A key distribution method, system, electronic device and storage medium

By introducing key distribution nodes into a quantum key distribution network and utilizing secure connections resistant to quantum cryptography algorithms, low-cost and secure key distribution is achieved in scenarios such as PCs and mobile devices, solving the problems of high cost of quantum key distribution and the ease with which resistant quantum cryptography algorithms can be cracked.

CN119788268BActive Publication Date: 2026-01-23ANHUI GUOKE QUANTUM NETWORK CO LTD
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202411832262.4
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2024-12-11
Publication Date
2026-01-23
Estimated Expiration
2044-12-11

AI Technical Summary

Technical Problem

Existing quantum key distribution schemes are too costly to deploy and apply, and quantum-resistant cryptographic algorithms are vulnerable to being cracked, making them unsuitable for low-cost application in scenarios such as PCs and mobile devices.

Method used

By combining quantum key distribution technology and quantum-resistant cryptographic algorithms, and using key distribution nodes as intermediaries, clients do not need fiber optic access. The secure connection using quantum-resistant cryptographic algorithms ensures that key components are distributed from different nodes, avoiding leakage through a single connection.

Benefits of technology

This reduces the deployment and application costs of the key distribution scheme while ensuring the security of key distribution and preventing key leakage.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN119788268B_ABST
    Figure CN119788268B_ABST
Patent Text Reader

Abstract

Embodiments of the present application relate to the field of quantum technology, and disclose a key distribution method and system, an electronic device and a storage medium. The key distribution method comprises: synchronizing with another key distribution node to obtain consistent key components from respective connected quantum key distribution nodes, and each quantum key distribution node is connected through a quantum key distribution network; and sending different key components in the consistent key components to a client through a secure connection based on an anti-quantum cryptography algorithm, respectively with the other key distribution node, so that the client and another client receiving the same key component negotiate to synthesize a symmetric key according to the obtained key component, and the same key component of the other client is from the key distribution node and the other key distribution node, and the key component from the key distribution node in the same key component is at least partially different. At least it is beneficial to reduce the deployment and application cost of the key distribution scheme while ensuring the security of the key distribution.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This application relates to the field of quantum technology, and in particular to a key distribution method, system, electronic device, and storage medium. Background Technology

[0002] Data confidentiality protection primarily relies on symmetric cryptography. In ensuring confidentiality during data transmission, symmetric key distribution between communicating parties is necessary. This is often achieved using key exchange protocols based on asymmetric cryptographic algorithms. For example, Figure 1 The example demonstrates a typical symmetric key exchange method, where Alice, as the initiator, first sends the encrypted public key to Bob, the responder. pub Bob received the key pub Then, using the key pub The locally generated protection key KEK (Key Encryption Key) is input to Alice, allowing Alice to encrypt the private key key. pri Decrypt the received key pub The encryption key protects the key, i.e., KEK ciphertext, and obtains KEK plaintext. This involves negotiating a symmetric key protection key KEK using an asymmetric algorithm between the communicating parties. Alice then uses the KEK plaintext to encrypt her locally generated key k and transmits it to Bob. Bob receives the KEK-encrypted key k, i.e., ciphertext K, and decrypts it using KEK to obtain the plaintext key k. This process of encrypting the final key k used for encrypting business data completes the synchronization of key k between the two parties. However, with the emergence and development of quantum technology, the above symmetric key negotiation process is easily cracked. To address the impact of quantum computing on existing cryptographic systems, two main approaches have been proposed: Quantum Key Distribution (QKD) and Post-Quantum Cryptography (PQC) algorithms. Quantum Key Distribution technology falls under the scope of quantum information theory, which relies on the established principles of quantum physics. If these principles are overturned, it means creating a new physics. Therefore, quantum key distribution is considered to possess a high level of security.

[0003] However, the deployment and application costs of quantum key distribution schemes are too high, which is not conducive to their application, while schemes resistant to quantum cryptography algorithms are at risk of being cracked. Summary of the Invention

[0004] This application provides a key distribution method, system, electronic device, and storage medium, which at least helps to reduce the deployment and application cost of the key distribution scheme while ensuring the security of key distribution.

[0005] According to some embodiments of this application, a first aspect of this application provides a key distribution method applied to a key distribution node. The method includes: synchronously obtaining a consistent key component from a quantum key distribution node connected to another key distribution node, wherein each of the quantum key distribution nodes is connected through a quantum key distribution network; and sending different key components from the consistent key component to a client through a secure connection based on a quantum cryptography algorithm, respectively, so that the client and another client receiving the same key component negotiate to synthesize a symmetric key based on the obtained key component, wherein the same key component of the other client comes from both the key distribution node and the other key distribution node, and the key components from the key distribution node in the same key component of the other client and the client are at least partially different.

[0006] According to some embodiments of this application, a second aspect of this application also provides a key distribution method applied to a client. The method includes: sending a key request to a key distribution node via a secure connection based on a quantum-resistant cryptographic algorithm; receiving key components sent by the key distribution node and another key distribution node via the secure connection based on a quantum-resistant cryptographic algorithm; and negotiating and synthesizing a symmetric key with another client that has received the same key components based on the received key components via the secure connection based on a quantum-resistant cryptographic algorithm, wherein the same key components of the other client come from the key distribution node and the other key distribution node, and the key components from the key distribution node in the same key components of the other client and the client are at least partially different.

[0007] According to some embodiments of this application, a third aspect of this application also provides a key distribution system, including: at least two key distribution centers, a plurality of clients, and a quantum key distribution network, wherein each key distribution center includes a key distribution node and a quantum key distribution node, the clients access at least two different key distribution centers through at least two different key distribution nodes, and each quantum key distribution node is connected to the quantum key distribution network; wherein the key distribution nodes and the clients are used to implement the key distribution method provided in the embodiments of this application.

