A method for supplementing keys in a unicast source global quantum secure multicast network
By initiating key replenishment requests through quantum secure multicast sources and combining the collaborative management of access base stations and multicast key centers, the problem of difficult key distribution in multicast networks is solved, reliable and secure key replenishment in multicast networks is achieved, and the real-time and continuity of the network are improved.
Patent Information
- Application Number
- CN202411814479.2
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2024-12-11
- Publication Date
- 2025-09-23
- Estimated Expiration
- 2044-12-11
AI Technical Summary
The existing key supplement mechanism is difficult to meet the security requirements of multicast networks in the global quantum security network, especially because the number of multicast network members is large and the relationships are complex, which leads to difficulty in key distribution, serious network congestion and resource consumption.
The quantum secure multicast source initiates a key supplement request, and through the collaborative work of the access base station and the multicast key center, it realizes the distributed management and encrypted transmission of the multicast group key, ensuring that multicast members can obtain the supplementary key reliably and securely.
This achieves reliable key replenishment in the multicast network, reduces the processing burden of the multicast key center, improves the flexibility and security of key management, and reduces network delay and resource consumption.
Smart Images

Figure CN119652511B_ABST
Abstract
Description
Technical Field
[0001] The present application relates to the fields of information security and quantum encryption technology, and in particular to a method for supplementing keys in a unicast source global quantum secure multicast network. Background Art
[0002] With the rapid development of information technology, the introduction of a global quantum secure communication solution marks a major innovation in the field of quantum secure communication. This solution aims to build a seamless and highly flexible communication network. Its core principle is to utilize access base stations as communication hubs to enable key relay between quantum secure network terminals. This innovative design ensures secure and efficient quantum communication between quantum secure terminals regardless of their geographic location, significantly improving the security and reliability of information transmission.
[0003] In everyday applications, multicast technology is widely used due to its efficiency and flexibility, such as command issuance, live video broadcasting, and multimedia classrooms. Therefore, integrating multicast technology into a global quantum security network will further enhance the practicality and application value of the network.
[0004] However, in a global quantum-safe network, key replenishment is a critical step in ensuring communication security. The key replenishment mechanism employed by quantum security terminals in this global quantum-safe network typically relies on an end-to-end communication model. Specifically, the quantum security terminal sends a key replenishment request to the access base station it connects to. The access base station then assigns a key center to the quantum security terminal to process the request. Upon receiving the key replenishment request, the key center generates an encryption key and a supplementary key for the quantum security terminal. The key center then sends the encryption key to the quantum security terminal via the access base station using quantum-safe encryption. Once the quantum security terminal receives the encryption key, it can then request the key center to distribute the supplementary key using quantum-safe encryption.
[0005] This traditional key replenishment mechanism is inadequate for multicast networks. Multicast networks are a specialized communication model in which information is sent to one or more multicast members via multicast, rather than traditional end-to-end communication. Because a multicast network can have a large number of members and complex and dynamic relationships among them, it's difficult to meet the security needs of all members with a single end-to-end key distribution method. This limitation makes the application of the aforementioned key replenishment mechanism in multicast networks challenging. Summary of the Invention
[0006] The present application provides a method for key supplementation in a unicast source global quantum secure multicast network, which is used to implement key supplementation in a unicast source global quantum secure multicast network.
[0007] In a first aspect, the present application provides a method for supplementing a key in a unicast source global quantum-secure multicast network, the method comprising:
[0008] The quantum secure multicast source initiates a key supplement request message to the first access base station to which it is connected; wherein the key supplement request carries a multicast group identifier of the quantum secure multicast group;
[0009] The first access base station receives the key supplement request; determines a multicast key center corresponding to the multicast group identifier; and sends a multicast key distribution request message carrying the multicast group identifier to the multicast key center;
[0010] The multicast key center receives the multicast key distribution request message; generates a supplementary multicast group key corresponding to the multicast group identifier, obtains an encryption key corresponding to the supplementary multicast group key; generates a multicast key distribution response message and sends it to the first access base station, so that the first access base station generates a key supplement response message based on the received multicast key distribution response message and sends it to the quantum secure multicast source; and, according to the multicast group identifier, multicasts the supplementary multicast group key encrypted based on the encryption key.
[0011] The quantum secure multicast source receives the key supplement response message and the encrypted supplementary multicast group key; obtains the encryption key, and decrypts the encrypted supplementary multicast group key based on the encryption key to obtain the supplementary multicast group key;
[0012] For any multicast member in the quantum secure multicast group, the encrypted supplementary multicast group key is received; the encryption key is obtained, and the encrypted supplementary multicast group key is decrypted based on the encryption key to obtain the supplementary multicast group key.
[0013] In some possible implementations, the communication mode between the quantum secure multicast source and the first access base station is: quantum secure encrypted communication based on a symmetric pairing key between the two parties.
[0014] In certain possible implementations, if both the key supplement request and the multicast key distribution request message carry a first key distribution identifier, and the first key distribution identifier indicates that the encryption key corresponding to the supplementary multicast group key was distributed by the multicast group key center when the multicast group key was distributed last time, then the multicast key center, the quantum secure multicast source, and the multicast group member all retrieve the encryption key from their respective local storage.
[0015] In some possible implementations, the method further includes:
[0016] The multicast key center generates a pre-distributed encryption key for encrypting a supplementary multicast group key to be distributed next time; performs quantum encryption on the pre-distributed encryption key based on the encryption key; and multicasts the encrypted pre-distributed encryption key according to the multicast group identifier;
[0017] The quantum secure multicast source receives the encrypted pre-distributed encryption key; decrypts the encrypted pre-distributed encryption key based on the encryption key to obtain the pre-distributed encryption key; and supplements the currently unused encryption key according to the pre-distributed encryption key.
[0018] In some possible implementations, if both the key supplement request and the multicast key distribution request message carry a second key distribution identifier, and the second key distribution identifier indicates that the encryption key corresponding to the supplemented multicast group key is newly generated by the multicast group key center, then both the multicast key distribution response message and the key supplement response message carry the encryption key;
[0019] The multicast key center multicasts the supplementary multicast group key encrypted based on the encryption key according to the multicast group identifier, including:
[0020] According to the multicast group identifier, multicast the current distribution identifier and the supplementary multicast group key encrypted based on the encryption key; wherein the current distribution identifier is used to query the encryption key generated this time;
[0021] The quantum secure multicast source obtains the encryption key, including:
[0022] Obtaining the encryption key from the key supplement response message;
[0023] The multicast group member obtains the encryption key in the following manner, including:
[0024] The multicast group member receives the current distribution identifier; sends an encryption key supplement request carrying the current distribution identifier and the multicast group identifier to the second access base station, so as to determine the multicast key center corresponding to the multicast group identifier through the second access base station, and forwards the encryption key supplement request to the multicast key center;
[0025] The encryption key response message carrying the encryption key sent by the multicast key center is received through the second access base station; wherein the multicast key center determines the encryption key requested by the multicast group member through the multicast group identifier and the current distribution identifier carried in the encryption key supplement request.
