File segment encryption processing method based on quantum key distribution
By encrypting files in segments and using quantum key distribution, the problems of low encryption strength and low security in existing technologies are solved, and efficient data transmission and secure decryption are achieved.
Patent Information
- Application Number
- CN202411954659.0
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2024-12-27
- Publication Date
- 2025-10-10
- Estimated Expiration
- 2044-12-27
AI Technical Summary
In the prior art, the use of a fixed key for overall file encryption results in low encryption strength and low security, and determining decryption permissions based on file attributes is complex and inefficient.
A file segmentation encryption method based on quantum key distribution is used to segment the original data, encrypt each segment of data using a random key generated by a quantum relay network, and perform identity authentication and decryption through a quantum security chip and key management system.
It improves the strength and security of data encryption, simplifies the decryption process, ensures that only the receiving device can decrypt the data, and improves transmission efficiency.
Smart Images

Figure CN119766549B_ABST
Abstract
Description
Technical Field
[0001] The present application relates to the field of data encryption technology, and in particular to a file segment encryption processing method based on quantum key distribution. Background Art
[0002] In the context of the Internet, encryption of transmitted files can be used to ensure that personal information will not be intercepted by a third party during transmission. Therefore, how to encrypt transmitted files has become a technical problem that needs to be solved urgently.
[0003] In the prior art, a file to be transmitted is usually encrypted as a whole using a fixed key, and whether decryption permission is available is determined based on file attributes.
[0004] However, encrypting the entire transmitted file has low encryption strength and uses a fixed key for transmission over a classic network, which is insecure. Determining whether decryption permissions are granted based on file attributes is complex and inefficient. Summary of the Invention
[0005] The purpose of this application is to address the deficiencies in the above-mentioned prior art and provide a file segment encryption processing method based on quantum key distribution to solve the problems of low encryption strength, low security and low efficiency in the prior art.
[0006] To achieve the above objectives, the technical solutions adopted in this application are as follows:
[0007] In a first aspect, the present application provides a file segment encryption processing method based on quantum key distribution, which is applied to a sending end device of a file segment processing system; the method comprises:
[0008] Obtaining multiple charging keys and identifiers of each charging key from a receiving device through a quantum relay network, and obtaining multiple groups of random key information through the quantum relay network, each group of random key information including a random key and an identifier of the random key;
[0009] Segmenting the original data to obtain a plurality of data to be encrypted, and assigning a target filling key and a target random key to each data to be encrypted;
[0010] For any data to be encrypted among the plurality of data to be encrypted, encrypt the data to be encrypted according to a target random key corresponding to the data to be encrypted to obtain encrypted data corresponding to the data to be encrypted;
[0011] Encrypting the identifier and the position identifier of the target random key according to the target charging key corresponding to the data to be encrypted to obtain identifier encrypted data, wherein the position identifier is used to identify the position of the data to be encrypted in the original data;
[0012] add the identification encryption data and the identification of the target recharging key to the encrypted data to obtain target data corresponding to the to-be-encrypted data, and send the target data to a receiving end device.
[0013] Optionally, the adding the identification encryption data and the identification of the target recharging key to the encrypted data to obtain target data corresponding to the to-be-encrypted data comprises:
[0014] adding preset separation data at the tail of the encrypted data;
[0015] adding the identification encryption data at the tail of the separation data to obtain the target data.
[0016] Optionally, before the obtaining, from the receiving end device through the quantum relay network, a plurality of recharging keys and an identification of each recharging key, the method further comprises:
[0017] determining a recharging key recharged in a quantum security chip of the sending end device by a quantum key recharging module;
[0018] obtaining user login information;
[0019] performing, by the quantum security chip in the sending end device, an encryption calculation on the user login information based on the recharging key to obtain authentication information;
[0020] sending the authentication information to a quantum cryptography management service system, so that the quantum cryptography management service system determines identity comparison information based on pre-stored user information and pre-recharged recharging keys, matches the authentication information based on the identity comparison information, and thus determines an identity authentication result.
[0021] Optionally, the obtaining, from the receiving end device through the quantum relay network, a plurality of recharging keys and an identification of each recharging key comprises:
[0022] obtaining, by the quantum cryptography management service system, an identification of a quantum key distribution module of a receiving end from a cryptography management service platform of the quantum relay network, and receiving a plurality of recharging keys and an identification of each recharging key sent by the receiving end device.
[0023] Optionally, the obtaining, through the quantum relay network, a plurality of groups of random key information comprises:
[0024] The identifier of the quantum key distribution module at the sending end and the identifier of the quantum key distribution module at the receiving end are sent to a quantum key distribution network controller of the quantum relay network, so that the quantum key distribution network controller determines the multiple sets of random key information according to the identifier of the quantum key distribution module at the sending end, the identifier of the quantum key distribution module at the receiving end, and the key manager topology link in the quantum relay network.
[0025] In a second aspect, the present application provides a file segment encryption processing method based on quantum key distribution, which is applied to a receiving device of a file segment encryption system, and the method includes:
[0026] Sending multiple charging keys and identifiers of each charging key to a sending end device through a quantum relay network, and obtaining multiple sets of random key information through the quantum relay network;
[0027] Receive multiple target data from a sending end device, each target data including: encrypted data, identifier encrypted data, and an identifier of a target charging key, the identifier encrypted data including: an encryption result of an identifier of a target random key corresponding to the encrypted data, and an encryption result of a position identifier, the position identifier being used to identify a position of the to-be-encrypted data corresponding to the encrypted data in the original data;
[0028] Obtaining each target charging key according to an identifier of each target charging key;
[0029] Decrypting the encrypted data according to each target charging key and each identification encryption data to obtain the data to be encrypted corresponding to the encrypted data and the location identifier of the data to be encrypted;
[0030] The original data is obtained by splicing the data to be encrypted and the position identifier corresponding to each encrypted data.
[0031] Optionally, decrypting the encrypted data according to each target charging key and each identifier encrypted data to obtain the data to be encrypted corresponding to the encrypted data and the location identifier of the data to be encrypted includes:
[0032] Decrypting the identification encrypted data according to the target charging key to obtain the identification of the target random key and the position identification;
[0033] Obtaining the target random key according to the identifier of the target random key;
[0034] The encrypted data is decrypted according to the target random key to obtain the data to be encrypted.
