sequence number has been successfully processed, the ciphertext data is determined to be replayed ciphertext.

[0011] If the packet sequence number is located before the out-of-order packet sequence number window, the ciphertext data is determined to be replayed ciphertext.

[0012] In a second aspect, the application provides a device for preventing ciphertext replay during quantum secure key relay encryption, which is applied to any quantum secure terminal that is connected to a global quantum secure network, and the device comprises the following steps:

[0013] A first processing unit is configured to obtain a saved out-of-order packet sequence number window if the received ciphertext data is determined to be legitimate, wherein the range of the out-of-order packet sequence number window is [q-m, q], q is the maximum packet sequence number successfully processed from the ciphertext data carried by the sending end, m is a preset window length, and q and m are both integers greater than 0;

[0014] A second processing unit is configured to determine the ciphertext data to be replayed ciphertext if the packet sequence number is located in the out-of-order packet sequence number window and the ciphertext data carrying the packet sequence number has been successfully processed, or to determine the ciphertext data to be replayed ciphertext if the packet sequence number is located before the out-of-order packet sequence number window.

[0015] In a third aspect, the application further provides a quantum secure terminal, which comprises a processor and a memory.

[0016] The processor is configured to execute the method for preventing ciphertext replay during quantum secure key relay encryption by calling programs or instructions stored in the memory.

[0017] In a fourth aspect, the present application also provides a computer readable storage medium storing a program or instructions, which cause a computer to execute the method for preventing ciphertext replay when quantum secure key relay encryption.

[0018] In a fifth aspect, the present application also provides a computer program product comprising computer program code which, when executed on a computer, causes the computer to execute the method for preventing ciphertext replay when quantum secure key relay encryption.

[0019] The present application has the following beneficial effects:

[0020] 1. When receiving ciphertext data, the legality of the ciphertext data is verified first to ensure the integrity and reliability of the data carried in the ciphertext data, which is a basic step for determining whether the ciphertext data is replayed ciphertext.

[0021] 2. When the received ciphertext data is determined to be legal, if the packet sequence number is within the saved out-of-order packet sequence number window and the ciphertext data carrying the packet sequence number has been successfully processed, the ciphertext data is determined to be replayed ciphertext; if the packet sequence number is before the out-of-order packet sequence number window, the ciphertext data is determined to be replayed ciphertext. Through this mechanism, the receiving end can accurately identify and exclude the replayed ciphertext data, thereby effectively maintaining the security and integrity of data transmission.

[0022] 3. The preset out-of-order packet sequence number window provides a reasonable range, allowing the receiving end to flexibly process out-of-order data packets without affecting data integrity. BRIEF DESCRIPTION OF DRAWINGS

[0023] In order to more clearly illustrate the technical solutions in the embodiments of the present application, the drawings needed in the embodiment description will be briefly introduced. Obviously, the drawings in the following description are only some embodiments of the present application, and other drawings can be obtained by those skilled in the art without creative labor.

[0024] Figure 1 A process diagram for preventing ciphertext replay when quantum secure key relay encryption is provided for the embodiments of the present application;

[0025] Figure 2 A specific process diagram for preventing ciphertext replay when quantum secure key relay encryption is provided for the embodiments of the present application;

[0026] Figure 3 A structure diagram of a device for preventing ciphertext replay when quantum secure key relay encryption is provided for the present application;

[0027] Figure 4 A structure diagram of a quantum security terminal provided by an embodiment of the present application. DETAILED DESCRIPTION

[0028] In order to make the purposes, technical solutions and advantages of the present application clearer, the present application will be further described in detail below with reference to the drawings. Obviously, the described embodiments are only some of the embodiments of the present application, but not all the embodiments of the present application. Based on the embodiments in the present application, all other embodiments obtained by those skilled in the art without creative work fall within the scope of protection of the present application.

[0029] The global quantum security network can support secure and efficient quantum communication between quantum security terminals accessing the global quantum security network, regardless of geographical location. A core of the global quantum security network is to use an access base station as a communication hub to access the global quantum security network for quantum security terminals, and to realize key relaying between terminals accessing the quantum security network.

[0030] In the access process, when a quantum security terminal accesses an access base station, the access base station allocates an access identifier for the quantum security terminal, i.e., a unique terminal identifier of the entire quantum security network, to identify the quantum security terminal. The access identifier carries information of a country, an operator, a large area, a small area, an access base station and a quantum security terminal. With the access identifier, the quantum security terminal can be determined in the global quantum security network within a time range in which the quantum security terminal has the access identifier. The quantum security terminal can then apply for services and request resources from the global quantum security network through the access base station.

[0031] In the key relaying process, the sending end relays the key through the sending end access base station to the decryption end access base station via the quantum security network, and then the decryption end access base station forwards the key to the decryption end, so as to form a symmetric quantum security key between the sending end and the decryption end, which can encrypt and decrypt communication. The global quantum security network also includes a key center, which mainly distributes keys, i.e., quantum keys, for quantum security terminals accessing the global quantum security network.

