Video transmission method, system and application thereof using quantum key encryption
By configuring additional frames of key index and verification information in video encryption transmission, the problem of insufficient quantum key distribution speed is solved, and efficient and secure video data transmission and decryption are achieved.
Patent Information
- Application Number
- CN202411823894.4
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2024-12-12
- Publication Date
- 2025-10-17
- Estimated Expiration
- 2044-12-12
AI Technical Summary
Existing encryption technologies based on computational complexity cannot guarantee the security of video data when facing quantum computers, and the existing quantum key distribution speed cannot meet the requirements of video encryption, which limits the application of quantum keys in video encryption.
By configuring specific additional frames of key index and verification information in the encrypted transmission data, the use of quantum keys is reduced, and encrypted video data is generated through a shared key library and check code to ensure that the receiving end can quickly decrypt and verify data integrity.
It effectively reduces the use of quantum keys, enhances the security of encrypted transmission, allows the video receiver to quickly decrypt and verify data integrity, and improves transmission decryption efficiency.
Smart Images

Figure CN119728102B_ABST
Abstract
Description
TECHNICAL FIELD
[0001] The present application relates to the field of quantum communication, in particular to a video transmission method and system using quantum key encryption, and application thereof, i.e. a video conference method and system. BACKGROUND
[0002] In the digital era, data security is becoming increasingly important. In video transmission, we need to encrypt the video to prevent data from being eavesdropped or tampered with. Existing encryption technologies are based on algorithm encryption with computational complexity, such as RSA, which protects data security through computational complexity. This encryption method is challenged by the development of computing power, such as quantum computers, which makes the data security of encrypted video vulnerable.
[0003] Quantum key distribution (QKD) is a new type of quantum communication protocol whose principle is based on quantum mechanics rather than computational complexity, which can prevent eavesdropping or tampering of the key. However, the data volume of video is very large, and the existing encryption method requires a large amount of key to encrypt video data, while the current QKD key generation speed is not as fast as the traditional algorithm-based key, thereby limiting the application prospect of QKD in video encryption. SUMMARY
[0004] To solve the above problems in the prior art, the present application provides a video transmission method and system using quantum key encryption, and a video conference method and system realized by the video transmission method. By configuring a specific additional frame including a key index and verification information in the encrypted transmission data, the use of quantum keys can be effectively reduced, without the need for additional transmission of key information, which can enhance the security of encrypted transmission, while allowing the video receiving end to easily retrieve the additional frame and improve the transmission decryption efficiency. In addition, by generating quantum keys based on the information of both parties of the video transmission, the verifiability of the integrity of the encryption key is provided.
[0005] Specifically, the first aspect of the present application relates to a video transmission method using quantum key encryption, which includes a shared key library establishment step, a video encryption transmission step and a video decryption step.
[0006] In the shared key library establishment step, a shared key library is established in the sending end and the receiving end, which includes quantum keys with a preset length L bits;
[0007] In the video encryption transmission step, the sending end divides the original video into N original data groups, wherein each original data group includes t data frames, and each data frame includes j bytes; the first quantum key K n1 and the second quantum key K n2 for the original data group n are obtained from the shared key library, and the original video is encrypted by using the first quantum key Kn1 The pth byte C p and the second quantum key K n2 The qth byte b q For the qth byte a of the pth frame in the original data group n p" The original data group n is encrypted in an encryption manner to generate an encrypted video data group n, wherein n=1, ..., N, p=1, ..., t, q=1, ..., j; and a first additional frame F is added before and after the encrypted video data group n respectively. n1 and the second additional frame F n2 To generate an encrypted video transmission data group n, wherein the first additional frame F n1 Including the first quantum key K n1 and the second quantum key K n2 The key sequence number of the second additional frame F n2 Including the hash value of the original data group n; generating encrypted video data based on the N encrypted video transmission data groups n and sending it to the receiving end;
[0008] In the video decryption step, the receiving end uses the first additional frame F n1 Obtain the first quantum key K for encrypting the video data set n n1 and the second quantum key K n2 , and with the help of the first quantum key K n1 and the second quantum key K n2 Decrypt the encrypted video data group n to generate the original data group n, and based on the second additional frame F n2 Perform integrity verification on the received original data group n.