[0035] Optionally, before the sending, to the sender device, of the plurality of top-up keys and the identification of each top-up key via the quantum relay network, the method further comprises:
[0036] determining, by a quantum key top-up module, a top-up key top-up in a quantum security chip of the receiver device;
[0037] obtaining user login information;
[0038] encrypting, by the quantum security chip in the receiver device, the user login information based on the top-up key, to obtain authentication information;
[0039] sending the authentication information to a quantum cryptography management service system, so that the quantum cryptography management service system determines identity comparison information based on pre-stored user information and pre-top-up top-up keys, matches the authentication information based on the identity comparison information, and determines an identity authentication result.
[0040] Optionally, the splicing of the original data based on the to-be-encrypted data corresponding to each of the encrypted data and the position identifier comprises:
[0041] determining a splicing order of each of the to-be-encrypted data based on the position data of each of the to-be-encrypted data;
[0042] merging each of the to-be-encrypted data in the splicing order to obtain the original data.
[0043] In a third aspect, the present application provides a file segmentation processing system, the system comprising a sender device, a receiver device, and a quantum relay network;
[0044] The sender device is configured to perform the steps of the file segmentation encryption processing method based on quantum key distribution as described in the first aspect, and the receiver device is configured to perform the steps of the file segmentation decryption processing method based on quantum key distribution as described in the second aspect.
[0045] In a fourth aspect, the present application provides an electronic device comprising a processor, a storage medium, and a bus. The storage medium stores machine-readable instructions executable by the processor. When the electronic device is running, the processor communicates with the storage medium via the bus. The processor executes the machine-readable instructions to perform the steps of the method of the first aspect or the steps of the method of the second aspect.
[0046] In a fourth aspect, the present application provides a computer-readable storage medium having a computer program stored thereon. When the computer program is executed by a processor, the computer program performs the steps of the method of the first aspect or the steps of the method of the second aspect.
[0047] The present application has the following beneficial effects: a transmitting device obtains multiple charging keys from a receiving device and then obtains multiple sets of random key information via a quantum relay network. Since multiple sets of random key information are generated in the quantum relay network, classical network transmission keys are not used, resulting in enhanced security. The original data is then segmented into multiple pieces of data to be encrypted. Each piece of data to be encrypted is encrypted using a target random key from the multiple random key information, and the identifier of each target random key is encrypted using each target charging key. Since this embodiment segments the entire original data and encrypts each piece of data to be encrypted using a different random key, the encryption strength is high and security is strong, preventing the entire data from being compromised due to key loss. The identifier of the encrypted target random key and the identifier of the target charging key are added to the encrypted data to obtain the target data, which is then sent to the receiving device. During this process, since the identifier of the random key is encrypted using the charging key of the receiving device, the receiving device, upon receiving the target data, decrypts the encrypted identifier of the random key using its own charging key, thereby obtaining the identifier of the random key corresponding to the encrypted data. The encrypted data is then decrypted using the identifier of the random key, achieving secure data transmission. It can be seen that if the encrypted data is not received by the receiving party, the random key identifier cannot be obtained, and thus the random key cannot be determined, and the encrypted data cannot be decrypted. Therefore, this embodiment simplifies the steps and process while ensuring data security, thereby improving transmission efficiency. BRIEF DESCRIPTION OF THE DRAWINGS
[0048] In order to more clearly illustrate the technical solutions of the embodiments of the present application, the following is a brief introduction to the drawings required for use in the embodiments. It should be understood that the following drawings only show certain embodiments of the present application and therefore should not be regarded as limiting the scope. For ordinary technicians in this field, other relevant drawings can be obtained based on these drawings without creative work.
[0049] Figure 1 This is a structural diagram of a file segmentation processing system provided in an embodiment of the present application;
[0050] Figure 2 This is a flowchart of a file segment encryption processing method based on quantum key distribution provided in an embodiment of the present application;
[0051] Figure 3 This is a flow chart of an identity authentication method provided in an embodiment of the present application;
[0052] Figure 4 This is a schematic diagram of the structure of a key manager relay link in a quantum relay network provided by an embodiment of the present application;
[0053] Figure 5This is a flowchart of a file segment decryption processing method based on quantum key distribution provided by an embodiment of the present application;
[0054] Figure 6 This is a schematic diagram of a process for determining data to be encrypted and a location identifier of the data to be encrypted, provided by an embodiment of the present application;
[0055] Figure 7 This is a flowchart of another identity authentication method provided in an embodiment of the present application;
[0056] Figure 8 This is a flowchart of a file segmentation processing method based on quantum key distribution provided in an embodiment of the present application;
[0057] Figure 9 This is a structural diagram of an electronic device provided in an embodiment of the present application. DETAILED DESCRIPTION
[0058] In order to make the purpose, technical solutions and advantages of the embodiments of the present application clearer, the technical solutions in the embodiments of the present application will be clearly and completely described below in conjunction with the drawings in the embodiments of the present application. It should be understood that the drawings in the present application only serve the purpose of illustration and description and are not used to limit the scope of protection of the present application. In addition, it should be understood that the schematic drawings are not drawn to scale. The flowcharts used in this application illustrate the operations implemented according to some embodiments of the present application. It should be understood that the operations of the flowcharts can be implemented out of sequence, and steps without logical context can be reversed or implemented simultaneously. In addition, those skilled in the art, under the guidance of the contents of this application, can add one or more other operations to the flowchart, or remove one or more operations from the flowchart.
[0059] In addition, the described embodiments are only a part of the embodiments of the present application, rather than all of the embodiments. The components of the embodiments of the present application generally described and shown in the drawings here can be arranged and designed in various configurations. Therefore, the following detailed description of the embodiments of the present application provided in the drawings is not intended to limit the scope of the claimed application, but merely represents selected embodiments of the present application. Based on the embodiments of the present application, all other embodiments obtained by those skilled in the art without making creative work are within the scope of protection of the present application.
[0060] It should be noted that the term "comprising" will be used in the embodiments of the present application to indicate the existence of the features declared thereafter, but does not exclude the addition of other features.
