An encryption and decryption method suitable for quantum database
By dynamically managing quantum key pools and adopting multi-threaded distribution technology, combining differential privacy algorithms to optimize perturbation signals, the shortcomings in security and efficiency in the key generation and distribution process in the prior art are solved, and efficient and secure quantum key management and communication are achieved.
Patent Information
- Application Number
- CN202510174810.7
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2025-02-18
- Publication Date
- 2025-05-02
- Estimated Expiration
- 2045-02-18
AI Technical Summary
The prior art lacks security and efficiency in the process of quantum key generation and distribution, it is difficult to dynamically adapt to the real-time access requirements of the database, and lacks integrity verification mechanisms, resulting in high-frequency reuse of keys and low distribution efficiency.
By collecting the access frequency and timestamp data of the database, a dynamic quantum key pool is generated, multi-threaded distribution and attached distribution sequence number for integrity verification, dynamically reorganize the session key, and combine differential privacy algorithms to optimize the noise distribution and intensity of random perturbation signals.
It realizes efficient management of quantum keys, improves the integrity and distribution efficiency of key transmission, enhances the flexibility and security of keys in dynamic environments, and improves the adaptability and anti-eavesdropping capabilities of quantum communication.
Smart Images

Figure CN119675865B_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the field of quantum encryption technology, and in particular to an encryption and decryption method suitable for a quantum database. Background Art
[0002] The field of quantum cryptography technology includes the intersection of quantum physics and information technology. The core is to use the principles of quantum mechanics, such as the non-cloning of quantum states and the measurement collapse characteristics, to ensure the security of information transmission. This technical field mainly covers quantum key distribution, quantum secure communication, and quantum random number generation. In quantum key distribution, keys are transmitted through quantum channels to achieve the generation and sharing of encryption keys, which has unconditional security; in quantum secure communication, quantum technology is used to build communication networks that resist eavesdropping and ensure the privacy of data; quantum random number generation is based on the uncertainty characteristics of quantum physics and is used to provide random numbers with a high level of security.
[0003] Among them, the encryption and decryption method applicable to quantum databases refers to the technical solution for realizing data encryption and decryption operations through quantum key distribution in the database environment. Mainly aimed at the security risks existing in the storage and transmission process of the database, a quantum random number generation device is used to generate random keys, and the keys are distributed to the application terminals and the quantum key authentication and encryption devices at the front end of the database through the key filling device. During the data interaction process, the quantum key authentication and encryption device is responsible for authenticating the access of the terminal, encrypting the read and write requests of the database, and storing the encrypted ciphertext in the database. At the same time, the trigger mechanism is used to regularly update the encryption keys of the database to ensure the dynamic management of the keys.
[0004] The existing technology mainly uses quantum key distribution for encryption and decryption operations in the storage and transmission stages, but there are deficiencies in security and efficiency in the key generation and distribution process. On the one hand, the generation of existing quantum keys relies on fixed random number generation devices, which is difficult to dynamically adapt to the real-time access requirements of the database, resulting in the disconnection between the key pool update and the database usage requirements, which may cause high-frequency reuse of keys and increase the risk of being cracked. On the other hand, key distribution adopts a single-threaded mode and lacks an integrity verification mechanism, resulting in low distribution efficiency. Keys may be lost or erroneous during transmission, and the stability of key distribution cannot be guaranteed. In the dynamic reorganization process of session keys, the existing technology does not fully verify and screen the shard data, which may introduce invalid or erroneous shards, resulting in reduced reliability of session keys. In addition, in the signal disturbance and descrambling links, the existing technology lacks effective control over the noise distribution and intensity of the disturbance signal. The disturbance signal may not be able to adapt to the transmission characteristics of the communication channel, resulting in data loss or incompleteness during the signal descrambling process, affecting the security and accuracy of the descrambling data. Summary of the invention
[0005] The present invention provides an encryption and decryption method suitable for a quantum database.
[0006] In order to achieve the above object, the present invention adopts the following technical scheme:
[0007] An encryption and decryption method applicable to a quantum database comprises the following steps:
[0008] S1: Collect the access frequency, request quantity and timestamp data of the database, process the data and generate a quantum key pool, mark the quantum key sequence in the quantum key pool to obtain the key sequence identification result, screen and update the quantum key in the quantum key pool according to the key sequence identification result, and generate dynamic quantum key pool data;
[0009] S2: Obtaining the quantum key distribution characteristics in the dynamic quantum key pool data for analysis, and performing multi-threaded quantum key distribution according to the analysis results to obtain distributed quantum key fragments;
[0010] S3: Collect the unique identifier and hash value of the target quantum key fragment in the distributed quantum key fragments and dynamically reorganize them to obtain the reorganized quantum key of the current session, dynamically match the reorganized quantum key of the current session with the key space required for the database encryption and decryption operation, and obtain the updated session quantum key data;
[0011] S4: Dynamically generate a random perturbation signal based on the updated session quantum key data and the encryption and decryption requirements of the database, optimize the noise distribution and perturbation intensity of the random perturbation signal in combination with the differential privacy algorithm, embed the optimized random perturbation signal into the transmission data in the quantum communication channel and obtain the perturbation descrambling key to generate descrambled quantum encrypted data.
[0012] The present invention is improved in that the steps of obtaining the key sequence identification result are specifically as follows:
[0013] S111: Based on the access frequency, request quantity and timestamp data of the database, record the data and perform data processing by superimposing a disturbance factor, combine the processed data with a sequence generated by a quantum random number, and generate a quantum key pool;
[0014] S112: Based on the quantum key pool, a unique identifier ID is added to each group of quantum key sequences in the quantum key pool to generate a key sequence identification result.
[0015] The present invention is improved in that the step of obtaining the dynamic quantum key pool data is specifically as follows:
[0016] S121: extracting the usage frequency data of each group of quantum keys in the quantum key pool based on the key sequence identification result, comparing the usage frequency data with the preset frequency threshold one by one, classifying the quantum keys according to the comparison result, and obtaining the key frequency comparison result;
[0017] S122: Based on the key frequency comparison result, screening and updating of quantum keys in the quantum key pool are performed to generate dynamic quantum key pool data.