[0008] According to some embodiments of this application, a fourth aspect of this application also provides an electronic device, including: at least one processor; and a memory communicatively connected to the at least one processor; wherein the memory stores instructions executable by the at least one processor, the instructions being executed by the at least one processor to enable the at least one processor to perform any of the key distribution methods provided in the embodiments of this application.

[0009] According to some embodiments of this application, a fifth aspect of this application also provides a computer-readable storage medium storing a computer program that, when executed by a processor, implements any of the key distribution methods provided in the embodiments of this application.

[0010] The technical solution provided in this application has at least the following advantages:

[0011] Building upon the distribution capabilities provided by quantum key distribution networks, key distribution nodes are introduced as intermediaries between quantum key distribution nodes and clients. This eliminates the need for clients to use fiber optic access, facilitating deployment and application. Furthermore, the key components synthesized on the same client originate from different key distribution nodes, and different key distribution nodes distribute different key components to different clients. This makes it impossible to obtain complete key information through a single connection. Simultaneously, a secure connection based on quantum-resistant cryptographic algorithms transmits key components between the client and key distribution nodes, ensuring the security of key component distribution. This achieves both reduced deployment and application costs of the key distribution scheme and guaranteed key distribution security. Attached Figure Description

[0012] One or more embodiments are illustrated by way of example with reference numerals in the accompanying drawings. These illustrations do not constitute a limitation on the embodiments. Elements with the same reference numerals in the drawings are denoted as similar elements. Unless otherwise stated, the figures in the drawings are not to be limited by scale.

[0013] Figure 1 This is a schematic diagram of the existing symmetric key negotiation process;

[0014] Figure 2 This is a schematic diagram of the key distribution system provided in the embodiments of this application;

[0015] Figure 3 This is the flow chart of the key distribution method provided in the embodiments of this application. Figure 1 ;

[0016] Figure 4 This is the flow chart of the key distribution method provided in the embodiments of this application. Figure 2 ;

[0017] Figure 5 This is the flow chart of the key distribution method provided in the embodiments of this application. Figure 3 ;

[0018] Figure 6 This is the flow chart of the key distribution method provided in the embodiments of this application. Figure 4 ;

[0019] Figure 6 This is the flow chart of the key distribution method provided in the embodiments of this application. Figure 4 ;

[0020] Figure 7 This is a schematic diagram illustrating an application scenario of the key distribution method provided in the embodiments of this application;

[0021] Figure 8 This is a schematic diagram of the structure of the electronic device provided in the embodiments of this application. Detailed Implementation

[0022] As the background technology shows, the current quantum key distribution schemes are too costly to deploy and apply, which is not conducive to their application, while quantum-resistant cryptographic algorithms are at risk of being cracked.

[0023] Analysis revealed that the aforementioned problems stem from the following: While quantum key distribution technology can achieve secure symmetric key distribution resistant to quantum computing and has achieved limited commercial application, its use is limited by the need for fiber optic access to quantum key distribution networks and the deployment of large-scale quantum key distribution nodes. This limits its low-cost application on PCs and mobile devices. Furthermore, quantum-resistant cryptographic algorithms are based on the assumption of difficult mathematical problems; for example, some current quantum-resistant cryptographic algorithms and protocols are constructed based on the difficult problem of lattices. Although some quantum-resistant cryptographic algorithms have been theoretically proven to resist quantum computing attacks and their security relies on the assumption of difficult mathematical problems, existing quantum-resistant cryptographic algorithms still need to withstand the test of time. With the development of quantum computers and the discovery of new attack algorithms, there is a small probability that they can be broken. The standardization of quantum-resistant cryptographic algorithms is also ongoing.

[0024] Further analysis revealed that quantum key distribution and quantum-resistant cryptography algorithms differ in their application scenarios and the specific cryptographic functions they implement, but they also have complementary advantages. The combined application of the two can achieve a more comprehensive quantum-resistant cryptographic solution.

[0025] Based on this, this application provides a key distribution method, system, electronic device, and storage medium. By combining quantum key distribution technology and quantum-resistant cryptographic algorithms, it provides clients with a solution to obtain key components distributed by the quantum key distribution network without requiring fiber optic access. Furthermore, for connections established by clients via non-fiber optic methods, security is ensured by using a secure connection employing quantum-resistant cryptographic algorithms. Additionally, by setting the keys of different clients to be synthesized from key components from different connections, and by obtaining key components from different clients through different nodes, it avoids the leakage problem caused by a single connection leak, further enhancing security. Ultimately, it achieves both reduced deployment and application costs of the key distribution scheme and guaranteed key distribution security.

[0026] To make the objectives, technical solutions, and advantages of the embodiments of this application clearer, the various embodiments of this application will be described in detail below with reference to the accompanying drawings. However, those skilled in the art will understand that many technical details have been presented in the various embodiments of this application to enable readers to better understand this application. However, the technical solutions claimed in this application can be implemented even without these technical details and various changes and modifications based on the following embodiments.

[0027] The division of the following embodiments is for ease of description and should not constitute any limitation on the specific implementation of this application. The various embodiments can be combined with and referenced by each other without contradiction.

[0028] To facilitate a better understanding by those skilled in the art, the key distribution system provided in the embodiments of this application will be described first. For example... Figure 2 As shown, the system includes at least two key distribution centers (KDCs), several clients, and a quantum key distribution network (QKDN). Each key distribution center includes one key distribution node (KDN) and one quantum key distribution node (QKD). Clients access at least two different key distribution centers through at least two different key distribution nodes, and each quantum key distribution node is connected to the quantum key distribution network.