[0009] Furthermore, in the shared key library establishment step, a quantum key is generated based on the shared bit string generated by quantum key distribution, the common signature of the sender and the receiver, and at least a part of the hash value of the shared bit string and the common signature, and the quantum keys are numbered to form a shared key library.
[0010] Furthermore, in the video encryption transmission step, by using a hash function, based on the first quantum key K n1 and its pth byte C p Generate a hash bit string and convert byte a p$ , Byte b $ The encrypted video data group n is generated by performing an XOR operation on the qth byte of the hash bit string.
[0011] Furthermore, the video transmission method of the present invention further includes a transmission request step provided before the video encryption transmission step;
[0012] In the transmission request step, the sending end Alice obtains a third quantum key K1 from the shared key library, encrypts the sending end signature and the timestamp with the third quantum key K1 to generate first verification information, and sends the transmission request and the first verification information to the receiving end;
[0013] The receiving end decrypts the first verification information with the third quantum key K1 to obtain the sending end signature and performs identity verification based on the sending end signature, and after the identity verification passes, encrypts the receiving end signature with the third quantum key K1 to generate second verification information, and sends the confirmation information and the second verification information to the sending end;
[0014] The sending end decrypts the second verification information with the third quantum key K1 to obtain the receiving end signature, and constructs a check code based on the receiving end signature, the sending end signature and the timestamp.
[0015] Further, in the transmission request step, the sending end and the receiving end further check the number of quantum keys in the shared key library according to a preset threshold after the identity verification passes; and / or, generate the check code based on a bit string composed of the sending end signature and the timestamp and a bit string composed of the receiving end signature by means of a congruence function.
[0016] Further, the first additional frame further comprises a verification code and a timestamp, and the second additional frame further comprises a verification code and a timestamp;
[0017] And the video transmission method further comprises a receiving verification step arranged before the video decryption step, wherein the receiving end extracts the first additional frame and the second additional frame from the received encrypted video data to obtain the received verification code and the timestamp, and performs identity verification by means of the receiving end signature and the received verification code and / or time verification by means of the received timestamp and the timestamp in the verification code.
[0018] Further, in the video decryption step, integrity verification is further performed by means of the hash value of the original data group n obtained by decryption and the hash value of the original data group n in the received second additional frame.
[0019] The second aspect of the application relates to a video transmission system comprising a sending end and a receiving end, and being arranged to realize video transmission between the sending end and the receiving end by means of the above-mentioned video transmission method using quantum key encryption.
[0020] The third aspect of the application relates to a video conference method comprising a secure channel establishment step and a conference video encrypted transmission step;
[0021] In the secure channel establishment step, the control end issues a master key to the server to which the user end belongs in an encrypted manner, the server generates a personal key based on the master key, a local quantum random number and a shared quantum key with the subordinate user end, and issues the personal key to the user end in an encrypted manner.
[0022] In the conference video encryption transmission step, the first user terminal as the sending end encrypts the video data and the audio data by means of the first personal key to generate first video encryption data and first audio encryption data, and uploads to the first server to which it belongs; the first server decrypts the first video encryption data by means of the first personal key, and decrypts the first audio encryption data by means of the local quantum random number and the shared quantum key for the first personal key to generate second audio encryption data; the video data is transmitted to the second server to which the second user terminal as the receiving end belongs by means of the video transmission method using quantum key encryption, and the second audio encryption data is directly transmitted to the second server; the second server encrypts the video data by means of the second personal key for the second user terminal to generate second video encryption data, encrypts the second audio encryption data by means of the local quantum random number and the shared quantum key for the second personal key to generate third audio encryption data, and delivers the second video encryption data and the third audio encryption data to the second user terminal; the second user terminal decrypts the second video encryption data and the third audio encryption data by means of the second personal key to obtain the audio data and the video data.