[0032] The global quantum security network can separate the key relaying process from the ciphertext data transmission process, thereby further improving the security of the ciphertext data transmission. However, the quantum security key relaying encryption communication method has the following problems:

[0033] In the data transmission process, an attacker captures and repeatedly sends legitimate ciphertext data, and uses the characteristics that the ciphertext data has been normally encrypted to make it pass the verification of the receiving end encryption layer and be decrypted. Once these replayed data packets are mistakenly delivered to the business layer, it may cause confusion of business logic, misinterpretation of data, and even cause the entire system to be paralyzed, thereby posing a serious threat to the security and stability of network communication.

[0034] To solve the above problems, the application provides a method and device for preventing ciphertext replay during quantum secure key relay encryption, so as to enable the receiving end to effectively cope with ciphertext replay attacks in the quantum secure key relay encryption communication mode and improve communication security.

[0035] Embodiment 1:

[0036] Figure 1 A process schematic diagram for preventing ciphertext replay during quantum secure key relay encryption is provided for the embodiments of the application, and the process includes:

[0037] S101: In the case where the received ciphertext data is determined to be legitimate, the saved out-of-order packet sequence number window is obtained; wherein the range of the out-of-order packet sequence number window is [q-m, q], q is the maximum packet sequence number carried by the ciphertext data successfully processed from the sending end, m is a preset window length, and q and m are both integers greater than 0.

[0038] For any quantum security terminal that joins the global quantum security network, the quantum security terminal can receive the ciphertext data sent by another quantum security terminal (for the sake of convenience, the quantum security terminal that sends the ciphertext data is referred to as the sending end) that joins the global quantum security network through the traditional network. At the same time, the quantum key relayed by the sending end can also be received through the global quantum security network. After receiving the ciphertext data, the receiving end can perform a legality check on the ciphertext data. If it is determined that the ciphertext data passes the legality check, it means that the ciphertext data is legitimate, but it is not determined whether the ciphertext data is a replayed ciphertext or normally received ciphertext data, so the method for preventing ciphertext replay during quantum secure key relay encryption provided by the application is used to further determine whether the ciphertext data is a replayed ciphertext. If it is determined that the ciphertext data does not pass the legality check, it means that the ciphertext data is not legitimate, and the ciphertext data cannot be a replayed ciphertext, so the ciphertext data is discarded.

[0039] In an example, the ciphertext data can be determined to be legal by checking the data carried in the encryption header of the ciphertext data. The data carried in the encryption header includes but is not limited to: session index of the receiving end, pairing index of the quantum key, and packet sequence number of the ciphertext data. The pairing index is used to indicate that the receiving end locates the quantum key corresponding to the ciphertext data from the relay key obtained from the global quantum secure network. The packet sequence number is used to indicate the sending order of the current data packet. For example, the receiving end and the sending end have previously agreed on a hash algorithm of the encryption header, and the ciphertext data carries a checksum of the encryption header determined by the sending end according to the hash algorithm (for the sake of distinction, the checksum determined by the sending end is denoted as K). After receiving the ciphertext data, the receiving end can determine the checksum of the encryption header (for the sake of distinction, the checksum determined by the receiving end is denoted as K') based on the data carried in the encryption header according to the hash algorithm agreed in advance. The receiving end determines whether the ciphertext data is legal by comparing whether K' is consistent with K carried in the ciphertext data. Specifically, if K' is consistent with K carried in the ciphertext data, it is determined that the ciphertext data is legal; if K' is not consistent with K carried in the ciphertext data, it is determined that the ciphertext data is fake.

[0040] In a possible implementation, the receiving end can perform format checking on the encryption header of the received ciphertext data before performing checksum checking and comparison on the encryption header, so as to identify fake ciphertexts with format not meeting requirements in time. For example, the length of the data carried in the encryption header meets a preset data length range, and the data carried in the encryption header is of a predetermined type. The receiving end further performs checksum checking and comparison on the encryption header of the ciphertext data only when it is determined that the format of the encryption header of the ciphertext data passes the format checking. If the receiving end determines that the format of the encryption header of the ciphertext data does not pass the format checking, it means that the ciphertext data is fake, and the receiving end rejects the ciphertext data.

[0041] For example, in the case where the device structure of the receiving end includes an encryption area, an isolation area, and a communication area, the encryption area is connected with the isolation area, and the isolation area is connected with the communication area, the communication area of the receiving end can deliver the ciphertext data to the isolation area of the receiving end after receiving the ciphertext data. The isolation area can perform format checking on the encryption header of the ciphertext data. The isolation area delivers the ciphertext data to the encryption area only when it is determined that the format of the encryption header passes the format checking, so that the encryption area performs checksum checking and comparison on the encryption header of the ciphertext data; the isolation area can directly discard the fake ciphertext data when it is determined that the format of the encryption header does not pass the format checking, so that the fake ciphertext data cannot enter the encryption area of the receiving end, which is beneficial to ensuring the security of the encryption area.