[0029] In this way, different key distribution centers can negotiate through the quantum key distribution network connected by their internal quantum key distribution nodes to obtain consistent quantum keys (components). This ensures that different key distribution nodes can obtain consistent key components based on the same key distribution center's quantum key distribution nodes, thus guaranteeing the consistency of the key components distributed to clients. Furthermore, different clients can access the key distribution center through key distribution nodes and obtain the same key components. Since key distribution nodes, unlike quantum key distribution nodes, do not require fiber optic connections, fiber optic networks are not needed for client access, reducing deployment and application costs. Simultaneously, the same client can obtain multiple key components through connections to different key distribution nodes, avoiding quantum key leakage caused by a single connection leak. Moreover, secure connections with key distribution nodes, such as those based on quantum-resistant algorithms, ensure communication security.

[0030] It should be noted that this application does not limit the number of key distribution centers. It is understood that they can be deployed based on the distribution range of clients. For example, key distribution centers can be deployed in a distributed manner according to the distribution of clients to support nearby client access, improve the response efficiency of providing services to clients, and enhance user experience. Of course, the above are merely illustrative examples. In some embodiments, the number and distribution of key distribution centers can be implemented in other ways, which will not be listed here.

[0031] It should also be noted that, in this application embodiment, "quantum key distribution node" is a general term for all devices (or clusters, etc.) in the key distribution center that support connection and interaction with the quantum key distribution network, and "key distribution node" is a general term for all devices (or clusters, etc.) in the key distribution center that support access and interaction with clients, rather than referring to specific devices or apparatuses in the key distribution center. "Quantum key distribution network" refers to the general term for the network composed of quantum key distribution metropolitan area networks, quantum key distribution backbone networks, etc., rather than referring to a specific, individual network.

[0032] Based on the key distribution system provided in the above embodiments, this application also provides a key distribution method that can be applied to key distribution nodes. By introducing key distribution nodes as intermediaries between quantum key distribution nodes and clients, the distribution capabilities provided by the quantum key distribution network are enhanced. This eliminates the need for clients to use fiber optic access, facilitating deployment and application. Furthermore, the key components synthesized on the same client originate from different key distribution nodes, and different key distribution nodes distribute different key components to different clients. This prevents the acquisition of complete key information through a single connection. Simultaneously, a secure connection based on quantum-resistant cryptographic algorithms transmits key components between the client and the key distribution nodes, ensuring the security of key component distribution. This achieves both reduced deployment and application costs of the key distribution scheme and guaranteed key distribution security. For ease of understanding, the following will be combined with... Figures 3 to 5 The method and flow shown are explained.

[0033] In some embodiments, the key distribution method applied to the key distribution node follows the following process: Figure 3 As shown, it includes the following steps:

[0034] Step 101: Synchronize with another key distribution node to obtain a consistent key component from the quantum key distribution node to which they are connected, wherein each quantum key distribution node is connected through a quantum key distribution network.

[0035] Step 102: Through a secure connection based on a quantum-resistant cryptographic algorithm, the client sends different key components from the same key component to another key distribution node, so that the client and another client that received the same key component can negotiate to synthesize a symmetric key based on the obtained key components. The same key component of the other client comes from the key distribution node and the other key distribution node, and the key components from the key distribution node in the same key component of the other client and the client are at least partially different.

[0036] In this way, by synchronously obtaining consistent key components from their respective connected quantum key distribution nodes, the consistency of key components across different key distribution nodes is ensured. This supports the consistency of key component distribution to different clients, and eliminates the need for clients to access quantum key distribution nodes via fiber optic cables, reducing the deployment cost and difficulty of distributing quantum keys to clients. Furthermore, the connection between the client and the key distribution node is a secure connection based on quantum-resistant cryptographic algorithms. Additionally, the key components used by the client to synthesize the key come from different key distribution nodes, and the same key distribution node distributes different key components to different clients for generating the same key. This avoids the leakage problem caused by clients requiring encrypted communication using a single connection, thus ensuring the security of key distribution and synthesis. Ultimately, this achieves both reduced deployment and application costs of the key distribution scheme and guaranteed key distribution security.

[0037] To facilitate better understanding by those skilled in the art Figure 3 The steps of the illustrated embodiment will be explained below.

[0038] In step 101, a consistent key component is obtained synchronously from the quantum key distribution node connected to it, along with another key distribution node. This embodiment does not limit the number of consistent key components or the timing of their acquisition; these can be set or configured based on client needs, key distribution node requirements, and the storage performance of the key distribution node. For example, a key distribution node can proactively request a certain number of key components from the quantum key distribution node based on its own needs. Alternatively, a key distribution node can passively accept key components distributed in batches by the quantum key distribution node. Another example is that the key distribution node can trigger the acquisition process of a certain number of key components based on client requests. Yet another example is that the key distribution node can trigger the acquisition of key components when its current key component storage drops to a threshold, etc., which will not be listed here.

[0039] Furthermore, considering that key components can be obtained directly or indirectly through key splitting, in some embodiments, to further improve the security of quantum keys, synchronously obtaining consistent key components from their respective connected quantum key distribution nodes with another key distribution node can be achieved as follows: requesting keys from their respective connected quantum key distribution nodes based on the same key request strategy with the other key distribution node; and splitting the obtained key with at least one other key distribution node based on the same key splitting strategy to obtain consistent key components. This strengthens the security of the key components through the splitting operation, thereby further improving the security of the key synthesized from the key components. Simultaneously, synchronous acquisition with another key distribution node is achieved through the same strategy, rather than through message interaction, which further enhances security. Of course, in some embodiments, the data sent from one quantum key distribution node to another is directly the key component; that is, the key distribution node directly obtains the key component from the quantum key distribution node without key splitting, thus improving the efficiency of the key distribution node in obtaining the key component. Alternatively, in some embodiments, when a key distribution node obtains a key component from a quantum key distribution node connected to it, it may notify another quantum key distribution node connected to that key distribution node via the quantum key distribution network to distribute the key component to the corresponding other key distribution node. After the other quantum key distribution node has distributed the key component, the other quantum key distribution node notifies the quantum key distribution node connected to the key distribution node via the quantum key distribution network to distribute the corresponding key component. In this way, it can be roughly the same as some existing quantum key distribution processes, thus having stronger compatibility, being more conducive to reusing existing networks and resources, and reducing costs, etc., which will not be listed here.