[0023] The fourth aspect of the present application relates to a video conference system comprising a control end, a server and user terminals, and is configured to realize the video conference between the user terminals by means of the video conference method described above, wherein the server is configured to be able to generate the local quantum random number. BRIEF DESCRIPTION OF DRAWINGS
[0024] The specific embodiments of the present application will be further described in detail below with reference to the accompanying drawings.
[0025] In order to more clearly illustrate the technical solutions in the embodiments of the present application or the prior art, hereinafter, the drawings required to be used in the embodiments or the prior art description will be briefly introduced. Obviously, the drawings in the following description are only some embodiments of the present application, and for those skilled in the art, other drawings can also be obtained without creative labor on the basis of these drawings.
[0026] Figure 1 An example of a video transmission system according to the present application is shown;
[0027] Figure 2 An example of a video transmission method using quantum key encryption according to the present application is shown;
[0028] Figure 3 An example of the structure of the shared quantum key for the sending end and the receiving end in the video transmission method and system using quantum key encryption according to the present application is shown;
[0029] Figure 4An example of the structure of an additional frame for encrypting a video transmission data group is shown in the video transmission method and system using quantum key encryption according to the present application;
[0030] Figure 5 An example of a video conference system according to the present application is shown.
[0031] Figure 6 An example of a video conference method according to the present application is shown. DETAILED DESCRIPTION
[0032] In the following, exemplary embodiments of the present application will be described in detail with reference to the accompanying drawings. The following embodiments are provided by way of example in order to fully convey the spirit of the present application to those skilled in the art to which the present application pertains. Therefore, the present application is not limited to the embodiments disclosed herein.
[0033] Figure 1 An example of a video transmission system according to the present application is shown, which includes a sending end Alice and a receiving end Bob.
[0034] QKD devices, data processing devices and data storage devices are provided in both the sending end Alice and the receiving end Bob, and a quantum channel and a classical channel are provided between the two.
[0035] Quantum state information such as polarized coded light pulses can be transmitted between the QKD devices via the quantum channel to allow distribution of shared quantum bit strings according to a quantum key distribution protocol.
[0036] The data processing devices can process and handle data, such as performing video encryption and decryption operations and generating quantum key libraries based on shared quantum bit strings.
[0037] The data storage modules can be used to store quantum key libraries and the like.
[0038] The classical channel can be used to transmit classical information. For example, the classical channel can be connected to the data processing devices to allow transmission of encrypted video data, feedback information and the like.
[0039] Figure 2 An example of a video transmission method using quantum key encryption according to the present application is shown, which can be implemented by means of the video transmission system shown above and mainly includes a shared key library establishment step, a transmission request step, a video encryption transmission step, a reception verification step and a video decryption step. Figure 1 The video transmission system shown above can be used to implement the video transmission method using quantum key encryption according to the present application.
[0040] The shared key library establishment step is used to generate quantum keys shared by both the sending end and the receiving end and to establish a shared key library based thereon.
[0041] In particular, the sender and the receiver can generate a quantum key based on a shared bit string generated by means of quantum key distribution, a common signature of the sender and the receiver, and at least a part of a hash value of the shared bit string and the common signature, and then number the quantum key to form a shared key library.
[0042] For example, the sender Alice and the receiver Bob can first generate a shared bit string by means of QKD, and then use the shared bit string to construct a quantum key of a length of L bits as shown in Figure 3
[0043] The shared bit string + the common signature of Alice and Bob + the hash value of the shared bit string and the common signature, wherein the shared bit string has a length of LI, the common signature has a length of L2, and the hash value is a hash of L-L1-L2 bits of the shared bit string and the common signature.
[0044] The sender Alice and the receiver Bob respectively generate a plurality of quantum keys of a length of L bits according to the above-mentioned manner, number these quantum keys in a sequence such as a chronological order, and store them in a data storage device to form a shared key library.
