A global quantum secure multicast information transmission method

By creating multicast groups and pre-setting keys in the global quantum security network, the problems of network bandwidth congestion and key consumption caused by key distribution and relay in unicast mode are solved, the real-time and low-latency of multicast services are achieved, and the user experience is improved.

CN119675918BActive Publication Date: 2025-10-21MATRICTIME DIGITAL TECH CO LTD
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202411721639.9
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2024-11-28
Publication Date
2025-10-21
Estimated Expiration
2044-11-28

AI Technical Summary

Technical Problem

In a global quantum security environment, when unicast is used to distribute messages to multiple devices, as the number of devices receiving messages increases and the amount of messages increases, the distribution and relay of keys become complicated, resulting in serious key loss and bandwidth load waste.

Method used

A global quantum secure multicast information transmission method is used to create a multicast group and pre-set or online pre-set keys. Data is transmitted through users in the multicast group. Through the communication of the multicast group, new equipment or systems are used to perform encryption and decryption operations, preventing unauthorized personnel from stealing communication messages and solving the problems of network bandwidth congestion and key consumption caused by key relay.

Benefits of technology

It achieves real-time and low latency for multicast services, improves user experience, and ensures the normal operation of high-load traffic services in the global quantum security network.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN119675918B_ABST
    Figure CN119675918B_ABST
Patent Text Reader

Abstract

The application discloses a kind of global quantum secure multicast information transmission methods, the method comprises: based on multicast service creates multicast group;Each edge gateway device and center gateway device downloads key file from key center;Center gateway device is associated with global quantum service link and is stored in mapping table with the IP of participant;Sender user sends the information of message receiver user to application server via edge gateway device and center gateway device with the message to be sent, own IP and message receiver user information;Application server sends the data processed to each receiver user in multicast group again.This application can only participate in communication in the user of multicast group, and the communication data is encrypted and decrypted by using the related key, so that the communication message is prevented from being stolen by irrelevant personnel;Meanwhile, the key is pre-installed or pre-installed online, and then the service is distributed, and the key relay service is ensured, so that the high-load traffic service can normally operate in the global quantum security network.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the field of secure communication technology, and in particular to a global quantum secure multicast information transmission method. Background Art

[0002] In a global quantum security environment, quantum encryption services use quantum keys to encrypt services at the edge device end. In addition to transmitting the ciphertext according to the original link, it is also necessary to notify the key center to distribute the quantum key to the corresponding client. The client uses the quantum key to decrypt the ciphertext before obtaining the information and continuing business processing.

[0003] If an edge device needs to distribute a message to multiple devices using unicast, each message sent to a device requires key distribution and relaying. As the number of devices receiving messages increases and the volume of messages grows, key distribution and relaying become increasingly complex, resulting in significant key loss and bandwidth waste. For example, in a group chat service, if user 1 wants to send a message to user 2 and user 3, user 1 sends the message to the edge device. The edge device obtains the key, encrypts the message, and sends it to the central device. The key center then forwards the key to the central device, which then obtains the ciphertext / key and performs quantum decryption. Subsequent messages are transmitted to user 2 and user 3. User 2's message is quantum encrypted, and the key is relayed by the key center. When both the key and ciphertext reach user 2's edge device, quantum decryption occurs, and user 2 receives the message and displays it. Messages sent to user 3 also relay the key and ciphertext to user 3's connected edge device. After decryption by the edge device, the plaintext is transmitted to user 3 and displayed.

[0004] Therefore, for one-to-many message encryption transmission services, the increase in network bandwidth brought by key relay and the key consumption of the key center are very huge. To solve this problem, this field urgently needs a multicast information transmission method to solve the problems of bandwidth congestion and huge key consumption, and ensure the normal operation of high-load traffic services in the global quantum security network. Summary of the Invention

[0005] Purpose of the Invention: The purpose of the present invention is to provide a global quantum secure multicast information transmission method, which solves the problem that when distributing messages to multiple devices using unicast, the distribution and relay of keys become very complicated as the number of devices receiving messages increases and the amount of messages increases, resulting in a large amount of key loss and bandwidth load waste. In the present invention, only users in the multicast group can participate in communication, and then use the relevant keys to encrypt and decrypt the communication data, preventing unauthorized personnel from stealing communication messages. At the same time, the key is preset in advance or successfully preset online before service distribution is carried out, without key relay services, which solves the problems of network bandwidth congestion and huge key consumption caused by key relay, and ensures the normal operation of high-load traffic services in the global quantum secure network.