[0018] The present invention is improved in that the steps of obtaining the distributed quantum key fragments are specifically as follows:
[0019] S211: Based on the distribution characteristics of the dynamic quantum key pool data, extract the call frequency, timestamp and usage status of the quantum key, sort the data according to the time axis and divide it into fixed time windows, bind the quantum key to the corresponding time window, and generate a distribution characteristic analysis result;
[0020] S212: Based on the distribution characteristic analysis result, the formula is used:
[0021] ;
[0022] Calculates the result of modular exponentiation , indicating the 'A generated encryption key;
[0023] in, It is the first The basic value of the quantum key, It is The timestamp value corresponding to the quantum key, is the number of quantum keys in the time window, is the exponent value of the power operation, is the modulus value of the modular operation, It is a modular operation, which means that the result of the power operation is modulo Take the remainder;
[0024] S213: Based on the encryption key, multi-threaded quantum key distribution is performed on the target node, the quantum key is encrypted and transmitted in fragments, and a distribution serial number is attached for integrity verification to obtain the distributed quantum key fragments.
[0025] The present invention is improved in that the step of obtaining the reorganized quantum key of the current session is specifically as follows:
[0026] S311: Based on the distributed quantum key shards, by collecting the unique identifier and hash value of each shard, performing hash calculation on the data content of the shards, and comparing them with the stored original hash values one by one, eliminating the shards that failed verification, and generating a list of quantum key shards that passed verification;
[0027] S312: Based on the verified quantum key shard list, the formula is used:
[0028] ;
[0029] Calculate the recombinant quantum key for the current session ;
[0030] in, Indicates the shard index currently being calculated. Indicates the index for traversing interpolation points outside the current slice. represents the number of quantum key shards that have passed consistency verification, Indicates The value of quantum key shards, Indicates The interpolation points corresponding to the slices, Indicates that the current product calculation excludes the fragment Other slice interpolation points of Indicates the target point for interpolation calculation.
[0031] The present invention is improved in that the step of obtaining the updated session quantum key data is specifically as follows:
[0032] S321: Based on the reorganized quantum key of the current session, extract the target key length, encryption algorithm and key structure requirements of the database key space, compare the length of the reorganized quantum key with the target key length, and if the lengths do not match, adjust the key length by intercepting or supplementing. After the adjustment, perform format verification on the quantum key and load it into the encryption environment of the current session to generate a loaded session quantum key;
[0033] S322: Based on the loaded session quantum key, extract the unique identifier and length information of the loaded key, compare them one by one with the identifier and length information recorded before loading, verify the key integrity and consistency, perform functional testing on the loaded key, and bind the loaded session quantum key to the current session identifier to generate updated session quantum key data.
[0034] The present invention is improved in that the step of optimizing the noise distribution and disturbance intensity of the random disturbance signal is specifically:
[0035] S411: Based on the updated session quantum key data and the encryption and decryption requirements of the database, extract the length and grouping information of the session quantum key data, initialize the communication node identification and communication parameters, generate a random disturbance signal and detect the distribution uniformity of the signal, embed the generated random disturbance signal into the quantum communication channel, complete the channel initialization, and obtain the communication channel embedded with the random disturbance signal;
[0036] S412: Based on the communication channel embedded with the random disturbance signal, extract the noise distribution characteristics and strength information of the disturbance signal, adjust the signal strength of each intensity area, re-detect the signal according to the adjustment result and confirm that the distribution range meets the requirements, so as to obtain an optimized communication signal.
[0037] The present invention is improved in that the step of obtaining the descrambled quantum encrypted data is specifically as follows:
[0038] S421: embed the optimized random perturbation signal into the transmission data in the quantum communication channel, and the receiving end obtains the perturbation descrambling key through quantum key distribution negotiation, using the formula:
[0039] ;
[0040] Calculate the average deviation between the perturbation signal in the transmitted data and the descrambling key , according to the average deviation Analyze the matching degree between the signal and the descrambling key at the target position, correct the unmatched part, and compare the signal and the key to obtain the pre-matched disturbance signal and descrambling key;
[0041] in, Indicates the index of the signal and the descrambling key, Indicates the total number of signal and key matching groups involved in the calculation, It is The value of the disturbance signal, It is The value of the descrambling key.
[0042] S422: Based on the pre-matched disturbance signal and the descrambling key, the signal is synchronously descrambled by parsing the correspondence between the descrambling key and the signal point by point, and the parsed data is redundancy checked with the original data. After the check is completed, the descrambled data is processed and stored to obtain the descrambled quantum encrypted data.
[0043] Compared with the prior art, the advantages and positive effects of the present invention are:
[0044] In the present invention, efficient management of quantum keys is achieved through the generation, screening and dynamic updating of quantum key pools. Multithreading is used to accelerate distribution during quantum key distribution, and the distribution sequence number is attached for integrity verification, which significantly improves the integrity of key transmission and distribution efficiency. In the process of dynamic reorganization of quantum keys, invalid fragments are eliminated by introducing a one-to-one comparison between unique identifiers and hash values, and the logic of reorganization calculation is used to ensure the security and dynamic adaptation of session keys, which greatly enhances the flexibility of keys in dynamic environments. In the stage of random perturbation signal generation and optimization, the noise distribution and intensity of the perturbation signal are accurately adjusted in combination with the differential privacy algorithm, which improves the adaptability and anti-eavesdropping ability of the perturbation signal in the quantum communication channel, and further optimizes the security of quantum communication by dynamically embedding the perturbation signal. In the signal descrambling link, the corresponding relationship between the signal and the key is analyzed point by point, the signal is descrambled synchronously, and the integrity and accuracy of the descrambled data are verified by redundant verification. BRIEF DESCRIPTION OF THE DRAWINGS
[0045] In order to more clearly illustrate the technical solutions of the embodiments of the present invention, the following briefly introduces the drawings required for describing the embodiments. The drawings are only used to illustrate the implementation methods and are not to be considered as limitations of the present invention.