[0026] In some possible implementations, after the second access base station determines the multicast key center corresponding to the multicast group identifier and before forwarding the encryption key supplement request to the multicast key center, the method further includes:
[0027] According to the identity information of the multicast member, it is determined whether the multicast member has the authority to obtain the encryption key.
[0028] The beneficial effects of this application are as follows:
[0029] 1. Initiating key replenishment requests through a quantum-safe multicast source can not only reliably and securely implement key replenishment in a unicast source-wide quantum-safe multicast network, but also effectively avoid the situation where each multicast member in the quantum-safe multicast group has to make a key replenishment request. This would cause the multicast key center to process multiple redundant key replenishment requests simultaneously, thus reducing the processing burden on the multicast key center.
[0030] 2. Through the interaction between the first access base station and the multicast key center, distributed key management is achieved. This management method not only improves the flexibility of key management, but also reduces the impact on the entire system when a single node is attacked or fails.
[0031] 3. After generating and distributing the supplementary multicast group key, the multicast key center can encrypt the supplementary multicast group key based on the encryption key corresponding to the supplementary multicast group key and multicast it to all multicast members in the quantum secure multicast group. This not only ensures the security of the supplementary multicast group key, but also improves the real-time and continuity of key supplementation, and reduces the delay in synchronizing the supplementary multicast group key among the multicast members. BRIEF DESCRIPTION OF THE DRAWINGS
[0032] In order to more clearly illustrate the technical solutions in the embodiments of the present application, the following briefly introduces the drawings required for use in the description of the embodiments. Obviously, the drawings described below are only some embodiments of the present application. For ordinary technicians in this field, other drawings can be obtained based on these drawings without paying any creative labor.
[0033] Figure 1 A schematic diagram of a method for supplementing keys in a global quantum-secure multicast network with a unicast source, provided in an embodiment of the present application;
[0034] Figure 2 A schematic diagram of the specific process of supplementing the global quantum-secure multicast network key from a unicast source provided in an embodiment of the present application;
[0035] Figure 3 A schematic diagram of the specific process of unicast source global quantum secure multicast network key supplementation provided in an embodiment of the present application. DETAILED DESCRIPTION
[0036] To make the objectives, technical solutions, and advantages of this application more clear, this application will be further described in detail below with reference to the accompanying drawings. It should be understood that the embodiments described herein are only a portion of the embodiments of this application, and not all of them. All other embodiments derived by persons of ordinary skill in the art based on the embodiments of this application without inventive effort are intended to fall within the scope of protection of this application.
[0037] The global quantum secure network supports secure and efficient quantum communication between any quantum secure terminals connected to the network, regardless of their geographic location. A key element of this global quantum secure network is the use of access base stations as communication hubs, connecting quantum secure terminals to the global quantum secure network and enabling key relay between terminals connected to the global quantum secure network.
[0038] During the access process, when a quantum secure terminal connects to an access base station, the access base station assigns it a network access identifier—a unique terminal identifier for the entire global quantum secure network. This identifier carries information about the country, operator, region, cell, access base station, and terminal. With this network access identifier, the terminal can be identified within the global quantum secure network for the duration of its possession. Subsequently, the quantum secure terminal can request services and resources from the global quantum secure network through the access base station.
[0039] During key relay, the encryption end relays the key through the encryption end access base station and then through the global quantum secure network to the decryption end access base station. The decryption end access base station then forwards the key to the decryption end, thereby ensuring a symmetric quantum secure key between the encryption end and the decryption end, enabling encryption and decryption communications. The global quantum secure network also includes a key center, which distributes keys, or quantum keys, to quantum secure terminals connected to the global quantum secure network.
[0040] In the above-mentioned global quantum security network, the two ends of direct communication, for example, between the quantum security terminal and the access base station, and between the access base stations, adopt a symmetric encryption method based on a true random number one-time pad. This symmetric encryption method requires that only the two ends of direct communication have a unique true random number symmetric key to ensure the privacy of communication.
[0041] In everyday applications, multicast technology is widely used due to its efficiency and flexibility, such as command issuance, live video broadcasting, and multimedia classrooms. Therefore, integrating multicast technology into a global quantum security network will further enhance the practicality and application value of the network.
[0042] During global quantum-secure multicast network communication with a unicast source, the quantum-secure multicast source, through its access base station (denoted as the first access base station), requests an encryption key and a multicast group key from a key center with global quantum-secure multicast capabilities to establish a quantum-secure multicast group. Multicast members who wish to join the quantum-secure multicast group first apply to join the quantum-secure multicast group from their access base station (denoted as the second access base station) based on the multicast group ID. After the second access base station authenticates the member's joining authority, it requests the encryption key for the quantum-secure multicast group from the key center corresponding to the multicast group ID and distributes the key center's address and encryption key to the member. According to the address information, the multicast group member downloads the multicast group key encrypted based on the encryption key from the key center, and then decrypts the encrypted multicast group key based on the obtained encryption key to obtain the multicast group key, thereby joining the unicast source global quantum secure multicast network. Subsequently, the multicast group member can receive multicast messages from the quantum secure multicast source that are quantum securely encrypted with the multicast group key.
[0043] During communications in a unicast-source, global quantum-secure multicast network, the multicast group key within the quantum-secure multicast group is constantly consumed. Therefore, renewing this multicast group key is crucial to ensuring the stability and continuity of communications in this unicast-source, global quantum-secure multicast network. However, in a global quantum-secure network, key renewing is a crucial step in ensuring communication security. The key renewing mechanism employed by quantum secure terminals in this global quantum-secure network typically relies on an end-to-end communication model. Specifically, the quantum secure terminal sends a key renewing request to its access base station, which then assigns a key center to the quantum secure terminal to process the request. Upon receiving the key renewing request, the key center generates an encryption key and a renewing key for the quantum secure terminal. The key center then sends the encryption key to the quantum secure terminal via the access base station using quantum-secure encryption. After receiving the encryption key, the quantum secure terminal can then request the renewing key from the key center using quantum-secure encryption.
