A Mesh Ad hoc Network Quantum-Safe Communication Method and System
By pre-storing truly random numbers representing the one-way receive and send relationships in each node of a Mesh self-organizing network, quantum-secure communication is achieved, solving the problem of vulnerability of Mesh self-organizing network communication information to attacks and realizing comprehensive data security transmission and network stability.
Patent Information
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- MATRICTIME DIGITAL TECH CO LTD
- Filing Date
- 2024-12-19
- Publication Date
- 2026-05-26
AI Technical Summary
Mesh self-organizing networks are vulnerable to attacks and eavesdropping due to their dynamic, multi-hop, and decentralized nature, leading to communication security and reliability issues.
In a Mesh self-organizing network, each node pre-stores decryption and encryption true random numbers corresponding to each one-way receive and send relationship, realizing quantum-secure communication and ensuring quantum-secure transmission between any two nodes.
It enables comprehensive secure data transmission between any two quantum-safe terminals in a Mesh self-organizing network, ensuring the security and stability of communication, and not affecting network security when a node loses connection.
Smart Images

Figure CN119675862B_ABST
Abstract
Description
Technical Field
[0001] This application relates to the fields of information security and quantum encryption technology, and in particular to a quantum-secure communication method and system for the entire Mesh self-organizing network. Background Technology
[0002] Mesh (wireless mesh) self-organizing networks, as an advanced network architecture, occupy a pivotal position in modern communications due to their unique self-organizing, self-configuring, and self-healing capabilities. The core advantage of this network architecture lies in the versatility of its node functions; each node in the network can not only act as an access point for end users, transmitting and receiving data, but also act as a router, forwarding data packets to other nodes. This design enables mesh self-organizing networks to build dynamic, multi-hop, and decentralized communication networks, greatly improving network flexibility and reliability.
[0003] In practical applications, this characteristic of mesh self-organizing networks has led to their widespread use in various important scenarios. For example, in some intelligent applications, mesh self-organizing networks can quickly establish temporary communication networks, providing stable and reliable communication support for staff; in drone communication, mesh self-organizing networks can ensure unimpeded communication between drones and between drones and ground control stations, providing strong communication support for drone communication; furthermore, in applications involving intelligent robots such as robotic dogs and robotic wolves, mesh self-organizing networks can also leverage their unique advantages to achieve information sharing and collaborative operation among robots.
[0004] However, with the widespread application of mesh self-organizing network communication in various fields, the security of its communication information has become increasingly prominent. Because data transmission in mesh self-organizing networks is dynamic, multi-hop, and lacks a fixed central node, information within the network is more vulnerable to attacks and eavesdropping. Once communication information is leaked or tampered with, it can seriously impact task execution and command and control in the workplace. Therefore, ensuring the security and reliability of communication information in mesh self-organizing networks has become a crucial issue that urgently needs to be addressed. Summary of the Invention
[0005] This application provides a quantum-safe communication method and system for the entire Mesh self-organizing network, which can be used to realize quantum-safe communication in the Mesh self-organizing network.
[0006] In a first aspect, this application provides a method for full-domain quantum-secure communication in a Mesh self-organizing network, the method being applied to any quantum-secure terminal in a Mesh self-organizing network, the method comprising:
[0007] For the first quantum encrypted data sent from any transmitter in the Mesh ad hoc network, a target decryption true random number is determined from the pre-saved decryption true random numbers corresponding to each one-way receiving relationship in the Mesh ad hoc network, representing the target one-way receiving relationship from the transmitter to the quantum secure terminal; based on the target decryption true random number, the first quantum encrypted data is quantum decrypted to obtain the first plaintext data; wherein, the type of the first plaintext data includes the following: application data, key file, and security signaling;
[0008] For the second plaintext data to be sent to any receiver in the Mesh ad hoc network, a target encrypted true random number representing the target transmission relationship from the quantum-secure terminal to the receiver is determined from the encrypted true random numbers corresponding to each one-way transmission relationship in the Mesh ad hoc network that are saved in advance; wherein, the type of the second plaintext data includes the following: application data, key file, and service signaling; based on the target encrypted true random number, the second plaintext data is quantum encrypted to obtain second quantum encrypted data; and the second quantum encrypted data is sent to the receiver.
[0009] Secondly, this application also provides a Mesh self-organizing network global quantum-safe communication system, the system including a quantum-safe terminal for performing the methods described above.
