Method and related apparatus for off-the-grid encrypted communication
By using quantum session key sets to encrypt communication data in a satellite-free network environment, the problem of information leakage between different communication clusters is solved, secure information exchange between communication devices in the same group is realized, and communication security and the ability to resist quantum computer attacks are enhanced.
Patent Information
- Application Number
- CN202411740097.X
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2024-11-29
- Publication Date
- 2026-02-17
- Estimated Expiration
- 2044-11-29
AI Technical Summary
In environments without satellite networks, the data transmission security of existing communication equipment is difficult to guarantee, especially in preventing information leakage between users in different communication clusters.
By using different quantum session keys to encrypt communication data between different communication clusters, the security of information exchange between communication devices in the same group is ensured. Quantum session key sets are used for encryption, and encrypted information is transmitted via radio transmission, decentralized communication, or digital walkie-talkie.
It achieves secure information exchange between communication devices in the same group in a satellite-free environment, prevents information leakage between different communication clusters, enhances the security of the communication process, and resists quantum computer attacks.
Smart Images

Figure CN119766424B_ABST
Abstract
Description
TECHNICAL FIELD
[0001] The application belongs to the technical field of quantum encryption communication, and particularly relates to a method for network-free encryption communication and a related device. BACKGROUND
[0002] With the development of user science and technology, a user may use a network-free communication device to interact in some activities. For example, the user may use a communication device such as a walkie-talkie to communicate in a mountain climbing process, because the satellite signal may not be stable in some mountain areas, and thus the user may need to use a communication device without a mobile network.
[0003] In this process, the communication device directly transmits data, and another communication device can receive information interaction when the communication device and the transmission information are on the same frequency channel. However, because it is not determined whether other communication devices are on the frequency channel, the risk of data leakage is relatively large in the data transmission scenario.
[0004] Therefore, how to strengthen the communication security between communication devices in the case of no satellite network has important significance. SUMMARY
[0005] The application aims to provide a method for network-free encryption communication and a related device, which uses different quantum session keys for communication data encryption between communication devices in different communication clusters, so that the communication devices in different communication clusters cannot interact, thereby ensuring the security of the communication devices in the same communication cluster in the information interaction process.
[0006] In a first aspect, one embodiment of the application provides a method for network-free encryption communication, applied to a key distribution terminal, wherein the key distribution terminal includes a quantum session key set, and the method includes: determining a first number of quantum session key subsets from the quantum session key set according to a first number of communication clusters; wherein the quantum session keys in different quantum session key subsets are different;
[0007] Each quantum session key subset is loaded into a communication device in each communication cluster in a manner that one quantum session key subset corresponds to one communication cluster, wherein the communication device is used to encrypt communication data based on the quantum session key to obtain ciphertext information, and the ciphertext information is transmitted out by using a predefined transmission mode; wherein the predefined transmission mode includes any one of the following:
[0008] A radio transmission mode, a decentralized communication mode, and a digital walkie-talkie communication mode.
[0009] Optionally, the quantum session key set in the key distribution terminal is stored in cipher text form; and the determination of the first number of quantum session key subsets from the quantum session key set comprises: dividing the first cipher text according to the memory occupied by the first cipher text, to obtain the first number of cipher text fragments, wherein one cipher text fragment corresponds to one quantum session key subset; and correspondingly, the loading of each quantum session key subset into the communication device in each communication cluster comprises: loading each cipher text fragment into the communication device in each communication cluster.
[0010] Optionally, the first cipher text corresponding to the quantum session key set is obtained by the following method:
[0011] generating a symmetric key and the quantum session key set by using a quantum random number generation unit;
[0012] encrypting the quantum session key set by using the symmetric key to obtain the first cipher text.
[0013] Optionally, the method further comprises: in response to detecting the establishment of a connection with a management user terminal, determining whether the identity information sent by the management user terminal has quantum session key distribution authority; in the case where the identity information sent by the management user terminal has quantum session key distribution authority, obtaining the public key in a first public-private key pair generated by the management user terminal; sending the public key in the first public-private key pair to the quantum random number generation unit, so that the quantum random number generation unit generates a symmetric key and the quantum session key set, wherein the public key in the first public-private key pair is used to encrypt the symmetric key to obtain second cipher text.
[0014] Optionally, the method further comprises: returning the second cipher text to the management user terminal;
[0015] wherein the management user terminal is configured to decrypt the second cipher text by using the private key in the first public-private key pair to obtain the symmetric key.
