A quantum-secure quantum key management and distribution method for the entire chain

By employing a quantum-secure quantum key management and distribution method with end-to-end quantum security, and utilizing a distributed architecture and a post-quantum-secure virtual private network tunnel to transmit keys, the security and efficiency issues of existing systems are resolved, achieving efficient and secure quantum key management and distribution.

CN119743250BActive Publication Date: 2025-10-31REGULAR QUANTUM (BEIJING) TECH CO LTD
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202411732572.9
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2024-11-28
Publication Date
2025-10-31
Estimated Expiration
2044-11-28

AI Technical Summary

Technical Problem

Existing key management and distribution systems face challenges such as the vulnerability of traditional public key infrastructure to quantum computing attacks, limitations of key distribution systems, lack of end-to-end protection, low efficiency in key synchronization and distribution, and insufficient auditing and trustworthiness.

Method used

A quantum key management and distribution method with full-link quantum security is adopted. Through a distributed architecture of a control platform, a first agent platform and a second agent platform, quantum keys are generated using a post-quantum key algorithm and transmitted through a post-quantum secure virtual private network tunnel to achieve full-link protection of quantum keys.

Benefits of technology

This improves the system's quantum security capabilities, enhances key management and distribution efficiency, strengthens the system's flexibility and scalability, and ensures the system's security and reliability.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN119743250B_ABST
    Figure CN119743250B_ABST
Patent Text Reader

Abstract

This application provides a quantum-secure quantum key management and distribution method with end-to-end quantum security. The method includes: a first proxy platform sending a first key request to a control platform and receiving a target quantum key and a unique identifier; the first proxy platform sending the unique identifier to a second proxy platform, enabling the second proxy platform to obtain the target quantum key from the control platform; the first proxy platform receiving a second key request from a first device and sending the target quantum key and the unique identifier to the first device, enabling the first device to send the unique identifier to the second device; and the second device sending a request including the unique identifier to the second proxy platform to obtain the target quantum key. This allows the first and second devices to communicate using the target quantum key; the transmission channel for the unique identifier and each key request is a quantum-secure virtual private network tunnel. Therefore, end-to-end protection of the quantum key management and distribution process can be achieved, improving the system's quantum security capabilities.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This application relates to the fields of quantum cryptography and network security technology, and in particular to a quantum-secure quantum key management and distribution method with full-link quantum security. Background Technology

[0002] With the rapid development of quantum computing technology, traditional cryptographic systems are facing unprecedented challenges. Existing key management and distribution systems have many shortcomings, including the vulnerability of traditional public key infrastructure to quantum computing attacks, limitations of key distribution systems, lack of end-to-end protection, low efficiency in key synchronization and distribution, and insufficient auditing and trustworthiness.

[0003] Therefore, there is an urgent need to propose a quantum key management and distribution method with end-to-end protection. Summary of the Invention

[0004] This application provides a quantum key management and distribution method with end-to-end quantum security, as well as a computer storage medium, which can realize end-to-end protection of the quantum key management and distribution process, thereby improving the quantum security protection capability of the system.

[0005] In a first aspect, this application provides a quantum key management and distribution method with end-to-end quantum security. The method includes: a first proxy platform sending a first key request to a control platform and receiving a returned target quantum key and a corresponding unique identifier; the target quantum key and the corresponding unique identifier being generated by the control platform using a post-quantum key algorithm; the first proxy platform sending the unique identifier to a second proxy platform, and the second proxy platform obtaining the target quantum key from the control platform based on the unique identifier; the first proxy platform and the second proxy platform being located in first and second scopes, respectively; the first proxy platform receiving a second key request from a first device in the first scope and sending the target quantum key and the unique identifier to the first device, so that the first device sends the unique identifier to a second device in the second scope; the second proxy platform responding to a request containing the unique identifier sent by the second device sending the target quantum key to the second device, so that the first device and the second device communicate using the target quantum key; the transmission channel for the unique identifier and the first and second key requests is a post-quantum secure virtual private network tunnel.

[0006] This enables end-to-end protection of the quantum key management and distribution process, thereby enhancing the system's quantum security capabilities.

[0007] In one possible implementation, the first agent platform sends a first key request to the control platform and receives the returned target quantum key and corresponding unique identifier, including: the first agent platform sends a first key request including a target number to the control platform and receives the returned target number of quantum keys and their respective unique identifiers; the first agent platform randomly selects from the target number of quantum keys and their respective unique identifiers to obtain the target quantum key and its corresponding unique identifier.

[0008] In one possible implementation, the first agent platform sends a first key request including a target number to the control platform, and receives the returned target number of quantum keys and their corresponding unique identifiers. This includes: periodically comparing the current key cache count of the first agent platform with a preset threshold at preset intervals; when the current key cache count is less than the preset threshold, obtaining the target number based on the current key cache count, the historical key usage count of the first agent platform, the maximum key cache count, and the current network state factor of the first scope; sending a first key request including the target number to the control platform; receiving the returned target number of quantum keys and their corresponding unique identifiers, and storing them in the cache of the first agent platform; checking the current network state of the first agent platform; and positively adjusting the preset threshold based on the current network state.

[0009] In one possible implementation, the worse the current network state of the first scope, the larger the current network state factor and the larger the number of targets.

[0010] In one possible implementation, the formula for calculating the target quantity includes:

[0011] Where R is the target number, U is the number of historical keys used, and C max C represents the maximum number of key caches. current N represents the current key cache size. status Let α be the current network state factor, and let β and γ be the weight coefficients. The relationship between the weight coefficients is: α + β + γ = 1.

[0012] In one possible implementation, after sending the target quantum key and unique identifier to the first device, the method further includes: deleting the target quantum key and the corresponding unique identifier from the cache.

[0013] In one possible implementation, before sending the first key request to the management platform, the process further includes: the first agent platform sending a registration and authentication request to the management platform and receiving a registration and authentication feedback message; if the registration and authentication feedback message results in a failure message, the updated registration and authentication request is then sent to the management platform again until the registration and authentication feedback message results in a success message.