[0010] The beneficial effects of this application are as follows:
[0011] For any quantum-secure terminal in a mesh network, since it pre-stores the decryption true random numbers corresponding to each one-way receiving relationship and the encryption true random numbers corresponding to each one-way sending relationship in the mesh network, the quantum-secure terminal can perform quantum decryption on the first quantum-encrypted data sent from any sender in the mesh network based on the decryption symmetric true random numbers corresponding to each one-way receiving relationship. Based on the encryption true random numbers corresponding to each one-way sending relationship in the mesh network, it can quantum-encrypt and send the second plaintext data to any receiver in the mesh network, thereby achieving quantum-secure communication between any two quantum-secure terminals in the mesh network and ensuring the communication security of the decentralized mesh network. Furthermore, the key files, security signaling, and application data used for communication between two quantum-secure terminals in the mesh network can all be transmitted using this quantum-secure communication method, thus achieving comprehensive protection of the data security of communication between the two quantum-secure terminals in the mesh network. Attached Figure Description
[0012] To more clearly illustrate the technical solutions in the embodiments of this application, the accompanying drawings used in the description of the embodiments will be briefly introduced below. Obviously, the accompanying drawings described below are only some embodiments of this application. For those skilled in the art, other drawings can be obtained based on these drawings without creative effort.
[0013] Figure 1 This application provides a schematic diagram of a process for global quantum-secure communication in a Mesh self-organizing network.
[0014] Figure 2 A communication topology diagram of 7 nodes in a Mesh self-organizing network provided in an embodiment of this application;
[0015] Figure 3 A communication topology diagram of 7 nodes in a Mesh self-organizing network provided in another embodiment of this application;
[0016] Figure 4 A communication topology diagram of 7 nodes in a Mesh self-organizing network provided in another embodiment of this application;
[0017] Figure 5 A communication topology diagram of 7 nodes in a Mesh self-organizing network provided in another embodiment of this application;
[0018] Figure 6 This application provides a system architecture diagram for a Mesh self-organizing network with full-domain quantum secure communication. Detailed Implementation
[0019] To make the objectives, technical solutions, and advantages of this application clearer, the application will be further described in detail below with reference to the accompanying drawings. Obviously, the described embodiments are only some embodiments of this application, and not all embodiments. Based on the embodiments in this application, all other embodiments obtained by those skilled in the art without creative effort are within the scope of protection of this application.
[0020] To improve the security of Mesh self-organizing network communication, this application provides a quantum-secure communication method and system for the entire Mesh self-organizing network.
[0021] Example 1:
[0022] Figure 1 A schematic diagram illustrating a process for full-domain quantum-secure communication in a Mesh self-organizing network, provided in this application embodiment, includes:
[0023] S101: For the first quantum encrypted data sent from any transmitter in the Mesh self-organizing network, a target decryption true random number is determined from the pre-saved decryption true random numbers corresponding to each one-way receiving relationship in the Mesh self-organizing network, representing the target one-way receiving relationship from the transmitter to the quantum secure terminal; based on the target decryption true random number, the first quantum encrypted data is quantum decrypted to obtain the first plaintext data; wherein, the type of the first plaintext data includes the following: application data, key file, and security signaling.
[0024] S102: For the second plaintext data to be sent to any receiving end in the Mesh self-organizing network, determine the target encrypted true random number corresponding to the target transmission relationship from the quantum-secure terminal to the receiving end from the encrypted true random numbers corresponding to each one-way transmission relationship in the pre-saved Mesh self-organizing network; wherein, the type of the second plaintext data includes the following: application data, key file, service signaling; based on the target encrypted true random number, perform quantum encryption on the second plaintext data to obtain second quantum encrypted data; send the second quantum encrypted data to the receiving end.
[0025] In this application, the Mesh self-organizing network is a decentralized, self-healing communication network. Each node in this network has a neighbor table and a routing table for communicating with neighbors or forwarding data. This means that any node in the Mesh self-organizing network can communicate with any other node, and the communication relationships between the nodes in the entire Mesh self-organizing network form a mesh structure. Furthermore, in the Mesh self-organizing network global quantum-safe communication method provided in this application, the nodes in the Mesh self-organizing network are quantum-safe terminals. These quantum-safe terminals possess quantum-safe communication capabilities, providing the device foundation for quantum-safe communication between the nodes in the Mesh self-organizing network.