[0046] Figure 1 is a flow chart of the main steps in an embodiment of the present invention;
[0047] Figure 2 A flowchart of obtaining a key sequence identification result in an embodiment of the present invention;
[0048] Figure 3 A flowchart of obtaining dynamic quantum key pool data in an embodiment of the present invention;
[0049] Figure 4 A flowchart of obtaining distributed quantum key fragments in an embodiment of the present invention;
[0050] Figure 5 A flowchart of obtaining a reorganized quantum key for a current session in an embodiment of the present invention;
[0051] Figure 6 A flowchart of obtaining updated session quantum key data in an embodiment of the present invention;
[0052] Figure 7 A flow chart for optimizing the noise distribution and disturbance intensity of a random disturbance signal in an embodiment of the present invention;
[0053] Figure 8 This is a flow chart for obtaining descrambled quantum encrypted data in an embodiment of the present invention. DETAILED DESCRIPTION
[0054] The technical scheme in the embodiment of the present invention will be clearly and completely described below in conjunction with the drawings in the embodiment of the present invention. Obviously, the described embodiment is only a part of the embodiment of the present invention, not all of the embodiments. Based on the embodiment of the present invention, all other embodiments obtained by ordinary technicians in this field without creative work are within the scope of protection of the present invention.
[0055] Unless otherwise defined, all technical and scientific terms used in the present invention have the same meaning as commonly understood by technicians in the field of the present invention; the terms used in the present invention are only for the purpose of describing specific embodiments, and are not intended to limit the terms "including" and "having" and any variations thereof in the specification and claims of the present invention and the above-mentioned drawings, and are intended to cover non-exclusive inclusions.
[0056] In the description of the embodiments of the present invention, the technical terms "first", "second", etc. are only used to distinguish different objects, and cannot be understood as indicating or implying relative importance or implicitly indicating the number, specific order or primary and secondary relationship of the indicated technical features. In the description of the embodiments of the present invention, the meaning of "multiple" is more than two, unless otherwise clearly and specifically defined.
[0057] In the description of the embodiments of the present invention, the term "and / or" is only a description of the association relationship of associated objects, indicating that three relationships may exist. For example, A and / or B may represent: A exists alone, A and B exist at the same time, and B exists alone. In addition, the character " / " in this article generally indicates that the associated objects before and after are in an "or" relationship.
[0058] In the description of the embodiments of the present invention, the term "multiple" refers to more than two (including two). Similarly, "multiple groups" refers to more than two groups (including two groups), and "multiple pieces" refers to more than two pieces (including two pieces).
[0059] In the description of the embodiments of the present invention, the technical terms "center", "longitudinal", "lateral", "length", "width", "thickness", "up", "down", "front", "back", "left", "right", "vertical", "horizontal", "top", "bottom", "inside", "outside", "clockwise", "counterclockwise", "axial", "radial", "circumferential", etc. indicate orientations or positional relationships based on the orientations or positional relationships shown in the accompanying drawings, and are only for the convenience of describing the embodiments of the present invention and simplifying the description, and do not indicate or imply that the referred device or element must have a specific orientation, be constructed and operated in a specific orientation, and therefore should not be understood as limiting the embodiments of the present invention.
[0060] In the description of the embodiments of the present invention, unless otherwise clearly specified and limited, technical terms such as "installed", "connected", "connected", "fixed" and the like should be understood in a broad sense, for example, it can be a fixed connection, a detachable connection, or an integral connection; it can be a mechanical connection or an electrical connection; it can be a direct connection or an indirect connection through an intermediate medium, it can be the internal connection of two elements or the interaction relationship between two elements. For ordinary technicians in this field, the specific meanings of the above terms in the embodiments of the present invention can be understood according to the specific circumstances. Example
[0061] The embodiment of the present invention provides an encryption and decryption method applicable to a quantum database, such as Figure 1 As shown, the following steps are included:
[0062] S1: Collect the access frequency, request quantity and timestamp data of the database, process the data and generate a quantum key pool, mark the quantum key sequence in the quantum key pool to obtain the key sequence identification result, screen and update the quantum key in the quantum key pool according to the key sequence identification result, and generate dynamic quantum key pool data;
[0063] S2: Obtain the quantum key distribution characteristics in the dynamic quantum key pool data for analysis, perform multi-threaded quantum key distribution according to the analysis results, and obtain the distributed quantum key fragments;
[0064] S3: Collect the unique identifier and hash value of the target quantum key shard in the distributed quantum key shards and dynamically reorganize them to obtain the reorganized quantum key of the current session, dynamically match the reorganized quantum key of the current session with the key space required for the database encryption and decryption operations, and obtain the updated session quantum key data;
[0065] S4: Dynamically generate a random perturbation signal based on the updated session quantum key data and the encryption and decryption requirements of the database, optimize the noise distribution and perturbation intensity of the random perturbation signal in combination with the differential privacy algorithm, embed the optimized random perturbation signal into the transmission data in the quantum communication channel and obtain the perturbation descrambling key to generate the descrambled quantum encrypted data;
[0066] The dynamic quantum key pool data includes the quantum key sequence, the unique identifier ID of the quantum key, and the frequency of use of the quantum key. The distributed quantum key shards are specifically the unique identifier of the target quantum key shard, the hash value of the target quantum key shard, and the distribution characteristics of the target quantum key shard. The updated session quantum key data includes the reorganized quantum key of the current session, the key space required for database encryption and decryption operations, and the loaded key after dynamic matching. The descrambled quantum encryption data are specifically the data after random disturbance signal denoising, the transmission data after redundancy check, and the final proofread quantum encryption data.