[0014] In one possible implementation, the method further includes: writing a kernel task module in the operating system kernel of the first agent platform to collect data corresponding to the unique identifier and the first and second key requests; setting access permissions for the hardware and software that receive and send the corresponding data in the operating system kernel; granting access permissions to the kernel task module so that the kernel task module can collect the corresponding data by accessing the hardware and software, and generate audit logs based on the corresponding data.

[0015] Secondly, this application provides a quantum key management and distribution method with end-to-end quantum security, applied to a first proxy platform, which is the initiator of the quantum key management and distribution process. The method includes: sending a first key request to a control platform and receiving a returned target quantum key and corresponding unique identifier; the target quantum key and corresponding unique identifier are generated by the control platform using a post-quantum key algorithm; sending the unique identifier to a second proxy platform so that the second proxy platform can obtain the target quantum key from the control platform based on the unique identifier; the first proxy platform and the second proxy platform are located in first and second scopes, respectively; in response to receiving a second key request from a first device within the scope corresponding to the first proxy platform, sending the target quantum key to the first device; the target quantum key is used for communication between the first device and the second device within the scope corresponding to the second proxy platform; the transmission channel for the unique identifier and the first and second key requests is a post-quantum secure virtual private network tunnel.

[0016] Thirdly, this application provides a quantum-secure quantum key management and distribution method for the entire chain, applied to a second proxy platform, which is the responder in the target quantum key management and distribution process. The method includes: receiving a unique identifier sent by a first proxy platform; the first proxy platform obtaining the target quantum key and the corresponding unique identifier from a control platform, and then sending the target quantum key to a first device within its corresponding scope; the target quantum key and the corresponding unique identifier being generated by the control platform using a post-quantum key algorithm; the first and second proxy platforms being located in different scopes; sending a third key request including the unique identifier to the control platform and receiving the returned target quantum key; responding to receiving a fourth key request from the second device within its corresponding scope, sending the target quantum key to the second device; the target quantum key being used for communication between the first and second devices; and the transmission channel for the unique identifier, the third key request, and the fourth key request being a post-quantum-secure virtual private network tunnel.

[0017] Fourthly, this application provides a computer storage medium storing instructions that, when executed on a computer, cause the computer to perform the method described in the first aspect or any possible implementation thereof.

[0018] It is understood that the beneficial effects of the second to fourth aspects mentioned above can be found in the relevant descriptions in the first aspect mentioned above, and will not be repeated here. Attached Figure Description

[0019] To more clearly illustrate the technical solutions of the embodiments of this application, the accompanying drawings used in the description of the embodiments will be briefly introduced below. Obviously, the accompanying drawings described below are only some embodiments of this application. For those skilled in the art, other drawings can be obtained based on these drawings without creative effort.

[0020] Figure 1 A diagram illustrating a quantum key management and distribution system architecture for end-to-end quantum security, provided in this application embodiment;

[0021] Figure 2 An interface design diagram for a quantum key management and distribution system with end-to-end quantum security is provided for embodiments of this application;

[0022] Figure 3 A flowchart illustrating a quantum key management and distribution method with end-to-end quantum security, provided for embodiments of this application;

[0023] Figure 4 This is a schematic diagram of the dynamic key pre-caching process provided in an embodiment of this application;

[0024] Figure 5 A flowchart illustrating a quantum key management and distribution method with end-to-end quantum security, provided for embodiments of this application;

[0025] Figure 6 A flowchart illustrating a quantum key management and distribution method with end-to-end quantum security, provided for embodiments of this application;

[0026] Figure 7 A flowchart illustrating a quantum key management and distribution method with end-to-end quantum security, provided for embodiments of this application. Detailed Implementation

[0027] To make the objectives, technical solutions, and advantages of the embodiments of this application clearer, the technical solutions of the embodiments of this application will be clearly and completely described below with reference to the accompanying drawings. Obviously, the described embodiments are only some embodiments of this application, not all embodiments. Based on the embodiments of this application, all other embodiments obtained by those skilled in the art without creative effort are within the scope of protection of this application.

[0028] The relevant technologies involved in this application are described below:

[0029] 1. Quantum random number generator (QRNG): A device that uses quantum physical processes to generate truly random numbers.

[0030] 2. Key Derivation Function (KDF): A cryptographic algorithm used to derive multiple subkeys from the master key material.

[0031] 3. Post-quantum cryptography (PQC) algorithm: A cryptographic algorithm that can resist attacks from quantum computers.

[0032] 4. Implicit authentication: Authentication is completed without directly exchanging identity information, enhancing the privacy protection of both parties in the communication.

[0033] 5. Representational State Transfer (REST) ​​Interface: An application programming interface (API) built on REST principles that allows communication between different software systems.

[0034] 6. Post-quantum secure Virtual Private Network Tunnel (PQ-WireGuard): A post-quantum secure version of the WireGuard protocol. The WireGuard protocol is an open-source, high-performance virtual private network (VPN) protocol.

[0035] 7. Internet Protocol Security (IPSec) and Transport Layer Security (TLS): These are network layer and transport layer security protocols, respectively.

[0036] 8. Auditing: This refers to the function of recording and inspecting system operations to enhance system credibility and security.

[0037] With the rapid development of quantum computing technology, traditional cryptographic systems are facing unprecedented challenges. Existing key management and distribution systems have many shortcomings, including the vulnerability of traditional public key infrastructure to quantum computing attacks, limitations of key distribution systems, lack of end-to-end protection, low efficiency in key synchronization and distribution, and insufficient auditing and trustworthiness.

[0038] To address the above shortcomings, this solution establishes a distributed quantum key management and distribution architecture. This includes utilizing a control platform to manage and distribute quantum keys to first and second proxy platforms located in different domains, and using the first and second proxy platforms to manage and distribute keys to devices within their respective domains. Ultimately, this enables the control platform to manage and distribute quantum keys to the devices, thereby facilitating quantum key management and distribution by the control platform.