[0016] Optionally, the communication cluster comprises a first communication device, the first communication device corresponds to a first quantum session key subset, and the first quantum session key subset is loaded into the first communication device by the following method:
[0017] obtaining the public key in a second public-private key pair pre-stored by the first communication device;
[0018] forwarding the public key in the second public-private key pair to the management user terminal, wherein the management user terminal is configured to encrypt the symmetric key by using the public key in the second public-private key pair to obtain third cipher text, and return the third cipher text to the key distribution terminal;
[0019] In response to receiving the third ciphertext, the ciphertext segment corresponding to the first subset of quantum session keys and the third ciphertext are sent to the first communication device, wherein the first communication device is configured to decrypt the third ciphertext based on the private key in the second public-private key pair to obtain the symmetric key, and decrypt the ciphertext segment corresponding to the first subset of quantum session keys using the symmetric key to obtain the first subset of quantum session keys.
[0020] Optionally, one communication device corresponds to one secure digital storage card, and the secure digital storage card is configured to store the subset of quantum session keys loaded by the key distribution terminal.
[0021] In a second aspect, another embodiment of the present application provides a device for off-network encrypted communication, applied to a key distribution terminal, wherein the key distribution terminal comprises a set of quantum session keys, and the device comprises:
[0022] A determination unit is configured to determine a first number of subsets of quantum session keys from the set of quantum session keys according to the first number of communication clusters, wherein the quantum session keys in different subsets of quantum session keys are different.
[0023] A distribution unit is configured to load each subset of quantum session keys into a communication device in each communication cluster in a manner that one subset of quantum session keys corresponds to one communication cluster, wherein the communication device is configured to encrypt communication data based on the quantum session key to obtain ciphertext information, and transmit the ciphertext information out of the communication cluster using a predefined transmission mode.
[0024] The predefined transmission mode comprises any one of the following:
[0025] Wireless transmission mode, decentralized communication mode, and digital walkie-talkie communication mode.
[0026] In a third aspect, another embodiment of the present application provides a storage medium, wherein the storage medium stores a computer program, and the computer program is configured to execute the off-network encrypted communication method when running.
[0027] In a fourth aspect, another embodiment of the present application provides an electronic device comprising a memory and a processor, wherein the memory stores a computer program, and the processor is configured to execute the off-network encrypted communication method by running the computer program.
[0028] Compared with the prior art, the method and the related device for network-free encryption communication provided by the application can determine a first number of quantum session key subsets from a quantum session key set according to a first number of communication clusters, the quantum session keys in different quantum session key subsets are different, and each quantum session key subset can be loaded into a communication device in each communication cluster in a manner that one quantum session key subset corresponds to one communication cluster, and the communication device can encrypt communication data by using a quantum session key when the communication data needs to be sent, and the quantum session keys stored in the communication devices in different communication clusters are different, so that the interaction of the communication devices in the same group of communication clusters can be more secure. BRIEF DESCRIPTION OF DRAWINGS
[0029] Figure 1 A flowchart of a method for network-free encryption communication provided by an embodiment of the application is shown.
[0030] Figure 2 An interaction diagram in a quantum session key charging process provided by an embodiment of the application is shown.
[0031] Figure 3 A diagram for issuing a ciphertext segment to a communication device provided by an embodiment of the application is shown.
[0032] Figure 4 A connection diagram of a device for network-free encryption communication provided by an embodiment of the application is shown.
[0033] Figure 5 A structural diagram of a computer device provided by an embodiment of the application is shown. DETAILED DESCRIPTION
[0034] The technical solutions in the embodiments of the application will be clearly and completely described below with reference to the drawings in the embodiments of the application. Obviously, the described embodiments are only part of the embodiments of the application, but not all the embodiments of the application. Based on the embodiments in the application, all other embodiments obtained by a person of ordinary skill in the art without creative work fall within the protection scope of the application.
[0035] From the description of the background art, it can be known that in network-free cluster communication, there may be a risk of data leakage.
[0036] For ease of understanding, a walkie-talkie is taken as an example of a communication device. The walkie-talkie usually has multiple channels preset. In the related art, a user who needs to communicate can be informed in advance of a specific channel to be used for this communication, so that when multiple walkie-talkies are in the same channel, the user can communicate by using the walkie-talkie.
[0037] However, in some scenarios, only specific users can receive the communication data, and other users do not need to receive the communication data. For example, in a field training activity, the trainees can be grouped, and the users in the same group can communicate with each other, and the users in different groups do not want to communicate with each other. In this case, the related art solution is difficult to implement. The reason is that when the users in different groups are close to each other, and the users in different groups adjust the intercom to the same channel, the transmitted data can also be received.
[0038] For example, groups A and B are in a field training competition, and it is specified that the members of group A use the intercom to communicate on channel A, and the members of group B use the intercom to communicate on channel B. If a member of group A uses the intercom on channel B, the communication data between the members of group B can also be received.
[0039] That is, the communication mode in the related art cannot guarantee the communication security between groups.
[0040] In the embodiments of the present disclosure, the communication devices between different communication groups use different quantum session keys to encrypt communication data, so that the communication devices between different communication groups cannot interact, thereby guaranteeing the security of the communication devices in the same communication group during information interaction.