[0044] This traditional key replenishment mechanism is inadequate for multicast networks. Multicast networks are a specialized communication model in which information is sent to one or more multicast members via multicast, rather than traditional end-to-end communication. Because a multicast network can have a large number of members and complex and dynamic relationships among them, it's difficult to meet the security needs of all members with a single end-to-end key distribution method. This limitation makes the application of the aforementioned key replenishment mechanism in multicast networks challenging.
[0045] Based on this, the present application provides a method for key supplementation in a unicast source global quantum secure multicast network to implement key supplementation in a unicast source global quantum secure multicast network.
[0046] Example 1:
[0047] Figure 1 A schematic diagram of a method for supplementing a key in a global quantum-secure multicast network with a unicast source is provided in an embodiment of the present application. The method includes:
[0048] S101: A quantum secure multicast source initiates a key supplement request message to a first access base station to which it is connected; wherein the key supplement request carries a multicast group identifier of a quantum secure multicast group.
[0049] In this application, the quantum security multicast source can be any quantum security terminal in the global quantum security network. The quantum security terminal can be a client such as a quantum security all-in-one machine, a quantum security privacy computer, etc., or a server such as a quantum security application server, a quantum security business server, etc.
[0050] In a unicast-source, global quantum-secure multicast network, the source and all members share a key pool—that is, the same multicast group key. Therefore, all members (including the source and members) in the network experience consistent consumption of the multicast group key. When one member discovers that the multicast group key is insufficient, all other members in the quantum-secure multicast group will also experience insufficient multicast group keys. In this situation, if each member requests a key replenishment request, the key center responsible for replenishing the quantum-secure multicast group's key (referred to as the multicast key center) will have to process multiple key replenishment requests simultaneously, causing network congestion. Furthermore, these multiple key replenishment requests are often redundant, indicating insufficient multicast group keys within the quantum-secure multicast group. This significantly increases the processing burden on the multicast key center and consumes network resources.
[0051] Since the existence of the quantum-secure multicast group's service conditions can be considered determined by the quantum-secure multicast source, when the quantum-secure multicast source ceases to exist, the multicast of this quantum-secure multicast group also ends. However, other multicast group members can leave or join the quantum-secure multicast group at any time between the time the quantum-secure multicast source establishes the unicast source global quantum-secure multicast network and the time the quantum-secure multicast source exits the unicast source global quantum-secure multicast network. Therefore, the existence of this multicast group member does not affect the existence and communication of the entire unicast source global quantum-secure multicast network. Based on this, in this application, the initiation of key replenishment for the unicast source global quantum-secure multicast network can be initiated by the quantum-secure multicast source in the quantum-secure multicast group. Exemplarily, during the multicast communication process, the quantum-secure multicast source in the unicast source global quantum-secure multicast network monitors the key quantity of its stored multicast group key in real time or periodically. This key quantity can be either the used key quantity of the stored multicast group key or the unused key quantity of the stored multicast group key. When it is determined that the number of unused multicast group keys stored is insufficient based on the key quantity of the multicast group key, a key replenishment request message may be initiated. The key replenishment request message carries the multicast group identifier of the quantum secure multicast group. The key replenishment request is then sent to the first access base station.
[0052] The multicast group identifier is used to identify a specific quantum-safe multicast group. This multicast group identifier can be represented by an IP address within a specific IP address block reserved for multicast communications. For example, in the IPv4 communication protocol, an IPv4 multicast group identifier might be 239.255.255.250. Another example, in the IPv6 communication protocol, a multicast group identifier might be FF02::1:FF00:0 / 104. The key type identifier indicates the required key type, in this case the multicast group key. The presentation format of this key type identifier can vary depending on the protocol or implementation. For example, the key type identifier can be a numeric value, such as 1 for the key required for point-symmetric encryption or 2 for the multicast group key. Another example is that the key type identifier can be a string that uniquely identifies the key type, such as "GROUP_KEY" for the multicast group key.
[0053] In one possible implementation, to ensure the continuity and security of multicast communications, a reasonable key quantity threshold is preconfigured, such as an unused key quantity threshold or a used key quantity threshold. Taking the preconfigured key quantity threshold as the used key quantity threshold as an example, if the quantum-secure multicast source determines that the amount of used keys exceeds the preconfigured used key quantity threshold, it determines that the number of stored unused multicast group keys is insufficient. Taking the preconfigured key quantity threshold as the unused key quantity threshold as an example, if the quantum-secure multicast source determines that the amount of unused keys is below the preconfigured unused key quantity threshold, it determines that the number of stored unused multicast group keys is insufficient.
[0054] S102: The first access base station receives the key supplement request; determines a multicast key center corresponding to the multicast group identifier; and sends a multicast key distribution request message carrying the multicast group identifier to the multicast key center.
[0055] Based on the above embodiment, a first access base station can receive a key replenishment request sent by a quantum-secure multicast source. The first access base station can parse the key replenishment request to obtain the multicast group identifier carried in the key replenishment request. A multicast key center that supports multicast is then assigned to the multicast group identifier and the address information of the multicast key center is obtained. Based on the multicast group identifier, a multicast key allocation request message is generated. Based on the address information, the multicast key allocation request message is sent to the multicast key center, requesting that the multicast key center replenish the multicast group key for the quantum-secure multicast group identified by the multicast group identifier.
[0056] Exemplarily, the first access base station can obtain a key center information library configured by the network management. The key center information library records detailed information such as the address information of at least one key center, supported key types, whether multicast functions are supported, and the key centers corresponding to each pre-configured multicast group identifier. After receiving a key replenishment request, the first access base station can query the key center information library. During the query process, the first access base station determines the multicast key center corresponding to the multicast group identifier carried in the key replenishment request from the pre-configured key centers corresponding to each multicast group identifier.
[0057] S103: The multicast key center receives the multicast key distribution request message; generates a supplementary multicast group key corresponding to the multicast group identifier, and obtains an encryption key corresponding to the supplementary multicast group key; generates a multicast key distribution response message and sends it to the first access base station, so that the first access base station generates a key supplement response message based on the received multicast key distribution response message and sends it to the quantum secure multicast source; and, according to the multicast group identifier, multicasts the supplementary multicast group key encrypted based on the encryption key.
[0058] Based on the above embodiment, the multicast key center can receive a multicast key distribution request message sent by the first access base station. The multicast key center can parse the multicast key distribution request message and obtain the multicast group identifier carried in the multicast key distribution request message. Based on the multicast group identifier, the multicast key center queries the multicast key pool previously established for the quantum-secure multicast group and generates a supplementary multicast group key corresponding to the multicast group identifier in the multicast key pool.