[0061] In existing technologies, the entire file to be transmitted is typically encrypted using a fixed key, and decryption permission is determined based on file attributes. However, encrypting the entire file for transmission results in low encryption strength, and using a fixed key for transmission over a traditional network is insecure. Determining decryption permission based on file attributes is complex and inefficient.
[0062] Based on this, this application proposes a file segmentation encryption method based on quantum key distribution. This method segments the original data sent by the sending device and encrypts it using different keys, thereby improving data security. Furthermore, the key used for each segment is a random key generated by the quantum relay network, which can further improve security compared to transmitting a fixed key through a classical network. After receiving the encrypted data, the receiving device decrypts the data using its own injection key, ensuring that only the receiving device can decrypt the encrypted data. The method is simple and the process is further streamlined.
[0063] Before introducing the file segment encryption processing method based on quantum key distribution and the file segment decryption processing method based on quantum key distribution, the structure of the file segment processing system used by the above methods is first explained.
[0064] Figure 1 This is a structural diagram of a file segmentation processing system provided by an embodiment of the present application. Figure 1 As shown, the file segmentation processing system includes a sending device, a quantum relay network and a receiving device.
[0065] The sending-end device includes a sending-end terminal, a quantum security chip at the sending end, a quantum key injection module at the sending end, a quantum cryptography management service system at the sending end, a key manager at the sending end, and a quantum key distribution module at the sending end. The sending-end terminal is connected to the quantum cryptography management service system at the sending end via a network, the quantum security chip in the sending-end device is connected to the quantum key injection module at the sending end, the quantum key injection module is connected to the quantum key management service system at the sending end, the quantum cryptography management service system at the sending end is connected to the key manager at the sending end, and the key manager at the sending end is connected to the quantum key distribution module at the sending end.
[0066] The receiving-end device includes a receiving-end terminal, a quantum security chip at the receiving-end, a quantum key injection module at the receiving-end, a quantum cryptography management service system at the receiving-end, a key manager at the receiving-end, and a quantum key distribution module at the receiving-end. The receiving-end terminal is connected to the quantum cryptography management service system at the receiving-end via a network, the quantum security chip in the receiving-end device is connected to the quantum key injection module at the receiving-end, the quantum key injection module is connected to the quantum key management service system at the receiving-end, the quantum cryptography management service system at the receiving-end is connected to the key manager at the receiving-end, and the key manager at the receiving-end is connected to the quantum key distribution module at the receiving-end.
[0067] The quantum relay network includes a cryptographic management service platform, a quantum key distribution network controller, multiple key managers, and multiple quantum key distribution modules. The cryptographic management service platform is connected to the quantum cryptographic management service system at the transmitter and the quantum cryptographic management service system at the receiver, respectively. The quantum key distribution network controller is connected to the key manager at the transmitter, the key manager at the receiver, and each key manager in the quantum relay network. Each key manager in the quantum relay network is connected to a quantum key distribution module. Each key manager in the quantum relay network is topologically connected, with two of the key managers being connected to the key manager at the transmitter and the key manager at the receiver, respectively. Each quantum key distribution module in the quantum relay network is topologically connected, with two of the quantum key distribution modules being connected to the quantum key distribution module at the transmitter and the quantum key distribution module at the receiver, respectively.
[0068] The quantum key distribution module is used to implement quantum key distribution for connected quantum key distribution modules. The quantum key distribution network controller is used to enable the quantum key distribution modules to negotiate and generate random keys based on the key manager topology in the quantum relay network, ensuring the secure, stable, efficient, and robust operation of the quantum key distribution module network. The key manager is used to receive and manage the random keys generated by the quantum key distribution module and relay them to key-requiring devices. The cryptographic management service platform is used to control routing and schedule resources for the quantum cryptography management service system. The quantum cryptography management service system is used to interact with device terminals and quantum security chips. The quantum key injection module is used to inject quantum keys from the quantum key distribution module into the quantum security chip. The quantum security chip is used to store the injected keys.
[0069] Based on the file segmentation processing system, refer to Figure 2 This paper introduces the file segment encryption processing method based on quantum key distribution. Figure 2 This is a flowchart of a file segment encryption processing method based on quantum key distribution provided in an embodiment of the present application.
[0070] S201. Acquire multiple charging keys and identifiers of each charging key from a receiving device through a quantum relay network, and acquire multiple groups of random key information through the quantum relay network, each group of random key information including a random key and an identifier of the random key.
[0071] Specifically, a key filling request message is sent to the receiving device via the quantum cryptography management service system at the sending end and the cryptography management service platform in the quantum relay network. This allows the cryptography management service platform to forward multiple filling keys received from the receiving device to the sending device via the quantum cryptography management service system at the sending end. The filling key is generated by the quantum key filling module by filling the quantum key into the quantum security chip. Each device has multiple filling keys. When the number of keys in the quantum security chip is less than a preset value, the quantum key distribution module generates a quantum key and sends it to the quantum cryptography management service system. The quantum cryptography management service system then sends the quantum key to the quantum key filling module, which then fills the received quantum key into the quantum security chip, completing the replenishment of the filling key.
[0072] It is worth noting that after the receiving device sends the charging key to the sending device, it sets the sent charging key as used to prevent other devices from using the same charging key and affecting information security.
[0073] Specifically, the random key information is randomly generated in real time by the quantum relay network. As an optional implementation, the sending end device can store multiple sets of random key information sent by the quantum relay network to be used for encrypting multiple data respectively.
[0074] It is worth mentioning that the quantum relay network can generate multiple random keys and send the random keys to the quantum cryptography management service system at the sending end and the quantum cryptography management service system at the receiving end respectively, so that the sending device and the receiving device can receive the same random key for encryption and decryption.
[0075] S202: Segment the original data to obtain a plurality of data to be encrypted, and assign a target filling key and a target random key to each data to be encrypted.
[0076] As an optional implementation, the sending end device may divide the original data according to the length of the original data and the preset number of segments, so that the amount of data to be encrypted is the same as the preset number of segments.
[0077] As another optional implementation, the sending end device may divide the original data according to a preset segment length so that the length of the data to be encrypted is the same as the preset segment length.
