Quantum key usage methods for smart home systems

By combining quantum key distribution methods with national cryptographic algorithms, the compatibility and security issues of devices in smart home systems have been resolved, enabling device registration and dynamic key management, and improving the system's secure communication capabilities.

CN119583240BActive Publication Date: 2025-10-31JIAXING NANHU DISTRICT GUOXIN DIGITAL ECONOMY INNOVATION & DEVELOPMENT RESEARCH INSTITUTE
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202411840282.6
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2024-12-13
Publication Date
2025-10-31
Estimated Expiration
2044-12-13

AI Technical Summary

Technical Problem

Smart home systems involve a wide variety of devices and inconsistent communication protocols, making traditional encryption technologies vulnerable to being cracked. Furthermore, the limited computing power of these devices makes data transmission susceptible to theft or tampering.

Method used

The system employs a quantum key distribution method, establishing a connection between the smart home gateway and the control center. It uses a symmetric key distributed by the quantum key distribution center for identity authentication, and combines it with national cryptographic algorithms for data encryption. Smart home devices and the gateway are assigned unique registration IDs, enabling device registration and key distribution, and supporting dynamic updates and renewals.

Benefits of technology

It improves the communication security of smart home systems, prevents man-in-the-middle attacks, and combines traditional encryption algorithms to create a more robust secure communication network, ensuring the security and reliability of data transmission.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN119583240B_ABST
    Figure CN119583240B_ABST
Patent Text Reader

Abstract

This invention discloses a method for using quantum keys in a smart home system, comprising the following steps: a smart home gateway requests a connection from a control center; the control center and the gateway authenticate each other using a symmetric key—identity key K1—distributed by a quantum key distribution center, through a national standard cryptographic verification function mechanism; after confirming the identity, the control center returns a successful authentication identifier and establishes a communication connection; the gateway selects a session key K3, encrypts it using a symmetric key—encryption key K2—distributed by the quantum key distribution center, and transmits it to the control center; the control center decrypts the encrypted data using the distributed encryption key K2 to obtain the session key K3; data transmission between the control center and the gateway uses the session key K3 and encrypts the data using a national standard cryptographic algorithm; when the control center receives the encrypted data, it decrypts it using the session key K3 and a national standard cryptographic algorithm; the gateway also decrypts the data using the session key K3 to obtain the instruction data.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This invention belongs to the field of electronic information security transmission technology, specifically, it relates to a method for using quantum keys in smart home systems. Background Technology

[0002] In recent years, with the rapid development and popularization of smart home systems, various devices in the home, such as smart lighting, smart security, and smart appliances, have increasingly become integrated into people's daily lives. These smart home devices connect and interact via the internet, providing users with a more convenient, comfortable, and intelligent living experience. However, with the increase in the number of devices and the growth in data transmission volume, the security issues of smart home systems have become increasingly prominent.

[0003] Against this backdrop, quantum key distribution technology, as an emerging encryption technology, has received widespread attention and research. Based on the principles of quantum mechanics, quantum key distribution achieves unconditionally secure key distribution by utilizing properties such as the no-cloning and measurement collapse of quantum states. Compared with traditional encryption technologies, quantum key distribution technology offers higher security and stronger resistance to attacks. Applying quantum key distribution technology in smart home systems can significantly improve the system's communication security. Through quantum key distribution, secure communication encryption can be established between smart home devices, ensuring that sensitive information such as user commands and device-sensed data is not stolen or tampered with.

[0004] However, applying quantum key distribution technology to smart home systems also faces a series of challenges. Smart home systems involve a wide variety of devices with inconsistent communication protocols and standards, making the compatibility and interoperability of quantum key distribution technology with existing systems a critical issue.