[0059] To ensure the security of the process in which multicast members in a unicast-source global quantum-secure multicast network supplement their multicast group keys from the multicast key center, in this application, the multicast key center also obtains the encryption key corresponding to the supplemented multicast group key and uses this encryption key to encrypt and transmit the supplemented multicast group key. The supplemented multicast group key and the encryption key are then stored in the multicast key pool corresponding to the multicast group identifier for easy subsequent query and use.
[0060] When the multicast key center obtains the supplementary multicast group key corresponding to the multicast group identifier and the encryption key corresponding to the supplementary multicast group key, it can generate a multicast key allocation response message and send it to the first access base station in response to the multicast key allocation request message sent by the first access base station. The multicast key allocation response message is used to notify the first access base station that the supplementary multicast group key has been allocated. Upon receiving the multicast key allocation response message, the first access base station can generate a key replenishment response message and send it to the quantum-secure multicast source to promptly respond to the key replenishment request sent by the quantum-secure multicast source.
[0061] To replenish the multicast group key in a timely manner, in this application, the multicast key center, upon obtaining the supplementary multicast group key corresponding to the multicast group identifier and the encryption key corresponding to the supplementary multicast group key, can quantum encrypt the supplementary multicast group key based on the encryption key. The encrypted supplementary multicast group key is then multicasted according to the multicast group identifier.
[0062] S104: The quantum secure multicast source receives the key supplement response message and the encrypted supplementary multicast group key; obtains the encryption key, and decrypts the encrypted supplementary multicast group key based on the encryption key to obtain the supplementary multicast group key.
[0063] Based on the above embodiment, the quantum-secure multicast source can not only receive the encrypted supplementary multicast group key multicasted by the multicast key center via the multicast group identifier, but also receive a key supplementation response message sent by the first access base station. Upon receiving the key supplementation response message and the encrypted supplementary multicast group key, the quantum-secure multicast source obtains the encryption key corresponding to the encrypted supplementary multicast group key. Then, based on the encryption key, it decrypts the encrypted supplementary multicast group key to obtain the supplementary multicast group key, thereby supplementing the stored multicast group key based on the supplementary multicast group key.
[0064] In one possible implementation, after the quantum secure multicast source obtains the supplementary multicast group key, it can determine whether the supplementary multicast group key passes a security check. Exemplarily, the security check includes one or more of the following:
[0065] 1. Integrity check.
[0066] To ensure that the supplementary multicast group key has not been tampered with or damaged during transmission or storage, in this application, the quantum-secure multicast source can perform an integrity check on the received supplementary multicast group key. For example, a hash check is performed on the supplementary multicast group key to determine whether it passes the integrity check. If the supplementary multicast group key passes the integrity check, the quantum-secure multicast source retains the supplementary multicast group key; if the supplementary multicast group key fails the integrity check, the quantum-secure multicast source discards the supplementary multicast group key.
[0067] 2. Consistency check
[0068] To prevent errors or inconsistencies in the distribution or storage of the supplementary multicast group key, the quantum-secure multicast source can also perform a consistency check on the supplementary multicast group key with the multicast key center. For example, the quantum-secure multicast source can compare the hash value of the supplementary multicast group key with the hash value of the supplementary multicast group key received by the multicast key center to determine whether the supplementary multicast group key meets the consistency check. If the supplementary multicast group key passes the consistency check, the quantum-secure multicast source retains the supplementary multicast group key; if the supplementary multicast group key fails the consistency check, the quantum-secure multicast source discards the supplementary multicast group key.
[0069] It should be noted that the quantum-secure multicast source may perform one or more of the security verification methods described above on the supplementary multicast group key. When the security verification includes multiple verification methods described above, that is, combining integrity and consistency checks to ensure the security of the supplementary multicast group key, the quantum-secure multicast source first uses an integrity check to ensure that the supplementary multicast group key has not been tampered with during transmission or storage. Then, it uses a consistency check to ensure the consistency between the supplementary multicast group key and the supplementary multicast group key generated by the multicast key center. If the supplementary multicast group key passes both checks, it can be considered secure and reliable and can be used for subsequent encrypted communications. If the supplementary multicast group key fails any of the checks, appropriate security measures must be taken, such as discarding the supplementary multicast group key, re-requesting the supplementary multicast group key, or reporting a security incident.
[0070] In a possible implementation, the communication mode between the quantum secure multicast source and the first access base station is: quantum secure encrypted communication based on a symmetric pairing key between the two parties.
[0071] In this application, to ensure the security of communication between a quantum-secure multicast source and a first access base station, the quantum-secure multicast source and the first access base station perform quantum-secure encrypted communication based on a symmetric pairing key. Exemplarily, the quantum-secure multicast source's key replenishment request is quantum-encrypted and sent to the first access base station based on the pairing key. The first access base station's key replenishment response message is also quantum-encrypted and sent to the quantum-secure multicast source based on the pairing key.
[0072] S105: For any multicast member in the quantum secure multicast group, receive the encrypted supplementary multicast group key; obtain the encryption key, and decrypt the encrypted supplementary multicast group key based on the encryption key to obtain the supplementary multicast group key.
[0073] For any multicast member currently joined in the quantum-safe multicast group, the member can receive the encrypted supplementary multicast group key broadcast by the multicast key center using the multicast group identifier. The member then obtains the encryption key corresponding to the encrypted supplementary multicast group key. The encrypted supplementary multicast group key is then decrypted based on the encryption key to obtain the supplementary multicast group key, thereby supplementing the stored multicast group key based on the supplementary multicast group key.
[0074] It should be noted that after obtaining the supplementary multicast group key, the multicast group member can perform a security verification on the supplementary multicast group key. The specific process of this security verification can be referred to the process of security verification of the supplementary multicast group key by the quantum secure multicast source described above, and the repeated parts are not repeated here.
[0075] The beneficial effects of this application are as follows:
[0076] 1. Initiating key replenishment requests through a quantum-safe multicast source can not only reliably and securely implement key replenishment in a unicast source-wide quantum-safe multicast network, but also effectively avoid the situation where each multicast member in the quantum-safe multicast group has to make a key replenishment request. This would cause the multicast key center to process multiple redundant key replenishment requests simultaneously, thus reducing the processing burden on the multicast key center.
[0077] 2. Through the interaction between the first access base station and the multicast key center, distributed key management is achieved. This management method not only improves the flexibility of key management, but also reduces the impact on the entire system when a single node is attacked or fails.