[0078] Optionally, after the sending device segments the original data, it randomly assigns a target injection key and a target random key to each data to be encrypted, wherein the target injection key is one of multiple injection keys obtained from the receiving device, and the target random key is one of multiple sets of random key information obtained from the quantum relay network.
[0079] S203 : For any data to be encrypted among the multiple data to be encrypted, encrypt the data to be encrypted according to the target random key corresponding to the data to be encrypted, and obtain encrypted data corresponding to the data to be encrypted.
[0080] Specifically, the sending end device encrypts each data to be encrypted using the corresponding target random key to obtain multiple encrypted data.
[0081] S204. Encrypt the identifier of the target random key and the position identifier according to the target charging key corresponding to the data to be encrypted to obtain identifier encrypted data, wherein the position identifier is used to identify the position of the data to be encrypted in the original data.
[0082] Specifically, the sending end device uses the target charging key corresponding to each data to be encrypted to encrypt the identifier of the target random key and the location identifier respectively, thereby obtaining a plurality of identifier encrypted data. The identifier encrypted data may be a string consisting of the encrypted identifier of the target random key and the encrypted location identifier.
[0083] Optionally, the position identifier is the relative position of each to-be-encrypted data in the original data.
[0084] S205: Add the identifier of the encrypted data and the target charging key to the encrypted data to obtain the target data corresponding to the data to be encrypted, and send the target data to the receiving end device.
[0085] Specifically, after obtaining multiple target data, the quantum cryptography management service system at the sending end sends the target data to the receiving end device via a key manager link. The key manager link is determined by the quantum key distribution network controller based on the identifiers of the quantum key distribution module at the sending end and the quantum key distribution module at the receiving end.
[0086] As an optional implementation, the sending device adds an identifier of the encrypted data and the target sufficient key to the encrypted data to obtain the target data corresponding to the data to be encrypted. The data to be encrypted are concatenated into the complete target data, and the complete target data is sent to the receiving device.
[0087] As another optional implementation, the sending device adds the identifier of the encrypted data and the target sufficient key to the encrypted data, obtains the target data corresponding to the data to be encrypted, and then directly sends the target data corresponding to each data to be encrypted to the receiving device.
[0088] In this embodiment, a transmitting device obtains multiple charging keys from a receiving device and then obtains multiple sets of random key information via a quantum relay network. Since these multiple sets of random key information are generated within the quantum relay network, rather than using classical network transmission keys, security is enhanced. The original data is then segmented into multiple pieces of data to be encrypted. Each piece of data to be encrypted is encrypted using the target random keys in the multiple random key information, and the identifier of each target random key is encrypted using each target charging key. Since this embodiment segments the entire original data and encrypts each piece of data to be encrypted using a different random key, encryption strength and security are enhanced, preventing the entire data from being compromised due to key loss. The identifiers of the encrypted target random keys and the target charging keys are then appended to the encrypted data to obtain the target data, which is then sent to the receiving device. During this process, since the random key identifier is encrypted using the receiving device's charging key, the receiving device decrypts the encrypted random key identifier using its own charging key upon receiving the target data, thereby obtaining the identifier of the random key corresponding to the encrypted data. The encrypted data is then decrypted using the random key identifier, achieving secure data transmission. It can be seen that if the encrypted data is not received by the receiving party, the random key identifier cannot be obtained, and thus the random key cannot be determined, and the encrypted data cannot be decrypted. Therefore, this embodiment simplifies the steps while ensuring data security.
[0089] As an optional implementation, in step S205, the process of adding the identifiers of the encrypted data and the target charging key to the encrypted data to obtain the target data corresponding to the data to be encrypted specifically includes the following steps:
[0090] Optionally, preset separator data is added to the end of the encrypted data.
[0091] Optionally, the preset separation data may be an encryption identifier for separating the encrypted data and identifying the encrypted data. Specifically, when the receiving device decrypts the target data, the sending device may determine the encrypted data and identify the encrypted data according to the preset separation data.
[0092] Optionally, the identification encrypted data is added to the end of the separated data to obtain the target data.
[0093] As an optional implementation, the sending end device may add preset separation data before the header of the encrypted data, and add the identification encryption data to the header of the separation data to obtain the target data.
[0094] In this embodiment, the target data is obtained by adding preset separation data to the end of the encrypted data and adding the identification encrypted data to the end of the separation data, thereby facilitating the distinction between the encrypted data and the identification encrypted data according to the separation data during data decryption.
[0095] As an optional implementation, Figure 3 As shown, before the above step S201, that is, before obtaining multiple injection keys and the identifiers of each injection key from the receiving device through the quantum relay network, the following method steps may also be included. Among them, Figure 3 This is a flowchart of an identity authentication method provided in an embodiment of the present application.
[0096] S301. Determine the injection key injected by the quantum key injection module into the quantum security chip of the sending end device.
[0097] Specifically, the quantum key injection module at the sending end injects the quantum key sent by the quantum key distribution module into the quantum security chip in the sending end device and the quantum cryptography management service system at the sending end at the same time, so that the injection key in the quantum security chip and the injection key in the quantum cryptography management service system are the same, so as to complete identity authentication.
[0098] S302: Obtain user login information.
[0099] It is worth noting that before obtaining the user login information, the sending terminal obtains the user information entered by the user when registering or activating the account, and sends the user information to the quantum cryptography management service system for storage. At the same time, the quantum cryptography management service system binds the user information and the quantum security chip.
[0100] For example, the user login information may be a user account name and a user login password, etc.
[0101] As an optional implementation, after obtaining the user login information, it is stored in the quantum security chip.
[0102] S303. The quantum security chip in the sending device encrypts the user login information based on the injected key to obtain authentication information.
[0103] Specifically, the quantum security chip in the sending device first encrypts the user login information based on the injection key, and then converts the encrypted information using the standard hash algorithm of the cryptographic hash function to obtain an encrypted hash value, which is used as the authentication information.
[0104] S304: Send the authentication information to the quantum cryptography management service system, so that the quantum cryptography management service system determines identity comparison information based on the pre-stored user information and the pre-charged key, matches the authentication information based on the identity comparison information, and thus determines the identity authentication result.