[0006] Technical solution: The present invention provides a global quantum secure multicast information transmission method, comprising the following steps:

[0007] (1) A multicast group is created based on the multicast service and the multicast group is marked as g. The multicast group includes multiple users, edge gateway devices corresponding to each user, and a central gateway device connected to the edge gateway device. One of the users is the sender user, and the rest of the users are the receiver users.

[0008] (2) Each edge gateway device and central gateway device downloads the key file from the key center;

[0009] (3) The central gateway device creates a global quantum service link for this multicast service, associates the IP address of the participant with the global quantum service link, and stores the link in a mapping table;

[0010] (4) The sending user sends the message to be sent, its own IP address and the message recipient's user information to the application server via the edge gateway device and the central gateway device;

[0011] (5) The application server sends the processed data data to each receiving user in the multicast group g via the central gateway device and the edge gateway device.

[0012] Furthermore, each edge gateway device and the central gateway device downloading the key file from the key center refers to:

[0013] Each edge gateway device and central gateway device requests a key file from the key center. The request sent by each gateway device to the key center carries the multicast group tag g; the key center responds to the request carrying the tag g and issues a key file, that is, each gateway device in the multicast group downloads the same key file.

[0014] Furthermore, the key file is issued in an offline or online manner.

[0015] Furthermore, the offline mode of issuing the key file means that the key is taken out from the key center by using an authenticated Ukey or a distribution machine, and distributed to the key pool of all central gateway devices and edge gateway devices in the multicast group, thereby forming a unified key pool for use when executing the service;

[0016] The method of issuing key files is online, which means that when any edge gateway device or central gateway device triggers a key download request, the key center distributes the same key to all central gateway devices and edge gateway devices in the multicast group through the Internet communication link and places them in their respective key pools, thereby forming a unified key pool for use when executing the business.

[0017] Furthermore, the specific process of step (3) is as follows:

[0018] The sender user sends its own IP to the corresponding edge gateway device in a preset format. The edge gateway device receives and forwards it to the central gateway device. After receiving the data in this format, the central gateway device determines that the sender user's IP is used to apply for multicast services based on the frame type in the preset format, and then uses the sender user's IP as the sender in the global quantum service link.

[0019] Similarly, the receiving user also sends its own IP to the central gateway device via the corresponding edge gateway device in a preset format. After receiving it, the central gateway device determines that the receiving user's IP is also used to apply for multicast services, and then uses the receiving user's IP as the receiver in the global quantum service link.

[0020] Then, the IP address of the sending user and the receiving user are associated with the global quantum service link link and stored in the mapping table. At the same time, the multicast group tag g is associated with the global quantum service link link and stored in the mapping table.

[0021] Furthermore, the preset format includes frame length, frame type, multicast group tag and check code.

[0022] Furthermore, the specific process of the sender user sending the to-be-sent message mes, his own IP and the message recipient user information to the application server via the edge gateway device and the central gateway device is as follows:

[0023] The sending user sends the message to be sent mes, its own IP address, and the user information of the message recipient to the corresponding edge gateway device. The edge gateway device obtains the encryption key K1 from the local key pool to encrypt the message to be sent mes, and obtains the ciphertext MES. Then, the edge gateway device sends the location information of the encryption key K1, the ciphertext MES, the sending user's IP address, and the message recipient's user information to the central gateway device.