[0045] On the basis of the formation of the shared key library, the sender Alice can send a transmission request to the receiver Bob by means of a transmission request step, and at the same time, perform identity verification.
[0046] As shown in Figure 2 In the transmission request step, the sender Alice can obtain a third quantum key K1 from the shared key library, use the third quantum key K1 to encrypt the signature of the sender Alice and the time stamp to generate first verification information, and then send the transmission request and the first verification information to the receiver.
[0047] After receiving the above-mentioned data, the receiver can use the third quantum key K1 to decrypt the first verification information to obtain the signature of the sender Alice, and perform identity verification based on the signature. After the identity verification is passed, the receiver uses the third quantum key K1 to encrypt the signature of the receiver Bob to generate second verification information, and sends the confirmation information about the transmission request and the second verification information to the sender in response to the transmission request.
[0048] After receiving the confirmation information, the sender Alice continues to use the third quantum key K1 to decrypt the second verification information to obtain the signature of the receiver Bob, and uses the signature of the receiver Bob, the signature of the sender Alice, and the time stamp to construct a check code.
[0049] In the present invention, the constructed check code can meet the following conditions, namely: the check code is a function H(A,B) of the bit string A consisting of the signature and timestamp of the sender Alice and the bit string B consisting of the signature of the receiver Bob, and when one of the parameters A and B is known, the other of the parameters A and B can be obtained through the check code H(A,B).
[0050] As a preferred example, the check code may be generated by using a congruence function, such as RSA and its variant algorithms.
[0051] In a preferred example, after identity verification is successful, the sender and receiver can also perform an operation to check the shared key library to see if the current shared key library is sufficient. For example, the sender and receiver can compare the current number of quantum keys in their shared key library with a preset threshold. If the current number is greater than the preset threshold, the next step is allowed to proceed. Otherwise, the process returns to the shared key library establishment step to replenish the shared key library.
[0052] In the video encryption transmission step, the sender Alice may first divide the original video into multiple (eg, N) original data groups n, wherein every t frames of data are considered as a group, each data frame includes j bytes, and n=1, ..., N.
[0053] In the present invention, a typical value of t may be between 60 and 120. Preferably, the value of t is not informed to the receiving end Bob in advance.
[0054] Then, for each original data group n, the sender Alice can obtain the corresponding first quantum key K from the shared key library n1 and the second quantum key K n2 , by using the first quantum key K n1 The pth byte C p and the second quantum key K n2 The qth byte b q For the qth byte a of the pth frame in the original data group n p" The original data group n is encrypted in an encryption manner to generate an encrypted video data group n, wherein p=1, ..., t, q=1, ..., j.
[0055] As a preferred example, the first quantum key K of length L can be obtained by using a hash function Hash. n1 and its p-th byte C p Generate a hash bit string Hash(K %1 ,c p ), then byte a p$ , Byte b $and the qth byte of the hash bit string, Hash(K %1 ,c p )- $ Perform XOR operation a p$ ⊕b $ ⊕,Hash(K %1 ,c p )- $ In this way, an encrypted video data group n is generated.
[0056] Then, the sender Alice can add the first additional frame F in front of the encrypted video data group n. n1 , and add a second additional frame F after the encrypted video data group n n2 , forming encrypted video transmission data group n.
[0057] In the present invention, the first additional frame F n1 The first quantum key K may be included n1 and the second quantum key K n2 The key sequence number is used to provide the index information of the quantum key used for the current encrypted video data group n in the shared key library. n2 The hash value of the original data group n may be included in to allow integrity verification of the received data.
[0058] Figure 4 shows an example of the structure of the additional frames according to the present invention, wherein: the first additional frame F n1 The first row of pixels is used to encode information, and the remaining pixels are the same as the remaining pixels of the first frame of the encrypted video data group n; the second additional frame F n2 The first row of pixels is used to encode information, and the remaining pixels are the same as the remaining pixels of the last frame of the encrypted video data group n.