[0042] In actual application scenarios, the transmission between the receiving end and the sending end can be reliable and in-sequence transmission or unreliable transmission. In the reliable and in-sequence transmission, the packet sequence number carried by the ciphertext data received by the receiving end from the sending end is continuous and each packet sequence number is unique and non-repeated, so the receiving end can confirm whether the ciphertext data is replayed ciphertext by comparing the packet sequence numbers. In the unreliable transmission, problems such as network congestion and delay can occur, which can cause unstable data transmission. In addition, there is a risk of counterfeiters counterfeiting ciphertext data. In the face of such a situation, the receiving end needs to take strict security measures to verify the packet sequence number to ensure that the legal ciphertext data will not be discarded by mistake, and at the same time accurately identify and exclude the counterfeit ciphertext data, so as to maintain the security and integrity of data transmission. Specifically, when the receiving end determines that the received ciphertext data is legal, it obtains the out-of-sequence packet sequence number window associated with the sending end previously saved. Then, based on the positional relationship between the packet sequence number and the out-of-sequence packet sequence number window, the receiving end can further determine whether the ciphertext data is replayed ciphertext. Through the out-of-sequence packet sequence number window, it is realized that the reliable and in-sequence transmission scenario can support the judgment of whether the ciphertext data is replayed ciphertext, and the unreliable transmission scenario can also support the judgment of whether the ciphertext data is replayed ciphertext.

[0043] wherein the range of the out-of-sequence packet sequence number window is set as [q-m, q], wherein q represents the maximum packet sequence number successfully processed by the receiving end from the ciphertext data carried by the sending end, and m is a preset window length, both of which are integers greater than 0. The out-of-sequence packet sequence number window indicates that the receiving end can receive out-of-sequence ciphertext data within a certain packet sequence number range.

[0044] It should be noted that in the reliable and in-sequence transmission scenario, the window length of the out-of-sequence packet sequence number window can be 1.

[0045] In a possible implementation, the window length m of the out-of-sequence packet sequence number window can be determined according to the number of ciphertext data that can be received within a unit time, for example, 300 ciphertext data can be received within one minute, and the maximum delay receiving time length of the ciphertext data, for example, 3 minutes. For example, the product of the number of ciphertext data that can be received within a unit time and the maximum delay receiving time length of the ciphertext data is determined as m.

[0046] S102: If the packet sequence number is located in the out-of-sequence packet sequence number window, and the ciphertext data carrying the packet sequence number has been successfully processed, it is determined that the ciphertext data is replayed ciphertext.

[0047] S103: If the packet sequence number is located before the out-of-sequence packet sequence number window, it is determined that the ciphertext data is replayed ciphertext.

[0048] The following describes four cases of determining whether the ciphertext data is a replay ciphertext based on the positional relationship between the packet sequence number and the out-of-order packet sequence number window:

[0049] Case one: the packet sequence number is within the out-of-order packet sequence number window, and the ciphertext data carrying the packet sequence number has been successfully processed.

[0050] When the packet sequence number of the received ciphertext data falls within the out-of-order packet sequence number window [q-m, q], and it is found that the ciphertext data corresponding to the packet sequence number has been successfully processed, it usually means that the ciphertext data is a replay ciphertext. Because in a reliable transmission protocol, the same packet sequence number should not correspond to different ciphertext data. Therefore, if the receiving end determines that the packet sequence number is within the out-of-order packet sequence number window, and the ciphertext data carrying the packet sequence number has been successfully processed, it is determined that the ciphertext data is a replay ciphertext.

[0051] Case two: the packet sequence number is within the out-of-order packet sequence number window, and the ciphertext data carrying the packet sequence number has not been successfully processed.

[0052] If the packet sequence number of the received ciphertext data also falls within the out-of-order packet sequence number window [q-m, q], but it is determined that the ciphertext data corresponding to the packet sequence number has not been successfully processed, it is very likely to be a normal out-of-order reception case. Therefore, if the receiving end determines that the packet sequence number is within the out-of-order packet sequence number window, and the ciphertext data carrying the packet sequence number has not been successfully processed, it is determined that the ciphertext data is not a replay ciphertext.

[0053] Case three: the packet sequence number is before the out-of-order packet sequence number window.

[0054] When the packet sequence number of the received ciphertext data is less than q-m, i.e., before the out-of-order packet sequence number window, it usually indicates that the ciphertext data is an outdated data packet, which may be caused by network delay or errors of the sending end, or may be a replay ciphertext sent by a forger. In this case, whether the ciphertext data with the same packet sequence number has been successfully processed before or not, the ciphertext data is not suitable for being processed as a compliant ciphertext data. Therefore, if the receiving end determines that the packet sequence number is before the out-of-order packet sequence number window, the receiving end can consider that the ciphertext data is a replay ciphertext.

[0055] Case four: the packet sequence number is after the out-of-order packet sequence number window.

[0056] When the packet sequence number of the ciphertext data is greater than the maximum packet sequence number in the current out-of-order packet sequence number window, i.e., the packet sequence number is behind the out-of-order packet sequence number window, since q in the current out-of-order packet sequence number window represents the maximum packet sequence number successfully processed from the ciphertext data carried by the sending end, the legitimate ciphertext data sent in the order behind q should also be logically unprocessed by the receiving end. This means that if the received ciphertext data carries a packet sequence number greater than q, the ciphertext data is likely to be the first arrival and unprocessed, and therefore it can be only a normal out-of-order reception or a normal reliable in-order transmission. Based on this, if the receiving end determines that the packet sequence number is behind the out-of-order packet sequence number window, it is determined that the ciphertext data is not a replayed ciphertext.