[0024] The central gateway device extracts the message recipient's user information from the received information, obtains the recipient's IP address based on the message recipient's user information, and then matches the global quantum service link link and the multicast group tag g from the mapping table based on the recipient's IP address and the sender's IP address. Then, through the multicast group tag g, the central gateway device retrieves the decryption key K1' from the key file related to the multicast group tag g based on the location information of the encryption key K1, decrypts the ciphertext MES, and obtains the plaintext message mes'. The central gateway device associates the plaintext message mes' with the multicast group tag g and sends it to the application server.

[0025] Furthermore, the specific process of the application server sending the processed data data to each receiving user in the multicast group g via the central gateway device and the edge gateway device is as follows:

[0026] The application server sends the processed data information data to the central gateway device, and at the same time sends the previously associated multicast group tag g to the central gateway device; the central gateway device obtains the second encryption key K2 from the key file related to the multicast group tag g to encrypt the data information data to obtain the ciphertext DATA; and matches the global quantum service link link from the mapping table according to the multicast group tag g, and then sends the ciphertext DATA to the edge gateway device corresponding to each receiving user related to the multicast group tag g according to the global quantum service link link for decryption. The edge gateway device sends the decrypted data information data′ to the corresponding receiving user.

[0027] Furthermore, the message recipient user information at least includes the recipient user's IP address and the recipient user's multicast group identifier.

[0028] Beneficial effects of the present invention:

[0029] (1) In the present invention, only users in the multicast group can participate in the communication and have the relevant keys to encrypt and decrypt the communication data, thus preventing unauthorized persons from eavesdropping on the communication messages.

[0030] (2) The present invention presets the key in advance or pre-sets it online successfully before distributing the service. There is no key relay service during service distribution, which solves the problems of network bandwidth congestion and huge key consumption caused by key relay. In this way, the central gateway device and edge gateway device of the global security network can directly distribute the ciphertext to their respective devices, and complete the current service after decryption with a fixed key, making the multicast service more real-time, with lower latency, easier to obtain user recognition, improving user experience, and ensuring the normal operation of high-load traffic services in the global quantum security network. BRIEF DESCRIPTION OF THE DRAWINGS

[0031] Figure 1 This is a schematic diagram of the global quantum secure multicast information transmission process of the present invention;

[0032] Figure 2 This is a schematic diagram of the structure of the global quantum secure multicast group of the present invention;

[0033] Figure 3 Schematic diagram of each device of the present invention downloading key files from the key center;

[0034] Figure 4 Schematic diagram of the mapping table structure of the present invention. DETAILED DESCRIPTION

[0035] The present invention will be further described below with reference to the accompanying drawings and embodiments:

[0036] As described in the background, when an existing edge device needs to distribute a message to multiple devices, it typically uses unicast. This means that each message sent to a device requires key distribution and relaying. However, as the number of devices receiving messages increases and the volume of messages increases, key distribution and relaying become increasingly complex. The increased network bandwidth and key consumption at the key center caused by key relaying are both significant, resulting in significant key loss and bandwidth load waste. In light of this, this application proposes a global quantum-secure multicast information transmission method.

[0037] like Figure 1 As shown, the present invention provides a global quantum secure multicast information transmission method, comprising the following steps:

[0038] (1) Create a multicast group based on the multicast service and mark the multicast group as g. The multicast group includes multiple users, edge gateway devices corresponding to each user, and a central gateway device connected to the edge gateway device. The central gateway device is also connected to the application server, such as Figure 2 As shown, one of the users is a sender user, and the other users are receiver users. In this embodiment, user 1 is a sender, and the other users are receivers, forming a one-to-many service relationship in the multicast group.

[0039] (2) Each edge gateway device and central gateway device downloads the key file from the key center;

[0040] Specifically, since each edge gateway device corresponds one-to-one with multiple users in the multicast group, each edge gateway device and the central gateway device requests a key file from the key center. Each request sent by each gateway device to the key center carries the multicast group tag g. The key center responds to requests carrying tag g by issuing key files. In other words, each gateway device in the multicast group downloads the same key file. Of course, the key file requested for multicast group tag g is associated with that multicast group tag g.