[0059] In a preferred example, the first additional frame F n1 The encoded information is in addition to the first quantum key K n1 and the second quantum key K n2 In addition to the key sequence number, it can also include a check code, a timestamp and an end mark. n2 The encoded information may include not only the hash value of the original data group n, but also a checksum, a timestamp, and an end marker. The end marker may be a specific bit string agreed upon in advance by the sender Alice and the receiver Bob.
[0060] Finally, the sending end Alice combines all N encrypted video transmission data groups n to generate encrypted video data (i.e., encrypted video files), and sends it to the receiving end Bob through classic signals.
[0061] After receiving the encrypted video data, the receiving end Bob can first verify the reliability of the received data by means of the receiving verification step.
[0062] In the example of Fig. 1, the receiving end Bob can locate all the additional frames and extract all the first additional frames and second additional frames by retrieving the check code and the termination marker. Figure 2 Subsequently, the receiving end Bob substitutes its signature into the check code for calculation, and if the signature and the timestamp of the sending end Alice can be solved, the identity verification is passed.
[0063] The receiving end Bob can further extract the timestamps of all the first and second additional frames for time verification. If the difference between the timestamps of the second additional frame and the first additional frame is less than a preset threshold Tl, and the difference between the timestamp solved from the check code and the timestamp is less than a preset threshold T2, the time verification is passed.
[0064] In the receiving verification step, if any of the identity verification and the time verification fails, the receiving end Bob terminates the subsequent decryption operation and broadcasts an error message.
[0065] After passing the identity verification and the time verification by means of the receiving verification step, the receiving end Bob can perform the video decryption step.
[0066] In the video decryption step, the receiving end Bob can obtain the first quantum key K n1 and the second quantum key K n1 for encrypting the video data group n from its shared key library by means of the key number in the first additional frame F n2 .
[0067] Therefore, the received encrypted video data group n can be decrypted by means of the first quantum key K n1 and the second quantum key K n2 to obtain the original data group n.
[0068] Further, the receiving end Bob can also perform integrity verification on the received original data group n by means of the hash value of the original data group n in the second additional frame F n2 .
[0069] Specifically, the receiving end Bob can calculate the hash value of each received original data group n and compare it with the hash value of the original data group n in the corresponding second additional frame. If the hash values of all groups are consistent, the integrity verification is passed, and the receiving end Bob can send a video received message to the sending end Alice; otherwise, a video incomplete message can be sent, and at this time, the sending end Alice can choose to resend.
[0070] To improve the security of data transmission, the shared key library of the sending end Alice and the receiving end Bob can delete the first, second and third quantum keys used for the current video transmission after the video transmission is successful, and then renumber the quantum keys in the shared key library in the order.
[0071] In the video transmission system and method of the present application, by configuring a specific additional frame structure in the encrypted video data group, such as index information of the shared key library, identity authentication information and timestamp information, and by using the quantum key corresponding to the index information in the encryption process of the video data frame associated with the additional frame, the use amount of quantum keys can be effectively reduced, and the security can be guaranteed. In addition, since the decryption information is attached in the form of an additional frame in the encrypted video transmission data, the encrypted video data can be directly transmitted without additional transmission of the quantum key information, which can enhance the security of encrypted transmission. Further, the present application also generates quantum keys with a specific structure based on the information of both parties of the video transmission, so that the integrity of the quantum keys used in encryption can be verified. Furthermore, the present application also generates a check code based on the information of both parties of the video transmission, so that the video receiving end can conveniently search for the additional frame based on the check code, and then quickly complete the decryption operation.
[0072] Figures 5-6 An application example of the video transmission scheme according to the present application in a video conference is shown.
[0073] As shown in Figure 5 , the video conference system can include user terminals, servers and control terminals, wherein the user terminals constitute a user layer, and the servers and control terminals constitute a service layer.