[0039] Devices in different domains can communicate quantum securely using quantum keys. This improves the efficiency of quantum key management and distribution, as well as enhances the system's flexibility and scalability.

[0040] Based on this, this solution also utilizes post-quantum-secure virtual private network tunneling technology to transmit messages related to quantum key management and distribution between the control platform and the first and second agent platforms, between the first and second agent platforms, and between the first and second agent platforms and devices in their respective domains, and between devices in their respective domains. This makes the entire link meet the requirements for resisting quantum computing attacks, thus improving the system's quantum security protection capabilities.

[0041] For example, Figure 1 The diagram illustrates an architecture of a quantum key management and distribution system with end-to-end quantum security, provided by an embodiment of this application.

[0042] like Figure 1 As shown, the full-link quantum-secure quantum key management and distribution system includes the following modules: a control platform 110, a first agent platform 120, a second agent platform 130, a first device (A) 140, a first device (B) 150, a second device (A) 160, and a second device (B) 170.

[0043] Among them, the control platform 110, the first agent platform 120, and the second agent platform 130 can be any computing unit, server, device, or device cluster with computing and processing capabilities. The first device (A) 140, the first device (B) 150, the second device (A) 160, and the second device (B) 170 can be communication terminals that use quantum keys for secure data transmission, such as quantum secure service mobile engines or quantum secure U-shields.

[0044] Specifically, the control platform 110 is the core of the entire system. It is used to generate quantum-safe quantum keys using post-quantum key algorithms, and is responsible for the storage, distribution and management of quantum keys.

[0045] The first agent platform 120 and the second agent platform 130 are each an intermediary entity. They reside in different scopes, such as the first and second scopes, and are used to cooperate with the control platform 110 to implement distributed quantum key management and distribution for devices 140-170. Specifically, this includes interacting with the control platform 110 to obtain quantum keys and providing key services to devices 140-170. These different scopes can be different geographical areas, network areas, business areas, security areas, or functional areas, etc.

[0046] In contrast to the control platform 110, the first agent platform 120 is the initiator of the quantum key management and distribution process, and the second agent platform 130 is the responder of the quantum key management and distribution process.

[0047] First device (A) 140 and first device (B) 150 are devices within the scope of first agent platform 120, and second device (A) 160 and second device (B) 170 are devices within the scope of second agent platform 130.

[0048] exist Figure 1 In the architecture shown, the process of quantum key management and distribution in the system includes:

[0049] Step 1: Complete the preparation tasks for the quantum key management and distribution process, including enabling the first agent platform 120 and the second agent platform 130 to complete the registration and authentication on the control platform 110, so as to establish a trusted connection with the control platform 110.

[0050] In step 2, as the initiator of the quantum key management and distribution process, the first agent platform 120 sends a key request to the control platform 110. The control platform 110 generates and distributes a key and its corresponding unique identifier to the first agent platform 120. The key distributed by the control platform 110 is a pre-generated quantum key.

[0051] In step 3, as the responders in the quantum key management and distribution process, the second agent platform 130 and the first agent platform 120 complete the exchange of unique identifiers corresponding to the keys.

[0052] Step 4: The second agent platform 130 obtains the quantum key from the control platform 110 based on the unique identifier corresponding to the key.

[0053] Step 5, the first agent platform 120 distributes the acquired key to the first device (A) 140 or the first device (B) 150, for example, the first device (A) 140.

[0054] Step 6: The first device (A) 140 and the second device (A) 160 or the second device (B) 170 complete the exchange of the unique identifier corresponding to the quantum key, for example, the second device (A) 160.

[0055] Step 7, the second agent platform 130 distributes the acquired key to the second device (A) 160 or the second device (B) 170, for example, the second device (A) 160.

[0056] Step 8: A quantum-secure communication link is established between the first device (A) 140 and the second device (A) 160, and encrypted communication is performed using the distributed key.

[0057] Before performing each message exchange in steps 1-7 above, a post-quantum-secure virtual private network tunnel is established between the control platform 110 and the first proxy platform 120 / second proxy platform 130, or between the first proxy platform 120 and the second proxy platform 130, or between the first proxy platform 120 and the first device (A) 140 / first device (B) 150, or between the second proxy platform 130 and the second device (A) 160 / first device (A) 170, or between the first device (A) 140 and the second device (A) 160.

[0058] In addition, during the message interactions in steps 1-7 above, the control platform 110, the first agent platform 120, and the second agent platform 130 also perform security audits, reliability audits, and other audit operations on each message interaction process, and provide complete and accurate audit logs to ensure the security, compliance, performance, and reliability of the system.

[0059] Therefore, in steps 1-7 above, by using the post-quantum key algorithm to generate quantum-safe quantum keys, and by using the post-quantum-safe virtual private network tunnel to transmit messages such as the unique identifier corresponding to the key, key requests and their responses, full-link protected quantum key management and distribution can be achieved.

[0060] Furthermore, by utilizing the first proxy platform 120 and the second proxy platform 130 in conjunction with the control platform 110 to implement distributed quantum key management and distribution for devices 140-170, the control platform 110 and devices 140-170 can be decoupled. This reduces the direct communication burden on the control platform 110 and improves key distribution efficiency. It also provides better flexibility and scalability, enabling the system to adapt to evolving security needs and network expansion.

[0061] For example, Figure 2 The diagram shows an interface design diagram of a quantum key management and distribution system with full-link quantum security provided in an embodiment of this application.

[0062] Combination Figure 1 The architecture diagram shown is as follows: Figure 2As shown in the diagram, this diagram illustrates the design of the main REST API interfaces in the system, as well as the possible parameters for each interface:

[0063] 1. QKMP_API: An API provided by the management platform 110.

[0064] -register(agentInfo): Agent platform registration.

[0065] -authenticate(credentials): Authentication by the proxy platform.

[0066] -requestKey(agentID): Request a new quantum key.