[0005] Traditional encryption technologies have played a role in protecting the security of data transmission in smart home systems, but they face several challenges. First, with the continuous advancement of computing technology, traditional encryption algorithms may be vulnerable to being cracked. Second, devices in smart home systems often have limited computing power and memory resources, making it difficult to handle complex encryption operations. Furthermore, data transmission in smart home systems often requires multiple relay nodes, which increases the risk of data theft or tampering. Summary of the Invention

[0006] To address the problem of poor security in protecting data transmission in existing smart home system encryption technologies, this invention provides a quantum key usage method for smart home systems.

[0007] To achieve the above-mentioned technical objectives, the technical solution adopted by the present invention is as follows:

[0008] A method for using quantum keys in smart home systems includes the following steps:

[0009] S1. The smart home gateway requests the control center to establish a connection;

[0010] S2. The control center and the gateway use a symmetric key—identity key K1—distributed by the quantum key distribution center to authenticate identities through a national standard cryptographic verification function mechanism.

[0011] S3. After confirming the gateway's identity, the control center returns a successful authentication indicator and establishes a communication connection.

[0012] S4. The gateway will select a session key K3 from the quantum key pool, encrypt the session key K3 using the symmetric key—encryption key K2 distributed by the quantum key distribution center, and transmit it to the control center.

[0013] S5. The control center also uses the distributed encryption key K2 to decrypt and obtain the session key K3.

[0014] S6. When transmitting data between the control center and the gateway, the session key K3 from step S4 is used to encrypt the data using the national cryptographic algorithm.

[0015] S7. When the control center receives encrypted data, it decrypts it using the national cryptographic algorithm with session key K3 to obtain the data. When the gateway receives instructions from the control center, it encrypts the data and decrypts it using session key K3 to obtain the instruction data.

[0016] Furthermore, each sensor device and home IoT gateway in the smart home system will be assigned a secure and unique registration ID; added devices must also be verified and registered through the control center, and detailed information will be recorded in the control center for secure login in the future.

[0017] Furthermore, the registration process for gateways and devices in a smart home system:

[0018] Registration includes gateway registration and new smart home devices, which first connect to the smart home gateway via a physical or wireless connection.

[0019] Initial Gateway Registration and Authentication: The smart home gateway (hereinafter referred to as the gateway) initiates an initial registration request for the device to the control center, including the gateway... <idmp>Basic information about the gateway;

[0020] The control center verifies the gateway's registration permissions by comparing the ID database and generates a unique registration credential, which is then returned to the gateway.

[0021] Gateway authentication: The gateway sends an authentication request to the quantum key distribution center (QKDC), which includes the gateway's authentication information. <idmp>The quantum key distribution center sends a gateway authentication request, including the gateway ID, to the control center. If the control center verifies the identity, it returns a confirmation of identity to the quantum key distribution center. Upon receiving the confirmation, the quantum key distribution center sends a confirmation of authentication request back to the gateway.

[0022] Quantum key distribution request: The gateway sends a key request to the control center. Upon receiving the request, the control center sends a quantum key request to the quantum key distribution center, which then initiates the quantum key distribution process.

[0023] The quantum key distribution center simultaneously distributes a shared symmetric quantum key to both the smart home gateway and the control center via a communication channel. Both the control center and the smart home gateway store the received quantum key in a security module, ensuring its confidentiality. Since the distance between the control center and the quantum key distribution center can be controlled, a quantum channel can be used to transmit the quantum key. This quantum key channel can ensure that the key cannot be eavesdropped on by exchanging quantum states (such as quantum superposition or entanglement).

[0024] Smart Home Device Registration: Users register new smart home devices (hereinafter referred to as devices) through the smart home system's registration interface, connecting them to the smart home gateway via physical or wireless connection. The gateway performs a preliminary hardware verification of the devices. <idp>And basic communication information.

[0025] Device authentication: After verification, the gateway generates an authentication result and sends it back to the device. At the same time, it sends the registration-related credentials distributed by the control center in step S2 to the device.

[0026] Next, the gateway will distribute the quantum key from step S5 to the device, ensuring encrypted communication between the device and the gateway. The gateway and device use the negotiated communication key for bidirectional encrypted communication, ensuring secure data transmission. Simultaneously, the gateway reports the device's authentication status to the control center, ensuring centralized management and tracking.