[0040] In step 102, through a secure connection based on a quantum-resistant cryptographic algorithm, different key components from a consistent key component are sent to the client by another key distribution node. This embodiment does not limit the specific quantum-resistant cryptographic algorithm used for the secure connection; any one or more quantum-resistant cryptographic algorithms can be used to form the secure connection. It is understood that quantum-resistant signature algorithms, quantum-resistant key negotiation protocols, and / or quantum-resistant block ciphers can all help strengthen the security of the connection, i.e., a secure connection is established based on the aforementioned quantum-resistant cryptographic algorithms; these will not be listed individually here.

[0041] Furthermore, this application does not limit the method of transmission. It is understood that the key can be synthesized from two or more key components. Depending on different needs, the number of key components sent by the key distribution node and another key distribution node to the same client can be flexibly set. The key components sent by the key distribution node and another key distribution node to the same client can be the same or different, as long as it can support the synthesis of two or more key components into a key, and can support the same key distribution node and another key distribution node to send different key components to different clients, and ultimately the key components received by different clients are the same. Thus, the security is enhanced by the above-mentioned key component distribution, while avoiding the key leakage problem caused by leakage of a single connection. It will not be listed here.

[0042] It should be noted that the embodiments of this application do not limit the method by which key distribution nodes and other key distribution nodes determine the key components that they need to send to the corresponding clients. They can negotiate through the quantum key distribution nodes and quantum key distribution networks they are connected to. For example, a key distribution node determines the key components that it and another key distribution node will send to the client and another client respectively, and notifies the other key distribution node. In order to enhance the security of quantum keys, the content of the notification can be the identifier of the key component. Alternatively, the key distribution nodes and another key distribution node determine the key components that they will send to the client respectively, and then notify each other, etc., which will not be listed here.

[0043] It should also be noted that in this embodiment, the connection between the key distribution node and the client does not employ quantum communication, a method that guarantees communication security. Therefore, a quantum-resistant cryptographic algorithm is used to enhance security. In some embodiments, to further improve security, in addition to communication methods such as quantum communication (mainly internal connections within the quantum key distribution network, connections between the quantum key distribution network and quantum key distribution nodes, and connections between quantum key distribution nodes (where connections between quantum key distribution nodes are all located at the key distribution center, facilitating deployment and controlling costs, avoiding random and wide distribution among clients, which is not conducive to cost control; fiber optic connections can be used)), all other connections employ secure connections based on quantum-resistant cryptographic algorithms. For example, key encryption protection, negotiation, and verification using cryptographic algorithms can all be implemented based on quantum-resistant cryptographic algorithms (or secure connections based on quantum-resistant cryptographic algorithms) to improve quantum-resistant security.

[0044] Based on the foregoing embodiments, it can also be understood that the consistency of key components is fundamental for subsequent client negotiation and synthesis of the symmetric key. Therefore, to ensure the consistency of key components, in some embodiments, such as... Figure 4 As shown, the key distribution method applied to the key distribution node may further include the following steps:

[0045] Step 201: Synchronize with another key distribution node to obtain a consistent key component from the quantum key distribution node to which they are connected, wherein each quantum key distribution node is connected through a quantum key distribution network.

[0046] Step 202: Send the hash value of the consistent key component obtained by the other key distribution node to the other key distribution node, so that the other key distribution node can verify the received hash value based on the consistent key component obtained by the other key distribution node; and / or receive the hash value of the consistent key component obtained by the other key distribution node sent by the other key distribution node, and verify the received hash value based on the consistent key component obtained by the other key distribution node; wherein, the key distribution node and the other key distribution node communicate through their respective connected quantum key distribution nodes and quantum key distribution network.

[0047] Step 203: If the consistent key components pass the verification, the client sends different key components from the consistent key components to another key distribution node through a secure connection based on the quantum-resistant cryptographic algorithm. This allows the client and another client that received the same key components to negotiate and synthesize a symmetric key based on the obtained key components. The same key components of the other client come from both the key distribution node and the other key distribution node, and the key components from the key distribution node in the same key components of the other client and the client are at least partially different.

[0048] Thus, based on the aforementioned embodiments, by verifying the key components received by the key distribution node and another key distribution node, the consistency of the key components between the key distribution node and the other key distribution node is further guaranteed, which enables better support for sending consistent key components to different clients in the future, and supports different clients to negotiate and synthesize consistent quantum keys.

[0049] For ease of understanding Figure 4 The steps of the illustrated embodiment will be explained below. Steps 201 and 203 are largely the same as steps 101-102 in the previous embodiment. The main difference is that step 202 is introduced between steps 201 and 203. Steps 201 and 203 will not be described in detail here.

[0050] In step 202, the hash value of the consistent key component obtained by the other key distribution node is sent to the other key distribution node, so that the other key distribution node can verify the received hash value based on the consistent key component obtained by the other key distribution node; and / or, the hash value of the consistent key component obtained by the other key distribution node is received from the other key distribution node, and the received hash value is verified based on the consistent key component obtained by the other key distribution node. This application embodiment does not limit the verification method. For example, it can be verification by the initiator to the responder (the key distribution node may be the initiator or the responder), or verification by the responder to the initiator. It can also be mutual verification between the initiator and the responder. Furthermore, this application embodiment does not limit the specific verification method. For example, it can be hashing and verifying each key component individually; if any key component fails verification, the distribution fails. Alternatively, it can be hashing and verifying all key components; if any character is inconsistent, the distribution fails. For example, hash calculations can be performed on each key component and its identifier, and each key component can be verified. Key components and their identifiers that pass the verification are retained, while the rest are deleted. These are just a few examples.