[0057] In a possible implementation, if the ciphertext data is determined to be a replayed ciphertext data based on the above embodiment, the ciphertext data is discarded.

[0058] Generally, the sending end relays the quantum key corresponding to the ciphertext data to the receiving end through the global quantum secure network while sending the ciphertext data, and the receiving end can receive the quantum keys relayed by each sending end through the global quantum secure network. In the case where the receiving end determines that the received ciphertext data is not a replayed ciphertext based on the above embodiment, the ciphertext data can be paired with the quantum key relayed to the receiving end based on the pairing index carried in the encryption header of the ciphertext data. The pairing here refers to determining the quantum key carrying the pairing index. If the quantum key corresponding to the ciphertext data is found, the ciphertext data is decrypted based on the quantum key corresponding to the ciphertext data to obtain the plaintext data. If the quantum key corresponding to the ciphertext data is not found, the ciphertext data is cached until the quantum key corresponding to the ciphertext data is found.

[0059] After the receiving end successfully decrypts the ciphertext data and recovers the plaintext data, in order to ensure the correctness of the decryption process and the integrity and authenticity of the plaintext data, the receiving end can perform a hash check (for example, SHA-256, MD5, or other hash algorithms) on the plaintext data. Only when it is determined that the plaintext data passes the hash check, it is determined that the ciphertext data is correctly decrypted, i.e., the ciphertext data is successfully processed. If it is determined that the plaintext data does not pass the hash check, it means that the decryption of the ciphertext data fails, and the plaintext data is discarded.

[0060] In a possible implementation, based on the successful processing of the ciphertext data in the above embodiment, if the packet sequence number carried by the ciphertext data is greater than the current recorded maximum packet sequence number, the out-of-order packet sequence number window needs to be updated in time according to the packet sequence number, that is, the out-of-order packet sequence number window is slid to the packet sequence number. For example, the current packet sequence number is q+2, and the saved out-of-order packet sequence number window is [q-m, q], the out-of-order packet sequence number window [q-m, q] is slid to q+2, and the slid out-of-order packet sequence number window is [q-m+2, q+2]. For another example, the current packet sequence number is q+1, and the saved out-of-order packet sequence number window is [q-m, q], the out-of-order packet sequence number window [q-m, q] is slid to q+1, and the slid out-of-order packet sequence number window is [q-m+1, q+1].

[0061] The beneficial effects of the present application are as follows:

[0062] 1. When receiving the ciphertext data, the legality of the ciphertext data is verified first to ensure the integrity and reliability of the data carried in the ciphertext data, which is a basic step for determining whether the ciphertext data is a replayed ciphertext.

[0063] 2. In the case where the received ciphertext data is determined to be legal, if the packet sequence number is located in the saved out-of-order packet sequence number window, and the ciphertext data carrying the packet sequence number has been successfully processed, the ciphertext data is determined to be a replayed ciphertext; if the packet sequence number is located before the out-of-order packet sequence number window, the ciphertext data is determined to be a replayed ciphertext. Through this mechanism, the receiving end can accurately identify and exclude the replayed ciphertext data, thereby effectively maintaining the security and integrity of data transmission.

[0064] 3. The preset out-of-order packet sequence number window provides a reasonable range, allowing the receiving end to flexibly process out-of-order data packets without affecting the integrity of the data.

[0065] Embodiment 2:

[0066] In order to ensure the legality of the ciphertext data, based on the above embodiment, in the present application, determining that the ciphertext data is legal comprises:

[0067] Based on the session index carried in the encryption header, an irreducible polynomial and an anti-fake true random number are obtained; wherein the sending end and the quantum security terminal have previously agreed on the irreducible polynomial, the anti-fake true random number, and the session index corresponding to the sending end and the quantum security terminal respectively;

[0068] Based on the irreducible polynomial and the anti-fake true random number, a Toeplitz matrix is determined;

[0069] The session index, the pairing index carried in the encryption header and the packet sequence number are hashed by the Toeplitz matrix to determine an anti-fake hash value H';

[0070] If it is determined that the H' is consistent with the H carried in the ciphertext data, it is determined that the ciphertext data is legitimate.

[0071] In a global quantum secure network, it is crucial to ensure the security of quantum secure key relay encrypted communication and the integrity of data. In order to achieve this goal, any two quantum secure terminals joined in the global quantum secure network need to agree on the irreducible polynomial, the anti-fake true random number and the session index corresponding to the two quantum secure terminals respectively before formally carrying out quantum secure key relay encrypted communication. Through these key parameters, combined with the feature data of the current session of the two quantum secure terminals, the anti-fake mark required for each session of the two quantum secure terminals, the anti-fake hash value, is generated. This anti-fake hash value not only contains the feature information of the current session, but also incorporates the randomness of the irreducible polynomial and the anti-fake true random number, so that it is difficult for a forger to generate a valid hash value by simply algorithmic attack. Even if the forger can partially crack or forge the hash algorithm, they cannot accurately predict or copy the irreducible polynomial and the anti-fake true random number, so they still cannot generate a fake hash value that can deceive the receiving end.