[0074] In the present application, the user terminal is a video conference device used by a user. The shared quantum key can be obtained between the user terminal and the server to which it belongs (for example, the user terminal can select a nearby server to connect) through, for example, key charging.
[0075] As an example, the shared quantum key can be generated by QKD or quantum random number generation.
[0076] The server can have the functions of the sending end and the receiving end in the above-mentioned video transmission method, and can generate local quantum random numbers.
[0077] In the present application, the server and the control terminal can be connected to build a shared key library, and the servers can also be connected through the control terminal to build a shared key library.
[0078] The control terminal of the video conference system can generate a shared key pool with each server through QKD.
[0079] For better understanding of the video conference process of the present application, the following will be combined with Figure 6 The video conference method of the present application mainly includes a secure channel establishment step and a conference video encryption transmission step.
[0080] Before starting the video conference, the user end can register with the control end through its belonging server.
[0081] After verification, the control end allows the corresponding server to charge the quantum key to the user end. And the user end can submit a video conference application to the control end, while attaching the identity information of the participants.
[0082] In response to the video conference application, the control end can generate a conference number and send it to the conference applicant.
[0083] Subsequently, the conference participants submit the conference number to the control end to apply for joining the conference.
[0084] After receiving the conference number, the control end compares the identity information of the conference participants with the identity information of the participants submitted by the conference creator, and allows the participants to join the conference after the comparison is consistent.
[0085] At this time, the secure channel establishment step can be used to establish a conference secure channel for the participating user end.
[0086] For example, in the example of Figure 6 , the control end can negotiate to formulate a master key P, and for example, by means of the quantum key shared with the corresponding server, the master key P is issued to the server where each participant user end is located in an encrypted manner.
[0087] The server can use its local quantum random number and its shared quantum key with the subordinate user end to encrypt the master key P to generate a personal key for the corresponding user end, and for example, by means of the quantum key shared with the corresponding user end, the personal key is issued to the corresponding user end in an encrypted manner.
[0088] For example Figures 5-6 , as shown in , for the user end A1, the server A connected with the user end A1 can use its local quantum random number Loc A and the quantum key Q A1 shared with the user end A1 to encrypt the master key P issued by the control end in turn, to obtain the personal key P A1 for the user end A1, and then send the encrypted personal key P A1 to the user end A1 by using the quantum key shared between the server A and the user end A1.
[0089] After establishing the conference security channel for each participant user terminal, the user terminal can transmit the video and audio recorded by the video and audio collection devices to the remaining participants (user terminals) through the conference security channel in the conference video encryption transmission step, and the remaining participants play the received video and audio after decryption.
[0090] In the conference video encryption transmission step of the present application, the first user terminal as the sending terminal can encrypt the video data and audio data by means of the personal key to generate first video encryption data and first audio encryption data, and upload them to the first server to which the first user terminal belongs.
[0091] Subsequently, the first server can decrypt the first video encryption data by means of the first personal key, and decrypt the first audio encryption data by means of the local quantum random number and shared quantum key for the first personal key to generate second audio encryption data; then transmit the video data to the second server to which the second user terminal as the receiving terminal belongs by means of the video transmission method, and directly transmit the second audio encryption data to the second server.
[0092] After obtaining the video data according to the video transmission method of the present application, the second server correspondingly encrypts the video data by means of the second personal key for the second user terminal to generate second video encryption data, and further encrypts the second audio encryption data by means of the local quantum random number and shared quantum key for the second personal key to generate third audio encryption data, and then delivers the second video encryption data and third audio encryption data to the second user terminal.
[0093] Therefore, the second user terminal can decrypt the second video encryption data and third audio encryption data by means of the second personal key to obtain the plaintext.
[0094] For example Figures 5-6 As shown, the first user terminal A1 encrypts the video data and audio data by means of the personal key P A1 to generate first video encryption data and first audio encryption data, and transmits them to the first server A.