[0041] Referring to Figure 1 , Figure 1 A flowchart of a method for network-free encryption communication provided by the embodiments of the present disclosure is shown. The method for network-free encryption communication can be applied to a key distribution terminal, and the key distribution terminal can include a quantum session key set. The key distribution terminal can be understood as a server or a terminal device, and the like, which has processing capability.
[0042] As shown in the figure, the method for network-free encryption communication can include the following steps: Figure 1
[0043] Step 101, determining a first number of quantum session key subsets from the quantum session key set according to a first number of communication groups.
[0044] Here, the quantum session keys in different quantum session key subsets are different.
[0045] Step 102, loading each quantum session key subset into the communication devices in each communication group in a manner that one quantum session key subset corresponds to one communication group.
[0046] Here, the communication device is used to encrypt the communication data based on the quantum session key to obtain ciphertext information, and the ciphertext information is transmitted out using a predefined transmission method.
[0047] Here, the predefined transmission mode includes any one of the following:
[0048] Radio transmission mode, decentralized communication mode, digital walkie-talkie communication mode, etc.
[0049] As an example, the quantum session key can be understood as a session key generated based on quantum random numbers and quantum key distribution protocols, and the ciphertext obtained after data encryption using the quantum session key makes the ciphertext have the ability to resist quantum computer cracking, thereby helping to make the ciphertext obtained after data encryption using the quantum session key more secure.
[0050] As an example, a certain number of quantum session keys can be generated to form a quantum key session set, and pre-stored in the key distribution terminal, then the quantum session key set is divided according to the number of communication clusters, and a number of quantum session key subsets consistent with the number of communication clusters is obtained.
[0051] The number of quantum session keys in each quantum session key subset can be limited according to actual conditions, for example, a session key subset can only include one quantum session key, or can include multiple quantum session keys, and the number of session keys in each session key subset can be set according to actual conditions.
[0052] As an example, the quantum session keys in different quantum session key subsets are different, and according to the mode that one quantum session key subset corresponds to one communication cluster, the quantum session keys in the communication devices in different communication clusters are different, and the communication devices in the communication cluster can encrypt the communication data using the quantum session key to obtain ciphertext information when they need to send communication data. In this way, since the quantum session keys in the communication devices in different communication clusters are different, the communication devices in different communication clusters cannot interact with each other.
[0053] It should be understood that one communication cluster can include multiple communication devices. The mode of the present disclosure can allow communication devices in the same communication cluster to interact with each other, while communication devices in different communication clusters cannot interact with each other.
[0054] For example, the communication cluster A includes communication device A1, communication device A2,..., and communication device An, and the communication cluster B includes communication device B1, communication device B2,..., and communication device Bn. The communication device A1, the communication device A2,..., and the communication device An all use the quantum session key subset A, the communication device B1, the communication device B2,..., and the communication device Bn all use the quantum session key subset B, and the quantum session key subset A is different from the quantum session key subset B. In this way, after the quantum session key in the quantum session key subset A encrypts the data to obtain the ciphertext information A, the quantum session key in the quantum session key subset B cannot decrypt the ciphertext information A. Correspondingly, the quantum session key in the quantum session key subset A cannot decrypt the information encrypted by the quantum session key in the quantum session key subset B. In this way, the communication devices in different communication clusters cannot interact, thereby ensuring the security of the communication devices in the same communication cluster in the information interaction process.
[0055] As an example, one communication cluster can include multiple communication devices, and the quantum session key subsets loaded in the communication devices in one communication cluster are the same.
[0056] It can be seen that in the present disclosure, the first number of quantum session key subsets can be determined from the quantum session key set according to the first number of communication clusters, the quantum session keys in different quantum session key subsets are different, each quantum session key subset can be loaded into the communication devices in the corresponding communication cluster in a one-to-one manner, the communication data can be encrypted by the quantum session key when the communication device needs to send the communication data, and the interaction of the communication devices in the same communication cluster can be more secure because the quantum session keys stored in the communication devices in different communication clusters are different.
[0057] It should be understood that the first number of communication clusters is limited according to actual conditions. For example, in a military exercise, the personnel are divided into three groups, and the first number of communication clusters can be 3. In this way, the information interaction between different groups of personnel can be avoided.
[0058] In some embodiments, the quantum session key set in the key distribution terminal is stored in the form of ciphertext; and the step of determining the first number of quantum session key subsets from the quantum session key set can specifically include:
[0059] According to the memory occupied by the first ciphertext corresponding to the quantum session key set, the first ciphertext is divided to obtain a first number of ciphertext segments, wherein one ciphertext segment corresponds to one quantum session key subset;
[0060] Correspondingly, the "loading each quantum session key subset into the communication device in each communication cluster" in step 102 includes:
[0061] Loading each ciphertext fragment into the communication device in each communication cluster.