[0026] To achieve quantum-secure communication between nodes in this mesh network, this application requires storing truly random numbers for quantum-secure communication in each node based on the communication relationships between the nodes. Taking a mesh network with 7 nodes as an example (nodes are labeled AG; the situation is similar for other numbers of nodes), a quantum-secure communication mechanism is established based on the communication relationships between these 7 nodes, as follows: Figure 2 The mathematical model shown. Figure 2 In this context, AG can act as both a receiver and a sender. Based on the one-way communication relationship between these seven nodes and excluding scenarios where the node sends data to itself, the remaining nodes will be... Figure 2 In the mathematical model, each empty cell represents a one-way communication relationship. For example... Figure 3As shown, the communication relationship between B and C occupies two blank cells. These two blank cells represent different one-way communication relationships between B and C. The one-way communication relationship from C to B indicates that C is the sender and B is the receiver. The one-way communication relationship from B to C indicates that B is the sender and C is the receiver.
[0027] For each empty cell, that is, for each type of one-way communication relationship, assign a set of truly random numbers, denoted as R(X, Y), to the sender and receiver in that type of one-way communication relationship, where X is the sender and Y is the receiver. Taking the one-way communication relationship between B and C as an example again, such as... Figure 4 This means that the truly random number corresponding to the one-way communication relationship C->B is R(C, B), and the truly random number corresponding to the one-way communication relationship B->C is R(B, C). Thus, each empty cell corresponds to a set of truly random numbers, meaning each type of one-way communication relationship corresponds to a set of truly random numbers. When performing quantum-secure communication using a specific type of one-way communication relationship, the sending and receiving ends can achieve quantum encryption and decryption based on the truly random numbers corresponding to that one-way communication relationship.
[0028] like Figure 5 As shown, if the nodes on the horizontal axis are the receivers and the nodes on the vertical axis are the senders, then for any node on the vertical axis, each blank cell on the horizontal axis corresponding to that node can be understood as an encrypted truly random number used by that node when sending data to other nodes on that horizontal axis. Similarly, for any node on the horizontal axis, each blank cell on the vertical axis corresponding to that node can be understood as a decrypted truly random number used by that node when receiving data from other nodes on that vertical axis. Taking C as an example... Figure 5 In the diagram, C corresponds to a horizontal axis and a vertical axis. That is, if C communicates with all other nodes in the Mesh self-organizing network in a quantum-safe manner, C needs to store the decrypted true random number and the encrypted true random number for communicating with all other nodes in a quantum-safe manner.
[0029] Therefore, each node in a mesh network is assigned two types of truly random numbers: a horizontally assigned encrypted truly random number and a vertically assigned decrypted truly random number. The encrypted truly random number contains the encrypted truly random numbers used by the node as a sender to send data to all other nodes in the mesh network; that is, the encrypted truly random numbers corresponding to each one-way transmission relationship in the mesh network. The decrypted truly random number contains the decrypted truly random numbers used by the node as a receiver to receive data sent from all other nodes in the mesh network; that is, the decrypted truly random numbers corresponding to each one-way reception relationship in the mesh network. Through this processing, any node in the mesh network can conduct bidirectional quantum-safe encrypted communication with all other nodes in the mesh network; it can both send quantum-safe encrypted messages and receive quantum-safe encrypted data and decrypt it.
[0030] It should be noted that in this mesh ad hoc network, for any two communicating nodes, the encrypted true random number corresponding to the one-way transmission relationship from one node to another, stored at the sending end, is symmetrical to the decrypted true random number corresponding to the one-way reception relationship from the sending end to the receiving end. For example, in this mesh ad hoc network, for any two communicating nodes C and A, the encrypted true random number stored in C corresponding to the one-way transmission relationship from C to A is symmetrical to the decrypted true random number stored in A corresponding to the one-way reception relationship from C to A, and the encrypted true random number stored in A corresponding to the one-way transmission relationship from A to C is symmetrical to the decrypted true random number stored in C corresponding to the one-way reception relationship from A to C.
[0031] For any quantum-safe terminal in this mesh self-organizing network, after pre-saving the truly random numbers corresponding to each unidirectional communication direction, the quantum-safe terminal can act as both a receiver and a transmitter, engaging in quantum-safe communication with all other quantum-safe terminals in the mesh self-organizing network. The following explains a specific scenario:
[0032] Scenario 1: A quantum-safe terminal acts as the receiver.
[0033] When a quantum-safe terminal acts as a receiver, it can continuously monitor the communication channels with all other quantum-safe terminals in the Mesh self-organizing network, i.e., the communication channels with each sender, in order to capture any encrypted data sent to it in a timely manner (denoted as the first quantum encrypted data).