[0067] -requestSpecificKey(agentID, keyID): Requests the corresponding quantum key based on a specific unique identifier.

[0068] -revokeKey(keyID): Revokes a specific quantum key.

[0069] -auditKeyUsage(timeRange): Audit key usage.

[0070] 2. Agent-API: The API provided by the first agent platform 120 / the second agent platform 130 to other agent platforms and devices 140-150 / 160-170.

[0071] -notifyKeyID(fromAgentID, toAgentID, keyID): Notifies other agent platforms of the unique identifier corresponding to the quantum key.

[0072] -getKey(agentID, deviceID): Provides a quantum key to the device.

[0073] -requestSpecificKeyForDevice(agentID, deviceID, keyID): Requests a quantum key corresponding to a specific unique identifier for a communication device.

[0074] 3. DataDevice-API: The API provided by devices 140-170.

[0075] -sendKeyID(fromDeviceID, toDeviceID, keyID): Sends a unique identifier corresponding to the quantum key to other devices.

[0076] -establishSecureComm(deviceAID, deviceBID, keyID): Establishes secure communication between devices.

[0077] These API interfaces implement quantum-secure IPSec / TLS channels using the PQ-WireGuard secure communication protocol, ensuring the security and reliability of the entire system. The PQ-WireGuard protocol integrates both Kyber and ClassicMcEliece PQC algorithms, providing a post-quantum-secure virtual private network tunnel for the system. Within this framework, RESTAPI, as a communication protocol providing efficient data exchange capabilities, works in conjunction with the PQ-WireGuard protocol to ensure efficient and secure data transmission in a quantum-safe environment.

[0078] Based on the above, a detailed description of the quantum key management and distribution method with full-link quantum security is provided.

[0079] For example, Figure 3 The diagram illustrates a flowchart of a full-link quantum-secure quantum key management and distribution method provided by an embodiment of this application. Figure 3 As shown, the method mainly includes the following steps:

[0080] In step S301, the first agent platform sends a first key request to the control platform and receives the returned target quantum key and corresponding unique identifier. The target quantum key and corresponding unique identifier are generated by the control platform using a post-quantum key algorithm.

[0081] For example, in Figure 1 In the control platform 110 shown, QRNG is used to measure the random collapse of quantum states to obtain truly random numbers. Then, KDF receives these truly random numbers as input to generate multiple security keys. Next, a post-quantum key algorithm is used to process these security keys to obtain quantum keys resistant to quantum computing attacks, which are then stored.

[0082] Furthermore, post-quantum-secure virtual private network tunnels are established between the control platform 110 and the first agent platform 120, as well as between the control platform 110 and the second agent platform 130, to transmit interactive information related to quantum key management and distribution. It is understood that in the following scheme, post-quantum-secure virtual private network tunnels will also be pre-established between the two entities transmitting interactive messages, which will not be elaborated further.

[0083] The process of establishing a post-quantum secure virtual private network tunnel includes: generating a post-quantum key using a post-quantum key generation algorithm, securely distributing the post-quantum key between two entities, and combining the distributed post-quantum key with the IPSec / TLS protocol to provide a post-quantum secure virtual private network tunnel.

[0084] The first proxy platform 120 is the initiator of the target quantum key management and distribution process. Before sending the first key request to the control platform, the first proxy platform 120 sends a registration and authentication request to the control platform 110 and receives the returned registration and authentication feedback message.

[0085] If the registration and authentication feedback message results in a failure message, the registration and authentication request will be updated and then resent to the management platform until the registration and authentication feedback message results in a success message.

[0086] In one implementation, utilizing Figure 2 The REST API provided by the central control platform 110 includes: register(agentInfo) to complete the registration of the first agent platform 120, and authenticate(credentials) to complete the authentication of the first agent platform 120. The parameter "agentInfo" includes the registration information provided by the first agent platform 120, such as username and password, and the parameter "credentials" includes the authentication information provided by the first agent platform 120, such as authentication certificates.

[0087] If the registration and authentication feedback message returned by the control platform 110 is a failure message, then modify the information in the parameters “agentInfo” and “credentials” until the first agent platform 120 completes registration and authentication on the control platform 110.

[0088] Optionally, the first agent platform 120 uses implicit identity authentication technology to collect information such as the user's touch screen behavior and movement patterns to obtain the "agentInfo" and "credentials" parameter information, and then provides the obtained parameter information to the management platform 110 for registration and authentication, which can further enhance the security and accuracy of identity authentication.

[0089] As the initiator of the quantum key management and distribution process, after receiving the successful registration and authentication feedback message from the control platform 110, the first agent platform 120 sends a first key request to the control platform and receives the returned target quantum key and corresponding unique identifier.

[0090] In one implementation, utilizing Figure 2The REST API provided by the central control platform 110, requestKey(agentID), sends the first key request to the control platform 110 and receives the target quantum key and the corresponding unique identifier returned by the control platform 110. The parameter "agentID" is the unique identifier of the first agent platform 120 in the system.

[0091] In addition, the first agent platform 120 can also implement a dynamic key pre-caching mechanism, sending a first key request including the target number to the control platform, receiving the target number of quantum keys and their corresponding unique identifiers at once, and storing them in the cache of the first agent platform 120.

[0092] When distributing quantum keys to devices within the scope of the first agent platform 120, the target quantum key and its corresponding unique identifier are obtained directly from the cache of the target number of quantum keys and their corresponding unique identifiers. This improves the system's response rate for quantum key management and distribution.

[0093] Optionally, a target quantum key and its corresponding unique identifier can be randomly selected from the target number of quantum keys and their corresponding unique identifiers.

[0094] Alternatively, the quantum keys can be sorted according to the generation time of the target number of quantum keys, and the most timely quantum key can be used as the target quantum key.

[0095] In step S302, the first proxy platform sends a unique identifier to the second proxy platform, which then obtains the target quantum key from the control platform based on the unique identifier. The first and second proxy platforms are located in the first and second scopes, respectively.