[0078] 3. After generating and distributing the supplementary multicast group key, the multicast key center can encrypt the supplementary multicast group key based on the encryption key corresponding to the supplementary multicast group key and multicast it to all multicast members in the quantum secure multicast group. This not only ensures the security of the supplementary multicast group key, but also improves the real-time and continuity of key supplementation, and reduces the delay in synchronizing the supplementary multicast group key among the multicast members.
[0079] Example 2:
[0080] In order to securely download the supplementary multicast group key, based on the above embodiment, in this application, if the key supplement request and the multicast key distribution request message both carry a first key distribution identifier, and the first key distribution identifier indicates that the encryption key corresponding to the supplementary multicast group key is distributed by the multicast group key center when the multicast group key was distributed last time, then the multicast key center, the quantum secure multicast source and the multicast group member all retrieve the encryption key from their respective local storage.
[0081] In this application, the multicast key center, quantum-safe multicast source, and multicast group members can use a pre-distributed encryption key method to obtain the encryption key corresponding to the supplementary multicast group key. Under this strategy, the multicast key center is not only responsible for generating and distributing new multicast group keys, but also pre-distributes an encryption key to the quantum-safe multicast source and all multicast group members during each distribution. This key is used to encrypt the supplementary multicast group key for the next distribution. This way, whenever a multicast group key needs to be supplemented, each party can quickly retrieve the corresponding encryption key from its local storage, eliminating the need to rely on network transmission, greatly improving the speed and security of key updates.
[0082] Exemplarily, a quantum-secure multicast source initiates a key replenishment request carrying a key group identifier and a first key distribution identifier, and sends the key replenishment request to the first access base station. The first key distribution identifier indicates that the encryption key corresponding to this replenishment of the multicast group key was distributed by the multicast group key center during the previous replenishment of the multicast group key. The first key distribution identifier can be implemented as a digital signature, a hash value, or a unique serial number. These methods all ensure the uniqueness and traceability of the first key distribution identifier, and are not specifically limited here.
[0083] After receiving a key replenishment request from a quantum-secure multicast source, the first access base station can parse the request to obtain the multicast group identifier and first key distribution identifier carried in the request. Based on the multicast group identifier, the first access base station can query the key center information database configured by the network administrator to determine the multicast key center corresponding to the quantum-secure multicast source and its address information. Based on the address information, the first access base station can then send a multicast key distribution request message carrying the multicast group identifier and first key distribution identifier to the multicast key center.
[0084] After receiving the multicast key distribution request message sent by the first access base station, the multicast key center parses the message to obtain the multicast group identifier and first key distribution identifier carried in the message. Based on the multicast group identifier, the center queries the multicast key pool previously established for the quantum-secure multicast group. A supplementary multicast group key corresponding to the multicast group identifier is generated from the multicast key pool. Furthermore, the center obtains the encryption key previously distributed for the quantum-secure multicast group from the multicast key pool, thereby obtaining the encryption key corresponding to the supplementary multicast group key.
[0085] When the multicast key center obtains the supplemental multicast group key corresponding to the multicast group identifier and the encryption key corresponding to the supplemental multicast group key, it can generate a multicast key distribution response message and send it to the first access base station in response to the multicast key distribution request message sent by the first access base station. Simultaneously, the multicast key center quantum encrypts the supplemental multicast group key based on the encryption key. Then, the encrypted supplemental multicast group key is multicasted according to the multicast group identifier.
[0086] In one possible implementation, to ensure continuity and stability of key replenishment, the multicast key center also generates an encryption key (referred to as a pre-distributed encryption key) for encrypting the next distributed supplementary multicast group key. This pre-distributed encryption key is distributed along with the current supplementary multicast group key. Exemplarily, the multicast key center quantum encrypts the pre-distributed encryption key based on the encryption key corresponding to the supplementary multicast group key. The encrypted pre-distributed encryption key is then multicasted according to the multicast group identifier.
[0087] Upon receiving the multicast key distribution response message, the first access base station may generate a key supplement response message and send the message to the quantum secure multicast source, thereby promptly responding to the key supplement request sent by the quantum secure multicast source.
[0088] Upon receiving the key supplement response message and the encrypted supplementary multicast group key, the quantum-secure multicast source can retrieve the saved encryption key from local storage. Based on the encryption key, it can then decrypt the encrypted supplementary multicast group key to obtain the supplementary multicast group key.
[0089] In one possible implementation, the quantum-secure multicast source can also receive an encrypted pre-distributed encryption key multicasted by the multicast key center. The quantum-secure multicast source can decrypt the encrypted pre-distributed encryption key based on a locally stored encryption key to obtain the pre-distributed encryption key. The stored encryption key can then be supplemented using the pre-distributed encryption key.
[0090] It should be noted that after the quantum secure multicast source obtains the pre-distributed encryption key, it also needs to perform a security verification on the pre-distributed encryption key. The security verification process can refer to the process of performing security verification on the supplementary multicast group key in the above embodiment, and will not be described in detail here.
[0091] Similarly, any multicast member currently joined in the quantum-safe multicast group can receive the encrypted supplementary multicast group key broadcast by the multicast key center using the multicast group ID. The member then retrieves the stored encryption key from local storage. Based on the encryption key, the encrypted supplementary multicast group key is decrypted to obtain the supplementary multicast group key, thereby supplementing the stored multicast group key based on the supplementary multicast group key.
[0092] In one possible implementation, the multicast member can also receive an encrypted pre-distributed encryption key multicasted by the multicast key center. The multicast member can decrypt the encrypted pre-distributed encryption key based on a locally stored encryption key to obtain the pre-distributed encryption key. The pre-distributed encryption key can then be used to supplement the stored encryption key.
[0093] It should be noted that after obtaining the pre-distributed encryption key, the multicast group member can perform a security verification on the pre-distributed encryption key. The specific process of this security verification can be referred to the process of security verification of the supplementary multicast group key by the quantum secure multicast source mentioned above, and the repeated parts are not repeated here.
[0094] Figure 2A schematic diagram of a specific process for supplementing a unicast source global quantum-secure multicast network key provided in an embodiment of the present application. The process includes:
[0095] S201: The quantum secure multicast source sends a key supplement request carrying a multicast group identifier and a first key distribution identifier to the first access base station to which it is connected.
[0096] S202: The first access base station queries the key center information database configured by the network management according to the multicast group identifier, and determines the multicast key center corresponding to the quantum secure multicast source and the address information of the multicast key center.