[0105] Specifically, the quantum cryptography management service system on the sending end first encrypts the pre-stored user information using the injection key. It then converts the encrypted information using a standard cryptographic hash function (a standard hash algorithm) to obtain identity comparison information. The received authentication information is then compared with the identity comparison information. If the comparison results are consistent, the identity authentication result is determined to be successful. If the comparison results are inconsistent, the identity authentication result is determined to be failed. It is worth noting that if the identity authentication result is failed, an authentication failure warning is output and execution of steps S201-S205 above is terminated.
[0106] In this embodiment, a charging key and user login information are received, and the user login information is encrypted and calculated based on the charging key to obtain authentication information. The authentication information is then sent to the quantum cryptography management service system. The quantum cryptography management service system then determines identity comparison information based on the user information and the pre-charged charging key, and matches the authentication information based on the identity comparison information to determine the identity authentication result. This embodiment ensures data security by authenticating the user to ensure that the data is sent to and received by the correct recipients.
[0107] Furthermore, the specific process of obtaining multiple charging keys and the identifiers of each charging key from the receiving device through the quantum relay network in the above step S201 is as follows.
[0108] Optionally, the quantum cryptography management service system obtains the identifier of the quantum key distribution module of the receiving end from the cryptography management service platform of the quantum relay network, and receives multiple injection keys and the identifier of each injection key sent by the receiving end device.
[0109] The cryptographic management service platform in the quantum relay network pre-stores the identifiers of the quantum key distribution modules in each device. Specifically, the sending device sends a node identification request message from the receiving device to the cryptographic management service platform through the sending device's quantum cryptography management service system. The cryptographic management service platform retrieves the identifier of the receiving device's quantum key distribution module from the database based on the node identification request message and sends the identifier to the sending device.
[0110] In this embodiment, the quantum cryptography management service system obtains the identifier of the quantum key distribution module at the receiving end, multiple charging keys, and the identifier of each charging key from the cryptography management service platform of the quantum relay network, so as to uniformly process the identifier of the quantum key distribution module, the charging keys, and the identifier of each charging key.
[0111] Furthermore, based on the above step of obtaining the identifier of the quantum key distribution module at the receiving end, the specific steps of obtaining multiple sets of random key information through the quantum relay network in the above step S201 are as follows:
[0112] Optionally, the identifier of the quantum key distribution module at the sending end and the identifier of the quantum key distribution module at the receiving end are sent to a quantum key distribution network controller of the quantum relay network, so that the quantum key distribution network controller determines multiple sets of random key information according to the identifier of the quantum key distribution module at the sending end, the identifier of the quantum key distribution module at the receiving end, and the key manager topology link in the quantum relay network.
[0113] Specifically, the transmitting device sends the identifier of its quantum key distribution module and the identifier of its receiving quantum key distribution module to the quantum key distribution network controller of the quantum relay network. The quantum key distribution network controller first determines the key manager relay link based on the identifier of the quantum key distribution module of the transmitting end and the identifier of the quantum key distribution module of the receiving end, and then negotiates and determines multiple sets of random key information based on the key manager relay link.
[0114] The key manager relay link is a link connected from the sending end to the receiving end determined based on the key manager topology link.
[0115] For example, Figure 4 This is a schematic diagram of the structure of a key manager relay link in a quantum relay network provided by an embodiment of the present application. Figure 4As shown, the quantum relay network includes five key managers and five corresponding quantum key distribution modules. Key manager 1 is connected to key manager 2, key manager 3, key manager 4, and key manager 5, respectively. Key manager 2 is connected to key manager 5, key manager 4 is connected to key manager 5, key manager 3 is connected to the key manager at the sender, and key manager 5 is connected to the key manager at the receiver. The key manager relay link can be key manager at the sender - key manager 3 - key manager 1 - key manager 4 - key manager 5 - key manager at the receiver. Random key information is determined based on the key manager relay link and the quantum key distribution module corresponding to the key manager in the link. In this embodiment, the sender device sends the identifier of the quantum key distribution module at the sender and the identifier of the quantum key distribution module at the receiver to the quantum key distribution network controller of the quantum relay network, so that the quantum key distribution network controller determines multiple random key information, thereby obtaining multiple random keys for encrypting the data to be encrypted. Because the random keys are determined based on the key manager topology link, they are highly secure and cannot be copied.
[0116] After introducing how the sending device performs the file segment encryption processing method based on quantum key distribution, refer to Figure 5 This paper introduces how the receiving device performs the file segment decryption processing method based on quantum key distribution. Figure 5 1 is a flowchart of a method for processing file segment decryption based on quantum key distribution provided by an embodiment of the present application. Optionally, the method for processing file segment decryption based on quantum key distribution can be applied to a receiving device.
[0117] S501. Send multiple charging keys and identifiers of each charging key to a sending end through a quantum relay network, and obtain multiple sets of random key information through the quantum relay network.
[0118] Specifically, the receiving device receives the key charging request information sent by the sending device through the password management service platform, and sends multiple charging keys and charging key identifiers to the password management service platform, so that the password management service platform sends multiple charging keys and the identifiers of each charging key to the sending device.
[0119] Optionally, after the sending terminal device obtains the identifier of the quantum key distribution module of the receiving terminal from the quantum security service platform, the quantum key distribution network controller determines a plurality of sets of random key information according to the identifier of the quantum key distribution module of the sending terminal, the identifier of the quantum key distribution module of the receiving terminal, and the key manager topology link in the quantum relay network. Then the quantum key distribution network controller sends the plurality of sets of random key information to the key manager of the sending terminal and the key manager of the receiving terminal respectively. After the key manager of the receiving terminal receives the plurality of sets of random key information, the key manager sends the random key information to the receiving terminal device through the quantum security service system.
[0120] S502, receiving a plurality of target data from the sending terminal device, each target data including: encrypted data, an identifier of the encrypted data, and an identifier of a target top-up key, the identifier of the encrypted data including: an encryption result of an identifier of a target random key corresponding to the encrypted data, and an encryption result of a position identifier, the position identifier being used to identify a position of the to-be-encrypted data corresponding to the encrypted data in the original data.
[0121] Optionally, the receiving terminal device receives the plurality of target data from the key manager of the receiving terminal.