[0062] As an example, the quantum session key set is stored in the form of ciphertext, so that the security can be increased, and the first ciphertext can be divided into each ciphertext fragment directly according to the memory occupied by the first ciphertext, and each ciphertext fragment can be efficiently divided.
[0063] As an example, the way of the present disclosure enables the transmission of the quantum session key subset in the form of ciphertext between the key distribution terminal and the communication device, so that the leakage of the quantum session key subset can be avoided, and the security of the whole communication process is further improved.
[0064] In some embodiments, the first ciphertext corresponding to the quantum session key set can be obtained by the following way:
[0065] Generating a symmetric key and a quantum session key set by using a quantum random number generation unit;
[0066] Encrypting the quantum session key set by using the symmetric key to obtain the first ciphertext.
[0067] As an example, the quantum random number generation unit generates a symmetric key and a quantum session key set, so that the characters in the quantum session key set are completely random, so that different quantum session key subsets in the quantum session key set are all different.
[0068] As an example, encrypting the quantum session key set by using the symmetric key can accelerate the generation efficiency of the first ciphertext.
[0069] In some embodiments, the above method further includes:
[0070] In response to detecting the establishment of a connection with the management user terminal, determining whether the identity information sent by the management user terminal has quantum session key distribution authority;
[0071] In the case that the identity information sent by the management user terminal has quantum session key distribution authority, obtaining the public key in the first public-private key pair generated by the management user terminal;
[0072] Sending the public key in the first public-private key pair to the quantum random number generation unit, so that the quantum random number generation unit generates a symmetric key and a quantum session key set.
[0073] Here, the public key in the first public-private key pair is used to encrypt the symmetric key to obtain the second ciphertext.
[0074] As an example, the user management terminal can be understood as a terminal device used by a manager for assigning quantum session keys.
[0075] As an example, the manager terminal can provide a secure digital security certificate (identity information) for the key assignment terminal to perform online authentication, so as to determine whether the user currently operating the manager terminal is a predefined manager.
[0076] In particular, the manager terminal can be understood as a UKEY. At this time, the establishment of a connection with the manager user terminal can be understood as inserting the UKEY into the key assignment terminal, and the key assignment terminal can identify that the UKEY stores a digital certificate for online service authentication, ensuring the authenticity of the user identity.
[0077] As an example, the manager user terminal can pre-store a first public-private key pair, and can send a public key in the first public-private key pair to the key assignment terminal, so that the key assignment terminal can send the public key in the first public-private key pair to the quantum random number generation unit, so that the quantum random number generation unit generates a symmetric key and a quantum session key set.
[0078] As an example, the key assignment terminal can also use the public key in the first public-private key pair to encrypt the symmetric key to obtain a second ciphertext, so that the symmetric key used to encrypt the quantum session key set is also protected, and only the manager user terminal has the private key in the first public-private key pair to obtain the symmetric key.
[0079] That is, in this way, the manager user terminal realizes indirect control over the quantum session key set, and any communication device that needs to obtain a quantum session key needs to send information to the manager user terminal to obtain the symmetric key.
[0080] As can be seen, this way not only makes the manager user terminal have the indirect control authority of the quantum session key set, but also makes the entire quantum session key distribution process more secure.
[0081] In some embodiments, the above method further comprises:
[0082] The second ciphertext is transmitted back to the manager user terminal.
[0083] Here, the manager user terminal can be used to decrypt the second ciphertext using the private key in the first public-private key pair to obtain the symmetric key.
[0084] That is, in this way, the symmetric key for decrypting the quantum session key set is stored in the management user terminal, so that the first ciphertext corresponding to the quantum session key set and the symmetric key are stored in different terminal devices respectively, so that the leakage of the quantum session key can be avoided to a certain extent, thereby ensuring the security of the quantum session key when it is issued to the communication device.
[0085] In some embodiments, the communication cluster includes a first communication device, the first communication device corresponds to a first quantum session key subset, and the first quantum session key subset can be loaded into the first communication device in the following way:
[0086] Obtaining the public key in the pre-stored second public-private key of the first communication device;
[0087] Forwarding the public key in the second public-private key to the management user terminal;
[0088] In response to receiving the third ciphertext, sending the ciphertext segment corresponding to the first quantum session key subset and the third ciphertext to the first communication device.
[0089] The administrator user terminal is configured to encrypt the symmetric key using the public key in the second public-private key to obtain the third ciphertext, and return the third ciphertext to the key allocation terminal.
[0090] The first communication device is configured to decrypt the third ciphertext based on the private key in the second public-private key to obtain the symmetric key, and decrypt the ciphertext segment corresponding to the first quantum session key subset using the symmetric key to obtain the first quantum session key.