[0027] Registration complete: Once the device and gateway are authenticated, the control center will mark them as registered.

[0028] Furthermore, the specific distribution process of the quantum key distribution center:

[0029] Key distribution request: Based on system security requirements, the smart home gateway determines whether a new quantum key needs to be updated or distributed. If a new key needs to be distributed, the gateway sends a key request to the control center, which then sends the key distribution request to the quantum key distribution center.

[0030] Quantum Key Distribution: Upon receiving a key request, the quantum key distribution center will distribute quantum keys to both the control center and the gateway, used to encrypt communication data between devices and the network. The quantum key distribution center will distribute authentication key K1 and encryption key K2 to the control center; simultaneously, it will distribute authentication key K1, encryption key K2, and a quantum key pool to the gateway. The quantum key pool contains three quantum keys, which will be used as session keys for data transmission between the gateway and the control center.

[0031] Session Key Distribution: When the gateway initiates a session request to the control center, it first sends an authentication request. The control center then verifies the identity and returns a confirmation request. Next, the gateway selects one of the three quantum keys from the quantum pool as the session key K3. The gateway and the control center can then use session key K3 for encrypted data transmission. This key is discarded after a session ends.

[0032] Key Updates and Renewals: In smart home systems, some devices may remain online continuously, and key security can decrease over time. The system supports dynamic key updates, i.e., updating keys through secure re-authentication or at preset time intervals. The system automatically triggers key renewal and redistributes new session keys to devices.

[0033] Furthermore, the specific process of identity verification:

[0034] In this invention, the authentication mechanism employing a cryptographic verification function includes single-item authentication, such as... Figure 1 Control Center B possesses identification. <idcp>And obtain the authentication quantum key K1 from the quantum key distribution center, and generate a random number R. B The identity identifier <idcp>Text1 and the random number Ra are sent to the smart home gateway A;

[0035] S2, Smart Home Gateway A has an identity identifier <idmp>And obtain the authentication quantum key K1 from the quantum key distribution center; gateway A receives the identity identifier from control center B. <idcp>and random number R B Combined with identity markers <idmp>The identity authentication quantum key K1 is used to calculate and generate a password verification value TokenAB, which is then sent to the control center B. The identity authentication information TokenAB of the gateway A is obtained using the following logic:

[0036] TokenAB = Text3 ||f K1 (R B ||B||Text2)

[0037] In the formula, f k1 (X) represents the password verification value calculated using the password verification function f and the key K1 on the data X. B It is a random number. B is a distinguishable identifier, which is selectable. K1 is the authentication key, and Text2 is the identity identifier of gateway A. <idmp>Text3 is a text field.

[0038] S3. Once control center B receives the password verification value TokenAB, it calculates and obtains comparison parameters, then verifies whether the obtained comparison parameters match the password verification value TokenAB sent by gateway A. The comparison parameters are obtained using the following logic:

[0039] f K1 (R B ||B||Text2)

[0040] After calculation, it is compared with the password verification value of gateway A to verify the correctness of the distinguishable identifier B and the random number R sent to A in step S1. B Whether it matches the random number contained in TokenAB, thus verifying TokenAB.

[0041] If so, the two-way authentication is considered successful, and an identity confirmation message is returned to gateway A.

[0042] Furthermore, the quantum key distribution center and the control center communicate via a quantum channel using the B92 protocol. In the B92 protocol, 50% of the 16 invalid bits are accepted. Of the bits considered valid, 37.5% are detected as potential eavesdroppers attempting to intercept the key distribution line. The bits detected by the quantum key distribution protocol are considered invalid, and communication via the quantum channel continues until valid bits of the encryption key are obtained.

[0043] Furthermore, the quantum key distribution center generates a quantum key, randomly selecting 16 bits consisting of 0s and 1s to create the primary key. These 16 bits are then sent one by one to the control center via a quantum channel.