[0034] Once the first quantum-encrypted data is received from any transmitter in the mesh network, the quantum-secure terminal can determine the one-way reception relationship (denoted as the target one-way reception relationship) representing the relationship from the transmitter to the quantum-secure terminal. Then, it determines the target decryption true random number (denoted as the target decryption true random number) from the pre-saved list of decryption true random numbers corresponding to each one-way reception relationship in the mesh network. For example, if the quantum-secure terminal is C, the transmitter is A, and the target one-way reception relationship is A->C, C will find the target decryption true random number R(A, C) corresponding to A->C from its pre-saved list of decryption true random numbers corresponding to each one-way reception relationship.
[0035] The quantum-safe terminal then decrypts the true random number based on the target to determine the decryption key. Based on this decryption key, the first quantum-encrypted data is quantum-decrypted to obtain plaintext data (denoted as the first plaintext data). This first plaintext data can be of the following types: application data, key file, and security signaling. The application data is the business data sent from the sender to the receiver, which the receiver then passes to the upper-layer application for processing. The key file contains supplementary true random numbers sent by the sender, which the receiver can store or update in the key management system. The security signaling refers to the signaling between the sender and receiver regarding quantum-safe services, such as supplementary messages.
[0036] It should be noted that this quantum decryption process is existing technology and will not be described in detail here.
[0037] Scenario 2: Quantum-safe terminal as the transmitter.
[0038] When a quantum-secure terminal in a mesh network acts as a transmitter, it first prepares plaintext data (denoted as the second plaintext data) to be sent to a receiver in the mesh network. This second plaintext data can be application data (such as business data generated by upper-layer applications, files, etc.), key files, or business signaling (such as supplementary messages). The target transmission relationship between the quantum-secure terminal and the receiver is determined. For example, if the quantum-secure terminal is C and the receiver is A, then the target transmission relationship is C->A. From the pre-saved encrypted true random numbers corresponding to each one-way transmission relationship in the mesh network, the encrypted true random number corresponding to the target transmission relationship is determined (denoted as the target encrypted true random number). For example, from the pre-saved encrypted true random numbers corresponding to each one-way transmission relationship in the mesh network, the target encrypted true random number R(C, A) corresponding to C->A is determined.
[0039] Based on a determined target encrypted true random number, an encryption key is determined. Using this encryption key, the second plaintext data is quantum encrypted to obtain quantum encrypted data (denoted as the second quantum encrypted data).
[0040] It should be noted that this quantum encryption process is existing technology and will not be described in detail here.
[0041] After obtaining the second quantum encrypted data, the quantum-safe terminal can send the second quantum encrypted data to the receiving end.
[0042] In one possible implementation, the method further includes:
[0043] If it is determined that the quantum-secure terminal at the other end of any one-way communication relationship is lost, the true random number corresponding to the one-way communication relationship is discarded; wherein, the one-way communication relationship includes one-way sending relationship and one-way receiving relationship.
[0044] When any node in the entire mesh network becomes disconnected—for example, due to offline status, theft, or system crash—this disconnection does not affect quantum-secure communication between all other nodes in the mesh network. This is because each node only possesses the truly random numbers corresponding to its own associated one-way communication relationship, and does not have the truly random numbers required for communication between other nodes. Therefore, the disconnection of any node in the mesh network does not affect the security and stability of the mesh network. Furthermore, for any quantum-secure terminal in the mesh network, if it determines that the peer quantum-secure terminal in a certain one-way communication relationship is disconnected, it can discard the truly random numbers corresponding to that one-way communication relationship. For example, if it is determined that the peer quantum-secure terminal in a certain one-way receiving relationship is disconnected, the decryption truly random number corresponding to that one-way receiving relationship is discarded; if it is determined that the peer quantum-secure terminal in a certain one-way sending relationship is disconnected, the encryption truly random number corresponding to that one-way sending relationship is discarded.
[0045] The beneficial effects of this application are as follows:
[0046] For any quantum-secure terminal in a mesh network, since it pre-stores the decryption true random numbers corresponding to each one-way receiving relationship and the encryption true random numbers corresponding to each one-way sending relationship in the mesh network, the quantum-secure terminal can perform quantum decryption on the first quantum-encrypted data sent from any sender in the mesh network based on the decryption symmetric true random numbers corresponding to each one-way receiving relationship. Based on the encryption true random numbers corresponding to each one-way sending relationship in the mesh network, it can quantum-encrypt and send the second plaintext data to any receiver in the mesh network, thereby achieving quantum-secure communication between any two quantum-secure terminals in the mesh network and ensuring the communication security of the decentralized mesh network. Furthermore, the key files, security signaling, and application data used for communication between two quantum-secure terminals in the mesh network can all be transmitted using this quantum-secure communication method, thus achieving comprehensive protection of the data security of communication between the two quantum-secure terminals in the mesh network.