[0091] As an example, in this way, the management user terminal encrypts the symmetric key using the public key pre-stored by the first communication device, so that the third ciphertext can be obtained, and the key allocation terminal can send the third ciphertext and the ciphertext segment to the first communication device, so that the data sent by the key allocation terminal to the first communication device is all encrypted data, thereby improving the security of the session key issuing process.
[0092] In some embodiments, one communication device can correspond to one secure digital storage card, and the secure digital storage card can be used to store the quantum session key subset loaded by the key allocation terminal.
[0093] As an example, since the secure digital storage card can be inserted into the communication device, while the key distribution terminal can not be portable, therefore, storing the subset of quantum session keys through the secure digital storage card, so that the key distribution terminal only needs to distribute the quantum session keys to the secure storage card, and in actual use, only needs to insert the secure digital storage card into the corresponding communication device. This way can make the communication device can more convenient to obtain the quantum session key, and update the quantum session key (for example, by updating the secure digital storage card).
[0094] As an example, the secure digital storage card can include but is not limited to: memory card, SIM card, etc.
[0095] It should be particularly emphasized that the quantum computer is a kind of physical device that performs high-speed mathematical and logical operations, stores and processes quantum information according to the laws of quantum mechanics. When a device processes and calculates quantum information and runs quantum algorithms, it is a quantum computer. Quantum computers have the ability to process mathematical problems more efficiently than ordinary computers, for example, they can speed up the time to crack RSA keys from hundreds of years to hours, so they are a key technology under research.
[0096] That is, with the development of quantum technology, the protection means in the existing communication process may not be ideal, that is, the protection means in the traditional communication process is difficult to resist the attack of quantum computer, and in the present disclosure, the data interaction between the communication devices uses quantum session key, so that it can resist quantum computer attack to a certain extent, and enhance the security of the communication process.
[0097] In order to better understand the idea of the present disclosure, the following Figure 2 For example, as Figure 2 As can be seen from the interaction diagram, first, the PC computer (key distribution terminal) can be opened, the administrator UKEY (management user terminal) can be inserted for identification, the PC can open the charging software to identify the UKEY and initialize, after initialization, the login interface can be entered. Input the login PIN code of the UKEY, then the PC inputs the PING code to the UKEY, the UKEY verifies and returns the PC verification success.
[0098] The PC requests the UKEY to generate a first public-private key pair, the UKEY successfully generates the first public-private key pair, returns the public key in the first public-private key pair to the PC, and the PC reports the public key of the first public-private key pair to the random number generator after receiving the public key in the first public-private key pair. The quantum random number generator generates 16 bytes as a protection key (symmetric key). The symmetric key is used to encrypt the quantum random number (quantum session key set), obtain a first ciphertext, encrypt the protection key using the public key generated by the UKEY, and then return to the PC, and the PC saves the first ciphertext, while the UKEY saves a second ciphertext.
[0099] After the PC obtains the first ciphertext, the TF card is inserted on the PC, the PC starts to detect the device of the TF card, the PC identifies the device of the TF, and then the PC starts to send an instruction to the TF card to generate a second public-private key pair. The TF card generates a second public-private key pair and sends the public key in the second public-private key pair to the PC in plaintext.
[0100] After the PC receives the public key of the TF, the PC reports the public key of the TF to the UKEY, the UKEY receives the public key of the TF, the UKEY can decrypt the public key ciphertext encrypted by itself to obtain the symmetric key plaintext, then encrypt the symmetric key plaintext using the public key of the TF to obtain a third ciphertext, and return the third ciphertext to the PC. The PC writes the third ciphertext into the secure TF card and writes the random number ciphertext (ciphertext segment) into the TF card. When the quantum random number plaintext is needed, the symmetric key plaintext is obtained by decrypting the TF private key, and the quantum session key is obtained by decrypting the quantum random number ciphertext using the symmetric key plaintext.
[0101] It should be understood that the TF card can be inserted into the communication device, so that the communication device can use the quantum session key to encrypt the communication data.
[0102] For better understanding, the following can be continued in combination with Figure 3 The schematic diagram of the present disclosure for distributing the ciphertext segment to the communication device is illustrated in the example scenario, in which the communication device is a walkie-talkie, as shown in Figure 3
[0103] For example, there is a command center using a walkie-talkie to distribute tasks to three sub-teams, three different channels can be set to distinguish the three sub-teams, channel 0 represents the first sub-team, channel 1 represents the second sub-team, and channel 2 represents the third sub-team. The command center can tune to channel 0 to communicate with the first sub-team to distribute tasks. In order to prevent the second and third sub-teams from eavesdropping, the second and third sub-teams can use an encrypted manner.