[0095] The first server A uses the same symmetric encryption algorithm, and uses the corresponding personal key P A1 to decrypt the first video encryption data to obtain the video data (plaintext), and then uses the video encryption transmission method of the present application to transmit the video to the second server C; at the same time, the first server A also uses the corresponding local quantum random number Loc A1 and quantum key Q A to decrypt the first audio encryption data to generate second audio encryption data, and transmits the second audio encryption data to the second server C. A1
[0096] After receiving the encrypted data, the second server C obtains the video data (plain text) according to the video encryption transmission method of the present invention, and then uses the personal key P C1 Perform encryption operation on the video data to generate the second video encrypted data; at the same time, use the personal key P C1 The corresponding local quantum random number Loc C and quantum key Q C1 The second audio encryption data is encrypted to generate third audio encryption data; then, the second video encryption data and the third audio encryption data are transmitted to the second client C1.
[0097] The second client C1 uses the same symmetric encryption algorithm and uses the personal key P C1 A decryption operation is performed on the second video encrypted data and the third audio encrypted data to obtain video data and audio data (plain text).
[0098] Finally, when the participating client sends a logout command to the control terminal, the control terminal can delete the personal key of the corresponding client from the conference key library after receiving the logout command. When the number of participating clients reaches 0, the conference ends.
[0099] The video conferencing method and system of the present invention utilizes different encryption schemes between the service layer and the user layer (i.e., the present invention's video encryption transmission scheme and the encrypted transmission of personal keys generated using quantum key injection). This effectively enhances data transmission security by preventing personal keys from decrypting ciphertext during transmission between other nodes. Furthermore, the service layer uses local random numbers to generate personal keys, effectively preventing the leakage of other people's personal keys due to the compromise of a single individual's personal key and shared key repository, thereby further enhancing the security of the conferencing system.
[0100] Although the present invention has been described above through specific embodiments in conjunction with the accompanying drawings, it is easy for those skilled in the art to recognize that the above embodiments are merely exemplary and are used to illustrate the principles of the present invention. They do not limit the scope of the present invention. Those skilled in the art can make various combinations, modifications and equivalent substitutions to the above embodiments without departing from the spirit and scope of the present invention.
Claims
1. A video transmission method using quantum key encryption, comprising a shared key library establishment step, a video encryption transmission step, and a video decryption step; In the shared key library establishment step, a shared key library is established in the transmitting end and the receiving end, which includes a quantum key with a preset length of L bits; In the video encryption transmission step, the sender divides the original video into N original data groups, where each original data group includes t data frames and each data frame includes j bytes; obtains the first quantum key K for the original data group n from the shared key library. n1 and the second quantum key K n2 , and by using the first quantum key K n1 The pth byte C p and the second quantum key K n2 The qth byte b q For the qth byte a of the pth frame in the original data group n p" The original data group n is encrypted in an encryption manner to generate an encrypted video data group n, wherein n=1, ..., N, p=1, ..., t, q=1, ..., j; and a first additional frame F is added before and after the encrypted video data group n respectively. n1 and the second additional frame F n2 To generate an encrypted video transmission data group n, wherein the first additional frame F n1 Including the first quantum key K n1 and the second quantum key K n2 The key sequence number of the second additional frame F n2 Including the hash value of the original data group n; generating encrypted video data based on the N encrypted video transmission data groups n and sending it to the receiving end; In the video decryption step, the receiving end uses the first additional frame F n1 Obtain the first quantum key K for encrypting the video data set n n1 and the second quantum key K n2 , and with the help of the first quantum key K n1 and the second quantum key K n2 Decrypt the encrypted video data group n to generate the original data group n, and based on the second additional frame F n2 Perform integrity verification on the received original data group n.
2. The video transmission method according to claim 1, wherein: In the shared key library establishment step, a quantum key is generated based on a shared bit string generated by quantum key distribution, a joint signature of the sender and the receiver, and at least a portion of a hash value of the shared bit string and the joint signature, and the quantum keys are numbered to form a shared key library.