[0051] Based on the foregoing embodiments, it can also be understood that the key components may change at the key distribution node. Therefore, in order to further ensure the consistency of the key components distributed to different clients, in some embodiments, such as... Figure 5 As shown, the key distribution method applied to the key distribution node may further include the following steps:

[0052] Step 301: Synchronize with another key distribution node to obtain a consistent key component from the quantum key distribution node to which they are connected, wherein each quantum key distribution node is connected through a quantum key distribution network.

[0053] Step 302: Negotiate with another key distribution node to determine at least two key components from a consistent key component.

[0054] Step 303: Verify at least two key components with another key distribution node.

[0055] Step 304: If at least two key components pass verification, a secure connection based on a quantum-resistant cryptographic algorithm is established, and a different key component from the same key component is sent to the client by another key distribution node, so that the client and another client that received the same key component can negotiate to synthesize a symmetric key based on the obtained key component. The same key component of the other client comes from the key distribution node and the other key distribution node, and the key components from the key distribution node in the same key components of the other client and the client are at least partially different.

[0056] Thus, based on the aforementioned embodiments, by verifying the key component to be sent to the client before sending the key component to the client, the consistency of the key component sent to the client is further guaranteed, which enables better support for sending consistent key components to different clients in the future, and supports different clients to negotiate and synthesize consistent quantum keys.

[0057] For ease of understanding Figure 5 The steps of the illustrated embodiment will be explained below. Steps 301 and 304 are largely the same as steps 101-102 in the previous embodiment. The main difference is that steps 302-303 are introduced between steps 301 and 304. Steps 301 and 304 will not be described again here.

[0058] In step 302, at least two key components are negotiated and determined with another key distribution node from a consistent set of key components. This embodiment does not limit the number of key distribution nodes, the other key distribution node, or the combined number of key components sent to the client. It is understood that these can be set or configured based on security requirements, the client, and the redundancy of key components among the key distribution nodes. For example, in some embodiments, negotiating and determining at least two key components with another key distribution node from a consistent set of key components can be achieved as follows: determining the key components to be sent to the client by each key distribution node and the other key distribution node from the consistent set of key components, and notifying the other key distribution node of the determined key components to be sent to the client; or, receiving notification from the other key distribution node of the key components to be sent to the client. These methods will not be listed exhaustively here.

[0059] In step 303, at least two key components are verified with another key distribution node. This embodiment does not limit the specific verification method; it is understood that different verification schemes will arise depending on different needs. For example, verifying at least two key components with another key distribution node can be achieved as follows: The identifier of the key component to be sent from the other key distribution node to the client, and the hash value of the key component and its identifier, are sent to the other key distribution node, allowing the other key distribution node to verify the received information based on the key component and its identifier in the other key distribution node; and / or, the other key distribution node receives the identifier of the key component to be sent from the other key distribution node to the client, and the hash value of the key component and its identifier, and verifies the received information based on the corresponding key component and its identifier in the key distribution node. This ensures that the key components to be sent to the client by both the key distribution node and the other key distribution node are verified, while reducing the amount of data required for verification, thus improving efficiency. For example, verifying at least two key components with another key distribution node can also be achieved in the following ways: The hash values ​​of at least two key components from one key distribution node are sent to the other key distribution node, allowing the other key distribution node to verify the received hash value based on the at least two key components from its own node; and / or, the hash values ​​of at least two quantum keys from another key distribution node are received from that node, allowing verification based on the at least two key components from its own node. This eliminates the need to distinguish between the key components sent by the local node and the peer node during verification, ensuring the same verification process on each node. This reduces the development difficulty of the verification service and improves development efficiency. Specifically, in the above example, verification can be performed by hashing and verifying each key component individually; if any key component fails verification, it is not sent to the client. Alternatively, all key components to be sent to the client can be hashed and verified; if even one character is inconsistent, it is not sent to the client. For example, hash calculations can be performed on each key component and each key component can be verified. If one key component fails verification, the client to be distributed to is re-determined until the key distribution node and another key distribution node have fewer than two consistent key components or a preset number, etc., which will not be listed here.

[0060] Of course, the above are just examples. In some embodiments, other methods can be used to achieve the same result, which will not be elaborated here.

[0061] It should be noted that, Figure 5 The embodiments shown are only for... Figure 3 Based on the illustrated embodiment, an example of verification before key component distribution is introduced. In some embodiments, further verification can also be performed. Figure 2 Based on the embodiment shown, a verification is introduced before key component distribution, that is, steps 302-303 are executed before step 203, which will not be described in detail here.

[0062] Accordingly, this application also provides a key distribution method that can be applied to a client, which is any electronic device capable of using quantum keys to implement business or services, such as a mobile phone or computer. The following will combine... Figure 6 The flowchart illustrates the key distribution method applied to the client.

[0063] In some embodiments, such as Figure 6 As shown, the key distribution method applied to the client may include the following steps:

[0064] Step 401: Send a key request to the key distribution node through a secure connection based on a quantum-resistant cryptographic algorithm.

[0065] Step 402: Receive key components sent by the key distribution node and another key distribution node through a secure connection based on a quantum-resistant cryptographic algorithm.

[0066] Step 403: Through a secure connection based on a quantum-resistant cryptographic algorithm, negotiate and synthesize a symmetric key with another client that has received the same key component, wherein the same key component of the other client comes from a key distribution node and another key distribution node, and the key components from the key distribution nodes in the same key components of the other client and the client are at least partially different.