[0047] Example 2:
[0048] For the Mesh self-organizing network of this application, its unique mesh structure makes the communication relationships between nodes intricate and complex. Especially when building a Mesh self-organizing network of tens of thousands, each node needs to pre-configure a large number of initial true random numbers corresponding to one-way communication relationships to ensure the smooth operation of quantum-secure communication. Specifically, for any node in this Mesh self-organizing network, the node needs to store the decryption true random numbers and encryption true random numbers corresponding to the quantum-secure communication between the node and tens of thousands of other nodes. This undoubtedly places extremely high demands on the storage space of the quantum-secure terminal.
[0049] However, limited by the storage space of current quantum-safe terminals, the number of pre-set truly random numbers cannot be infinitely large. Therefore, replenishing truly random numbers becomes a necessary requirement during long-term task execution. To maintain the continuity and stability of quantum-safe communication across the entire Mesh self-organizing network, this application proposes an innovative key replenishment mechanism.
[0050] Conventional key replenishment is based on a key center distributing keys to a requesting quantum-safe terminal. However, a Mesh self-organizing network is a decentralized communication network, where any node may go offline or leave the network at any time. To ensure that the offline or exiting of any node does not affect the quantum-safe communication security of the entire Mesh self-organizing network, every node in the Mesh self-organizing network needs to have key distribution capabilities. That is, every node in the Mesh self-organizing network must have quantum-safe encryption and decryption capabilities and key distribution capabilities for full-domain quantum-safe encrypted communication. Only in this way can the decentralization of the Mesh self-organizing network be satisfied.
[0051] Specifically, since each node possesses the capability to generate truly random numbers, when a quantum-secure terminal detects an insufficiency of truly random numbers with a particular node, it can proactively trigger a key distribution mechanism. This mechanism encrypts the supplementary truly random numbers using existing encrypted truly random numbers and distributes these supplementary numbers to the other end. In the communication relationship between two nodes, each is responsible for key detection and distribution for a one-way communication relationship. Because encrypted truly random numbers are used first and then replenished, each node is responsible for monitoring the usage of encrypted truly random numbers in its own one-way transmission relationship and promptly replenishing the other end with truly random numbers when a shortage is detected.
[0052] Therefore, in this application, the type of plaintext data used for communication between two nodes in a Mesh ad hoc network can be a key file containing supplementary true random numbers. For example, when the second plaintext data is a key file, obtaining the second plaintext data to be sent to the receiving end includes:
[0053] The remaining capacity of the encrypted true random number corresponding to the target sending relationship is determined to meet the preset supplementary conditions;
[0054] A corresponding supplementary true random number is generated for the target sending relationship, so as to determine the second plaintext data through the supplementary true random number.
[0055] The quantum-safe terminal can monitor the remaining capacity of encrypted true random numbers corresponding to a receiver in a Mesh self-organizing network, that is, determine the remaining capacity of encrypted true random numbers corresponding to the target transmission relationship of the quantum-safe terminal -> receiver.
[0056] To determine when to replenish truly random numbers, the quantum-safe terminal makes a decision based on pre-configured replenishment conditions. These replenishment conditions can be set based on a percentage of the remaining capacity, for example, triggering the replenishment mechanism when the remaining capacity falls below a certain percentage (such as 20%, 30%, etc.); or they can be based on a capacity threshold, i.e., initiating the replenishment process when the remaining capacity drops below that threshold.
[0057] Once the supplementary conditions are met, the quantum-secure terminal will generate supplementary true random numbers corresponding to the target transmission relationship, and construct a key file based on these true random numbers. This key file will then be sent as second plaintext data to the receiving end. Subsequently, the key file carrying the supplementary true random numbers can be sent to the receiving end in the same manner as sending second plaintext data in the above embodiment.
[0058] In one example, after determining that the remaining capacity of the encrypted true random number corresponding to the target sending relationship meets a preset supplementary condition, before generating a corresponding supplementary true random number for the target sending relationship and determining the second plaintext data using the supplementary true random number, the method further includes:
[0059] Generate supplementary messages;
[0060] Based on the target encrypted true random number, the supplementary message is quantum encrypted and sent to the receiving end;
[0061] Receive the supplementary response sent by the receiving end.