[0072] Among them, the way these two quantum secure terminals agree on these key parameters can be achieved by manually charging the key parameters to the two quantum secure terminals.

[0073] Based on the above embodiment, after the two quantum secure terminals that need to communicate determine the irreducible polynomial, the anti-fake true random number and the session index of the two quantum secure terminals respectively, they can carry out formal quantum secure key relay encrypted communication.

[0074] Illustratively, the following is described by a specific quantum secure key relay encrypted communication process:

[0075] In the case where there is plaintext data that needs to be sent to the receiving end at the sending end, the sending end obtains quantum keys for the plaintext data from the saved key pool. For example, according to the data length of the plaintext data and the pre-configured encryption ratio, the quantum keys are determined from the saved key pool. Among them, the encryption ratio is used to indicate the ratio between each bit of quantum key and the length of data that each bit of quantum key can encrypt.

[0076] The sender can then use a pre-configured quantum encryption algorithm and the quantum key to quantum encrypt the plaintext data to obtain ciphertext data. For example, the sender uses the quantum key to encrypt the plaintext data according to the encryption ratio and the pre-configured quantum encryption algorithm to obtain ciphertext data. The encryption header of the ciphertext data is determined based on the stored session index of the receiver, the pairing index of the quantum key, and the packet sequence number of the ciphertext data. The encryption header is assembled with the ciphertext data. The session index of the receiver indicates the irreducible polynomial and anti-counterfeiting true random number required for the receiver to distinguish different sessions and locate the current session.

[0077] To prevent ciphertext data from being forged, the present application also determines a Toplitz matrix based on an irreducible polynomial and a true random number. Using this Toplitz matrix, a hash calculation is performed on the current session's feature information (including the session index, pairing index, and packet sequence number) to determine an anti-counterfeiting hash value. (For ease of description, the following embodiments may represent the anti-counterfeiting hash value determined by the sender as H.)

[0078] For example, the irreducible polynomial p and the anti-counterfeiting true random number s are used as parameters to generate a Toplitz matrix, including:

[0079] 1) The number of rows and columns of the Toplitz matrix is ​​related to the degree of the irreducible polynomial p: Assume that the highest-degree index of p is n;

[0080] 2) The elements of the first row are equal to the elements of the anti-counterfeiting true random number s;

[0081] 3) Starting from the second row, the elements of each row are equal to the elements of the previous row shifted right by one position and multiplied by the coefficient of the irreducible polynomial p;

[0082] 4) For the anti-counterfeiting true random number s=[s0,s1,…,s n-1 ] and the irreducible polynomial p=a0*x^0+a1*x^1+…+a n-1 *x^(n-1), the i-th row of the Toplitz matrix T will be [s i , s i-1 *a0,s i-2 *a1,…,s i-n+1 *a n-2 , s i-n *a n-1 ].

[0083] 5) According to the dimension of the Toeplitz matrix, the size of the data block is determined, and then the combined feature data of the session index, the pairing index and the packet sequence number, for example, the combined feature data is represented as session index || pairing index || packet sequence number length, etc., is divided into several data blocks according to the size of the data block. For example: M = [m0, m1, …], where m represents the data block obtained by division, and M is the combined feature data;

[0084] 6) Each data block is taken as a column vector; for each data block, it is multiplied by the Toeplitz matrix T, and the hash value of the first row of the multiplication result is obtained;

[0085] 7) Repeat the above step 6), multiply each data block, and combine the first row of each result to form the final hash value H(M) = [h0, h1, …].

[0086] Based on the above embodiment, the sender obtains H, which can be encapsulated into the ciphertext data. Then through the traditional network, the ciphertext data carrying H is sent to the receiver.

[0087] At the same time, the sender also needs to relay the quantum key to the receiver through the global quantum secure network. For example, the sender sends the key index of the quantum key and the second network access identifier to the access base station (denoted as the first access base station) accessed by the sender. The first access base station obtains the quantum key from the key pool paired with the sender based on the key index. Then the first access base station relays the quantum key and the second network access identifier to the access base station (denoted as the second access base station) accessed by the receiver according to the second network access identifier. The second access base station can encrypt and send the quantum key to the receiver according to the second network access identifier.

[0088] For the receiver, after receiving the ciphertext data sent by the sender, the receiver can parse the ciphertext data to obtain the session index, pairing index and packet sequence number carried in the encryption header of the ciphertext data. Then the same method as the above sender is used to verify the legitimacy of the ciphertext data based on the session index, pairing index and packet sequence number, combined with the saved irreducible polynomial and anti-false random number, to determine whether the ciphertext data is a fake ciphertext. For example, the receiver obtains the session index carried in the encryption header of the ciphertext data, and then locates the irreducible polynomial and the anti-false random number pre-agreed for the session according to the session index. Then based on the irreducible polynomial and the anti-false random number, the Toeplitz matrix is determined. The session index, pairing index and packet sequence number carried in the encryption header of the ciphertext data are calculated by the Toeplitz matrix, so as to determine the anti-fake hash value (in order to distinguish, the anti-fake hash value determined by the receiver in the following embodiment can be represented as H').