[0067] like Figure 2 As shown, the steps for obtaining the key sequence identification result are as follows:
[0068] S111: Based on the access frequency, request quantity and timestamp data of the database, record the data and process the data by superimposing the disturbance factor, combine the processed data with the sequence generated by the quantum random number, and generate a quantum key pool;
[0069] The access frequency is recorded as the number of accesses per hour, the number of requests is recorded as the number of operations involved in each access, and the timestamp is recorded as the specific second-level time point of each request. The initial random perturbation sequence is generated by setting the perturbation factor, and the access frequency, number of requests and timestamp data are superimposed with the random perturbation sequence one by one. The superposition process is performed by adding the access frequency data and the request number data to each value in the random perturbation sequence and rounding them. The obtained superposition results are sorted with time as the main axis, and the sorted data are randomized by the linear congruential method. The randomization is completed by repeatedly performing weighted random perturbations on the data set and eliminating repeated values. The processed data is combined with the random sequence generated by the quantum random number generator to form a quantum key sequence, and the quantum key sequences are merged to generate a quantum key pool, which contains multiple independent quantum key sequences.
[0070] S112: Based on the quantum key pool, a unique identifier ID is added to each group of quantum key sequences in the quantum key pool to generate a key sequence identification result;
[0071] Collect each group of quantum key sequence data in the quantum key pool, extract the storage address, generation time and key length of each group of quantum key sequence, convert the extracted storage address into a hexadecimal string, combine the timestamp data of the generation time and the integer value of the key length, use string concatenation to sequentially combine the hexadecimal string, timestamp data and key length into a unique identifier ID, repeat the above operation for each group of quantum key sequence in the quantum key pool to ensure that each group of quantum key sequence is attached with a unique identifier ID, map the generated identifier with the corresponding quantum key sequence and store it, and finally generate a key sequence identification result.
[0072] like Figure 3 As shown, the steps for obtaining dynamic quantum key pool data are as follows:
[0073] S121: based on the key sequence identification result, extract the usage frequency data of each group of quantum keys in the quantum key pool, compare the usage frequency data with the preset frequency threshold one by one, classify the quantum keys according to the comparison result, and obtain the key frequency comparison result;
[0074] The usage frequency data of each group of quantum keys in the quantum key pool is extracted, and the usage frequency is recorded as a time series on an hourly basis, and compared one by one with the preset frequency threshold. The preset frequency threshold is calculated through statistical calculation of historical access records and is set to a range of no less than 50 times and no more than 200 times per day. The SQL database is called to query the usage frequency of the quantum key. If the usage frequency of a quantum key is greater than 200 times, it is marked as a high-frequency key. If the usage frequency of a quantum key is less than 50 times, it is marked as a low-frequency key. The remaining keys are marked as medium-frequency keys. All comparison results are integrated to form key frequency comparison data.
[0075] S122: Based on the key frequency comparison result, screening and updating the quantum key in the quantum key pool are performed to generate dynamic quantum key pool data;
[0076] High-frequency keys and low-frequency keys are screened out from the key frequency comparison data, and the cumulative usage frequency of high-frequency keys is aggregated and analyzed. Keys with a cumulative usage frequency of more than 2,000 times are screened out and marked as keys that need to be eliminated, and removed from the quantum key pool; time series analysis is performed on low-frequency keys, and keys with 0 calls for two consecutive days are screened out and marked as invalid keys, and removed from the quantum key pool; the current state of the medium-frequency keys is maintained and their usage frequency is marked as normal, the screened key data is reintegrated to form an updated quantum key pool, and dynamic quantum key pool data is generated.
[0077] like Figure 4 As shown, the steps for obtaining the distributed quantum key fragments are as follows:
[0078] S211: Based on the distribution characteristics of the dynamic quantum key pool data, extract the call frequency, timestamp and usage status of the quantum key, sort the data according to the time axis and divide it into fixed time windows, bind the quantum key to the corresponding time window, and generate the distribution characteristic analysis results;
[0079] The calling frequency, timestamp and usage status of each quantum key record in the dynamic quantum key pool are extracted, and the extracted data are sorted based on time as the main axis and divided into continuous time windows. Each time window contains a quantum key group called within a fixed time range. The length of the time window is determined by the statistical distribution of historical usage records. For example, based on a 24-hour access record, the time window is set to 2 hours, and the quantum key calling frequency in each time window is cumulatively counted. The distribution characteristics of each group of quantum keys are bound to their corresponding time windows, and the bound data are cross-validated through SQL database query operations to ensure that the correlation between the distribution characteristics and the time windows is correct, and the distribution characteristic analysis results are generated for subsequent quantum key operation division.
[0080] S212: Based on the distribution characteristics analysis results, the formula is used:
[0081] ;
[0082] Calculates the result of modular exponentiation , indicating the 'A generated encryption key;
[0083] in, It is the first The basic value of a quantum key represents the integer value of each key in the dynamic quantum key pool. The key data in the dynamic quantum key pool is extracted and directly read through the quantum key value stored in the database. For example, the keys contained in the dynamic quantum key pool are sequentially , It is The timestamp value corresponding to each quantum key is used to enhance the timing characteristics of the quantum key and extract the timestamp data when the quantum key is generated or called. Specifically, it can be directly obtained through the timestamp field recorded by the quantum key management system, for example, reading the timestamp record from the database , is the number of quantum keys in the time window, indicating the length of the quantum key group divided in the current time window. It is obtained by counting the number of quantum keys in the dynamic quantum key pool that meet the time window division criteria. For example, the time window contains A quantum key, It is the exponential value of the power operation, which is used to increase the complexity and randomness of the encryption key. A fixed value is determined by the historical call frequency of the quantum key distribution. It is the modulus value of the modular operation, which is used to limit the range of the power operation result and prevent numerical overflow. From the distribution data of the historical quantum key pool, a prime number greater than the maximum value of all quantum key groups is selected. Indicates from arrive The product calculation symbol is used to multiply the sum of all quantum key base values and timestamps. It is a modular operation, which means that the result of the power operation is modulo Take the remainder and limit the result of the power operation to arrive The modulus operation is used to reduce the range of values after the exponentiation operation to ensure that the result can adapt to the actual key length requirements.