[0097] S203: The first access base station sends a multicast key distribution request message carrying the multicast group identifier and the first key distribution identifier to the multicast key center according to the address information.
[0098] S204: The multicast key center queries the multicast key pool previously established for the quantum secure multicast group according to the multicast group identifier carried in the multicast key distribution request message.
[0099] S205: The multicast key center generates a supplementary multicast group key and a pre-distributed encryption key corresponding to the multicast group identifier in the multicast key pool based on the first key distribution identifier, and obtains the encryption key last distributed to the quantum secure multicast group in the multicast key pool.
[0100] S206: The multicast key center generates a multicast key distribution response message and sends it to the first access base station.
[0101] S207: The multicast key center performs quantum encryption on the supplementary multicast group key and the pre-distributed encryption key based on the encryption key, and multicasts the encrypted supplementary multicast group key and the encrypted pre-distributed encryption key according to the multicast group identifier.
[0102] S208: The first access base station generates a key supplement response message based on the multicast key distribution response message and sends it to the quantum secure multicast source.
[0103] S209: Upon receiving the key supplement response message, the encrypted supplementary multicast group key, and the encrypted pre-distributed encryption key, the quantum secure multicast source queries the stored encryption key from the local storage.
[0104] S210: The quantum secure multicast source decrypts the encrypted supplementary multicast group key and the encrypted pre-distributed encryption key based on the encryption key to obtain the supplementary multicast group key and the pre-distributed encryption key, supplements the stored multicast group key according to the supplementary multicast group key, and supplements the locally stored encryption key according to the pre-distributed encryption key.
[0105] For any multicast member currently joined in the quantum secure multicast group, the following steps S211 to S212 are executed:
[0106] S211: The multicast group member receives the encrypted supplementary multicast group key and the encrypted pre-distributed encryption key multicasted by the multicast key center through the multicast group identifier.
[0107] S212: The multicast group member obtains the saved encryption key from the local storage, decrypts the encrypted supplementary multicast group key based on the encryption key to obtain the supplementary multicast group key, supplements the saved multicast group key according to the supplementary multicast group key, and supplements the locally saved encryption key according to the pre-distributed encryption key.
[0108] Example 3:
[0109] To securely download the supplementary multicast group key, based on the above embodiments, in this application, if both the key supplementation request and the multicast key distribution request message carry a second key distribution identifier, where the second key distribution identifier indicates that the encryption key corresponding to the supplementary multicast group key is newly generated by the multicast group key center, then both the multicast key distribution response message and the key supplementation response message carry the encryption key.
[0110] The multicast key center multicasts the supplementary multicast group key encrypted based on the encryption key according to the multicast group identifier, including:
[0111] According to the multicast group identifier, multicast the current distribution identifier and the supplementary multicast group key encrypted based on the encryption key; wherein the current distribution identifier is used to query the encryption key generated this time;
[0112] The quantum secure multicast source obtains the encryption key, including:
[0113] Obtaining the encryption key from the key supplement response message;
[0114] The multicast group member obtains the encryption key in the following manner, including:
[0115] The multicast group member receives the current distribution identifier; sends an encryption key supplement request carrying the current distribution identifier and the multicast group identifier to the second access base station, so as to determine the multicast key center corresponding to the multicast group identifier through the second access base station, and forwards the encryption key supplement request to the multicast key center;
[0116] The encryption key response message carrying the encryption key sent by the multicast key center is received through the second access base station; wherein the multicast key center determines the encryption key requested by the multicast group member through the multicast group identifier and the current distribution identifier carried in the encryption key supplement request.
[0117] For a public unicast-source, global quantum-secure multicast network, members may frequently join and leave the group. Furthermore, in the case where the behavior of multicast members is uncontrollable, to ensure the independence of each supplementary multicast group key, members who exit the unicast-source, global quantum-secure multicast network must be prevented from illegally obtaining the subsequently distributed supplementary multicast group key. Based on this, in this application, a new encryption key distribution method can be adopted to obtain the encryption key corresponding to the current supplementary multicast group key. Specifically, under this strategy, the multicast key center is not only responsible for generating and distributing new multicast group keys, but also generates an encryption key corresponding to the current supplementary multicast group key during each distribution. Then, under the legitimate request mechanism of the multicast member, the newly generated encryption key is distributed to the multicast member. In this way, whether a multicast member has joined the quantum-secure multicast group or has exited the quantum multicast group, they can only receive the encrypted supplementary multicast group key through the multicast group identifier, but not the encryption key corresponding to the supplementary multicast group key. Only when the encryption key corresponding to the supplementary multicast group key is obtained from the multicast key center according to the legal request process can the real supplementary multicast group key be obtained, ensuring the independence of each supplementary multicast group key, thereby effectively preventing the risk of key leakage.
[0118] Exemplarily, the quantum-secure multicast source initiates a key replenishment request carrying a key group identifier and a second key distribution identifier, and sends the key replenishment request to the first access base station. The second key distribution identifier indicates that the encryption key corresponding to this replenished multicast group key was newly generated by the multicast group key center. This second key distribution identifier can be implemented as a digital signature, a hash value, or a unique serial number. These methods all ensure uniqueness and traceability of the second key distribution identifier, and are not specifically limited here.
[0119] After receiving a key replenishment request from a quantum-secure multicast source, the first access base station can parse the request to obtain the multicast group identifier and the second key distribution identifier carried in the request. Based on the multicast group identifier, the first access base station can query the key center information database configured by the network administrator to determine the multicast key center corresponding to the quantum-secure multicast source and its address information. Based on the address information, the first access base station can then send a multicast key distribution request message carrying the multicast group identifier and the second key distribution identifier to the multicast key center.
[0120] After receiving the multicast key distribution request message from the first access base station, the multicast key center parses the message to obtain the multicast group identifier and second key distribution identifier carried in the message. Based on the multicast group identifier, the multicast key pool previously established for the quantum-secure multicast group is retrieved. The multicast key pool generates and stores a supplementary multicast group key corresponding to the multicast group identifier, an encryption key corresponding to the supplementary multicast group key, and a current distribution identifier. The current distribution identifier facilitates subsequent multicast key center queries for the currently generated encryption key.
[0121] When the multicast key center obtains the supplementary multicast group key corresponding to the multicast group identifier and the encryption key corresponding to the supplementary multicast group key, it can generate a multicast key distribution response message carrying the encryption key and send it to the first access base station in response to the multicast key distribution request message sent by the first access base station. Simultaneously, the multicast key center quantum encrypts the supplementary multicast group key based on the encryption key. Then, the multicast key center multicasts the current distribution identifier and the encrypted supplementary multicast group key according to the multicast group identifier.