[0089] In a normal case, the method for determining the anti-fake hash value, the required irreducible polynomial and the anti-fake true random number are all secret information unique to the sending end and the receiving end. The same method and consistent data are used to calculate the same anti-fake hash value. For a forger, since he cannot obtain the irreducible polynomial and the anti-fake true random number used by the sending end and the receiving end to generate the anti-fake hash value, and the irreducible polynomial and the anti-fake true random number are not transmitted in the quantum secure key relay encryption communication process, it is difficult for the forger to generate an effective hash value, i.e., the same anti-fake hash value as the receiving end, by simply using algorithm attack means. Therefore, in the present application, after the receiving end obtains H', the receiving end can compare H' with H carried in the ciphertext data to ensure the authenticity and integrity of the ciphertext data. If H is consistent with H', it is proved that the ciphertext data is indeed generated by the sending end, and it is determined that the ciphertext data is legal. If H is inconsistent with H', it is proved that the ciphertext data may be forged by a forger, and it is determined that the ciphertext data is a forged ciphertext.

[0090] Embodiment 3

[0091] A method for preventing ciphertext replay in quantum secure key relay encryption provided by the present application is described below through specific embodiments, Figure 2 A specific flowchart for preventing ciphertext replay in quantum secure key relay encryption provided by the present application is shown in the figure, and the flowchart includes:

[0092] S201: receiving the ciphertext data sent by the sending end.

[0093] S202: determining whether the ciphertext data passes the legality check. If it is determined that the ciphertext data is legal, S203 is executed, otherwise, S212 is executed.

[0094] In a possible implementation, determining whether the ciphertext data is legal includes:

[0095] Based on the session index carried in the encryption header, the irreducible polynomial and the anti-fake true random number are obtained; wherein the sending end and the quantum secure terminal have previously agreed on the irreducible polynomial, the anti-fake true random number and the session indexes corresponding to the sending end and the quantum secure terminal respectively;

[0096] Based on the irreducible polynomial and the anti-fake true random number, the Toeplitz matrix is determined;

[0097] The session index, the pairing index and the packet sequence number carried in the encryption header are hashed by the Toeplitz matrix to determine the anti-fake hash value H';

[0098] If it is determined that H' is consistent with H carried in the ciphertext data, it is determined that the ciphertext data is legal;

[0099] If it is determined that H' is inconsistent with H carried in the ciphertext data, it is determined that the ciphertext data is fake ciphertext.

[0100] S203: Obtain an out-of-order packet sequence number window associated with the sending end.

[0101] The range of the out-of-order packet sequence number window is [q-m, q], q is the maximum packet sequence number successfully processed from the ciphertext data carried by the sending end, and m is a preset window length, q and m are both integers greater than 0.

[0102] S204: If the packet sequence number is located in the out-of-order packet sequence number window, and the ciphertext data carrying the packet sequence number has been successfully processed, it is determined that the ciphertext data is replayed ciphertext, and S212 is executed.

[0103] S205: If the packet sequence number is located before the out-of-order packet sequence number window, it is determined that the ciphertext data is replayed ciphertext, and S212 is executed.

[0104] S206: If the packet sequence number is located in the out-of-order packet sequence number window, and the ciphertext data carrying the packet sequence number has not been successfully processed, it is determined that the ciphertext data is not replayed ciphertext, and S208 is executed.

[0105] S207: If the packet sequence number is located after the out-of-order packet sequence number window, it is determined that the ciphertext data is not replayed ciphertext.

[0106] S208: Based on the pairing index carried by the encryption header, the ciphertext data is paired with the quantum key relayed to the quantum security terminal through the global quantum security network to determine the quantum key corresponding to the ciphertext data, and the ciphertext data is decrypted through the quantum key corresponding to the ciphertext data to obtain plaintext data.

[0107] S209: In the case where it is determined that the plaintext data passes the hash check, it is determined that the ciphertext data is successfully processed.

[0108] S210: Determine whether the packet sequence number is greater than the maximum packet sequence number, if yes, execute S211, otherwise, execute S201.

[0109] S211: Slide the out-of-order packet sequence number window to the packet sequence number, and execute S201.

[0110] S212: Discard the ciphertext data, and execute S201.

[0111] Embodiment 4:

[0112] Based on the same inventive concept, the application also provides a device for preventing ciphertext replay during quantum security key relay encryption, which is applied to a sending end joined to a global quantum security network, Figure 3A structure diagram of a device for preventing ciphertext replay in quantum secure key relay encryption is provided in the present application, and the device comprises:

[0113] The first processing unit 31 is configured to acquire a saved out-of-order packet sequence number window in a case where it is determined that the received ciphertext data is legitimate; wherein the range of the out-of-order packet sequence number window is [q-m, q], q is the maximum packet sequence number successfully processed from the ciphertext data carried by the sending end, m is a preset window length, and q and m are both integers greater than 0.

[0114] The second processing unit 32 is configured to determine that the ciphertext data is replay ciphertext if the packet sequence number is located in the out-of-order packet sequence number window and the ciphertext data carrying the packet sequence number has been successfully processed, or determine that the ciphertext data is replay ciphertext if the packet sequence number is located before the out-of-order packet sequence number window.