[0084] Parameter assignment: Extracting quantum key sequence from time window , sequence length ; Extract timestamp sequence ; Set the power index , modulus . Calculate the sum of each set of quantum keys and timestamps: ; ; ; .
[0085] Compute the product: ;
[0086] Pair product Exponentiation: ;
[0087] Modulo the result of the power operation: ;
[0088] The result of the modulo operation is: ;
[0089] The results showed that the results The generated encryption key is used for quantum key distribution operation of the target node. The numerical key needs to be converted into a coded key through a mapping method for actual encryption and decryption operations or distribution operations. The following is the specific mapping process to determine the encoding format: the encryption key usually needs to be converted into a fixed-length binary code or string code to adapt to the specific encryption algorithm (such as AES, RSA, etc.). Assume that the target key format is a 128-bit binary key. The result of the operation is Convert to binary representation: The binary form is If the target key length is greater than the current binary length (e.g. 128 bits are required), expansion is required. Only 12 bits, but 128 bits are required), then it is extended by the following method: Prefix random padding: Randomly generate a sequence of 0s and 1s before the current key and fill it to the target length. For example, generate Random sequence of bits , after concatenation, a complete 128-bit key is obtained. Suffix repetition padding: the binary sequence of the original key is repeated cyclically until the target length is reached. For example, If the length of the generated key exceeds the target length (for example, a 256-bit key needs to be converted to 128 bits), the first 128 bits are truncated as the final key. ) is converted to string form through Base64 or Hex encoding for encryption and decryption operations or distribution. For example: binary Convert to hexadecimal string ; or convert it to a string through Base64. To enhance the integrity and tamper-proofness of the key, a checksum can be added to the encoded key. For example, a checksum can be generated using CRC32 or SHA256 and appended to the end of the key.
[0090] S213: Based on the encryption key, multi-threaded quantum key distribution is performed on the target node, the quantum key is encrypted and transmitted in fragments, and a distribution sequence number is attached for integrity verification to obtain the distributed quantum key fragments;
[0091] According to the calculation results To generate the encryption key, use the encryption key to perform multi-threaded quantum key distribution on the target node, and send the calculation result The data is input into the distribution process, and the quantum key distribution task is divided into several threads through a preset multi-threaded distribution method. Each thread uses the same encryption key to encrypt the quantum key data in shards. The granularity of the shard encryption is determined according to the computing power of the target node. For example, a total of 1,000 keys are distributed to 10 threads, and each thread is responsible for encrypting and distributing 100 key shards. After each shard data is encrypted, it is transmitted to the target node through a secure transmission protocol. During the transmission process, a distribution serial number is attached to each encrypted shard, and the number of encrypted shards transmitted each time is counted and recorded. After the transmission is completed, the encrypted key shard is restored in the target node cache according to the serial number to obtain the distributed quantum key shard.
[0092] like Figure 5 As shown, the steps for obtaining the reorganized quantum key of the current session are as follows:
[0093] S311: Based on the distributed quantum key shards, by collecting the unique identifier and hash value of each shard, performing hash calculation on the data content of the shards, and comparing them one by one with the stored original hash values, removing the shards that failed verification, and generating a list of quantum key shards that passed verification;
[0094] Collect the unique identifier and hash value of each shard in the distributed quantum key shards, extract the shard records in the shard transmission log, store the shard unique identifier and the corresponding hash value in the verification list according to the comparison relationship, re-hash the data content of each shard using the SHA-256 algorithm, and compare the calculation result with the original hash value of the shard. The comparison process checks the matching of the hash values byte by byte. For example, when the unique identifier of the target quantum key shard is "ID001", its original hash value is "6f1ed002ab5595859014ebf0951522d9", and the value obtained after re-hashing the shard data content is "6f1ed002ab5595859014ebf0951522d9". If the two are consistent, it is marked as verified. If the verification fails, the shard is recorded as abnormal data, and the abnormal shard is eliminated. Finally, the list of shards that have passed the verification is sorted out as the result of consistency verification.
[0095] S312: Based on the verified quantum key shard list, the formula is:
[0096] ;
[0097] Calculate the recombinant quantum key for the current session ;
[0098] in, The summation symbol represents the sum of each quantum key shard The contribution of each shard is calculated by the interpolation polynomial. Indicates the shard index currently being calculated, ranging from arrive , Indicates the index for traversing interpolation points outside the current slice. and All are from the total number of quantum key shards Determined in, used to traverse each slice and interpolation point, Indicates the number of quantum key shards that have passed the consistency verification. The total number of quantum key shards that have passed the consistency verification is counted. For example, among the 10 distributed shards, 7 have passed the consistency verification. , Indicates The value of a quantum key shard, that is, the specific key data content stored in the shard, is directly extracted from the shard that has passed the consistency verification. For example, the shard data can extract the original value from the distribution log. The product symbol indicates that the interpolation polynomial weight is calculated, excluding the current shard The dynamic weights of all other shard points ensure the uniqueness of the interpolation polynomial. Indicates The interpolation point corresponding to each shard is used as the reference position for interpolation calculation. The unique identifier of the quantum key shard is mapped to the integer space through a hash function. For example, after the shard identifier is hashed by SHA-256, the first few bits are converted into integer values. Indicates that the current product calculation excludes the fragment The other slice interpolation points of is obtained in the same way, by mapping the hash identifier to the integer space, Indicates the target point of the interpolation calculation, which is used to generate the dynamic position of the reorganized key. It is dynamically set according to the key requirements of the current session. For example, or other session-related interpolation points, is the weight term of the interpolation polynomial, indicating the current interpolation point Dynamic contribution ratio to the re-key, through , and The specific value of is directly calculated.
[0099] Parameter assignment: interpolation points , the fragment value , interpolation target point .
[0100] Compute each interpolant:
[0101] for : ;
[0102] ;
[0103] for : ;
[0104] ;
[0105] for : ;
[0106] ;
[0107] Sum calculation: ;
[0108] This result shows that the calculation results The current session key is obtained by reassembling the quantum key fragments through consistency verification.