[0096] For example, Figure 1 The second proxy platform 130 is an intermediary entity located in a different scope from the first proxy platform 120. Specifically, the first proxy platform 120 is located in the first scope, and the second proxy platform 130 is located in the second scope. The second proxy platform 130 is a responder in the target quantum key management and distribution process. The first proxy platform 120 and the second proxy platform 130 cooperate with the control platform 110 to implement distributed quantum key management and distribution for devices 140-170.

[0097] The first agent platform 120 sends the unique identifier corresponding to the target quantum key to the second agent platform 130. The second agent platform 130 then sends a key request message containing the unique identifier to the control platform 110, thereby obtaining the target quantum key.

[0098] It is understandable that before the second agent platform 130 sends a key request message including a unique identifier to the management platform 110, it also uses the method described in step S301 to register and authenticate with the management platform 110.

[0099] In one implementation, the first agent platform 120 utilizes... Figure 2 The REST API provided by the middle agent platform, notifyKeyID(fromAgentID, toAgentID, keyID), sends a unique identifier to the second agent platform 130. The parameter "fromAgentID" is the first agent platform 120, the parameter "toAgentID" is the second agent platform 130, and the parameter "keyID" is the unique identifier of the target quantum key.

[0100] In step S303, the first proxy platform receives the second key request from the first device within the first scope and sends the target quantum key and unique identifier to the first device, so that the first device sends the unique identifier to the second device within the second scope.

[0101] For example, the first device may be Figure 1 The first device (A) 140 or the first device (B) 150 shown are located within the first domain corresponding to the first proxy platform 120, and therefore the first proxy platform 120 manages and distributes the quantum keys to them.

[0102] In response to receiving the second key request from the first device, the first proxy platform 120 sends the target quantum key and its corresponding unique identifier to the first device. This causes the first device to send the corresponding unique identifier to a second device within the corresponding scope of the second proxy platform 130. The second device is a peer communication partner of the first device and is the target object for which the first device intends to conduct secure data transmission.

[0103] In one implementation, the first device utilizes Figure 2 The REST API provided by the agent platform, getKey(agentID, deviceID), sends a second key request to the first agent platform 120. The parameter “agentID” is the first agent platform 120, and the parameter “deviceID” is the first device.

[0104] In one implementation, the first device utilizes Figure 2The REST API provided by the device platform, sendKeyID(fromDeviceID, toDeviceID, keyID), sends a unique identifier of the target quantum key to a second device. The parameter "fromDeviceID" is the first device, the parameter "toDeviceID" is the second device, and the parameter "keyID" is the unique identifier of the target quantum key.

[0105] The second device can be Figure 1 The second device (A) 160 or the second device (B) 170 shown are located within the second domain corresponding to the second proxy platform 130, and therefore the second proxy platform 130 manages and distributes the quantum keys to them.

[0106] In step S304, the second proxy platform responds to the request containing a unique identifier sent by the second device by sending the target quantum key to the second device, enabling the first device and the second device to communicate using the target quantum key. The transmission channel for the unique identifier, the first and second key requests is a post-quantum-secure virtual private network tunnel.

[0107] For example, after receiving the corresponding unique identifier sent by the first device, the second device sends a key request including the corresponding unique identifier to the second agent platform 130 to obtain the target quantum key corresponding to the unique identifier.

[0108] In one implementation, the second device utilizes Figure 2 The REST API provided by the middle agent platform, requestSpecificKeyForDevice(agentID, deviceID, keyID), sends a key request to the second agent platform 130. The parameter "agentID" is the second agent platform 130, the parameter "deviceID" is the second device, and the parameter "keyID" is the unique identifier of the target quantum key.

[0109] At this point, the first device and the second agent can conduct secure data communication based on the target quantum key.

[0110] In one implementation, the first device utilizes Figure 2 The REST API provided by the device platform, `establishSecureComm(deviceAID, deviceBID, keyID)`, initiates a connection request to the second device. The parameter "deviceAID" is the first device, the parameter "deviceID" is the second device, and the parameter "keyID" is the unique identifier of the target quantum key.

[0111] Optionally, the first agent platform 120 also implements a one-time use principle, deleting the target quantum key and its corresponding unique identifier from the cache after sending the target quantum key to the first device. This improves system security.

[0112] Optionally, the first agent platform 120 also generates audit logs for the sending operations of the first and second key requests, which can further improve the security of the system.

[0113] In one implementation, a kernel task module is written in the operating system kernel of the first agent platform 120 to collect data corresponding to the unique identifier and the first and second key requests; access permissions are set for the hardware and software that receive and send the corresponding data in the operating system kernel; the access permissions are granted to the kernel task module so that the kernel task module can collect the corresponding data by accessing the hardware and software and generate audit logs based on the corresponding data.

[0114] Specifically, the kernel task module runs in kernel space and has the ability to directly access hardware and internal operating system data. Access permissions are set within the operating system kernel for the hardware and software that receive and send this data. This can be achieved using kernel-provided permission control mechanisms, such as capabilities in the Linux kernel, or using security policies (such as SELinux or AppArmor). Access permissions are granted to the kernel task module so that it can collect this data by accessing the hardware and software and generate audit logs based on that data. This can be achieved by using appropriate system calls within the kernel task module, such as using `cap-set-proc` to set process capabilities. The kernel task module should generate audit logs simultaneously while collecting data. This can be achieved using kernel-provided auditing frameworks, such as the Linux `auditd` service.

[0115] It is understandable that similar auditing functions can also be implemented in the control platform 110 and the second agent platform 130 to ensure the security, compliance, performance and reliability of the system.

[0116] For example, the auditing operations of the control platform 110 will generate audit logs for each critical operation in the quantum key management and distribution process, including but not limited to:

[0117] - Agent platform registration and authentication,

[0118] - Quantum key generation and distribution

[0119] -Use of quantum key distribution

[0120] - System configuration changes.

[0121] For example, the transmission channel for the aforementioned unique identifier and the first and second key requests is a post-quantum secure virtual private network tunnel.