[0062] When the number of encrypted true random numbers corresponding to the target transmission relationship is insufficient, the quantum-safe terminal can generate a supplementary message. This supplementary message is used to notify the receiving end to receive the distributed key file. Then, this supplementary message is sent to the receiving end as second plaintext data using the method described in the above embodiments, employing quantum encryption. Specifically, when the number of encrypted true random numbers corresponding to the target transmission relationship is insufficient, the quantum-safe terminal obtains the supplementary message to be sent to the receiving end. The target transmission relationship between the quantum-safe terminal and the receiving end is determined. From the pre-saved encrypted true random numbers corresponding to each unidirectional transmission relationship in the Mesh ad hoc network, the target encrypted true random number (denoted as the target encrypted true random number) corresponding to the target transmission relationship is determined. Based on the determined target encrypted true random number, an encryption key is determined. According to the encryption key, the second plaintext data is quantum-encrypted to obtain second quantum-encrypted data. The quantum-safe terminal sends this second quantum-encrypted data to the receiving end. After receiving the encrypted supplementary message, the receiving end can decrypt the encrypted supplementary message using the method described in Scenario 1 of the above embodiments to obtain the plaintext supplementary message. If the receiving end determines that replenishment is allowed, it generates a replenishment permission response and sends the replenishment permission response to the quantum secure terminal in the manner described in Scenario 2 above, so as to notify the quantum secure terminal that it can replenish true random numbers.
[0063] by Figure 4Taking the communication relationship between B and C as an example, C checks the remaining capacity of R(C, B), and B checks the remaining capacity of R(B, C). When the remaining capacity of R(C, B) is insufficient, C initiates a true random number replenishment to B, using R(C, B) to encrypt and send the replenishment message to B. Upon receiving a replenishment permission response from B, C uses R(C, B) to encrypt and send the generated replenishment true random number to B. Similarly, when the remaining capacity of R(B, C) is insufficient, B initiates a true random number replenishment to C, using R(B, C) to encrypt and send the replenishment message to C. Upon receiving a replenishment permission response from C, B uses R(B, C) to encrypt and send the generated replenishment true random number to C.
[0064] In one example, when the second plaintext data is a key file, the step of performing quantum encryption on the second plaintext data based on the target encrypted true random number to obtain second quantum encrypted data includes:
[0065] A dedicated encrypted true random number is obtained from the target encrypted true random number; wherein, the dedicated encrypted true random number is obtained by expanding the base true random number of the target encrypted true random number of a first preset length through a first preset expansion algorithm and a first preset expansion ratio, and the first preset expansion ratio represents the length multiple by which each 1-bit true random number is expanded.
[0066] Based on the data length of the second plaintext data, an encryption key is determined from the dedicated encrypted true random number;
[0067] Based on the encryption key, the second plaintext data is quantum encrypted to obtain the second quantum encrypted data.
[0068] To rapidly replenish a large number of truly random numbers and reduce the amount of encrypted truly random numbers consumed during distribution, this application allows for the determination of a base truly random number from the encrypted truly random numbers of a preset length (denoted as the first preset length) within any one-way transmission relationship. Then, a preset expansion algorithm (denoted as the first preset expansion algorithm) and a first expansion ratio (denoted as the first preset expansion ratio) are used to expand this base truly random number to obtain a dedicated encrypted truly random number. This dedicated encrypted truly random number is primarily used for encrypting and supplementing random numbers. The expansion algorithm can be AES or DES, etc., without specific limitations. The first preset expansion ratio represents the length multiple of each 1-bit truly random number after expansion. For example, if the expansion ratio is 10, then a 1-bit truly random number will be expanded into a 10-bit key segment.
[0069] The timing for expanding the dedicated encrypted true random number can be either real-time expansion by the quantum-safe terminal when initiating key replenishment, or pre-expansion so that it can be used directly when replenishing the key.
[0070] It should be noted that the first preset length can be flexibly adjusted according to the needs of the actual application scenario. For example, in scenarios with extremely high security requirements, a longer first preset length can be selected to ensure that the basic true random numbers have sufficient entropy and unpredictability, thereby enhancing the security of the encryption system; if it is desired to minimize the encrypted true random numbers consumed during the distribution process, a shorter first preset length can be selected. Similarly, the first expansion ratio can also be set to different values depending on the scenario. If it is desired to minimize the consumption of true random numbers, the expansion ratio can be set larger; if it is desired to ensure high security and anti-cracking capability of the encryption key, the expansion ratio can be set smaller.