[0122] S503, obtaining each target top-up key according to the identifier of each target top-up key.
[0123] Optionally, the receiving terminal terminal retrieves each target top-up key from the quantum security chip pre-stored according to the identifier of each target top-up key.
[0124] S504, decrypting the encrypted data according to each target top-up key and each identifier-encrypted data to obtain the to-be-encrypted data corresponding to the encrypted data and the position identifier of the to-be-encrypted data.
[0125] Specifically, the receiving terminal terminal decrypts the identifier-encrypted data according to the target top-up key to obtain the identifier of the target random key and the position identifier, and decrypts the encrypted data according to the identifier of the target random key to obtain the to-be-encrypted data corresponding to the encrypted data.
[0126] S505, splicing the original data according to the to-be-encrypted data corresponding to each encrypted data and the position identifier.
[0127] Optionally, the receiving terminal terminal splices the to-be-encrypted data according to the to-be-encrypted data corresponding to each encrypted data and the position identifier to obtain the original data.
[0128] Optionally, after the receiving terminal device obtains the original data, the receiving terminal device deletes the plurality of top-up keys marked with the used identifier.
[0129] In this embodiment, multiple charging keys and charging key identifiers are sent to the transmitter via a quantum relay network, and multiple sets of random key information are obtained via the quantum relay network. Since multiple sets of random key information are generated in the quantum relay network, classical network transmission keys are not used, resulting in higher security. Multiple target data are received, and each target charging key is obtained based on the identifier of each target charging key. If a non-receiving device receives the target data, it cannot obtain the target charging key based on the representation of the target charging key, thereby improving data security. The encrypted data is decrypted based on the target charging key and the encrypted data of each identifier to obtain the encrypted data corresponding to the encrypted data and the location identifier of the encrypted data. The encrypted data is then spliced together based on the location identifier to obtain the original data. In this embodiment, data security can be improved by segmenting the original data and encrypting it, and then decrypting and splicing it based on the encrypted data of each segment.
[0130] Further, refer to Figure 6 , the specific steps of decrypting the encrypted data according to each target charging key and each identifier encryption data in step S504 to obtain the encrypted data corresponding to the encrypted data and the location identifier of the encrypted data are introduced. Figure 6 This is a flow chart of determining data to be encrypted and a location identifier of the data to be encrypted, provided in an embodiment of the present application.
[0131] S601. Decrypt the identifier encrypted data according to the target charging key to obtain the identifier and position identifier of the target random key.
[0132] As an optional implementation, the encrypted target random key identifier and the encrypted location identifier may have different formats, so that they can be decrypted separately using the target charging key. The format difference may be that the encrypted target random key identifier is always numeric, while the encrypted location identifier is always alphabetic. The format difference may also be that the encrypted target random key identifier has a preset separator at the end.
[0133] S602: Obtain the target random key according to the identifier of the target random key.
[0134] Optionally, since the quantum cryptography management service system pre-stores multiple sets of random key information, the receiving terminal can determine the target random key through the identifier of the target random key and the pre-stored multiple sets of random key information.
[0135] S603: Decrypt the encrypted data according to the target random key to obtain the data to be encrypted.
[0136] Specifically, there may be preset separation data after the encrypted data, and the data before the preset separation data is decrypted according to the target random key to obtain the data to be encrypted.
[0137] In this embodiment, the encrypted data is parsed using the target charging key to obtain the target random key identifier and location identifier. The encrypted data is then decrypted using the target random key corresponding to the target random key identifier to obtain the encrypted data. In this process, encrypting the target random key identifier with the receiving end's charging key ensures that only the receiving end device can decrypt the target random key identifier and, thus, the original data. This improves data security and simplifies the encryption and decryption process.
[0138] As an optional implementation, Figure 7 As shown, before the above step S501, that is, before sending multiple injection keys and the identifiers of each injection key to the sending end device through the quantum relay network, the following method steps may also be included. Among them, Figure 7 This is a flowchart of another identity authentication method provided in an embodiment of the present application.
[0139] S701. Determine the injection key injected by the quantum key injection module into the quantum security chip of the receiving device.
[0140] Specifically, the quantum key injection module at the receiving end injects the quantum key sent by the quantum key distribution module into the quantum security chip in the receiving end device and the quantum cryptography management service system at the receiving end at the same time, so that the injection key in the quantum security chip and the injection key in the quantum cryptography management service system are the same, so as to complete identity authentication.
[0141] S702: Obtain user login information.
[0142] It is worth noting that before obtaining the user login information, the receiving terminal obtains the user information entered by the user when registering or activating the account, and stores the user information in the receiving quantum cryptography management service system. At the same time, the quantum cryptography management service system binds the user information and the quantum security chip.
[0143] For example, the user login information may be a user account name and a user login password, etc.
[0144] As an optional implementation, after obtaining the user login information, it is stored in the quantum security chip.
[0145] S703. The quantum security chip in the receiving device encrypts the user login information based on the injected key to obtain authentication information.
[0146] Specifically, the quantum security chip in the receiving device first encrypts the user login information based on the injection key, and then converts the encrypted information using the standard hash algorithm of the cryptographic hash function to obtain an encrypted hash value, which is used as the authentication information.
[0147] S704: Send the authentication information to the quantum cryptography management service system, so that the quantum cryptography management service system determines the identity comparison information based on the pre-stored user information and the pre-charged key, matches the authentication information based on the identity comparison information, and thus determines the identity authentication result.
[0148] Specifically, the receiving quantum cryptography management service system first encrypts the pre-stored user information using the injection key. It then converts the encrypted information using a standard cryptographic hash function (a standard hash algorithm) to obtain identity comparison information. The received authentication information is then compared with the identity comparison information. If the comparison results are consistent, the identity authentication result is determined to be successful. If the comparison results are inconsistent, the identity authentication result is determined to be a failure. It is worth noting that if the identity authentication result is a failure, an authentication failure warning is output and execution of steps S501-S505 above is terminated.
[0149] In this embodiment, a charging key and user login information are received, and the user login information is encrypted and calculated based on the charging key to obtain authentication information. The authentication information is then sent to the quantum cryptography management service system. The quantum cryptography management service system then determines identity comparison information based on the user information and the pre-charged charging key, and matches the authentication information based on the identity comparison information to determine the identity authentication result. This embodiment ensures data security by authenticating the user to ensure that the data is sent to and received by the correct recipients.