[0041] like Figure 3 As shown, the key center can issue key files in an offline or online manner. The offline method means: using a certified Ukey or a distribution machine and other security devices to take out the key from the key center and distribute it to the key pool of all central gateway devices and edge gateway devices in the multicast group, thereby forming a unified key pool for use when executing the business. The online method means: when any edge gateway device or central gateway device triggers a key download request, the key center distributes the same key to all central gateway devices and edge gateway devices in the multicast group through the Internet communication link and places it in their respective key pools, thereby forming a unified key pool for use when executing the business.

[0042] Later, during service execution, when the usage of the key files in any gateway device's key pool reaches a preset threshold, the gateway device can request additional keys from the key center. Although only one gateway device is requesting a key, the key center, upon receiving the request with the multicast group tag g, will proactively distribute the additional key files to all gateway devices carrying the multicast group tag g. It should be noted that the central gateway device can have different key pools for different multicast groups, e.g., one key pool for each multicast group.

[0043] In some embodiments, the order of step (1) and step (2) can be interchanged. If step (2) is performed first, the same key file is preset in the key pool of each device, and then some users are selected from all users to form a multicast group.

[0044] (3) The central gateway device creates a global quantum service link for this multicast service, associates the IP address of the participant with the global quantum service link, and stores the link in a mapping table;

[0045] First, the sending user sends its own IP to the corresponding edge gateway device in a preset format. The edge gateway device receives and forwards it to the central gateway device. After receiving the data in this format, the central gateway device determines that the sending user's IP is used to apply for multicast services based on the frame type in the preset format, and then uses the sending user's IP as the sender in the global quantum service link link. In this embodiment, user 1 is the sender, and it sends its own IP1 to the corresponding edge gateway device in a preset format. The preset format includes frame length, frame type, multicast group tag and check code. The edge gateway device receives the corresponding user 1's IP1 and sends the IP1 to the central gateway device. The central gateway device determines that this IP1 is used to apply for multicast services based on the frame type, and uses this IP1 as the sender in the global quantum service link link, that is, user 1 is the sender.

[0046] Similarly, the receiving user also sends their IP address in a preset format via the corresponding edge gateway device to the central gateway device. After receiving the IP address, the central gateway device determines that the receiving user's IP address is also used to apply for multicast services. It then uses the receiving user's IP address as the recipient of the global quantum service link. In this embodiment, users 2, 3, and 4 are the recipients of this communication service, and IP2, IP3, and IP4 are correspondingly used as recipients of the global quantum service link. At this point, the global quantum service link is complete, covering the sender IP address of this multicast service, IP1, and the recipients IP2, IP3, and IP4.

[0047] If a new receiver joins, repeat this step, bind the new receiver's IP to link, update the link's connection relationship, and obtain a new global quantum service link link′.

[0048] The sender's and receiver's IP addresses are then associated with the global quantum service link link and stored in a mapping table. The multicast group tag g is also associated with the global quantum service link link and stored in a mapping table. The multicast group tag g, the sender's IP address 1, and the receivers' IP addresses 2, IP3, and IP4 are associated with the global quantum service link link and stored in the mapping table.

[0049] To ensure smooth service delivery, the central gateway forwards the received IP1 to the application server, which then adds it to the application service group. Similarly, users 2, 3, and 4, recipients of this communication service, also send their IP2, IP3, and IP4 to the application server via their corresponding edge gateways and central gateway, adding them to the application service group. The application service group here corresponds to the participants in the multicast group.

[0050] Since the central gateway device may serve multiple communication services at the same time, the IP in different communication services and the global quantum service link form a binding mapping table, such as Figure 4 shown.