[0122] Upon receiving the multicast key distribution response message, the first access base station may generate a key replenishment response message carrying the encryption key and send it to the quantum-secure multicast source, thereby promptly responding to the key replenishment request sent by the quantum-secure multicast source. For example, the first access base station may quantum-encrypt the key replenishment request and send it to the quantum-secure multicast source based on a pairing key symmetric with the quantum-secure multicast source to ensure the security of the encryption key.
[0123] Upon receiving the key supplement response message and the encrypted supplementary multicast group key, the quantum-secure multicast source can obtain the encryption key from the key supplement response message. The encrypted supplementary multicast group key is then decrypted based on the encryption key to obtain the supplementary multicast group key. For example, the quantum-secure multicast source decrypts the received encrypted key supplement request based on a symmetric pairing key with the first access base station to obtain the encryption key carried in the key supplement request.
[0124] For any multicast member currently participating in the quantum-safe multicast group, the member can receive the current distribution identifier and encrypted supplementary multicast group key from the multicast key center using the multicast group identifier. The member can then generate an encryption key supplement request based on the current distribution identifier and the multicast group identifier and send it to the second access base station. For example, the member can quantum-encrypt the encryption key supplement request using a symmetric pairing key with the second access base station.
[0125] After receiving the encryption key supplement request, the second access base station can parse the encryption key supplement request and extract the multicast group identifier and current distribution identifier carried in the encryption key supplement request. It then queries the pre-configured key centers corresponding to the multicast group identifiers to determine whether a multicast key center corresponding to the multicast group identifier carried in the encryption key supplement request exists. If it is determined that a multicast key center corresponding to the multicast group identifier exists, indicating that a quantum-secure multicast group corresponding to the multicast group identifier exists, the address information of the multicast key center is obtained. Based on the address information, the encryption key supplement request is sent to the multicast key center. If it is determined that a multicast key center corresponding to the multicast group identifier does not exist, indicating that the quantum-secure multicast group corresponding to the multicast group identifier has not yet been established, the multicast group member can be refused to respond.
[0126] In a possible implementation manner, after the second access base station determines the multicast key center corresponding to the multicast group identifier and before forwarding the encryption key supplement request to the multicast key center, the method further includes:
[0127] According to the identity information of the multicast member, it is determined whether the multicast member has the authority to obtain the encryption key.
[0128] To ensure the legitimacy of the multicast group member requesting the encryption key, in this application, the second access base station can verify the identity information of the quantum security terminal requesting the encryption key to determine whether the quantum security terminal has permission to request the encryption key. This identity information may include, but is not limited to, a MAC address, IP address, network access ID, or other security credentials that can be used to verify identity. Exemplarily, after receiving the encryption key replenishment request, the second access base station can obtain the multicast group ID and the identity information of the quantum security terminal that sent the encryption key replenishment request from the encryption key replenishment request. If the quantum security multicast group corresponding to the multicast group ID is found in the network management configuration based on the multicast group ID, the second access base station determines whether the quantum security terminal meets the request conditions for requesting the encryption key based on the identity information. This request condition can take various forms, including but not limited to: the identity information of the multicast member is the identity information of an authorized member who is authorized to join the quantum security multicast group, the identity information of the multicast member is not the identity information of an denied member who is denied to join the quantum security multicast group, and the number of times the identity information has joined the quantum security multicast group within a unit time period is less than a preset threshold. If, based on the identity information, it is determined that the quantum security terminal meets the request conditions for requesting an encryption key, indicating that the quantum security terminal has the authority to request an encryption key, then the multicast key center is determined based on the multicast group identifier. If, based on the identity information, it is determined that the quantum security terminal does not meet the request conditions for requesting an encryption key, indicating that the quantum security terminal is in violation of the regulations and does not have the authority to request an encryption key, then the quantum security terminal is rejected.
[0129] Based on the above embodiment, the multicast key center can receive an encryption key supplement request sent by the second access base station, parse the encryption key supplement request, and obtain the multicast group identifier and current distribution identifier carried in the multicast group key. Based on the multicast group identifier, the center then searches a multicast key pool previously established for the multicast group identifier and, based on the current distribution identifier, obtains the encryption key corresponding to the currently supplemented multicast group key from the multicast key pool. The center then sends an encryption key response message carrying the encryption key to the second access base station, so that the second access base station can forward the encryption key to the multicast member.
[0130] Once the second access base station receives the encryption key response message from the multicast key center, it can forward the encryption key response message to the multicast member. For example, the second access base station can use the symmetric key paired with the multicast member to quantum encrypt the encryption key response message and send it to the multicast member, thereby preventing the encryption key from being directly exposed in plain text on the network.
[0131] If the multicast group member receives the encrypted encryption key response message sent by the second access base station, it can obtain the symmetric key with the second access base station and then decrypt the encrypted encryption key response message based on the symmetric key to obtain the encryption key. After obtaining the encryption key, the multicast group member can decrypt the received encrypted supplemental multicast group key based on the encryption key to obtain the supplemental multicast group key.
[0132] It should be noted that after obtaining the encryption key, the multicast member can perform a security verification on the encryption key. The specific process of this security verification can be referred to the process of security verification of the supplementary multicast group key by the quantum secure multicast source mentioned above, and the repeated parts are not repeated here.
[0133] Figure 3 A schematic diagram of a specific process for supplementing a unicast source global quantum-secure multicast network key provided in an embodiment of the present application. The process includes:
[0134] S301: The quantum secure multicast source sends a key supplement request carrying a multicast group identifier and a second key distribution identifier to the first access base station to which it is connected.
[0135] S302: The first access base station queries the key center information database configured by the network management according to the multicast group identifier, and determines the multicast key center corresponding to the quantum secure multicast source and the address information of the multicast key center.
[0136] S303: The first access base station sends a multicast key distribution request message carrying the multicast group identifier and the second key distribution identifier to the multicast key center according to the address information.
[0137] S304: The multicast key center queries the multicast key pool previously established for the quantum secure multicast group according to the multicast group identifier carried in the multicast key distribution request message.
[0138] S305: The multicast key center generates, based on the second key distribution identifier, a supplementary multicast group key corresponding to the multicast group identifier, an encryption key corresponding to the supplementary multicast group key, and a current distribution identifier in the multicast key pool.
[0139] S306: The multicast key center generates a multicast key distribution response message carrying the encryption key and sends the message to the first access base station.