[0122] Therefore, the quantum key management and distribution process in this scheme has full-chain quantum security protection capabilities.

[0123] In summary, the end-to-end quantum-secure quantum key management and distribution process described in this solution not only achieves efficient quantum key management and distribution, but also improves the overall performance and reliability of the system by implementing a dynamic key pre-caching mechanism and a security audit mechanism.

[0124] For example, Figure 4 The diagram illustrates a dynamic key pre-caching process provided in an embodiment of this application. Figure 4 As shown, the implementation steps of this process include:

[0125] Step S401: Detect the current key cache quantity.

[0126] For example, a periodic detection strategy can be designed in the first agent platform 120, which is triggered by starting a timer of a preset duration.

[0127] For each detection, compare the current key cache count of the first agent platform with the preset threshold.

[0128] If the current key cache count is determined to be not less than or greater than a preset threshold, the implementation process of this dynamic key pre-caching mechanism ends, and the timer restarts to enter the next waiting cycle to trigger this detection. The preset threshold is not greater than the maximum key cache count C. max .

[0129] Step S402: Calculate the required number of quantum keys.

[0130] For example, if it is determined that the current key cache quantity is less than a preset threshold, the target quantity is obtained based on the influence factors of the pre-determined dynamic key pre-caching mechanism, such as the current key cache quantity, the historical key usage quantity, the maximum key cache quantity, and the current network status factor of the first agent platform 120 in the first scope.

[0131] Based on each influencing factor and its respective weighting coefficient, the formula for calculating the target number of quantum keys required is as follows:

[0132]

[0133] In formula (1), R is the target quantity, U is the historical key usage quantity, and C is the target quantity. max C represents the maximum number of key caches. current N represents the current key cache size.status Let α be the current network state factor, and let β and γ be the weight coefficients. The relationship between the weight coefficients is: α + β + γ = 1.

[0134] Among them, the worse the current network state in the first scope, the higher the current network state factor N. status The larger the value, the larger the target quantity R.

[0135] Specifically, N status The value of N ranges from 0 to 1, with smaller values ​​indicating better network conditions. For example, if network latency is low, packet loss rate is low, bandwidth utilization is reasonable, and network connection is stable, the value of the network state factor will be small, indicating good network operation. Conversely, if network latency is high, packet loss rate is high, bandwidth utilization is overloaded, or network connection is unstable, the value of the network state factor will be high, indicating potential performance problems or poor network health. Since a worse network condition makes quantum key acquisition more difficult, a larger value of N is preferable when the network condition is poor. status To obtain a larger target quantity, more quantum keys can be obtained from the control platform 110 at once, thereby improving the efficiency of the system in quantum key management and distribution.

[0136] For example, in formula (1), U can be the average key usage rate over a period of time, assuming an average of 100 keys are used per second. The maximum number of keys cached is C. max =500keys, meaning a maximum of 500 keys can be cached. Current key cache count C. current =200keys, indicating that 200 keys are currently cached. Network state factor N status The value is 0.2. α, β, and γ are 0.5, 0.3, and 0.1, respectively.

[0137] At this point, in formula (1), This indicates that the first agent platform 120 needs to obtain 141 quantum keys from the control platform 110 at once.

[0138] It is understandable that formula (1) can be optimized based on the actual operation of the first agent platform 120. For example, the influence factors in formula (1) can be added or deleted, and their respective weight coefficients can be adjusted, so that the first agent platform 120 can achieve the best performance and resource utilization efficiency under different network conditions and business needs.

[0139] Step S403: Request the target number of quantum keys.

[0140] For example, after determining the target quantity, the first agent platform 120 sends a first key request including the target quantity to the control platform 110 to obtain the target quantity of quantum keys and their corresponding unique identifiers.

[0141] Step S404: Update the cache.

[0142] For example, the target number of quantum keys and their corresponding unique identifiers returned by the receiving and control platform 110 are stored in the cache of the first agent platform 120 for updating the cache.

[0143] Step S405: Check network status.

[0144] For example, the current network status of the first agent platform 120 in the scope is also checked and determined.

[0145] Step S406: Increase the cache threshold.

[0146] For example, if the current network condition is good, the preset threshold is increased.

[0147] Step S407: Reduce the cache threshold.

[0148] For example, if the current network condition is poor, it will be more difficult to obtain quantum keys. Therefore, reducing the preset threshold can increase the probability that the first agent platform 120 will initiate the quantum key management and distribution process, so as to obtain more quantum keys from the control platform 110.

[0149] Therefore, by introducing a dynamic key pre-caching mechanism into the first agent platform 120, the system's response rate for managing and distributing quantum keys can be improved.

[0150] For example, Figure 5 The diagram illustrates a flowchart of a full-link quantum-secure quantum key management and distribution method provided by an embodiment of this application. This method is applied to, for example... Figure 1 The first proxy platform 120 shown is the initiator of the target quantum key management and distribution process. For example... Figure 5 As shown, the main steps include:

[0151] Step S501: Send a first key request to the control platform and receive the returned target quantum key and corresponding unique identifier. The target quantum key and corresponding unique identifier are generated by the control platform using a post-quantum key algorithm.

[0152] In step S502, a unique identifier is sent to the second proxy platform so that the second proxy platform can obtain the target quantum key from the control platform based on the unique identifier. The first proxy platform and the second proxy platform are located in the first and second scopes, respectively.

[0153] Step S503: In response to receiving a second key request from a first device within a first scope, a target quantum key is sent to the first device; the target quantum key is used for communication between the first device and the second device within the corresponding second scope of the second proxy platform. The transmission channel for the unique identifier and the first and second key requests is a post-quantum-secure virtual private network tunnel.

[0154] In one implementation, in response to receiving a second key request from a first device within the scope corresponding to the first agent platform, the method further includes: sending a unique identifier to the first device so that the first device sends the unique identifier to the second device.