[0044] Furthermore, the IoT gateway and control center assess the security of communication by comparing the symmetric quantum key they share; when errors and mismatches exceed a specified equality value, the entire key sequence is regenerated; when the presence of an eavesdropper monitoring the bit transmission is detected but not exceeding a threshold, the bit is canceled and a secure bit is retained; when 16 secure bits are obtained and a key is generated, the communication is complete.

[0045] Furthermore, if an eavesdropper is listening on the communication line to obtain master key information, the quantum key distribution center sends photons with 0° linear polarization and photons with 45° diagonal polarization. The eavesdropper captures and measures the photons, and then sends the photons to the control center to maintain the same polarization state.

[0046] If the eavesdropper's measurement affects the polarization of the photon, the eavesdropper's presence can be detected. The control center measures the transmitted photon and reports the measurement result to the quantum key distribution center.

[0047] If the control center's measurement results are 0° and 45°, these bits are considered invalid. When 90° and -45° are found, they are considered valid. The control center then reports the measurement results to the quantum key distribution center.

[0048] Compared with the prior art, the present invention has the following advantages:

[0049] This invention addresses the problem in current smart home system security applications where data transmission between the gateway and the cloud using classical encryption methods is easily decrypted in the event of a quantum attacker. This invention employs a quantum key distribution method, enabling more secure key distribution between the gateway and the cloud. With quantum key distribution, the smart home system will be more securely protected against man-in-the-middle threats. Furthermore, once secure key sharing is achieved, combining the key with traditional encryption algorithms (asymmetric or symmetric) makes it possible to securely encrypt and transmit data. This method combines quantum cryptography with traditional cryptography to create a more robust and secure communication network. Attached Figure Description

[0050] Figure 1 This is a flowchart illustrating a method for using quantum keys in a smart home system, as described in an embodiment of the present invention.

[0051] Figure 2 This is a flowchart illustrating the registration process of the gateway and devices in the smart home system according to an embodiment of the present invention.

[0052] Figure 3 This is a flowchart illustrating the specific distribution process of the quantum key distribution center in an embodiment of the present invention. Detailed Implementation

[0053] To facilitate understanding by those skilled in the art, the present invention will be further described below with reference to embodiments and accompanying drawings. The content mentioned in the embodiments is not intended to limit the present invention.

[0054] like Figure 1 As shown, this embodiment provides a method for using quantum keys in smart home systems, including the following steps:

[0055] S1. The smart home gateway requests the control center to establish a connection;

[0056] S2. The control center and the gateway use a symmetric key—identity key K1—distributed by the quantum key distribution center to authenticate identities through a national standard cryptographic verification function mechanism.

[0057] S3. After confirming the gateway's identity, the control center returns a successful authentication indicator and establishes a communication connection.

[0058] S4. The gateway will select a session key K3 from the quantum key pool, encrypt the session key K3 using the symmetric key—encryption key K2 distributed by the quantum key distribution center, and transmit it to the control center.

[0059] S5. The control center also uses the distributed encryption key K2 to decrypt and obtain the session key K3.

[0060] S6. When transmitting data between the control center and the gateway, the session key K3 from step S4 is used to encrypt the data using the national cryptographic algorithm.

[0061] S7. When the control center receives encrypted data, it decrypts it using the national cryptographic algorithm with session key K3 to obtain the data. When the gateway receives instructions from the control center, it encrypts the data and decrypts it using session key K3 to obtain the instruction data.

[0062] Each sensor device and home IoT gateway in the smart home system will be assigned a secure and unique registration ID; added devices must also be verified and registered through the control center, and detailed information will be recorded in the control center for secure login in the future.

[0063] like Figure 2 The registration process for gateways and devices in a smart home system is shown below:

[0064] Registration includes gateway registration and new smart home devices, which first connect to the smart home gateway via a physical or wireless connection.

[0065] Initial Gateway Registration and Authentication: The smart home gateway (hereinafter referred to as the gateway) initiates an initial registration request for the device to the control center, including the gateway... <idmp>Basic information about the gateway;

[0066] The control center verifies the gateway's registration permissions by comparing the ID database and generates a unique registration credential, which is then returned to the gateway.