3. The video transmission method according to claim 1, wherein: In the video encryption transmission step, the first quantum key K is used to obtain the n1 and its pth byte C p Generate a hash bit string and convert byte a p$ , Byte b $ The encrypted video data group n is generated by performing an XOR operation on the qth byte of the hash bit string.
4. The video transmission method according to claim 1, further comprising a transmission request step provided before the video encryption transmission step; In the transmission request step, the sending end Ali ce obtains the third quantum key K1 from the shared key library to encrypt the sending end signature and timestamp to generate the first verification information, and sends the transmission request and the first verification information to the receiving end; The receiving end uses the third quantum key K1 to decrypt the first verification information to obtain the sender's signature and performs identity authentication based on it. After the identity authentication is passed, the receiving end signature is encrypted with the third quantum key K1 to generate the second verification information, and the confirmation information and the second verification information are sent to the sender. The sender uses the third quantum key K1 to decrypt the second verification information to obtain the receiver's signature, and constructs a check code with the receiver's signature, the sender's signature and the timestamp.
5. The video transmission method according to claim 4, wherein: In the transmission request step, the sender and receiver also check the number of quantum keys in the shared key library based on a preset threshold after authentication; And / or, a check code is generated based on a bit string consisting of the sender's signature and the timestamp and a bit string consisting of the receiver's signature using a congruence function.
6. The video transmission method according to claim 5, wherein: The first additional frame further includes a verification code and a timestamp, and the second additional frame further includes a verification code and a timestamp; The video transmission method also includes a receiving verification step provided before the video decryption step, wherein the receiving end extracts the first additional frame and the second additional frame from the received encrypted video data to obtain the received verification code and timestamp, and performs identity authentication with the help of the receiving end signature and the received verification code and / or performs time verification with the help of the received timestamp and the timestamp in the verification code.
7. The video transmission method according to claim 1, wherein: In the video decryption step, an integrity check is also performed using the hash value of the decrypted original data group n and the hash value of the original data group n received in the second additional frame.
8. A video transmission system comprising a transmitting end and a receiving end, and configured to implement video transmission between the transmitting end and the receiving end by means of a video transmission method using quantum key encryption as claimed in any one of claims 1 to 7.
9. A video conferencing method comprising a secure channel establishment step and a conference video encryption transmission step; In the secure channel establishment step, the control end sends the master key to the server to which the user terminal belongs in an encrypted manner. The server generates a personal key based on the master key, the local quantum random number, and the shared quantum key with the subordinate user terminal, and sends it to the user terminal in an encrypted manner. In the conference video encryption transmission step, the first user end as the sending end encrypts the video data and audio data with the first personal key to generate first video encrypted data and first audio encrypted data, and uploads them to the first server to which it belongs; The first server decrypts the first video encrypted data using the first personal key, and decrypts the first audio encrypted data using the local quantum random number and the shared quantum key used for the first personal key to generate second audio encrypted data; With the help of the video transmission method using quantum key encryption as described in any one of claims 1 to 7, the video data is transmitted to the second server belonging to the second user terminal as the receiving end, and the second audio encrypted data is directly transmitted to the second server; the second server encrypts the video data with the help of the second personal key for the second user terminal to generate second video encrypted data, encrypts the second audio encrypted data using the local quantum random number and shared quantum key used for the second personal key to generate third audio encrypted data, and sends the second video encrypted data and the third audio encrypted data to the second user terminal; the second user terminal uses the second personal key to decrypt the second video encrypted data and the third audio encrypted data to obtain audio data and video data.
10. A video conferencing system comprising a control terminal, a server and a user terminal, and configured to implement a video conferencing between user terminals by means of the video conferencing method according to claim 9, wherein: The server is configured to generate local quantum random numbers.
Citation Information
Patent Citations
Cloud video conference system based on quantum key encryption and encryption and decryption method thereof
CN111835997A
Quantum digital signature and quantum digital signcryption method
WO2023082823A1