[0104] The specific charging mode of the quantum session key for the three sub-teams is as follows:
[0105] In the PC terminal, 300KB keys are filled, and the 300KB keys are filled into the command center. The 300KB keys are managed, and the 300KB keys are divided into three 100KB keys for management, each 100KB representing a subunit and being allocated to three subunits. When using channel 0, the first 100KB key is used, when using channel 1, the key used starts from the 100KB to the 200KB, and when using channel 2, the key used starts from the 200KB to the 300KB.
[0106] In the PC terminal, the first subunit is filled with keys, the first 100KB key is filled, the second subunit is filled with keys, the 100KB key to the 200KB key is filled, and the third subunit is filled with keys, the 200KB to the 300KB key is filled.
[0107] In this way, the memory is directly divided, the efficient division of the quantum session key set can be realized, and the key filling for the secure TF card can be more efficiently realized.
[0108] Referring to Figure 4 , Figure 4 A structure diagram of a device for network-free encrypted communication is provided for an embodiment of the application, and the device 400 is applied to a key distribution terminal, wherein the key distribution terminal comprises a quantum session key set, and the device 400 comprises:
[0109] A determination unit 401 is configured to determine a first number of quantum session key subsets from the quantum session key set according to the first number of communication clusters, wherein the quantum session keys in different quantum session key subsets are different.
[0110] A distribution unit 402 is configured to load each quantum session key subset into a communication device in each communication cluster in a manner that one quantum session key subset corresponds to one communication cluster, wherein the communication device is configured to encrypt communication data based on the quantum session key to obtain ciphertext information, and transmit the ciphertext information out by using a predefined transmission mode.
[0111] The predefined transmission mode comprises any one of the following:
[0112] A wireless transmission mode, a decentralized communication mode, and a digital walkie-talkie communication mode.
[0113] In some embodiments, the quantum session key set in the key distribution terminal is stored in the form of ciphertext, and the determination unit 401 is specifically configured to divide the first ciphertext according to the memory occupied by the first ciphertext, to obtain a first number of ciphertext fragments, wherein one ciphertext fragment corresponds to one quantum session key subset.
[0114] Correspondingly, the distribution unit 402 is specifically further configured to load each ciphertext fragment into a communication device in each communication cluster.
[0115] In some embodiments, the apparatus 400 can be specifically configured to obtain the first ciphertext corresponding to the quantum session key set in the following manner:
[0116] generating the symmetric key and the quantum session key set by using the quantum random number generation unit;
[0117] encrypting the quantum session key set by using the symmetric key to obtain the first ciphertext.
[0118] In some embodiments, the apparatus 400 can be specifically further configured to: in response to detecting the establishment of a connection with a management user terminal, determining whether the identity information sent by the management user terminal has quantum session key distribution authority;
[0119] in a case where the identity information sent by the management user terminal has quantum session key distribution authority, obtaining the public key in a first public-private key pair generated by the management user terminal;
[0120] sending the public key in the first public-private key pair to the quantum random number generation unit, so that the quantum random number generation unit generates the symmetric key and the quantum session key set, wherein the public key in the first public-private key pair is used to encrypt the symmetric key to obtain a second ciphertext.
[0121] In some embodiments, the apparatus 400 can be specifically further configured to: return the second ciphertext to the management user terminal;
[0122] wherein the management user terminal is configured to decrypt the second ciphertext by using the private key in the first public-private key pair to obtain the symmetric key.
[0123] In some embodiments, the communication cluster includes a first communication device, the first communication device corresponds to a first quantum session key subset, and the apparatus 400 can be specifically further configured to load the first quantum session key subset into the first communication device in the following manner:
[0124] obtaining the public key in a second public-private key pre-stored by the first communication device;
[0125] forwarding the public key in the second public-private key to the management user terminal, wherein the management user terminal is configured to encrypt the symmetric key by using the public key in the second public-private key to obtain a third ciphertext, and return the third ciphertext to the key distribution terminal;
[0126] In response to receiving the third ciphertext, the first communication device is configured to send the ciphertext segment corresponding to the first subset of quantum session keys and the third ciphertext to the second communication device, wherein the second communication device is configured to decrypt the third ciphertext based on the private key in the second public-private key pair to obtain the symmetric key, and decrypt the ciphertext segment corresponding to the first subset of quantum session keys based on the symmetric key to obtain the first subset of quantum session keys.
[0127] In some embodiments, one communication device corresponds to one secure digital storage card, and the secure digital storage card is configured to store the subset of quantum session keys loaded by the key distribution terminal.
[0128] Figure 5 A structural diagram of a computer device is shown, which includes a memory and a processor. The memory stores a computer program, and the processor implements the function of the computer system of the generation method of the amplitude preparation circuit in any of the above embodiments when executing the computer program.
[0129] The embodiment of the present application further provides a computer readable storage medium, which stores a computer program. The computer program is executed by a computer to make the computer execute the function of the computer system of the method of the network-free encryption communication in any of the above embodiments.