[0051] Through the above steps (1) to (3), the system has completed the preparation work for the execution of multicast services, including the creation of multicast groups, key file preparation, and business party association. Only users in the multicast group can participate in the communication and have the relevant keys to encrypt and decrypt the communication data, thus preventing irrelevant personnel from stealing communication messages. The key is preset in advance or the online preset is successful before the service is distributed. In this way, there is no key relay service during service distribution, which solves the problems of network bandwidth congestion and huge key consumption caused by key relay. The central gateway device and the edge gateway device can directly distribute the ciphertext to their respective devices in the later stage, and complete the current service after decryption with a fixed key, making the multicast service more real-time;

[0052] (4) The sending user sends the message to be sent, its own IP address, and the message recipient's user information to the application server via the edge gateway device and the central gateway device. The specific process is as follows:

[0053] The sending user, user 1, sends the message to be sent mes, its own IP1 and the message recipient user information to the corresponding edge gateway device. The message recipient user information at least includes the recipient user's IP and the multicast group tag of the recipient user; the edge gateway device obtains the encryption key K1 from the local key pool to encrypt the message to be sent mes to obtain the ciphertext MES; then, the edge gateway device sends the location information of the encryption key K1, the ciphertext MES, the sending user's IP (that is, user 1's IP1) and the message recipient user information to the central gateway device; since user 1 is the sender in the multicast group, the encryption key used by user 1 must be the key in the communication process of multicast group g.

[0054] The central gateway device extracts the message recipient user information from the received information, obtains the recipient user's IP based on the message recipient user information, and then matches the global quantum service link link and the multicast group tag g from the mapping table based on the recipient user's IP and the sender user's IP. By matching the recipient user's IP and the sender user's IP in the mapping table at the same time, the correctness and security of the matched global quantum service link link and the multicast group tag g can be guaranteed. For example, Figure 4 As shown, the central gateway device learns that the sender is user 1 and the receivers are user 2, user 3, and user 4. Then, the multicast group for this message communication is matched from the mapping table as g1. Correspondingly, the global quantum service link for this multicast service is link1.

[0055] Then, through the multicast group tag g, the central gateway device takes out the decryption key K1′ from the key file related to the multicast group tag g according to the location information of the encryption key K1, decrypts the ciphertext MES, and obtains the plaintext message mes′; the central gateway device associates the plaintext message mes′ with the multicast group tag g and sends it to the application server, and the application service performs subsequent processing.

[0056] (5) The application server sends the processed data data to each receiving user in the multicast group g via the central gateway device and the edge gateway device. The specific process is as follows:

[0057] The application server sends the processed data information data to the central gateway device, and at the same time sends the previously associated multicast group tag g to the central gateway device; the central gateway device obtains the second encryption key K2 from the key file related to the multicast group tag g to encrypt the data information data to obtain the ciphertext DATA; and matches the global quantum service link link from the mapping table according to the multicast group tag g, and then sends the ciphertext DATA to the edge gateway device corresponding to each receiving user related to the multicast group tag g according to the global quantum service link link for decryption. The edge gateway device sends the decrypted data information data′ to the corresponding receiving user.

[0058] Only users in the multicast group of the present invention can participate in communication, and then use the relevant keys to encrypt and decrypt the communication data, preventing irrelevant personnel from stealing communication messages; at the same time, the key is preset in advance or successfully preset online before the service is distributed, and there is no key relay service, which solves the problems of network bandwidth congestion and huge key consumption caused by key relay, and ensures the normal operation of high-load traffic services in the global quantum security network.

Claims

1. A global quantum secure multicast information transmission method, characterized in that: The following steps are involved: (1) Create a multicast group based on the multicast service and mark the multicast group as g. The multicast group includes multiple users, edge gateway devices corresponding to each user, and central gateway devices connected to the edge gateway devices. One of the users is the sender user, and the rest of the users are the receiver users. (2) Each edge gateway device and central gateway device downloads the key file from the key center; (3) The central gateway device creates the global quantum service link for this multicast service, associates the IP of the participant with the global quantum service link, and stores it in the mapping table; (4) The sending user sends the message to be sent, its own IP address and the user information of the message recipient to the application server via the edge gateway device and the central gateway device; (5) The application server sends the processed data data to each receiving user in the multicast group g via the central gateway device and the edge gateway device; The edge gateway devices and the central gateway device downloading the key file from the key center refers to: Each edge gateway device and central gateway device requests a key file from the key center. The request sent by each gateway device to the key center carries the multicast group tag g; the key center responds to the request carrying the tag g and issues a key file, that is, each gateway device in the multicast group downloads the same key file.