[0109] like Figure 6 As shown, the steps for obtaining the updated session quantum key data are specifically as follows:
[0110] S321: Based on the reorganized quantum key of the current session, extract the target key length, supported encryption algorithms and key structure requirements of the database key space, compare the length of the reorganized quantum key with the target key length, and if the lengths do not match, adjust the key length by interception or supplementation. After the adjustment, perform format verification on the quantum key and load it into the encryption environment of the current session to generate a loaded session quantum key;
[0111] Dynamically match the reorganized quantum key of the current session with the key space required for database encryption and decryption operations, extract relevant parameters of the database key space, including target key length, supported encryption algorithms and key structure requirements, analyze the difference between the actual length of the reorganized quantum key and the target key length, and if the length of the reorganized quantum key is greater than the target length, intercept the front of the reorganized quantum key. bits, of which The target length is, for example, when the target length is 128 bits and the length of the reorganized key is 256 bits, the first 128 bits are intercepted; if the length of the reorganized quantum key is less than the target length, supplementary data is dynamically generated by a pseudo-random number generator, and the supplementary data is appended to the end of the reorganized quantum key to meet the target length requirement; after the length matching is completed, the adjusted quantum key is matched with the database encryption algorithm, and the format of the adjusted quantum key is verified, including whether the key structure and format meet the input requirements of the database encryption and decryption algorithm. After the verification is completed, the quantum key is loaded into the encryption environment of the current session, and finally the loaded session quantum key is obtained.
[0112] S322: Based on the loaded session quantum key, extract the unique identifier and length information of the loaded key, compare them one by one with the identifier and length information recorded before loading, verify the key integrity and consistency, perform a functional test on the loaded key, and bind the loaded session quantum key with the current session identifier to generate updated session quantum key data;
[0113] Perform integrity check on the loaded quantum key, including consistency check on the key format, length and unique identifier, extract the quantum key unique identifier recorded before loading, compare it with the loaded key identifier, and ensure that the key has not been modified or erroneous during the loading process; compare the actual length of the key with the target key length bit by bit to ensure that it matches the input parameters of the database encryption algorithm, and perform encryption function test on the loaded key at the same time, call the database encryption and decryption algorithm to test the stability of the loaded key in encryption and decryption operations. After the test is completed, bind the loaded session quantum key to the current session identifier and record it in the session cache, and finally obtain the updated session quantum key data.
[0114] like Figure 7 As shown, the steps for optimizing the noise distribution and disturbance intensity of the random disturbance signal are as follows:
[0115] S411: Based on the updated session quantum key data and the encryption and decryption requirements of the database, extract the length and grouping information of the session quantum key data, initialize the communication node identification and communication parameters, generate a random disturbance signal and detect the distribution uniformity of the signal, embed the generated random disturbance signal into the quantum communication channel, complete the channel initialization, and obtain the communication channel embedded with the random disturbance signal;
[0116] A quantum communication channel is established through quantum key distribution, and the length, format and grouping information of the session quantum key data are extracted. According to the encryption and decryption requirements of the database, the identifier of the target communication node and the initial negotiation parameters of the quantum key distribution protocol are determined, for example, the identity authentication key and encryption algorithm requirements of the target node are extracted, the target node information is associated with the updated session quantum key data, the initialization process of the quantum communication channel is started, and a secure communication channel is established through the quantum key distribution protocol; then, a pseudo-random number generator is called to initialize the pseudo-random number generator with the updated session quantum key data as the seed value, and a random perturbation signal is generated through the pseudo-random number generator. The signal generation rule includes setting the value range of the random number to [-1,1] and adjusting the period of the pseudo-random sequence to match the data packet transmission rate of the communication channel; the distribution characteristics of the generated random perturbation signal are detected, and the detection content includes the distribution uniformity and randomness of the signal to ensure that the random perturbation signal meets the noise distribution requirements of the communication channel, and the generated random perturbation signal is embedded in the quantum communication channel for perturbation embedding processing of subsequent data transmission to complete the embedding of the random perturbation signal.
[0117] S412: based on the communication channel in which the random disturbance signal is embedded, extract the noise distribution characteristics and strength information of the disturbance signal, adjust the signal strength of each intensity area, re-detect the signal according to the adjustment result and confirm that the distribution range meets the requirements, and obtain the optimized communication signal;
[0118] Extract the random perturbation signal embedded in the quantum communication channel, analyze its current noise distribution and perturbation intensity, including the noise intensity range and distribution ratio of the signal value in the statistical signal, extract the mean and standard deviation of the noise, obtain the extreme points of the noise distribution, call the differential privacy algorithm to adjust the noise distribution, and set the intensity adjustment parameters of the noise injection according to the statistical results of the noise intensity. For example, weaken the intensity of the high-intensity noise area and inject an appropriate amount of noise into the low-intensity area to ensure that the disturbance intensity of the signal is within the range allowed by the communication channel; re-detect the optimized random perturbation signal to confirm that the optimized noise distribution meets the preset requirements of the communication channel, such as uniformity detection and coverage verification of the distribution, reintegrate the optimized random perturbation signal for the perturbation embedding process in the channel, and complete the optimized storage and output of the signal.
[0119] like Figure 8 As shown, the steps for obtaining the descrambled quantum encrypted data are as follows:
[0120] The characteristic parameters of the optimized random perturbation signal embedded in the transmitted data are extracted, including the amplitude range, frequency distribution and noise intensity of the signal. The descrambling key is obtained based on the negotiation process of quantum key distribution. The parameters of the descrambling key are compared with the embedding rules of the random perturbation signal. The comparison content includes the perturbation position of the embedded signal, the length of the descrambling key and the signal matching. The descrambling key is preprocessed in combination with the characteristics of the transmitted data to ensure that the descrambling key can completely correspond to the embedded perturbation signal; by analyzing the perturbation signal and the descrambling key transmitted by the quantum communication channel, the matching degree between the signal and the descrambling key at a specific position is calculated, and the unmatched parts are corrected to complete the correct positioning of the perturbation signal in the transmitted data and the preparation of the descrambling key, ensuring that the subsequent denoising process can accurately remove the embedded signal in the transmitted data.