[0115] In some possible implementation manners, the second processing unit 32 is further configured to determine that the ciphertext data is not replay ciphertext if the packet sequence number is located in the out-of-order packet sequence number window and the ciphertext data carrying the packet sequence number has not been successfully processed, or determine that the ciphertext data is not replay ciphertext if the packet sequence number is located after the out-of-order packet sequence number window.

[0116] In some possible implementation manners, the device further comprises an encryption and decryption unit.

[0117] The encryption and decryption unit is configured to pair the ciphertext data with a quantum key relayed to the quantum secure terminal through a global quantum secure network based on the pairing index carried by the encryption header, to determine the quantum key corresponding to the ciphertext data; decrypt the ciphertext data through the quantum key corresponding to the ciphertext data, to obtain plaintext data; and record that the ciphertext data is successfully processed in a case where it is determined that the plaintext data passes a hash check.

[0118] In some possible implementation manners, the first processing unit 31 is further configured to slide the out-of-order packet sequence number window to the packet sequence number in a case where the packet sequence number is greater than the maximum packet sequence number.

[0119] In some possible implementation manners, m is determined according to the number of ciphertext data that can be received in a unit time length and the maximum delay receiving time length of the ciphertext data.

[0120] In some possible implementation manners, the first processing unit 31 is specifically configured to obtain an irreducible polynomial and an anti-counterfeit true random number based on the session index carried in the encryption header; the sending end and the quantum security terminal have the irreducible polynomial, the anti-counterfeit true random number, and the session indexes corresponding to the sending end and the quantum security terminal respectively agreed in advance; a Toeplitz matrix is determined based on the irreducible polynomial and the anti-counterfeit true random number; the session index, the pairing index carried in the encryption header, and the packet sequence number are subjected to hash calculation through the Toeplitz matrix to determine an anti-counterfeit hash value H'; and if it is determined that the H' is consistent with H carried in the ciphertext data, it is determined that the ciphertext data is legitimate.

[0121] It should be noted that the principle of solving the technical problems of the ciphertext replay device provided in the embodiment of preventing quantum security key relay encryption is the same as the principle of solving the technical problems in the above method embodiments, and the repeated parts will not be described herein.

[0122] Embodiment 5:

[0123] On the basis of the above-mentioned embodiments, the quantum security terminal provided in the embodiments of the present application further comprises: Figure 4 A structure diagram of the quantum security terminal provided in the embodiments of the present application is shown in FIG. 5, which comprises a processor 41, a communication interface 42, a memory 43, and a communication bus 44, wherein the processor 41, the communication interface 42, and the memory 43 complete mutual communication through the communication bus 44. Figure 4

[0124] The memory 43 stores a computer program, and when the program is executed by the processor 41, the processor 41 can execute the following steps:

[0125] In a case where it is determined that the received ciphertext data is legitimate, a saved out-of-order packet sequence number window is obtained; the range of the out-of-order packet sequence number window is [q-m, q], q is a maximum packet sequence number carried in the ciphertext data successfully processed from the sending end, m is a preset window length, and q and m are both integers greater than 0.

[0126] If the packet sequence number is located in the out-of-order packet sequence number window and the ciphertext data carrying the packet sequence number has been successfully processed, the ciphertext data is determined to be replayed ciphertext.

[0127] If the packet sequence number is located before the out-of-order packet sequence number window, the ciphertext data is determined to be replayed ciphertext.

[0128] ​Since the principle of the above quantum security terminal to solve the problem is similar to the method of preventing ciphertext replay when quantum security key relay encryption, the implementation of the above quantum security terminal can refer to the embodiments of the method, and the repeated parts will not be described again.

[0129] Embodiment 6:

[0130] On the basis of the above embodiments, the embodiment of the present application further provides a computer readable storage medium, and the computer readable storage medium stores a computer program executable by a processor. When the program runs on the processor, the processor executes the following steps:

[0131] In the case of determining that the received ciphertext data is legal, the saved out-of-order packet sequence number window is acquired; wherein the range of the out-of-order packet sequence number window is [q-m, q], the q is the maximum packet sequence number successfully processed from the ciphertext data carried by the sending end, and the m is a preset window length, and the q and the m are both integers greater than 0;

[0132] If the packet sequence number is located in the out-of-order packet sequence number window, and the ciphertext data carrying the packet sequence number has been successfully processed, it is determined that the ciphertext data is a replay ciphertext;

[0133] If the packet sequence number is located before the out-of-order packet sequence number window, it is determined that the ciphertext data is a replay ciphertext.

[0134] Since the principle of the above computer readable storage medium to solve the problem is similar to the method of preventing ciphertext replay when quantum security key relay encryption, the implementation of the above computer readable storage medium can refer to the embodiments of the method, and the repeated parts will not be described again.