2. A global quantum secure multicast information transmission method according to claim 1, characterized in that: The key file is issued in an offline or online manner.

3. A global quantum secure multicast information transmission method according to claim 2, characterized in that: The offline mode of issuing key files means that the key is taken out from the key center by using a certified Ukey or a distribution machine and distributed to the key pools of all central gateway devices and edge gateway devices in the multicast group, thereby forming a unified key pool for use when executing services; The method of issuing key files is online, which means that when any edge gateway device or central gateway device triggers a key download request, the key center distributes the same key to all central gateway devices and edge gateway devices in the multicast group through the Internet communication link and places them in their respective key pools, thereby forming a unified key pool for use when executing the business.

4. A global quantum secure multicast information transmission method according to claim 1, characterized in that: The specific process of step (3) is as follows: The sender user sends its own IP to the corresponding edge gateway device in a preset format. The edge gateway device receives and forwards it to the central gateway device. After receiving the data in this format, the central gateway device determines that the sender user's IP is used to apply for multicast services based on the frame type in the preset format, and then uses the sender user's IP as the sender in the global quantum service link. Similarly, the receiving user also sends its own IP to the central gateway device via the corresponding edge gateway device in a preset format. After receiving it, the central gateway device determines that the receiving user's IP is also used to apply for multicast services, and then uses the receiving user's IP as the receiver in the global quantum service link. Then, the IP address of the sending user and the receiving user are associated with the global quantum service link link and stored in the mapping table. At the same time, the multicast group tag g is associated with the global quantum service link link and stored in the mapping table.

5. The global quantum secure multicast information transmission method according to claim 4, characterized in that: The preset format includes frame length, frame type, multicast group tag and check code.

6. A global quantum secure multicast information transmission method according to claim 4, characterized in that: The specific process of the sender user sending the message to be sent mes, his own IP and the message recipient user information to the application server via the edge gateway device and the central gateway device is as follows: The sending user sends the message to be sent mes, its own IP address and the user information of the message recipient to the corresponding edge gateway device. The edge gateway device obtains the encryption key K1 from the local key pool to encrypt the message to be sent mes and obtains the ciphertext MES. Then, the edge gateway device sends the location information of the encryption key K1, the ciphertext MES, the sender's user IP, and the message receiver's user information to the central gateway device; The central gateway device extracts the message recipient's user information from the received information, obtains the recipient's IP address based on the message recipient's user information, and then matches the global quantum service link link and the multicast group tag g from the mapping table based on the recipient's IP address and the sender's IP address. Then, based on the multicast group tag g, the central gateway device retrieves the decryption key K1' from the key file associated with the multicast group tag g based on the location information of the encryption key K1, decrypts the ciphertext MES, and obtains the plaintext message mes'. The central gateway device associates the plaintext message mes' with the multicast group tag g and sends it to the application server.

7. A global quantum secure multicast information transmission method according to claim 6, characterized in that: The specific process of the application server sending the processed data data to each receiving user in the multicast group g via the central gateway device and the edge gateway device is as follows: The application server sends the processed data information data to the central gateway device, and also sends the previously associated multicast group tag g to the central gateway device; the central gateway device obtains the second encryption key K2 from the key file associated with the multicast group tag g to encrypt the data information data, obtaining the ciphertext DATA; The global quantum service link link is matched from the mapping table according to the multicast group tag g, and then the ciphertext DATA is sent to the edge gateway device corresponding to each receiving user related to the multicast group tag g for decryption. The edge gateway device sends the decrypted data information data' to the corresponding receiving user.

8. The global quantum secure multicast information transmission method according to claim 6, characterized in that: The message recipient user information at least includes the recipient user's IP address and the multicast group identifier of the recipient user.

Citation Information

Patent Citations

  • Audio and video communication method for global quantum security

    CN115051857A

  • Method and system for realizing transparent encryption and decryption of multicast data by adopting quantum key distribution

    CN115567192A