[0130] The embodiment of the present application further provides a computer program product containing instructions, which are executed by a computer to make the computer execute the function of the computer system of the method of the network-free encryption communication in any of the above embodiments.
[0131] It can be understood that the specific examples in the present application are only to help those skilled in the art better understand the embodiments of the present application, and do not limit the scope of the present application.
[0132] It can be understood that in various embodiments of the present application, the size of the serial number of each process does not mean the order of execution, and the execution order of each process should be determined according to its function and inherent logic, and should not constitute any limitation on the implementation process of the embodiments of the present application.
[0133] It can be understood that the various embodiments described in the present application can be implemented alone or in combination, and the embodiments of the present application do not limit this.
[0134] Unless otherwise defined, all technical and scientific terms used herein have the same meaning as commonly understood by one of ordinary skill in the art to which this application belongs. The terminology used in the description herein is for describing particular embodiments only and is not intended to be limiting of the application. The use herein of the terms "and / or" includes a combination of one or more of the associated listed items. As used in this description and the appended claims, the singular forms "a," "an," and "the" are intended to include the plural forms as well, unless the context clearly indicates otherwise.
[0135] It can be understood that the processor in the embodiments of the present application can be an integrated circuit chip with a signal processing capability. In the implementation process, the steps of the above method embodiments can be completed by hardware integrated logic circuits in the processor or by instructions in the form of software. The processor mentioned above can be a general processor, a digital signal processor (DSP), an application specific integrated circuit (ASIC), a field programmable gate array (FPGA) or other programmable logic devices, discrete gates or transistor logic devices, discrete hardware components. The disclosed methods, steps and logic block diagrams in the embodiments of the present application can be implemented or executed. The general processor can be a microprocessor or the processor can also be any conventional processor. The steps of the method disclosed in combination with the embodiments of the present application can be directly embodied as a hardware code processor for execution, or a combination of hardware and software modules in the code processor for execution. The software module can be located in a random access memory, a flash memory, a read only memory, a programmable read only memory or an electrically erasable programmable memory, a register, and other mature storage media in the art. The storage medium is located in the memory, and the processor reads the information in the memory and combines the hardware to complete the steps of the above method.
[0136] It can be understood that the memory in the embodiments of the present application can be a volatile memory or a non-volatile memory, or can include both volatile and non-volatile memories. Among them, the non-volatile memory can be a read only memory (ROM), a programmable read only memory (PROM), an erasable programmable read only memory (EPROM), an electrically erasable programmable read only memory (EEPROM) or a flash memory. The volatile memory can be a random access memory (RAM). It should be noted that the memory of the system and method described herein is intended to include but not limited to these and any other suitable type of memory.
[0137] Those skilled in the art can clearly understand that the units and algorithm steps of each example described in combination with the embodiments disclosed herein can be realized by electronic hardware or a combination of computer software and electronic hardware. Whether the functions are performed in hardware or software depends on the specific application and design constraints of the technical solution. Those skilled in the art can use different methods to implement the described functions for each specific application, but such implementation should not be considered beyond the scope of the present application.
[0138] Those skilled in the art can clearly understand that, for the convenience and brevity of the description, the specific working processes of the above-described system, device and unit can refer to the corresponding processes in the foregoing method embodiments, which will not be repeated here.
[0139] In several embodiments provided in the present application, it should be understood that the disclosed system, device and method can be implemented in other ways. For example, the above-described device embodiments are merely schematic, for example, the division of units is only a logical function division, and actual implementation can have another division manner, for example, multiple units or components can be combined or integrated into another system, or some features can be ignored or not executed. In addition, the coupling or direct coupling or communication connection between the displayed or discussed units can be indirect coupling or communication connection through some interfaces, devices or units, which can be electrical, mechanical or other forms.
[0140] The units described as separate components can or can not be physically separated, and the components shown as units can or can not be physical units, that is, they can be located in one place, or can be distributed on multiple network units. Part or all of the units can be selected according to actual needs to achieve the purpose of the present embodiment scheme.
[0141] In addition, each functional unit in each embodiment of the present application can be integrated into a processing unit, or each unit can exist physically independently, or two or more units can be integrated into one unit.
[0142] If the functions are implemented in the form of software function units and sold or used as independent products, they can be stored in a computer readable storage medium. Based on this understanding, the technical solutions of the present application or the parts of the technical solutions that essentially contribute to the prior art can be embodied in the form of a software product. The computer software product is stored in a storage medium and includes a plurality of instructions for causing a computer device (which can be a personal computer, a server, or a network device, etc.) to execute all or part of the steps of the methods of the various embodiments of the present application. The aforementioned storage medium includes a U disk, a mobile hard disk, a read-only memory (ROM), a random access memory (RAM), a magnetic disk or an optical disk, and various media that can store program codes.