[0067] In this way, by introducing key distribution nodes as intermediaries between quantum key distribution nodes and clients, based on the distribution capabilities provided by quantum key distribution networks, clients no longer need to use fiber optic access, which is beneficial for deployment and application. Furthermore, the key components synthesized on the same client come from different key distribution nodes, and different key distribution nodes distribute different key components to different clients, making it impossible to obtain complete key information through a single connection. At the same time, a secure connection based on quantum-resistant cryptographic algorithms transmits key components between clients and key distribution nodes, ensuring the security of key component distribution. This achieves both a reduction in the deployment and application costs of the key distribution scheme and the guarantee of key distribution security.

[0068] In some embodiments, the negotiation and synthesis of a symmetric key between a client and another client that has received the same key component can be achieved in the following ways: via a secure connection resistant to quantum cryptography, the client sends the hash value of the synthesized key to the other client, allowing the other client to verify the received hash value against the synthesized key; and / or, via a secure connection resistant to quantum cryptography, the client receives the hash value of the synthesized key from the other client and verifies the received hash value against the synthesized key. In other words, the client and the other client autonomously synthesize a key based on the received key component, with one party verifying the other's key, or vice versa. This prevents leakage and ensures the symmetry of the key between the client and the other client, guaranteeing the effectiveness and reliability of subsequent encrypted communication.

[0069] It is not difficult to see that this embodiment is a method embodiment corresponding to the foregoing embodiments, and this embodiment can be implemented in conjunction with the foregoing embodiments. The relevant technical details mentioned in the foregoing embodiments are still valid in this embodiment, and will not be repeated here to reduce repetition. Accordingly, the relevant technical details mentioned in this embodiment can also be applied to the foregoing embodiments.

[0070] To facilitate a better understanding of the key distribution method provided in the embodiments of this application by those skilled in the art, the following will be combined with the key distribution method based on... Figure 7 The application scenarios shown are explained.

[0071] like Figure 7 As shown, there are two clients that need to communicate encrypted: User1 and User2. User1 uses client KDN-Client1, and User2 uses client KDN-Client2. KDN-Client1 can access key distribution node KDN1 through secure connection 2 based on quantum-resistant cryptography algorithm and key distribution node KDN2 through secure connection 3 based on quantum-resistant cryptography algorithm; KDN-Client2 can access key distribution node KDN1 through secure connection 4 based on quantum-resistant cryptography algorithm and key distribution node KDN2 through secure connection 5 based on quantum-resistant cryptography algorithm. Furthermore, KDN1 belongs to key distribution center KDC1, and KDN2 belongs to key distribution center KDC2. Quantum key distribution nodes QKD1 and QKD2 in KDC1 are connected through the quantum key distribution network QKDN. Other communication application components in this scenario are not the focus of the key distribution method provided in this embodiment; therefore, in... Figure 7 It is not shown in the document, but that does not mean it does not exist.

[0072] The following example illustrates the key distribution process to KDN-Client1 and KDN-Client2. It should be noted that the parties involved in the communication have already completed identity authentication in some way. At the same time, QKD1 and QKD2 implement quantum key distribution based on QKDN and can continuously output quantum keys. This process is basically the same as the existing QKDN-to-QKD distribution process, so it will not be described in detail here.

[0073] First, KDN1 and KDN2 synchronously acquire consistent key components. Specifically:

[0074] 1. KDN1 and KDN2 execute key request strategy S1, requesting quantum keys from QKD1 and QKD2 respectively, and then dividing them into n key components {k1,k2,...,k} according to key splitting strategy S2. n}, corresponding to the key index numbers {kid1,kid2,...,kid n}

[0075] 2. The key components {k1,k2,...,k} of KDN1 for this node n Calculate the hash values ​​{H1, H2, ..., H} respectively. n}, and send it to KDN2.

[0076] 3. The key components {k1,k2,...,k} of KDN2 for this node n Calculate the hash values ​​{H1′, H2′, ..., H} respectively. n ′}, and {H1,H2,...,H n The key components are compared one by one. If they all match, the verification passes, and the acquired key component is recognized as a usable key component for key distribution to the client. Otherwise, the verification fails, and the acquired key component is discarded. Sometimes, KDN2 can also send an acknowledgment message to KDN1 when the verification passes, or send an error message to KDN1 when the verification fails, so that KDN1 can process the verification result. Alternatively, KDN1 may assume that no result is received, which would be considered either a successful or failed verification, and will process accordingly.

[0077] That is, each KDN sets a key pool policy according to the user's key distribution requirements, and achieves consistent key pool key generation among the KDNs based on the QKD network.

[0078] Secondly, KDN1 and KDN2 respectively send the corresponding key components to KDN-Client1 and KDN-Client2.

[0079] Specifically:

[0080] 1. KDN-Client1 initiates registration with KDN1 through connection 2 to establish a secure link with KDN1 based on quantum-resistant cryptography algorithm, and initiates registration with KDN2 through connection 3 to establish a secure link with KDN2 based on quantum-resistant cryptography algorithm.

[0081] 2. KDN-Client2 initiates registration with KDN1 through connection 4 to establish a secure link with KDN1 based on quantum-resistant cryptography algorithm, and initiates registration with KDN2 through connection 5 to establish a secure link with KDN2 based on quantum-resistant cryptography algorithm.

[0082] 3. KDN-Client1 and KDN-Client2 begin a key negotiation process collaboratively through Connection 1.

[0083] 4. KDN-Client1 initiates a key request to KDN1, and KDN1 prepares to transfer the key component k. i1 This will be the key component that this node will send to KDN-Client1, and at the same time, it will inform KDN2 to send key component k to KDN-Client1. i1+1 The notification method involves sending the key component k. i1 and key component k i1+1 The identifiers kid(i1) and kid(i 1+1 Notify KDN2.