[0150] As an optional implementation, the specific process of obtaining the original data by splicing the encrypted data and the position identifier corresponding to each encrypted data in step S505 includes:
[0151] Optionally, determining the splicing order of each data to be encrypted according to the position data of each data to be encrypted;
[0152] Optionally, the data to be encrypted are merged in a splicing order to obtain the original data.
[0153] The concatenation order of the data to be encrypted may be the arrangement order of the data to be encrypted in the original data.
[0154] In this embodiment, the splicing order of each data to be encrypted is determined according to the position data of each data to be encrypted, and the data to be encrypted are merged according to the splicing order to obtain the original data, thereby obtaining the complete data sent by the sending end device to complete the data transmission.
[0155] As an optional implementation, Figure 8 This is a flowchart of a file segmentation processing method based on quantum key distribution provided by an embodiment of the present application. Figure 8 As shown, the file segmentation processing method is generally described below.
[0156] The sending device and the receiving device complete identity authentication in advance to ensure the integrity and confidentiality of the user's identity. After successful authentication, the sending device obtains the identifier of the receiving device's quantum key distribution module from the password management service platform in the quantum relay network through the sending device's quantum cryptography management service system, and sends a key injection request message to the receiving device through the password management service platform. The receiving device sends multiple injection keys and multiple injection key identifiers to the sending device through the password management service platform based on the injection key request message, and marks the multiple injection keys sent as used. Based on the identifier of the sending device's quantum key distribution module and the identifier of the receiving device's quantum key distribution module, the sending device obtains multiple random key information through the quantum key distribution network controller in the quantum relay network. The receiving device obtains the same multiple random key information through the receiving device's quantum cryptography management service system and the receiving device's key manager.
[0157] The sending device segments the original data to obtain multiple data to be encrypted. It assigns a target label key and a target random key to each data to be encrypted. For any of the multiple data to be encrypted, the sending device encrypts the data using the target random key corresponding to the data to be encrypted, obtaining encrypted data corresponding to the data to be encrypted. The sending device encrypts the identifier and location identifier of the target random key using the target charging key corresponding to the data to be encrypted, obtaining identifier-encrypted data. The identifiers of the identifier-encrypted data and the target charging key are added to the encrypted data to obtain target data corresponding to the data to be encrypted, and the target data is sent to the receiving device.
[0158] The receiving device receives multiple target data from the sending end, obtains each target charging key according to the identifier of each target charging key, decrypts the identified encrypted data according to each target charging key, obtains the identifiers and position identifiers of multiple random keys, determines multiple target random keys according to the identifiers of the multiple random keys, uses the target random keys to decrypt the encrypted data, obtains the data to be encrypted corresponding to the encrypted data, and splices the original data according to the data to be encrypted and the position identifier corresponding to the encrypted data.
[0159] The embodiment of the present application also provides a file segmentation processing system, the system including a sending end device, a receiving end device and a quantum relay network;
[0160] The sending end device is used to execute the steps of the file segment encryption processing method based on quantum key distribution, and the receiving end device is used to execute the steps of the file segment decryption processing method based on quantum key distribution.
[0161] The present application also provides an electronic device, such as Figure 9 , which is a schematic diagram of the structure of an electronic device provided in an embodiment of the present application, includes: a processor 901, a memory 902, and a bus. The memory 902 stores machine-readable instructions executable by the processor 901. When the computer device is running, the processor 901 and the memory 902 communicate via the bus. The machine-readable instructions are executed by the processor 901 to perform the steps of the file segment encryption processing method based on quantum key distribution. The receiving device is used to perform the steps of the file segment decryption processing method based on quantum key distribution.
[0162] An embodiment of the present application also provides a computer-readable storage medium, which stores a computer program. When the computer program is executed by a processor, it performs the steps of a file segment encryption processing method based on quantum key distribution, and the receiving device is used to perform the steps of a file segment decryption processing method based on quantum key distribution.
[0163] Those skilled in the art can clearly understand that, for the convenience and brevity of description, the specific working process of the system and device described above can refer to the corresponding process in the method embodiment, and will not be repeated in this application. In the several embodiments provided in this application, it should be understood that the disclosed system, device and method can be implemented in other ways. The device embodiments described above are merely schematic. For example, the division of the modules is only a logical function division. There may be other division methods in actual implementation. For example, multiple modules or components can be combined or integrated into another system, or some features can be ignored or not executed. Another point is that the mutual coupling or direct coupling or communication connection shown or discussed can be through some communication interfaces, indirect coupling or communication connection of devices or modules, which can be electrical, mechanical or other forms.
[0164] In addition, each function unit in each embodiment of the present application can be integrated in one processing unit, or each unit can exist physically separately, or two or more units can be integrated in one unit. When the functions are realized in the form of software function units and sold or used as an independent product, they can be stored in a computer readable storage medium. Based on this understanding, the technical solutions of the present application or the parts that essentially contribute to the prior art or the parts of the technical solutions can be embodied in the form of a software product. The computer software product is stored in a storage medium and includes a plurality of instructions for causing a computer device (which can be a personal computer, a server, or a network device, etc.) to execute all or part of the steps of the method described in each embodiment of the present application. The aforementioned storage medium includes: a U disk, a mobile hard disk, a read-only memory (ROM, Read-Only Memory), a random access memory (RAM, Random Access Memory), a magnetic disk or an optical disk, and various media that can store program codes.
[0165] The above is only a specific embodiment of the present application, but the protection scope of the present application is not limited thereto. Any person skilled in the art can easily think of changes or replacements within the technical scope disclosed in the present application, which should be covered within the protection scope of the present application.