[0067] Gateway authentication: The gateway sends an authentication request to the quantum key distribution center (QKDC), which includes the gateway's authentication information. <idmp>The quantum key distribution center sends a gateway authentication request, including the gateway ID, to the control center. If the control center verifies the identity, it returns a confirmation of identity to the quantum key distribution center. Upon receiving the confirmation, the quantum key distribution center sends a confirmation of authentication request back to the gateway.

[0068] Quantum key distribution request: The gateway sends a key request to the control center. Upon receiving the request, the control center sends a quantum key request to the quantum key distribution center, which then initiates the quantum key distribution process.

[0069] The quantum key distribution center simultaneously distributes a shared symmetric quantum key to both the smart home gateway and the control center via a communication channel. Both the control center and the smart home gateway store the received quantum key in a security module, ensuring its confidentiality. Since the distance between the control center and the quantum key distribution center can be controlled, a quantum channel can be used to transmit the quantum key. This quantum key channel can ensure that the key cannot be eavesdropped on by exchanging quantum states (such as quantum superposition or entanglement).

[0070] Smart Home Device Registration: Users register new smart home devices (hereinafter referred to as devices) through the smart home system's registration interface, connecting them to the smart home gateway via physical or wireless connection. The gateway performs a preliminary hardware verification of the devices. <idp>And basic communication information.

[0071] Device authentication: After verification, the gateway generates an authentication result and sends it back to the device. At the same time, it sends the registration-related credentials distributed by the control center in step S2 to the device.

[0072] Next, the gateway will distribute the quantum key from step S5 to the device, ensuring encrypted communication between the device and the gateway. The gateway and device use the negotiated communication key for bidirectional encrypted communication, ensuring secure data transmission. Simultaneously, the gateway reports the device's authentication status to the control center, ensuring centralized management and tracking.

[0073] Registration complete: Once the device and gateway are authenticated, the control center will mark them as registered.

[0074] like Figure 3 As shown, the specific distribution process of the quantum key distribution center is as follows:

[0075] Key distribution request: Based on system security requirements, the smart home gateway determines whether a new quantum key needs to be updated or distributed. If a new key needs to be distributed, the gateway sends a key request to the control center, which then sends the key distribution request to the quantum key distribution center.

[0076] Quantum Key Distribution: Upon receiving a key request, the quantum key distribution center will distribute quantum keys to both the control center and the gateway, used to encrypt communication data between devices and the network. The quantum key distribution center will distribute authentication key K1 and encryption key K2 to the control center; simultaneously, it will distribute authentication key K1, encryption key K2, and a quantum key pool to the gateway. The quantum key pool contains three quantum keys, which will be used as session keys for data transmission between the gateway and the control center.

[0077] Session Key Distribution: When the gateway initiates a session request to the control center, it first sends an authentication request. The control center then verifies the identity and returns a confirmation request. Next, the gateway selects one of the three quantum keys from the quantum pool as the session key K3. The gateway and the control center can then use session key K3 for encrypted data transmission. This key is discarded after a session ends.

[0078] Key Updates and Renewals: In smart home systems, some devices may remain online continuously, and key security can decrease over time. The system supports dynamic key updates, i.e., updating keys through secure re-authentication or at preset time intervals. The system automatically triggers key renewal and redistributes new session keys to devices.