[0084] 5. KDN2 sends key component k to KDN-Client1 i1+1 The identifier of the key component, kid(i) 1+1 and key component k i1+1 The hash values ​​of the three are H i1+1 The key component k in the KDN-Client1 local node i1+1 The identifier of the key component, kid(i) 1+1 and key component k i1+1 The hash values ​​of the three are combined with H i1+1 The verification process is completed, and upon successful verification, an acknowledgment message is sent back to KDN2. It should be noted that the key component k here... i1+1 and key component k i1 This is an example provided for ease of understanding only. Other key components or more key components may be used, but they will not be listed here.

[0085] 6. After receiving the confirmation message returned to KDN-Client1, KDN2 replies to KDN1 that the key component for KDN-Client1 has been sent. KDN1 then sends the key component k to KDN-Client1. i1The identifier of the key component, kid(i1), and the key component k i1 Hash value H i1 KDN-Client1 uses the relevant information of this node to access H i1 Perform a verification; if the verification passes, send a confirmation message back to KDN1.

[0086] 7. KDN-Client1 informs KDN-Client2 that the local key component has been received. Then, KDN-Client2, as described in the previous steps, retrieves the key component k from KDN1. i1+1 Obtain key component k from KDN2 i1 .

[0087] 8. KDN-Client2 sends the key component identifiers kid(i1) and kid(i2) to KDN-Client1. 1+1 KDN-Client1 verifies the hash value of the four key components (key components, key components, and corresponding key components) based on the information stored on its own end. If the verification passes, it means that both ends have received two identical key components.

[0088] Sometimes, depending on different needs, KDN-Client1 and KDN-Client2 can continue to obtain key components, such as repeating the above step 2l times until both KDN-Client1 and KDN-Client2 have obtained key components {k i1 ,k i2 ,...,k i2l}, where connection 2 and connection 4 send one key component, and connection 3 and connection 5 send another key component.

[0089] In other words, the KDN-Client establishes a secure connection with each KDN based on PQC, and executes a key distribution protocol. Only a portion of the key components are transmitted on a single link between the KDN-Client and the KDN, making it impossible for an attacker to obtain all the key components from a single link.

[0090] Finally, KDN-Client1 and KDN-Client2 negotiate and synthesize the key. Specifically:

[0091] 1. KDN-Client1 and KDN-Client2 securely negotiate the key synthesis method and the ID number KID of the synthesized key through Connection 1. Each client then selects the same key component from the previously obtained key components and synthesizes the key K locally. There are various key synthesis methods, such as using different key derivation algorithms, which will not be elaborated upon here.

[0092] 2. KDN-Client1 calculates the hash value H of K and sends KID and H to KDN-Client2. KDN-Client2 calculates the hash value of the locally synthesized key K and verifies it. If the verification matches, the key distribution process between the two parties is completed.

[0093] This means that KDN-Clients collaborate to synthesize key components, ensuring that the KDC side does not know the key ultimately used by the user.

[0094] It is evident that the key distribution method provided in this application combines quantum key distribution and quantum-resistant cryptography, enhancing the security of key distribution between communicating parties. Furthermore, the quantum key distribution network ensures high security for key distribution and synchronization between key distribution centers. Building upon this, a quantum-resistant cryptographic algorithm is used on the classical link between the key distribution center and the user (specifically, from the key distribution node to the client) to improve the security of link transmission. Attackers cannot obtain complete plaintext or ciphertext key information from a single key distribution link, nor can they obtain all key components from a single key distribution link. Compared to users directly using a quantum-resistant key negotiation protocol to obtain symmetric keys, an attacker with quantum-resistant cryptographic capabilities could directly obtain the final negotiated key. Moreover, compared to deploying quantum key distribution equipment and fiber optic access to the quantum key distribution network on the user side to achieve symmetric key distribution, this application uses a classical link between the key distribution center and the user, eliminating the need to deploy quantum key distribution equipment on the user side, significantly reducing the cost for users to obtain quantum keys. Users can securely and flexibly negotiate quantum key synthesis methods based on key components obtained from key distribution, preventing attackers from obtaining the user's final key from the key distribution center operator and meeting user key security requirements. Ultimately, by combining quantum key distribution and quantum-resistant cryptography, the security of key distribution is improved through the integration of these two technologies.

[0095] It should be noted that the description in the above embodiments is mainly based on two clients and two key distribution nodes. When multi-party group communication and multiple key distribution nodes are involved, it can be regarded as implementing the solution provided in the above embodiments by any two clients and key distribution nodes among the multiple clients and key distribution nodes. It will not be described in detail here.

[0096] The steps of the various methods described above are only for clarity. In practice, they can be combined into one step or some steps can be split into multiple steps. As long as they include the same logical relationship, they are all within the scope of protection of this patent. Adding insignificant modifications or introducing insignificant designs to the algorithm or process, but without changing the core design of the algorithm and process, are also within the scope of protection of this patent.

[0097] Another aspect of this application embodiment also provides an electronic device, such as... Figure 8 As shown, it includes: at least one processor 801; and a memory 802 communicatively connected to at least one processor 801; wherein the memory 802 stores instructions executable by at least one processor 801, which are executed by at least one processor 801 to enable at least one processor 801 to perform the key distribution method described in any of the above method embodiments.

[0098] The memory 802 and processor 801 are connected via a bus, which can include any number of interconnecting buses and bridges. The bus connects various circuits of one or more processors 801 and memory 802 together. The bus can also connect various other circuits, such as peripheral devices, voltage regulators, and power management circuits, which are well known in the art and therefore will not be described further herein. A bus interface provides an interface between the bus and the transceiver. The transceiver can be a single element or multiple elements, such as multiple receivers and transmitters, providing a unit for communicating with various other devices over a transmission medium. Data processed by processor 801 is transmitted over a wireless medium via an antenna, which further receives data and transmits it to processor 801.