[0071] When the second plaintext data is determined based on the supplementary true random number corresponding to a certain one-way transmission relationship, the encryption key can be determined from the dedicated encrypted true random number corresponding to the one-way transmission relationship, based on the data length of the second plaintext data. Then, based on the encryption key, the second plaintext data is quantum encrypted to obtain the second quantum-encrypted data.
[0072] With a first preset expansion ratio of 8 and a first preset length of 1 megabyte (M), Figure 4 Taking each empty cell as an example with 2M preset true random numbers, the storage required for the preset true random numbers of a quantum-safe terminal in an n-level mesh self-organizing network is 2*(2n-2)M, where 2*(n-1)M are encrypted true random numbers and 2*(n-1)M are decrypted true random numbers. If n is 7, i.e., a mesh self-organizing network with 7 nodes, then the space required for storing true random numbers in one node is 24M, of which 12M are encrypted true random numbers and 12M are decrypted true random numbers. For any node in a certain one-way transmission relationship, such as C->B, 1M true random numbers can be taken from the encrypted true random numbers corresponding to C->B as the base true random numbers. Through the first preset expansion algorithm and the first preset expansion ratio, the 1M base true random numbers are expanded into 8M dedicated encrypted true random numbers. With an encryption ratio of 1:1, the 8M dedicated encrypted true random numbers can encrypt 8M supplementary true random numbers.
[0073] In one example, to ensure that any receiver in a Mesh ad hoc network can correctly decrypt the key file distributed by the quantum-safe terminal, in this application, for each one-way transmission relationship, the quantum-safe terminal first uses a first preset expansion algorithm and a first preset expansion ratio to expand a basic true random number (whose length is determined by a first preset length) to generate a dedicated encrypted true random number. Subsequently, the quantum-safe terminal notifies the corresponding receiver of these expansion parameters (i.e., the first preset expansion algorithm, the first preset expansion ratio, and the first preset length) and negotiates confirmation with it. In this way, the receiver can obtain a basic true random number of the same length from a pre-saved list of decrypted true random numbers representing the one-way transmission relationship from the quantum-safe terminal to the receiver, and perform the same expansion operation to obtain a dedicated decrypted true random number paired with the sender. For example, when sending supplementary messages or key files to the receiver, the quantum-safe terminal can carry the first preset expansion algorithm, the first preset expansion ratio, and the first preset length.
[0074] Based on the above embodiments, it can be seen that in a Mesh self-organizing network, the quantum secure terminal can also act as a receiver, negotiating with each transmitter in the Mesh self-organizing network to determine the augmentation algorithm (denoted as the second augmentation algorithm), augmentation ratio (denoted as the second augmentation ratio), and preset length (denoted as the second preset length) corresponding to the communication direction from the transmitter to the quantum secure terminal. This allows the quantum secure terminal to obtain a dedicated decryption true random number from the decryption true random number corresponding to the one-way reception relationship from the transmitter to the quantum secure terminal. For example, the quantum secure terminal obtains a basic true random number of the second preset length from the pre-saved decryption true random number corresponding to the one-way reception relationship from the transmitter to the quantum secure terminal, and augments the basic true random number based on the second preset augmentation algorithm and the second preset augmentation ratio to obtain the dedicated decryption true random number. When the quantum-secure terminal performs quantum decryption on the encrypted key file (i.e., the first quantum encrypted data) sent by the transmitter, it determines a target decryption true random number representing the target one-way receiving relationship from the transmitter to the quantum-secure terminal based on the pre-saved decryption true random numbers corresponding to each one-way receiving relationship in the Mesh ad hoc network. A dedicated decryption true random number is then obtained from this target decryption true random number. Finally, based on the data length of the first quantum encrypted data, a decryption key is determined from this dedicated decryption true random number. Based on this decryption key, the first quantum encrypted data is quantum decrypted to obtain the first plaintext data.
[0075] Taking a first preset expansion ratio of 8, a first preset length of 1 megabyte (M), and 2M as the critical point for initiating true random number replenishment as an example, even if all nodes initiate true random number replenishment at the same time, after all nodes have replenished, the true random number storage of any node is 9*(2n-2)M. If it is a mesh network with 10,000 nodes, the maximum true random number storage of any node is: 9*(2*10000-2)M, which is less than 180G. This storage is very small for the storage device size.