[0121] S421: The optimized random perturbation signal is embedded into the transmission data in the quantum communication channel. The receiving end obtains the perturbation descrambling key through quantum key distribution negotiation, using the formula:
[0122] ;
[0123] Calculate the average deviation between the perturbation signal in the transmitted data and the descrambling key The smaller the value, the better the match between the signal and the descrambling key. Analyze the matching degree between the signal and the descrambling key at the target position, correct the unmatched part, and compare the signal and the key to obtain the pre-matched disturbance signal and descrambling key;
[0124] in, represents the sum of the absolute deviations between all signals and the descrambling key, Indicates the index of the signal and descrambling key, which is used to identify the group of signals and keys currently being matched and calculated. The value range is 1 to , that is, the sequence number of the current data, determined according to the grouping or sequence rules of data transmission, Indicates the total number of signal and key matches involved in the calculation. The number of samples is counted according to the signal grouping rule. For example, if 1000 groups of signals are transmitted in the channel, then , It is The value of a disturbance signal represents the value of the random disturbance signal embedded in the transmission data at a specific position, which is obtained from the transmission data of the quantum communication channel by signal extraction, for example, using a monitoring tool to extract the signal data and record the corresponding value. It is The value of the descrambling key represents the restored value of the descrambling key at the corresponding position. The key data corresponding to the signal is extracted from the descrambling key of quantum key distribution. The key distribution and recording process is completed through the quantum key distribution protocol. It indicates the degree of difference between the signal and the descrambling key at a specific position. The smaller the deviation value, the higher the match between the two.
[0125] Extracting embedded disturbance signals from transmitted data , and extract the corresponding key data from the descrambling key of quantum key distribution For example, the transmitted signal data value is , the descrambling key is .
[0126] Calculate the absolute deviation for each set of data:
[0127] Group 1: ;
[0128] Group 2: ;
[0129] Group 3: ;
[0130] Group 4: ;
[0131] Group 5: ;
[0132] Compute the sum of absolute deviations: ;
[0133] Sample size , then the matching degree for: ;
[0134] According to the calculation results, the unmatched part is corrected, and the calculation results of the transmission signal and the descrambling key are extracted, indicating that the average deviation between the two is , analyze the source of deviation between the current signal and the key, including possible transmission noise interference or key distribution error, for all signal values and the corresponding key value Perform point-by-point matching and comparison; for the signal part with large matching deviation, record its corresponding signal index And deviation value, for example, the deviation of the 5th group of data is , which is significantly higher than the average deviation of other groups of data ; For the unmatched signal area, adjustments are made through an error correction mechanism based on neighboring values. For example, the signal values of the 4th and 6th groups are extracted as reference values, and the 5th group of signals are interpolated and corrected to a value closer to the descrambling key. At the same time, the corrected signal and key data are re-compared to confirm whether the matching deviation between the two is reduced to within the threshold range after error correction; finally, a pre-matched disturbance signal and descrambling key are generated to provide optimized input data for subsequent descrambling processing.
[0135] S422: Based on the pre-matched disturbance signal and the descrambling key, the corresponding relationship between the descrambling key and the signal is analyzed point by point, the signal is descrambled synchronously, the parsed data is redundancy checked with the original data, and after the verification is completed, the descrambled data is processed and stored to obtain the descrambled quantum encrypted data;
[0136] By analyzing the correspondence between the descrambling key and the signal point by point, each data point in the signal is analyzed one by one, the data value in the disturbance signal is extracted and compared with the corresponding position value in the descrambling key, and the difference information between the two is recorded. For positions with large matching deviations, the signal data is adjusted according to the descrambling rules, and the adjusted signal data is corrected point by point to a range consistent with the descrambling key; then, the descrambled signal data is compared with the redundant check code of the pre-stored original data, and the integrity of the signal data is judged by comparing the check code generated by the signal descrambling data with the consistency of the original check code. If the check fails at some positions, the data point is recorded and the key is re-parsed and adjusted until the check passes; after the check is completed, the final descrambled signal data is sorted, and its data format and storage requirements are standardized. The processed data is stored in the encrypted area of the database to obtain the descrambled quantum encrypted data.
[0137] Finally, it should be noted that the above embodiments are only used to illustrate the technical solutions of the present invention, not to limit them; although the present invention has been described in detail with reference to the above embodiments, those skilled in the art should understand that they can still modify the technical solutions described in the above embodiments, or replace some or all of the technical features therein by equivalents; and these modifications or replacements do not make the essence of the corresponding technical solutions deviate from the scope of the technical solutions of the embodiments of the present invention, and they should all be included in the scope of the claims and specification of the present invention. In particular, as long as there is no structural conflict, the various technical features mentioned in each embodiment can be combined in any way. The present invention is not limited to the specific embodiments disclosed herein, but includes all technical solutions that fall within the scope of the claims.
Claims
1. An encryption and decryption method suitable for a quantum database, characterized in that: The following steps are involved: S1: Collect the access frequency, request quantity and timestamp data of the database, process the data and generate a quantum key pool, mark the quantum key sequence in the quantum key pool to obtain the key sequence identification result, screen and update the quantum key in the quantum key pool according to the key sequence identification result, and generate dynamic quantum key pool data; S2: Obtaining the quantum key distribution characteristics in the dynamic quantum key pool data for analysis, and performing multi-threaded quantum key distribution according to the analysis results to obtain distributed quantum key fragments; S3: Collect the unique identifier and hash value of the target quantum key fragment in the distributed quantum key fragments and dynamically reorganize them to obtain the reorganized quantum key of the current session, dynamically match the reorganized quantum key of the current session with the key space required for the database encryption and decryption operation, and obtain the updated session quantum key data; S4: Dynamically generate a random perturbation signal based on the updated session quantum key data and the encryption and decryption requirements of the database, optimize the noise distribution and perturbation intensity of the random perturbation signal in combination with the differential privacy algorithm, embed the optimized random perturbation signal into the transmission data in the quantum communication channel and obtain the perturbation descrambling key to generate descrambled quantum encrypted data.