Claims
1. A file segment encryption processing method based on quantum key distribution, characterized in that: A sending end device applied to a file segmentation processing system; the method comprises: Obtaining multiple charging keys and identifiers of each charging key from a receiving device through a quantum relay network, and obtaining multiple groups of random key information through the quantum relay network, each group of random key information including a random key and an identifier of the random key; Segmenting the original data to obtain a plurality of data to be encrypted, and assigning a target filling key and a target random key to each data to be encrypted; For any data to be encrypted among the plurality of data to be encrypted, encrypt the data to be encrypted according to a target random key corresponding to the data to be encrypted to obtain encrypted data corresponding to the data to be encrypted; Encrypting the identifier and the position identifier of the target random key according to the target charging key corresponding to the data to be encrypted to obtain identifier encrypted data, wherein the position identifier is used to identify the position of the data to be encrypted in the original data; The identification encryption data and the identification of the target charging key are added to the encrypted data to obtain target data corresponding to the data to be encrypted, and the target data is sent to a receiving device.
2. The file segment encryption processing method based on quantum key distribution according to claim 1 is characterized in that: The step of adding the identifier of the encrypted data and the identifier of the target charging key to the encrypted data to obtain target data corresponding to the data to be encrypted includes: Adding preset separation data at the end of the encrypted data; The identification encrypted data is added to the end of the separation data to obtain the target data.
3. The file segment encryption processing method based on quantum key distribution according to claim 1 is characterized in that: Before obtaining multiple charging keys and identifiers of each charging key from the receiving device through the quantum relay network, the method further includes: Determine the injection key injected by the quantum key injection module into the quantum security chip of the sending end device; Get user login information; The quantum security chip in the sending end device performs encryption calculation on the user login information based on the injection key to obtain authentication information; The authentication information is sent to a quantum cryptography management service system, so that the quantum cryptography management service system determines identity comparison information based on pre-stored user information and a pre-charged key, matches the authentication information based on the identity comparison information, and thereby determines an identity authentication result.
4. The file segment encryption processing method based on quantum key distribution according to claim 1 is characterized in that: The step of obtaining multiple charging keys and identifiers of each charging key from a receiving device through a quantum relay network includes: The quantum cryptography management service system obtains the identifier of the quantum key distribution module of the receiving end from the cryptography management service platform of the quantum relay network, and receives multiple injection keys and the identifier of each injection key sent by the receiving end device.
5. The file segment encryption processing method based on quantum key distribution according to claim 4 is characterized in that: The obtaining of multiple sets of random key information through the quantum relay network includes: The identifier of the quantum key distribution module at the sending end and the identifier of the quantum key distribution module at the receiving end are sent to a quantum key distribution network controller of the quantum relay network, so that the quantum key distribution network controller determines the multiple sets of random key information according to the identifier of the quantum key distribution module at the sending end, the identifier of the quantum key distribution module at the receiving end, and the key manager topology link in the quantum relay network.
6. A file segment decryption processing method based on quantum key distribution, characterized in that: A receiving device applied to a file segment encryption system, the method comprising: Sending multiple charging keys and identifiers of each charging key to a sending end device through a quantum relay network, and obtaining multiple sets of random key information through the quantum relay network; Receive multiple target data from a sending end device, each target data including: encrypted data, identifier encrypted data, and an identifier of a target charging key, the identifier encrypted data including: an encryption result of an identifier of a target random key corresponding to the encrypted data, and an encryption result of a position identifier, the position identifier being used to identify a position of the to-be-encrypted data corresponding to the encrypted data in the original data; Obtaining each target charging key according to an identifier of each target charging key; Decrypting the encrypted data according to each target charging key and each identification encryption data to obtain the data to be encrypted corresponding to the encrypted data and the location identifier of the data to be encrypted; The original data is obtained by splicing the data to be encrypted and the position identifier corresponding to each encrypted data.
7. The file segmentation decryption processing method based on quantum key distribution according to claim 6 is characterized in that: The decrypting of the encrypted data according to each of the target charging keys and each of the identification encrypted data to obtain the data to be encrypted corresponding to the encrypted data and the location identifier of the data to be encrypted includes: Decrypting the identification encrypted data according to the target charging key to obtain the identification of the target random key and the position identification; Obtaining the target random key according to the identifier of the target random key; The encrypted data is decrypted according to the target random key to obtain the data to be encrypted.
8. The file segmentation decryption processing method based on quantum key distribution according to claim 6 is characterized in that: Before sending the plurality of charging keys and identifiers of the charging keys to the transmitting end device through the quantum relay network, the method further includes: Determine the injection key injected by the quantum key injection module into the quantum security chip of the receiving device; Get user login information; The quantum security chip in the receiving device performs encryption calculation on the user login information based on the injection key to obtain authentication information; The authentication information is sent to a quantum cryptography management service system, so that the quantum cryptography management service system determines identity comparison information based on pre-stored user information and a pre-charged key, matches the authentication information based on the identity comparison information, and thereby determines an identity authentication result.
9. The file segment decryption processing method based on quantum key distribution according to claim 6 is characterized in that: The step of splicing the encrypted data and the position identifiers corresponding to the encrypted data to obtain the original data includes: Determining a splicing order of each of the data to be encrypted according to the position data of each of the data to be encrypted; The data to be encrypted are combined in the splicing order to obtain the original data.
10. A file segmentation processing system, characterized in that: The system includes a transmitting device, a receiving device and a quantum relay network; The sending end device is used to execute the steps of the file segment encryption processing method based on quantum key distribution as described in any one of claims 1 to 5, and the receiving end device is used to execute the steps of the file segment decryption processing method based on quantum key distribution as described in any one of claims 6 to 9.
11. An electronic device, characterized in that: include: A processor and a memory, wherein the memory stores machine-readable instructions executable by the processor, and when the electronic device is running, the processor executes the machine-readable instructions to perform the steps of the file segment encryption processing method based on quantum key distribution according to any one of claims 1 to 5, or perform the steps of the file segment decryption processing method based on quantum key distribution according to any one of claims 6 to 9.
12. A computer-readable storage medium, characterized in that The computer-readable storage medium stores a computer program, which, when executed by a processor, executes the steps of the file segment encryption processing method based on quantum key distribution as described in any one of claims 1 to 5, or executes the steps of the file segment decryption processing method based on quantum key distribution as described in any one of claims 6 to 9.
Citation Information
Patent Citations
Method and device for outputting quantum security key and authentication parameter, and root key center
CN116032473A
Quantum key charging method and device and electronic equipment
CN117081732A