[0076] Example 3:
[0077] Based on the same inventive concept, this application also provides a Mesh self-organizing network global quantum secure communication system. Figure 6 This application provides a system architecture diagram for full-domain quantum-secure communication in a Mesh self-organizing network. The system includes multiple quantum-secure terminals for performing the methods described in any of the above embodiments.
[0078] It should be noted that the principle of this Mesh self-organizing network global quantum secure communication system in solving the problem is the same as the principle of solving the technical problem in the above method embodiments, and the repetition will not be repeated.
Claims
1. A mesh ad hoc network global quantum secure communication method, characterized in that, The method is applied to any quantum-safe terminal in a Mesh self-organizing network, and the method includes: For the first quantum encrypted data sent from any transmitter in the Mesh ad hoc network, a target decryption true random number is determined from the pre-saved decryption true random numbers corresponding to each one-way receiving relationship in the Mesh ad hoc network, representing the target one-way receiving relationship from the transmitter to the quantum secure terminal; based on the target decryption true random number, the first quantum encrypted data is quantum decrypted to obtain the first plaintext data; wherein, the type of the first plaintext data includes the following: application data, key file, and security signaling; For the second plaintext data to be sent to any receiver in the Mesh ad hoc network, a target encrypted true random number representing the target transmission relationship from the quantum-secure terminal to the receiver is determined from the encrypted true random numbers corresponding to each one-way transmission relationship in the Mesh ad hoc network that are saved in advance; wherein, the type of the second plaintext data includes the following: application data, key file, and service signaling; based on the target encrypted true random number, the second plaintext data is quantum encrypted to obtain second quantum encrypted data; and the second quantum encrypted data is sent to the receiver.
2. The method of claim 1, wherein, The method further includes: If it is determined that the quantum-secure terminal at the other end of any one-way communication relationship is lost, the true random number corresponding to the one-way communication relationship is discarded; wherein, the one-way communication relationship includes one-way sending relationship and one-way receiving relationship.
3. The method of claim 1, wherein, When the second plaintext data is a key file, obtaining the second plaintext data to be sent to the receiving end includes: The remaining capacity of the encrypted true random number corresponding to the target sending relationship is determined to meet the preset supplementary conditions; A corresponding supplementary true random number is generated for the target sending relationship, so as to determine the second plaintext data through the supplementary true random number.
4. The method of claim 3, wherein, After determining that the remaining capacity of the encrypted true random number corresponding to the target transmission relationship meets the preset supplementary condition, before generating a corresponding supplementary true random number for the target transmission relationship and determining the second plaintext data using the supplementary true random number, the method further includes: Generate supplementary messages; Based on the target encrypted true random number, the supplementary message is quantum encrypted and sent to the receiving end; Receive the supplementary response sent by the receiving end.
5. The method of claim 3, wherein, When the second plaintext data is a key file, the step of performing quantum encryption on the second plaintext data based on the target encrypted true random number to obtain second quantum encrypted data includes: A dedicated encrypted true random number is obtained from the target encrypted true random number; wherein, the dedicated encrypted true random number is obtained by expanding the base true random number of the target encrypted true random number of a first preset length through a first preset expansion algorithm and a first preset expansion ratio, and the first preset expansion ratio represents the length multiple by which each 1-bit true random number is expanded. Based on the data length of the second plaintext data, an encryption key is determined from the dedicated encrypted true random number; Based on the encryption key, the second plaintext data is quantum encrypted to obtain the second quantum encrypted data.
6. The method of claim 5, wherein, When the first plaintext data is the key file, and the sending end and the quantum-secure terminal negotiate and determine the second preset expansion algorithm, the second preset expansion ratio, and the second preset length, the first quantum encrypted data is quantum decrypted based on the target decryption true random number to obtain the first plaintext data, including: A dedicated decryption true random number is obtained from the target decryption true random number; wherein, the dedicated decryption true random number is obtained by expanding the base true random number of the target decryption true random number of a second preset length through the second preset expansion algorithm and the second preset expansion ratio; Based on the data length of the first quantum encrypted data, a decryption key is determined from the dedicated decryption true random number; Based on the decryption key, the first quantum encrypted data is quantum decrypted to obtain the first plaintext data.
7. A mesh ad hoc network global quantum secure communication system, characterized in that, The system includes a plurality of quantum-safe terminals for performing the method as described in any one of claims 1-6.