2. The encryption and decryption method applicable to a quantum database according to claim 1, characterized in that: The steps for obtaining the key sequence identification result are specifically as follows: S111: Based on the access frequency, request quantity and timestamp data of the database, record the data and perform data processing by superimposing a disturbance factor, combine the processed data with a sequence generated by a quantum random number, and generate a quantum key pool; S112: Based on the quantum key pool, a unique identifier ID is added to each group of quantum key sequences in the quantum key pool to generate a key sequence identification result.
3. The encryption and decryption method applicable to a quantum database according to claim 1, characterized in that: The steps for obtaining the dynamic quantum key pool data are specifically as follows: S121: extracting the usage frequency data of each group of quantum keys in the quantum key pool based on the key sequence identification result, comparing the usage frequency data with the preset frequency threshold one by one, classifying the quantum keys according to the comparison result, and obtaining the key frequency comparison result; S122: Based on the key frequency comparison result, screening and updating of quantum keys in the quantum key pool are performed to generate dynamic quantum key pool data.
4. The encryption and decryption method applicable to a quantum database according to claim 1, characterized in that: The steps for obtaining the distributed quantum key fragments are specifically as follows: S211: Based on the distribution characteristics of the dynamic quantum key pool data, extract the call frequency, timestamp and usage status of the quantum key, sort the data according to the time axis and divide it into fixed time windows, bind the quantum key to the corresponding time window, and generate a distribution characteristic analysis result; S212: Based on the distribution characteristic analysis result, the formula is used: ; Calculates the result of modular exponentiation , indicating the 'A generated encryption key; in, It is the first The basic value of the quantum key, It is The timestamp value corresponding to the quantum key, is the number of quantum keys in the time window, is the exponent value of the power operation, is the modulus value of the modular operation, It is a modular operation, which means that the result of the power operation is modulo Take the remainder; S213: Based on the encryption key, multi-threaded quantum key distribution is performed on the target node, the quantum key is encrypted and transmitted in fragments, and a distribution serial number is attached for integrity verification to obtain the distributed quantum key fragments.
5. The encryption and decryption method applicable to a quantum database according to claim 1, characterized in that: The steps for obtaining the reorganized quantum key of the current session are specifically as follows: S311: Based on the distributed quantum key shards, by collecting the unique identifier and hash value of each shard, performing hash calculation on the data content of the shards, and comparing them with the stored original hash values one by one, eliminating the shards that failed verification, and generating a list of quantum key shards that passed verification; S312: Based on the verified quantum key shard list, the formula is used: ; Calculate the recombinant quantum key for the current session ; in, Indicates the shard index currently being calculated. Indicates the index for traversing interpolation points outside the current slice. represents the number of quantum key shards that have passed consistency verification, Indicates The value of quantum key shards, Indicates The interpolation points corresponding to the slices, Indicates that the current product calculation excludes the fragment Other slice interpolation points of Indicates the target point for interpolation calculation.
6. The encryption and decryption method applicable to a quantum database according to claim 1, characterized in that: The steps for obtaining the updated session quantum key data are specifically as follows: S321: Based on the reorganized quantum key of the current session, extract the target key length, encryption algorithm and key structure requirements of the database key space, compare the length of the reorganized quantum key with the target key length, and if the lengths do not match, adjust the key length by intercepting or supplementing. After the adjustment, perform format verification on the quantum key and load it into the encryption environment of the current session to generate a loaded session quantum key; S322: Based on the loaded session quantum key, extract the unique identifier and length information of the loaded key, compare them one by one with the identifier and length information recorded before loading, verify the key integrity and consistency, perform functional testing on the loaded key, and bind the loaded session quantum key to the current session identifier to generate updated session quantum key data.
7. The encryption and decryption method applicable to a quantum database according to claim 1, characterized in that: The step of optimizing the noise distribution and disturbance intensity of the random disturbance signal is specifically as follows: S411: Based on the updated session quantum key data and the encryption and decryption requirements of the database, extract the length and grouping information of the session quantum key data, initialize the communication node identification and communication parameters, generate a random disturbance signal and detect the distribution uniformity of the signal, embed the generated random disturbance signal into the quantum communication channel, complete the channel initialization, and obtain the communication channel embedded with the random disturbance signal; S412: Based on the communication channel embedded with the random disturbance signal, extract the noise distribution characteristics and strength information of the disturbance signal, adjust the signal strength of each intensity area, re-detect the signal according to the adjustment result and confirm that the distribution range meets the requirements, so as to obtain an optimized communication signal.
8. The encryption and decryption method applicable to a quantum database according to claim 1, characterized in that: The steps for obtaining the descrambled quantum encrypted data are specifically as follows: S421: embed the optimized random perturbation signal into the transmission data in the quantum communication channel, and the receiving end obtains the perturbation descrambling key through quantum key distribution negotiation, using the formula: ; Calculate the average deviation between the perturbation signal in the transmitted data and the descrambling key , according to the average deviation Analyze the matching degree between the signal and the descrambling key at the target position, correct the unmatched part, and compare the signal and the key to obtain the pre-matched disturbance signal and descrambling key; in, Indicates the index of the signal and the descrambling key, Indicates the total number of signal and key matching groups involved in the calculation, It is The value of the disturbance signal, It is The value of a descrambling key; S422: Based on the pre-matched disturbance signal and the descrambling key, the signal is synchronously descrambled by parsing the correspondence between the descrambling key and the signal point by point, and the parsed data is redundancy checked with the original data. After the check is completed, the descrambled data is processed and stored to obtain the descrambled quantum encrypted data.
Citation Information
Patent Citations
Power dispatching business oriented quantum key dynamic supply method and management system
CN108134669A
Quantum resistant blockchain with multi-dimensional quantum key distribution
US10708046B1