[0155] To enable the second agent platform to obtain the target quantum key from the control platform based on the unique identifier, the method includes: after the second agent platform obtains the target quantum key from the control platform based on the unique identifier, sending the target quantum key to the second device that received the unique identifier.

[0156] The specific implementation process of steps S501-503 is the same as that of steps S301-304, and will not be repeated here.

[0157] For example, Figure 6 The diagram illustrates a flowchart of a full-link quantum-secure quantum key management and distribution method provided by an embodiment of this application. This method is applied to, for example... Figure 1 The second proxy platform 130 shown is the responder in the target quantum key management and distribution process. For example... Figure 6 As shown, the main steps include:

[0158] Step S601: Receive the unique identifier sent by the first proxy platform. The first proxy platform obtains the target quantum key and the corresponding unique identifier from the control platform, and then sends the target quantum key to the first device within its corresponding scope. The target quantum key and the corresponding unique identifier are generated by the control platform using a post-quantum key algorithm. The first proxy platform and the second proxy platform are located in different scopes.

[0159] For example, Figure 1 The first proxy platform 120 shown is the initiator of the quantum key management and distribution process, and the second proxy platform 130 is the responder of the quantum key management and distribution process. The first proxy platform 120 and the second proxy platform 130 are used to cooperate with the control platform 110 to implement distributed quantum key management and distribution for devices 140-170.

[0160] As the initiator of the quantum key management and distribution process, the first agent platform 120 is used to obtain the target quantum key and its corresponding unique identifier from the control platform.

[0161] As a respondent in the quantum key management and distribution process, the second proxy platform 130 receives a unique identifier sent by the first proxy platform 120. The unique identifier corresponds to the target quantum key generated by the control platform 110 using the post-quantum key algorithm.

[0162] Furthermore, after obtaining the target quantum key and its corresponding unique identifier from the control platform, the first proxy platform 120 also responds to the key transmission request from the first device within its corresponding scope by sending the target quantum key and its corresponding unique identifier to the first device. This enables the first device to send its unique identifier to the second device within the corresponding scope of the second proxy platform 130. The second device is a peer communication partner of the first device and is the target object for the first device to conduct secure data transmission.

[0163] Step S602: Send a third key request including a unique identifier to the control platform and receive the returned target quantum key.

[0164] For example, the second agent platform 130 sends a third key request including a unique identifier to the control platform 110 and receives the target quantum key corresponding to the returned unique identifier.

[0165] Step S603: In response to receiving the fourth key request from the second device within the corresponding domain of the second proxy platform, a target quantum key is sent to the second device. The target quantum key is used for communication between the first and second devices. It serves as a unique identifier, and the transmission channel for the third and fourth key requests is a post-quantum-secure virtual private network tunnel.

[0166] For example, the fourth key request of the second device includes a unique identifier corresponding to the target quantum key.

[0167] In response to receiving the fourth key request from the second device, the second agent platform 130 sends the target quantum key to the second device.

[0168] At this point, the first and second devices can communicate securely using the target quantum key.

[0169] For example, Figure 7 A flowchart illustrating a full-link quantum-secure quantum key management and distribution method provided in an embodiment of this application is shown. Figure 7 As shown, the method mainly includes the following steps:

[0170] Step S701: Agent platform registration and authentication.

[0171] For example, Figure 1 The first agent platform 120 and the second agent platform 130 shown in the diagram register and authenticate with the control platform 110. Only the successfully authenticated agent platform can request a key.

[0172] Step S702: The agent platform requests the key.

[0173] For example, the first agent platform 120 requests the quantum key from the control platform 110. The control platform 110 generates the quantum key and the corresponding unique identifier, and returns them to the first agent platform 120.

[0174] Step S703: Exchange of unique identifiers between agent platforms.

[0175] For example, the first agent platform 120 notifies the second agent platform 130 of the unique identifier of the target quantum key.

[0176] In step S704, the first agent platform 120 requests the quantum key corresponding to the unique identifier.

[0177] For example, the first agent platform 120 uses the received unique identifier to obtain the target quantum key from the control platform 110.

[0178] Step S705: The first agent platform 120 requests a quantum key from the first device within its corresponding domain.

[0179] For example, the first device requests a quantum key from the first proxy platform 120. The first proxy platform 120 returns the target quantum key and its corresponding unique identifier.

[0180] In step S706, the first device sends a unique identifier to the second device within the corresponding scope of the second agent platform 130.

[0181] For example, the first device sends a unique identifier to the second device.

[0182] In step S707, the second device requests the target quantum key corresponding to the unique identifier from the second agent platform 130.

[0183] For example, the second device requests the target quantum key corresponding to the unique identifier from the second agent platform 130, and receives the returned target quantum key. Figure 1 Step 7 in the process.

[0184] Step S708: The first device and the second device establish a quantum-secure communication link.

[0185] For example, the first device and the second device establish quantum-secure communication using the same quantum key obtained.

[0186] Based on the methods in the above embodiments, this application provides a computer-readable storage medium storing a computer program. When the computer program is run on a processor, it causes the processor to execute the methods described in the above embodiments. Figure 3 , Figure 5 , Figure 6 or Figure 7 The method shown.

[0187] The foregoing has described specific embodiments of this specification. Other embodiments are within the scope of the appended claims. In some cases, the actions or steps recited in the claims may be performed in a different order than that shown in the embodiments and may still achieve the desired result. Furthermore, the processes depicted in the drawings do not necessarily require the specific or sequential order shown to achieve the desired result. In some embodiments, multitasking and parallel processing are possible or may be advantageous.

[0188] Those skilled in the art will further recognize that the units and algorithm steps of the various examples described in conjunction with the embodiments disclosed herein can be implemented in electronic hardware, computer software, or a combination of both. To clearly illustrate the interchangeability of hardware and software, the components and steps of the various examples have been generally described in terms of functionality in the foregoing description. Whether these functions are implemented in hardware or software depends on the specific application and design constraints of the technical solution. Those skilled in the art can use different methods to implement the described functions for each specific application, but such implementation should not be considered beyond the scope of this application.