[0079] The specific process of identity verification:

[0080] In this invention, the authentication mechanism employing a cryptographic verification function includes single-item authentication, such as... Figure 1 Control Center B possesses identification. <idcp>And obtain the authentication quantum key K1 from the quantum key distribution center, and generate a random number R. B The identity identifier <idcp>Text1 and the random number Ra are sent to the smart home gateway A;

[0081] S2, Smart Home Gateway A has an identity identifier <idmp>And obtain the authentication quantum key K1 from the quantum key distribution center; gateway A receives the identity identifier from control center B. <idcp>and random number R B Combined with identity markers <idmp>The identity authentication quantum key K1 is used to calculate and generate a password verification value TokenAB, which is then sent to the control center B. The identity authentication information TokenAB of the gateway A is obtained using the following logic:

[0082] TokenAB = Text3 ||f K1 (R B ||B||Text2)

[0083] In the formula, f k1 (X) represents the password verification value calculated using the password verification function f and the key K1 on the data X. B It is a random number. B is a distinguishable identifier, which is selectable. K1 is the authentication key, and Text2 is the identity identifier of gateway A. <idmp>Text3 is a text field.

[0084] S3. Once control center B receives the password verification value TokenAB, it calculates and obtains comparison parameters, then verifies whether the obtained comparison parameters match the password verification value TokenAB sent by gateway A. The comparison parameters are obtained using the following logic:

[0085] f K1 (R B ||B||Text2)

[0086] After calculation, it is compared with the password verification value of gateway A to verify the correctness of the distinguishable identifier B and the random number R sent to A in step S1. B Whether it matches the random number contained in TokenAB, thus verifying TokenAB.

[0087] If so, the two-way authentication is considered successful, and an identity confirmation message is returned to gateway A.

[0088] The quantum key distribution center and the control center communicate via a quantum channel using the B92 protocol. In the B92 protocol, 50% of the 16 invalid bits are accepted. Of the bits considered valid, 37.5% are detected as potential eavesdroppers attempting to intercept the key distribution line. The bits detected by the quantum key distribution protocol are considered invalid, and communication via the quantum channel continues until valid bits of the encryption key are obtained.

[0089] The quantum key distribution center generates a quantum key, randomly selecting 16 bits (consisting of 0s and 1s) to create the primary key. These 16 bits are then sent one by one to the control center via a quantum channel.

[0090] The IoT gateway and control center assess the security of communication by comparing the symmetric quantum key they share; when errors and mismatches exceed a specified equality value, the entire key sequence is regenerated; when the presence of an eavesdropper monitoring the bit transmission is detected but not exceeding a threshold, the bit is canceled and a secure bit is retained; when 16 secure bits are obtained and the key is generated, the communication is complete.

[0091] If an eavesdropper listens on the communication line to obtain master key information, the quantum key distribution center sends photons with 0° linear polarization and 45° diagonal polarization. The eavesdropper captures and measures the photons, and then sends the photons to the control center to maintain the same polarization state.

[0092] If the eavesdropper's measurement affects the polarization of the photon, the eavesdropper's presence can be detected. The control center measures the transmitted photon and reports the measurement result to the quantum key distribution center.

[0093] If the control center's measurement results are 0° and 45°, these bits are considered invalid. When 90° and -45° are found, they are considered valid. The control center then reports the measurement results to the quantum key distribution center.

[0094] Compared with the prior art, the present invention has the following advantages:

[0095] This invention addresses the problem in current smart home system security applications where data transmission between the gateway and the cloud using classical encryption methods is easily decrypted in the event of a quantum attacker. This invention employs a quantum key distribution method, enabling more secure key distribution between the gateway and the cloud. With quantum key distribution, the smart home system will be more securely protected against man-in-the-middle threats. Furthermore, once secure key sharing is achieved, combining the key with traditional encryption algorithms (asymmetric or symmetric) makes it possible to securely encrypt and transmit data. This method combines quantum cryptography with traditional cryptography to create a more robust and secure communication network.