[0143] The above is only a specific implementation of the present application, but the protection scope of the present application is not limited thereto. Any person skilled in the art can easily think of changes or replacements within the technical scope disclosed in the present application, which should be covered within the protection scope of the present application. Therefore, the protection scope of the present application should be subject to the protection scope of the claims.
Claims
1. A method of netless encrypted communication, characterized in that, The application is applied to a key distribution terminal, wherein the key distribution terminal comprises a quantum session key set, the quantum session key set in the key distribution terminal is stored in the form of ciphertext; and the method comprises the following steps: According to the memory occupied by the first ciphertext corresponding to the quantum session key set, the first ciphertext is divided to obtain a first number of ciphertext fragments, wherein one ciphertext fragment corresponds to one quantum session key subset; wherein the quantum session keys in different quantum session key subsets are different; In a manner that one quantum session key subset corresponds to one communication cluster, each quantum session key subset is loaded into a communication device in each communication cluster, wherein the communication device is used to encrypt communication data based on the quantum session key to obtain ciphertext information, and the ciphertext information is transmitted out by using a predefined transmission mode; The predefined transmission mode comprises any one of the following: Wireless transmission mode, decentralized communication mode, digital intercom communication mode.
2. The method of claim 1, wherein, The step of loading each quantum session key subset into the communication device in each communication cluster comprises the following steps: Each ciphertext fragment is loaded into the communication device in each communication cluster.
3. The method of claim 1, wherein, The first ciphertext corresponding to the quantum session key set is obtained by the following method: A symmetric key and the quantum session key set are generated by using a quantum random number generation unit; The quantum session key set is encrypted by using the symmetric key to obtain the first ciphertext.
4. The method of claim 3, wherein, The method further comprises the following steps: In response to detecting the establishment of a connection with a management user terminal, it is determined whether the identity information sent by the management user terminal has quantum session key distribution authority; In the case where the identity information sent by the management user terminal has quantum session key distribution authority, the public key in the first public-private key pair generated by the management user terminal is obtained; The public key in the first public-private key pair is sent to the quantum random number generation unit, so that the quantum random number generation unit generates a symmetric key and the quantum session key set, wherein the public key in the first public-private key pair is used to encrypt the symmetric key to obtain second ciphertext.
5. The method of claim 4, wherein, The method further comprises the following steps: The second ciphertext is transmitted back to the management user terminal; The management user terminal is used to decrypt the second ciphertext by using the private key in the first public-private key pair to obtain the symmetric key.
6. The method of claim 5, wherein, The first communication device in the communication cluster corresponds to the first quantum session key subset, and the first quantum session key subset is loaded into the first communication device by the following method: The public key in the second public-private key pre-stored by the first communication device is obtained; The public key in the second public-private key is forwarded to the management user terminal, wherein the management user terminal is used to encrypt the symmetric key by using the public key in the second public-private key to obtain third ciphertext, and the third ciphertext is returned to the key distribution terminal; In response to receiving the third ciphertext, the first communication device is configured to send the ciphertext segment corresponding to the first subset of quantum session keys and the third ciphertext to the first communication device, and the first communication device is configured to decrypt the third ciphertext based on a private key in the second public-private key pair to obtain the symmetric key, and decrypt the ciphertext segment corresponding to the first subset of quantum session keys using the symmetric key to obtain the first subset of quantum session keys.
7. The method of claim 1, wherein, A communication device corresponds to a secure digital storage card, and the secure digital storage card is configured to store the subset of quantum session keys loaded by the key distribution terminal.
8. An apparatus for netless encrypted communication, the apparatus comprising: The application is applied to a key distribution terminal, wherein the key distribution terminal comprises a set of quantum session keys, the set of quantum session keys in the key distribution terminal is stored in the form of ciphertext, and the device comprises: a determination unit configured to divide the first ciphertext according to the memory occupied by the first ciphertext to obtain a first number of ciphertext segments, wherein one ciphertext segment corresponds to one subset of quantum session keys, and quantum session keys in different subsets of quantum session keys are different; a distribution unit configured to load each subset of quantum session keys into a communication device in each communication cluster in a manner that one subset of quantum session keys corresponds to one communication cluster, wherein the communication device is configured to encrypt communication data based on quantum session keys to obtain ciphertext information, and transmit the ciphertext information out of the communication device using a predefined transmission mode; The predefined transmission mode comprises any one of the following: a radio transmission mode, a decentralized communication mode, and a digital walkie-talkie communication mode.
9. A storage medium, characterized by The storage medium stores a computer program, and the computer program is configured to execute the method in any one of claims 1 to 7 when running.
10. An electronic device comprising a memory and a processor, characterized in that, The storage medium stores a computer program, and the processor is configured to execute the computer program to execute the method in any one of claims 1 to 7.
Citation Information
Patent Citations
Method and system for realizing cluster encryption of dual-mode interphone based on public network
CN113612608A