[0099] The processor 801 is responsible for managing the bus and general processing, and can also provide various functions, including timing, peripheral interfaces, voltage regulation, power management, and other control functions. The memory 802 can be used to store data used by the processor 801 during operation.

[0100] Another aspect of this application provides a computer-readable storage medium storing a computer program. When executed by a processor, the computer program implements the above-described method embodiments.

[0101] That is, those skilled in the art will understand that all or part of the steps in the methods of the above embodiments can be implemented by a program instructing related hardware. This program is stored in a storage medium and includes several instructions to cause a device (which may be a microcontroller, chip, etc.) or processor to execute all or part of the steps of the methods described in the various embodiments of this application. The aforementioned storage medium includes various media capable of storing program code, such as a USB flash drive, a portable hard drive, a read-only memory (ROM), a random access memory (RAM), a magnetic disk, or an optical disk.

[0102] Those skilled in the art will understand that the above embodiments are specific embodiments for implementing this application, and in practical applications, various changes can be made to them in form and detail without departing from the spirit and scope of this application.

Claims

1. A key distribution method, characterized in that, Applied to a key distribution node, the method includes: The key components are obtained synchronously from the respective connected quantum key distribution nodes with another key distribution node, wherein the quantum key distribution nodes are connected through a quantum key distribution network; Through a secure connection based on a quantum-resistant cryptographic algorithm, the other key distribution node sends different key components from the consistent key components to the client, so that the client and the other client that received the same key components can negotiate to synthesize a symmetric key based on the obtained key components. The same key components of the other client come from the key distribution node and the other key distribution node, and the key components from the key distribution node in the same key components of the other client and the client are at least partially different.

2. The key distribution method according to claim 1, characterized in that, After synchronizing with another key distribution node to obtain a consistent key component from their respective connected quantum key distribution nodes, the method further includes: Send the hash value of the consistent key component obtained by the other key distribution node to the other key distribution node, so that the other key distribution node can verify the received hash value based on the consistent key component obtained by the other key distribution node; And / or, The system receives the hash value of the consistent key component obtained by the other key distribution node and verifies the received hash value based on the consistent key component obtained by the other key distribution node. The key distribution node communicates with the other key distribution node through the quantum key distribution node and the quantum key distribution network to which they are respectively connected.

3. The key distribution method according to claim 1, characterized in that, Before the step of sending different key components from the consistent key components to the client, respectively, with the other key distribution node, the method further includes: Negotiate and determine at least two key components from the consistent key components with the other key distribution node; The other key distribution node verifies the at least two key components.

4. The key distribution method according to claim 3, characterized in that, The verification of the at least two key components with the other key distribution node includes: The identifier of the key component to be sent to the client by the other key distribution node, and the hash value of the key component and its identifier to be sent to the client by the other key distribution node, are sent to the other key distribution node so that the other key distribution node can verify the received information based on the key component and its identifier in the other key distribution node. And / or, The other key distribution node receives the identifier of the key component to be sent to the client by the other key distribution node, and the hash value of the key component to be sent to the client and its identifier, so as to verify the received information according to the corresponding key component and its identifier in the key distribution node.

5. The key distribution method according to any one of claims 1 to 4, characterized in that, The step of synchronizing with another key distribution node to obtain a consistent key component from the respective connected quantum key distribution node includes: Both nodes request keys from the quantum key distribution nodes they are connected to, based on the same key request strategy. The obtained key is divided using the same key splitting strategy as the other key distribution node to obtain the consistent key components.

6. A key distribution method, characterized in that, Applied to a client, the method includes: Send a key request to the key distribution node through a secure connection based on quantum-resistant cryptography algorithms; Through a secure connection based on quantum-resistant cryptography, the key components sent by the key distribution node and another key distribution node are received; Through a secure connection based on a quantum-resistant cryptographic algorithm, a symmetric key is negotiated and synthesized with another client that receives the same key component, wherein the same key component of the other client comes from the key distribution node and the other key distribution node, and the key components from the key distribution node in the same key components of the other client and the client are at least partially different.

7. The key distribution method according to claim 6, characterized in that, The other client, which receives the same key component, negotiates and synthesizes a symmetric key based on the received key component, including: A secure connection based on quantum-resistant cryptography algorithms sends the hash value of the key synthesized by the client to the other client, so that the other client can verify the received hash value based on the key synthesized by the other client. And / or, A secure connection based on quantum-resistant cryptography algorithms receives the hash value of a key synthesized by another client, and verifies the received hash value based on the key synthesized by the client.

8. A key distribution system, characterized in that, include: The system comprises at least two key distribution centers, a number of clients, and a quantum key distribution network. Each key distribution center includes a key distribution node and a quantum key distribution node. The clients access at least two different key distribution centers through at least two different key distribution nodes, and each quantum key distribution node is connected to the quantum key distribution network. The key distribution node is used to implement the key distribution method as described in any one of claims 1 to 5, and the client is used to implement the key distribution method as described in claim 6 or 7. When performing key distribution, the client cooperates with two of the at least two different key distribution centers connected to implement the corresponding key distribution method.

9. An electronic device, characterized in that, include: At least one processor; as well as, A memory communicatively connected to the at least one processor; wherein, The memory stores instructions that can be executed by the at least one processor to enable the at least one processor to perform the key distribution method as described in any one of claims 1 to 5, or to perform the key distribution method as described in claim 6 or 7.

10. A computer-readable storage medium storing a computer program, characterized in that, When the computer program is executed by a processor, it implements the key distribution method as described in any one of claims 1 to 5, or implements the key distribution method as described in claim 6 or 7.

Citation Information

Patent Citations

  • Efficient satellite quantum key pairing generation method

    CN111385088A

  • Secret communication method, secret key distribution center, equipment, medium and product

    CN118827016A