[0096] The above provides a detailed description of a quantum key distribution method for smart home systems provided by this application. The specific embodiments are described only to aid in understanding the method and its core concepts. It should be noted that those skilled in the art can make various improvements and modifications to this application without departing from its principles, and these improvements and modifications also fall within the scope of protection of the claims.< / idmp> < / idmp> < / idcp> < / idmp> < / idcp> < / idcp> < / idp> < / idmp> < / idmp> < / idmp> < / idmp> < / idcp> < / idmp> < / idcp> < / idcp> < / idp> < / idmp> < / idmp>

Claims

1. A method for using quantum keys in smart home systems, characterized in that, Including the following steps: S1. The smart home gateway requests the control center to establish a connection; S2. The control center and the gateway use a symmetric key—identity key K1—distributed by the quantum key distribution center to authenticate identities through a national standard cryptographic verification function mechanism. S3. After confirming the gateway's identity, the control center returns a successful authentication indicator and establishes a communication connection. S4. The gateway will select a session key K3 from the quantum key pool, encrypt the session key K3 using the symmetric key—encryption key K2 distributed by the quantum key distribution center, and transmit it to the control center. S5. The control center also uses the distributed encryption key K2 to decrypt and obtain the session key K3. S6. When transmitting data between the control center and the gateway, the session key K3 from step S4 is used to encrypt the data using the national cryptographic algorithm. S7. When the control center receives encrypted data, it decrypts it using the national cryptographic algorithm with session key K3 to obtain the data. When the gateway receives instructions from the control center, it encrypts the data and decrypts it using session key K3 to obtain the instruction data.

2. The method for using quantum keys in a smart home system according to claim 1, characterized in that, Each sensor device and home IoT gateway in the smart home system will be assigned a secure and unique registration ID; added devices must also be verified and registered through the control center, and detailed information will be recorded in the control center for secure login in the future.

3. The method for using quantum keys in a smart home system according to claim 2, characterized in that, Registration process for gateways and devices in a smart home system: Registration includes gateway registration and new smart home devices; First, connect to the smart home gateway via physical or wireless connection; Initial gateway registration and authentication: The smart home gateway initiates an initial registration request for the device to the control center, which includes the gateway and its basic information; The control center verifies the gateway's registration permissions by comparing the ID database and generates a unique registration credential, which is then returned to the gateway. Gateway authentication: The gateway sends an authentication request to the quantum key distribution center, containing the gateway and its basic information; the quantum key distribution center sends a gateway authentication request to the control center, containing the gateway ID. If the control center verifies the gateway's identity, it returns a confirmation of identity to the quantum key distribution center; after receiving the identity confirmation, the quantum key distribution center returns a confirmation of authentication request to the gateway. Quantum key distribution request: The gateway sends a key request to the control center. Upon receiving the request, the control center sends a quantum key request to the quantum key distribution center, which then initiates the quantum key distribution process. The quantum key distribution center uses communication channels to simultaneously distribute shared symmetric quantum keys to the smart home gateway and control center. The control center and smart home gateway store the received quantum keys in security modules and ensure the confidentiality of the keys. Smart home device registration: Users register new smart home devices through the smart home system's registration interface, either via physical or wireless connection, to the smart home gateway. The gateway then preliminarily confirms the hardware and basic communication information of the smart home devices. Device authentication: After verification, the gateway generates an authentication result and sends it back to the smart home device. At the same time, it sends the registration-related credentials distributed by the control center to the smart home device. Next, the gateway will distribute the quantum key stored in the security module to the smart home devices to ensure that the communication between the smart home devices and the gateway is encrypted. The gateway and the smart home devices use the negotiated communication key to conduct bidirectional encrypted communication. At the same time, the gateway reports the authentication status of the smart home devices to the control center. Registration complete: Smart home devices and gateways are certified, and the control center will mark them as registered.

4. The method for using quantum keys in a smart home system according to claim 3, characterized in that, The specific distribution process of the quantum key distribution center: Key distribution request: The smart home gateway determines whether a new quantum key needs to be updated or distributed based on system security requirements; Quantum key distribution: After receiving a key request, the quantum key distribution center will distribute quantum keys to the control center and the gateway respectively, which will be used to encrypt communication data between devices and the network. The quantum key distribution center will distribute an authentication key K1 and an encryption key K2 to the control center. At the same time, the quantum key distribution center will distribute the authentication key K1, the encryption key K2 and a quantum key pool to the gateway. The quantum key pool contains 3 quantum keys, which will be used as session keys for data transmission between the gateway and the control center. Session key distribution: When the gateway wants to initiate a session request to the control center, it first sends an authentication request, and then the control center confirms the identity and returns a confirmation request. Next, the gateway will select one of the three quantum keys in the quantum pool as the session key K3. The gateway and the control center can then use the session key K3 to encrypt and transmit data. When a session ends, the key is discarded. Key update and renewal: In the smart home system, the system supports dynamic key updates. By updating the key through secure re-authentication or at preset time intervals, the system automatically triggers key renewal and redistributes new session keys to smart home devices.