Claims

1. A method for preventing ciphertext replay when quantum secure key relay is encrypted, characterized by, The method is applied to any quantum security terminal joining a global quantum security network, and the method comprises: In a case where it is determined that the received ciphertext data is legitimate, a saved out-of-order packet sequence number window is obtained; wherein the range of the out-of-order packet sequence number window is [q-m, q], q is the maximum packet sequence number successfully processed from the ciphertext data carried by the sending end, and m is a preset window length, q and m are both integers greater than 0; If the packet sequence number is located in the out-of-order packet sequence number window, and the ciphertext data carrying the packet sequence number has been successfully processed, it is determined that the ciphertext data is replayed ciphertext; If the packet sequence number is located before the out-of-order packet sequence number window, it is determined that the ciphertext data is replayed ciphertext; If the packet sequence number is located in the out-of-order packet sequence number window, and the ciphertext data carrying the packet sequence number has not been successfully processed, it is determined that the ciphertext data is not replayed ciphertext; If the packet sequence number is located after the out-of-order packet sequence number window, it is determined that the ciphertext data is not replayed ciphertext; The data carried in the encryption header of the ciphertext data is verified to determine whether the ciphertext data is legitimate, wherein the data carried in the encryption header includes but is not limited to: a session index of the receiving end, a pairing index of the quantum key, and a packet sequence number of the ciphertext data; Based on the pairing index carried in the encryption header, the ciphertext data is paired with the quantum key relayed to the quantum security terminal through the global quantum security network to determine the quantum key corresponding to the ciphertext data; The ciphertext data is decrypted through the quantum key corresponding to the ciphertext data to obtain plaintext data; In a case where it is determined that the plaintext data passes the hash verification, it is recorded that the ciphertext data is successfully processed. Wherein, determining that the ciphertext data is legitimate comprises: Based on the session index carried in the encryption header, an irreducible polynomial and an anti-fake true random number are obtained; wherein the sending end and the quantum security terminal have previously agreed on the irreducible polynomial, the anti-fake true random number, and the session index corresponding to the sending end and the quantum security terminal respectively; Based on the irreducible polynomial and the anti-fake true random number, a Toeplitz matrix is determined; The session index, the pairing index carried in the encryption header, and the packet sequence number are hashed through the Toeplitz matrix to determine an anti-fake hash value H'; If it is determined that H' is consistent with H carried in the ciphertext data, it is determined that the ciphertext data is legitimate.

2. The method of claim 1, wherein, The method further comprises: In a case where the packet sequence number is greater than the maximum packet sequence number, the out-of-order packet sequence number window is slid to the packet sequence number.

3. The method of claim 1, wherein, The m is determined according to the number of ciphertext data that can be received within a pre-configured unit time length, and the maximum delay receiving time length of the ciphertext data.

4. A device for preventing ciphertext replay during quantum secure key relay encryption, characterized in that: The device is applied to any quantum security terminal joining a global quantum security network, and is used for executing the method for preventing ciphertext replay when relaying quantum security keys, as claimed in any one of claims 1-3, and the device comprises: The first processing unit is configured to, in a case where it is determined that the received ciphertext data is legitimate, acquire a saved out-of-order packet sequence number window; wherein the range of the out-of-order packet sequence number window is [q-m, q], q is the maximum packet sequence number successfully processed from the ciphertext data carried by the sending end, m is a preset window length, q and m are both integers greater than 0, and based on the session index carried in the encryption header, an irreducible polynomial and an anti-fake true random number are acquired; wherein the sending end and the quantum security terminal have previously agreed on the irreducible polynomial, the anti-fake true random number, and the session index corresponding to the sending end and the quantum security terminal respectively; based on the irreducible polynomial and the anti-fake true random number, a Toeplitz matrix is determined; the session index, the pairing index carried in the encryption header, and the packet sequence number are subjected to hash calculation through the Toeplitz matrix to determine an anti-fake hash value H'; if it is determined that H' is consistent with H carried in the ciphertext data, it is determined that the ciphertext data is legitimate; The second processing unit is configured to, if the packet sequence number is located within the out-of-order packet sequence number window and the ciphertext data carrying the packet sequence number has been successfully processed, determine that the ciphertext data is a replay ciphertext; or, if the packet sequence number is located before the out-of-order packet sequence number window, determine that the ciphertext data is a replay ciphertext; or, if the packet sequence number is located within the out-of-order packet sequence number window and the ciphertext data carrying the packet sequence number has not been successfully processed, determine that the ciphertext data is not a replay ciphertext; or, if the packet sequence number is located after the out-of-order packet sequence number window, determine that the ciphertext data is not a replay ciphertext; The encryption and decryption unit is configured to, based on the pairing index carried in the encryption header, pair the ciphertext data with the quantum key relayed to the quantum security terminal through the global quantum security network to determine the quantum key corresponding to the ciphertext data; decrypt the ciphertext data through the quantum key corresponding to the ciphertext data to obtain plaintext data; and in a case where it is determined that the plaintext data passes the hash check, record that the ciphertext data is successfully processed.

5. A quantum secure terminal, characterized by It comprises: a processor and a memory; The processor is configured to execute the method for preventing ciphertext replay when quantum security key relay encryption is performed according to any one of claims 1-3 by calling programs or instructions stored in the memory.

6. A computer readable storage medium characterized by, The computer readable storage medium stores programs or instructions, which cause the computer to execute the method for preventing ciphertext replay when quantum security key relay encryption is performed according to any one of claims 1-3.

Citation Information

Patent Citations

  • Replay attack prevention method and device

    CN109756460A

  • Universe quantum security equipment and system

    CN115001686A