[0189] The steps of the methods or algorithms described in conjunction with the embodiments disclosed herein can be implemented in hardware, a software module executed by a processor, or a combination of both. The software module can be located in random access memory (RAM), main memory, read-only memory (ROM), electrically programmable ROM, electrically erasable programmable ROM, registers, hard disk, removable disk, CD-ROM, or any other form of storage medium known in the art.

[0190] The specific embodiments described above further illustrate the purpose, technical solution, and beneficial effects of this application. It should be understood that the above description is only a specific embodiment of this application and is not intended to limit the scope of protection of this application. Any modifications, equivalent substitutions, improvements, etc., made within the spirit and principles of this application should be included within the scope of protection of this application.

Claims

1. A quantum-secure quantum key management and distribution method for the entire chain, the method comprising: The first agent platform sends a first key request to the control platform and receives the returned target quantum key and corresponding unique identifier. The target quantum key and its corresponding unique identifier are generated by the control platform using a post-quantum key algorithm. The first proxy platform sends the unique identifier to the second proxy platform, and the second proxy platform obtains the target quantum key from the control platform based on the unique identifier; the first proxy platform and the second proxy platform are located in the first and second scopes, respectively; The first agent platform receives the second key request from the first device within the first scope and sends the target quantum key and the unique identifier to the first device; This enables the first device to send the unique identifier to the second device within the second scope; In response to a request containing the unique identifier sent by the second device, the second proxy platform sends the target quantum key to the second device, enabling the first device and the second device to communicate using the target quantum key; The transmission channel for the unique identifier and the first and second key requests is a post-quantum secure virtual private network tunnel.

2. The method according to claim 1, wherein the first agent platform sends a first key request to the control platform and receives the returned target quantum key and corresponding unique identifier, including: The first agent platform sends a first key request including the target number to the control platform, and receives the returned target number of quantum keys and their corresponding unique identifiers; The first agent platform randomly selects from the target number of quantum keys and their corresponding unique identifiers to obtain the target quantum key and its corresponding unique identifier.

3. The method according to claim 2, wherein the first agent platform sends a first key request including a target number to the control platform, and receives the returned target number of quantum keys and their corresponding unique identifiers, including: The current key cache count of the first agent platform is periodically compared with a preset threshold at preset intervals. When the current key cache count is less than a preset threshold, the target count is obtained based on the current key cache count, the historical key usage count of the first agent platform, the maximum key cache count, and the current network state factor of the first scope. Send a first key request, including the target number, to the control platform; The system receives the target number of quantum keys and their corresponding unique identifiers, and stores them in the cache of the first agent platform. Check the current network status of the first agent platform; The preset threshold is adjusted positively based on the current network status.

4. The method according to claim 3, wherein, The worse the current network state of the first scope, the larger the current network state factor and the larger the number of targets.

5. The method according to claim 3, wherein the formula for calculating the target quantity includes: Where R is the target quantity, U is the number of historical keys used, and C max C represents the maximum number of key caches. current N represents the current key cache size. status Let α, β, and γ be the current network state factors, and let α, β, and γ be the weight coefficients. The relationship between the weight coefficients is: α + β + γ = 1.

6. The method according to claim 3, wherein after sending the target quantum key and the unique identifier to the first device, the method further comprises: Delete the target quantum key and its corresponding unique identifier from the cache.

7. The method according to claim 1, further comprising, before sending the first key request to the management platform: The first agent platform sends a registration and authentication request to the control platform and receives a registration and authentication feedback message in return; If the registration and authentication feedback message results in a failure message, the registration and authentication request is updated and then resent to the management platform until the registration and authentication feedback message results in a success message.

8. The method according to claim 1, further comprising: In the operating system kernel of the first agent platform, a kernel task module is written to collect the unique identifier and the corresponding data of the first and second key requests; In the operating system kernel, access permissions are set for the hardware and software that receive and send the corresponding data. Grant the kernel task module the access permission so that the kernel task module can collect the corresponding data by accessing the hardware and software, and generate audit logs based on the corresponding data.

9. A quantum-secure quantum key management and distribution method for the entire chain, applied to a first proxy platform, wherein the first proxy platform is the initiator of the quantum key management and distribution process, the method comprising: Send the first key request to the control platform and receive the returned target quantum key and corresponding unique identifier; The target quantum key and its corresponding unique identifier are generated by the control platform using a post-quantum key algorithm. The unique identifier is sent to the second proxy platform, so that the second proxy platform can obtain the target quantum key from the control platform based on the unique identifier; the first proxy platform and the second proxy platform are located in the first and second scopes, respectively; In response to receiving a second key request from a first device within the scope corresponding to the first agent platform, the target quantum key is sent to the first device; The target quantum key is used for communication between the second device within the corresponding scope of the first device and the second proxy platform; The transmission channel for the unique identifier and the first and second key requests is a post-quantum secure virtual private network tunnel.

10. A quantum-secure quantum key management and distribution method for the entire chain, applied to a second proxy platform, the second proxy platform being the responder in the target quantum key management and distribution process, the method comprising: Receive the unique identifier sent by the first agent platform; The first proxy platform is used to obtain the target quantum key and the corresponding unique identifier from the control platform, and then send the target quantum key to the first device within the corresponding scope of the first proxy platform; the target quantum key and the corresponding unique identifier are generated by the control platform using a post-quantum key algorithm; the first proxy platform and the second proxy platform are located in different scopes; Send a third key request, including the unique identifier, to the control platform, and receive the returned target quantum key; In response to receiving a fourth key request from a second device within the scope corresponding to the second agent platform, the target quantum key is sent to the second device; The target quantum key is used for communication between the first device and the second device; The unique identifier, the third key, and the fourth key request transmission channel are a post-quantum secure virtual private network tunnel.

Citation Information

Patent Citations

  • Quantum key management method based on security chip and cloud collaboration

    CN115913528A

  • Key distribution method, device and system applied to quantum key management scene

    CN118487749A