[0140] S307: The multicast key center performs quantum encryption on the supplementary multicast group key based on the encryption key, and multicasts the current distribution identifier and the encrypted supplementary multicast group key according to the multicast group identifier.
[0141] S308: The first access base station generates a key supplement response message carrying the encryption key based on the multicast key distribution response message and sends the message to the quantum secure multicast source.
[0142] S309: Upon receiving the key supplement response message and the encrypted supplemented multicast group key, the quantum secure multicast source obtains the encryption key from the key supplement response message.
[0143] S310: The quantum secure multicast source decrypts the encrypted supplementary multicast group key based on the encryption key to obtain the supplementary multicast group key, and supplements the stored multicast group key according to the supplementary multicast group key.
[0144] For any multicast member currently joined in the quantum secure multicast group, the following steps S311 to S312 are executed:
[0145] S311: The multicast group member receives the current distribution identifier and the encrypted supplementary multicast group key multicasted by the multicast key center through the multicast group identifier.
[0146] S312: The multicast group member sends an encryption key supplement request carrying the current distribution identifier and the multicast group identifier to the second access base station to which it is connected.
[0147] S313: After receiving the encryption key supplement request, the second access base station obtains the identity information of the multicast member from the encryption key supplement request, and determines whether the multicast member has the authority to request the encryption key based on the identity information.
[0148] S314: When determining that the multicast group member has the authority to request the encryption key, the second access base station determines the multicast key center and the address information of the multicast key center based on the multicast group identifier.
[0149] S315: The second access base station forwards the encryption key supplement request to the multicast key center according to the address information.
[0150] S316: After receiving the encryption key supplement request, the multicast key center searches for the multicast key pool previously established for the multicast group identifier according to the multicast group identifier carried in the encryption key supplement request, and obtains the encryption key corresponding to the supplemented multicast group key from the multicast key pool based on the current distribution identifier carried in the encryption key supplement request.
[0151] S317: The multicast key center sends an encryption key response message carrying the encryption key to the second access base station.
[0152] S318: After receiving the encryption key response message, the second access base station encrypts and sends the encryption key response message to the multicast member based on the symmetric key with the multicast member.
[0153] S319: The multicast member decrypts the received encrypted encryption key response message based on the symmetric key with the second access base station to obtain the encryption key.
[0154] S320: The multicast group member decrypts the received encrypted supplementary multicast group key based on the encryption key to obtain the supplementary multicast group key, and supplements the stored multicast group key according to the supplementary multicast group key.
Claims
1. A method for supplementing keys in a unicast source global quantum secure multicast network, characterized in that: The method comprises: The quantum secure multicast source initiates a key supplement request message to the first access base station to which it is connected; wherein the key supplement request carries a multicast group identifier of the quantum secure multicast group; The first access base station receives the key supplement request; determines a multicast key center corresponding to the multicast group identifier; and sends a multicast key distribution request message carrying the multicast group identifier to the multicast key center; The multicast key center receives the multicast key distribution request message; generates a supplementary multicast group key corresponding to the multicast group identifier, obtains an encryption key corresponding to the supplementary multicast group key; generates a multicast key distribution response message and sends it to the first access base station, so that the first access base station generates a key supplement response message based on the received multicast key distribution response message and sends it to the quantum secure multicast source; and, according to the multicast group identifier, multicasts the supplementary multicast group key encrypted based on the encryption key. The quantum secure multicast source receives the key supplement response message and the encrypted supplementary multicast group key; obtains the encryption key, and decrypts the encrypted supplementary multicast group key based on the encryption key to obtain the supplementary multicast group key; For any multicast member in the quantum secure multicast group, the encrypted supplementary multicast group key is received; the encryption key is obtained, and the encrypted supplementary multicast group key is decrypted based on the encryption key to obtain the supplementary multicast group key.
2. The method according to claim 1, wherein The communication mode between the quantum secure multicast source and the first access base station is: quantum secure encrypted communication based on a symmetric pairing key between the two parties.
3. The method according to claim 1, wherein If both the key supplement request and the multicast key distribution request message carry a first key distribution identifier, and the first key distribution identifier indicates that the encryption key corresponding to the supplementary multicast group key was distributed by the multicast group key center when the multicast group key was distributed last time, then the multicast key center, the quantum secure multicast source, and the multicast group member all retrieve the encryption key from their respective local storage.
4. The method according to claim 3, wherein The method further comprises: The multicast key center generates a pre-distributed encryption key for encrypting a supplementary multicast group key to be distributed next time; performs quantum encryption on the pre-distributed encryption key based on the encryption key; and multicasts the encrypted pre-distributed encryption key according to the multicast group identifier; The quantum secure multicast source receives the encrypted pre-distributed encryption key; decrypts the encrypted pre-distributed encryption key based on the encryption key to obtain the pre-distributed encryption key; and supplements the currently unused encryption key according to the pre-distributed encryption key.
5. The method according to claim 1, wherein If both the key supplement request and the multicast key distribution request message carry a second key distribution identifier, and the second key distribution identifier indicates that the encryption key corresponding to the supplemented multicast group key is newly generated by the multicast group key center, then both the multicast key distribution response message and the key supplement response message carry the encryption key; The multicast key center multicasts the supplementary multicast group key encrypted based on the encryption key according to the multicast group identifier, including: According to the multicast group identifier, multicast the current distribution identifier and the supplementary multicast group key encrypted based on the encryption key; wherein the current distribution identifier is used to query the encryption key generated this time; The quantum secure multicast source obtains the encryption key, including: Obtaining the encryption key from the key supplement response message; The multicast group member obtains the encryption key in the following manner, including: The multicast group member receives the current distribution identifier; sends an encryption key supplement request carrying the current distribution identifier and the multicast group identifier to the second access base station, so as to determine the multicast key center corresponding to the multicast group identifier through the second access base station, and forwards the encryption key supplement request to the multicast key center; The encryption key response message carrying the encryption key sent by the multicast key center is received through the second access base station; wherein the multicast key center determines the encryption key requested by the multicast group member through the multicast group identifier and the current distribution identifier carried in the encryption key supplement request.
6. The method according to claim 4, wherein After the second access base station determines the multicast key center corresponding to the multicast group identifier and before forwarding the encryption key supplement request to the multicast key center, the method further includes: According to the identity information of the multicast member, it is determined whether the multicast member has the authority to obtain the encryption key.
Citation Information
Patent Citations
Quantum key security supplement method, device and system and medium
CN115664654A
Method for distributing pairing key for quantum security terminal through access base station
CN117528533A