5. A method for using quantum keys in a smart home system according to claim 4, characterized in that, The specific process of identity verification: Using a single-entry authentication mechanism employing a password verification function, control center B possesses an identity identifier. <idcp>And obtain the authentication quantum key K1 from the quantum key distribution center, and generate a random number R. B The identity identifier <idcp> Text1 and a random number Ra are sent to smart home gateway A;< / idcp> < / idcp> S2, Smart Home Gateway A has an identity identifier <idmp>And obtain the authentication quantum key K1 from the quantum key distribution center; gateway A receives the identity identifier from control center B. <idcp>and random number R B Combined with identity markers <idmp> The identity authentication quantum key K1 is used to calculate and generate a password verification value TokenAB, which is then sent to the control center B. The identity authentication information TokenAB of the gateway A is obtained using the following logic:< / idmp> < / idcp> < / idmp> TokenAB=Text3||f K1 (R B ||B||Text2) In the formula, f k1 (X) represents the password verification value calculated using the password verification function f and the key K1 on the data X, R B It is a random number, B is a distinguishable identifier (which is selectable), K1 is the authentication key, and Text2 is the identity identifier of gateway A. <idmp> Text3 is a text field;< / idmp> S3. Once control center B receives the password verification value TokenAB, it calculates and obtains comparison parameters, and verifies whether the obtained comparison parameters are consistent with the password verification value TokenAB sent by gateway A. The comparison parameters are obtained using the following logic: f K1 (R B ||B||Text2) After calculation, it is compared with the password verification value of gateway A to verify the correctness of the distinguishable identifier B and the random number R sent to A in step S1. B Whether it matches the random number contained in TokenAB, thus verifying TokenAB; If so, the two-way authentication is considered successful, and an identity confirmation message is returned to gateway A.

6. A method for using quantum keys in a smart home system according to claim 5, characterized in that, The quantum key distribution center and the control center communicate via a quantum channel using the B92 protocol.

7. A method for using quantum keys in a smart home system according to claim 6, characterized in that, The quantum key distribution center generates a quantum key and randomly selects 16 bits consisting of 0s and 1s to create the primary key.

8. A method for using quantum keys in a smart home system according to claim 7, characterized in that, The IoT gateway and control center assess the security of communication by comparing the symmetric quantum key they share; when errors and mismatches exceed a specified equality value, the entire key sequence is regenerated; when the presence of an eavesdropper monitoring the bit transmission is detected but not exceeding a threshold, the bit is canceled and a secure bit is retained; when 16 secure bits are obtained and the key is generated, the communication is complete.

9. A method for using quantum keys in a smart home system according to claim 8, characterized in that, If an eavesdropper listens on the communication line to obtain master key information, the quantum key distribution center sends photons with 0° linear polarization and 45° diagonal polarization. The eavesdropper captures and measures the photons, and then sends the photons to the control center to maintain the same polarization state. If the eavesdropper's measurement affects the polarization of the photon, the eavesdropper's presence can be detected. The control center measures the transmitted photon and reports the measurement result to the quantum key distribution center. If the control center's measurement results are 0° and 45°, these bits are considered invalid. When 90° and -45° are found, they are considered valid. The control center then reports the measurement results to the quantum key distribution center.

Citation Information

Patent Citations

  • Identity authentication method during quantum secret key application process

    CN105763563A

  • Lightweight authentication method, system and equipment for local communication of power terminal and medium

    CN118449786A