A quantum secure communication method of QKD and global quantum security fusion

By establishing communication connections for quantum security devices within the basic service area, utilizing QKD key distribution channels and classical communication channels, and combining key centers and border base stations, the problem that existing QKD technology cannot be directly transmitted to users or IoT devices is solved, enabling full-domain quantum secure communication, ensuring the security of data transmission and reducing costs.

CN119788277BActive Publication Date: 2025-10-24MATRICTIME DIGITAL TECH CO LTD
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202510012953.8
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2025-01-06
Publication Date
2025-10-24
Estimated Expiration
2045-01-06

AI Technical Summary

Technical Problem

Existing quantum key distribution (QKD) technology cannot be directly transmitted to users or IoT device terminals, resulting in the inability to fully guarantee the security of the communication process. At the same time, the deployment of dedicated optical fibers and optical equipment will increase the cost for end users and limit the mobility of equipment.

Method used

By establishing communication connections between quantum security devices within the same basic service area, utilizing QKD key distribution channels and classical communication channels, combined with key centers and border base stations, end-to-end encrypted communication between quantum security terminals is achieved, and through the relay of access base stations and border base stations, security and adaptability across service areas are ensured.

Benefits of technology

It realizes full-domain quantum secure communication between user devices and IoT devices, ensures the security of data transmission, reduces costs, and improves the mobility of devices and the adaptability of the network.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN119788277B_ABST
    Figure CN119788277B_ABST
Patent Text Reader

Abstract

The application relates to the technical field of information security, in particular to a quantum secure communication method of QKD and global quantum security fusion. In the scheme of the application, for quantum secure terminals arranged in the same basic service area, quantum secure keys distributed by a key center are used to encrypt communication data, so that the security of the communication is guaranteed. Between the basic service areas, the quantum secure keys are relayed through boundary base stations, and symmetric quantum keys are distributed between the basic service areas by using a QKD key distribution channel, so that the relayed quantum secure keys are encrypted. The process ensures the security of cross-service area communication, and makes the network topology have high adaptability. End-to-end encrypted communication between quantum secure terminals is realized, and the privacy of user data is effectively protected.
Need to check novelty before this filing date? Find Prior Art

Description

TECHNICAL FIELD

[0001] The present application relates to the field of information security technology, and in particular to a quantum secure communication method of QKD and global quantum security fusion. BACKGROUND

[0002] At present, quantum key distribution (QKD) technology is mainly used for quantum key distribution between various hub nodes. However, this key distribution method cannot directly transmit quantum keys to the terminals of user equipment or Internet of Things devices. Therefore, in the actual scenario of data generation and consumption, user equipment or Internet of Things devices are not completely protected by quantum security, resulting in the security of the entire communication process being unable to be comprehensively guaranteed.

[0003] In addition, due to the mobility, complex environment, and simple and economical characteristics of user equipment and Internet of Things devices, the existing QKD technology has the following problems when applied to these devices:

[0004] Deploying special optical fibers and optical equipment on user equipment or Internet of Things devices will cause terminal users to face high costs.

[0005] The installation and use of special optical fibers and optical equipment limit the mobility of the devices, causing inconvenience to users.

[0006] In summary, the existing QKD technology has deficiencies in realizing quantum key distribution for user equipment or Internet of Things device terminals, and brings great cost burden and use inconvenience to terminal users in actual application. SUMMARY

[0007] To solve the above problems, the present application discloses a quantum secure communication method of QKD and global quantum security fusion, comprising the following steps:

[0008] According to the network topology planning, quantum secure devices belonging to the same basic service area are established for communication connection, wherein the quantum secure devices belonging to the same basic service area include quantum secure terminals, access base stations, key centers and boundary base stations, the quantum secure terminals access the access base stations, the key centers are in communication connection with the access base stations, and the access base stations are in communication connection with the boundary base stations;

[0009] A QKD key distribution channel and a classical communication channel are established between two basic service areas that need to communicate, wherein the QKD key distribution channel connects the boundary base stations of the two basic service areas, respectively, and symmetric quantum keys are distributed to the two boundary base stations through the QKD key distribution channel;

[0010] When the quantum secure terminals belonging to the same basic service area communicate, the communication data encrypted by the quantum secure key is sent through the local network; and the quantum secure key used for encrypting the communication data is relayed to the receiving end by the access base station;

[0011] When the quantum secure terminals between the basic service areas communicate, the sending end encrypts the data by using its own quantum secure key, and sends the ciphertext obtained by the encryption to the receiving end through the classical communication channel between the basic service areas; meanwhile, the sending end forwards the quantum secure key used for encryption after encryption to the corresponding access base station, and the access base station forwards the quantum secure key to the border base station of the sending end after decryption, and the border base station forwards the quantum secure key to the border base station of the receiving end after encryption, wherein the key used by the border base station for encrypting the quantum secure key is the symmetric quantum key distributed through the QKD key distribution channel and successfully verified.

[0012] The process of distributing the symmetric quantum key for the two border base stations through the QKD key distribution channel includes:

[0013] The sending end sends a series of polarized photons to the receiving end through the QKD key distribution channel, wherein each photon represents a bit of the key;

[0014] The receiving end measures each received photon by using the basis state randomly selected by itself;

[0015] The sending end and the receiving end perform a verification process, and the part consistent with the verification is reserved as the distributed symmetric quantum key.

[0016] The step of performing the verification process between the sending end and the receiving end includes:

[0017] The sending end and the receiving end compare the basis states selected by themselves through the classical communication channel, and in the comparison process, the information corresponding to the part with consistent basis states is taken as the key.

[0018] The process of relaying the quantum secure key used for encrypting the communication data to the receiving end by the access base station includes:

[0019] The sending end encrypts the quantum secure key used for encrypting the data by using the paired session key between the sending end and the access base station to form key relay data ciphertext, and sends the key relay data ciphertext and the key index of the session key to the corresponding access base station;

[0020] The access base station determines the corresponding session key according to the key index, and decrypts the key relay data ciphertext to obtain the quantum secure key;

[0021] The access base station forwards the quantum security key to the receiving end when the receiving end belongs to the access base station according to the receiving end network access identification information; forwards the quantum security key to the access base station to which the receiving end belongs, and then forwards the quantum security key to the receiving end by the access base station when the receiving end belongs to the same basic service area but does not belong to the access base station according to the receiving end network access identification information; forwards the quantum security key to the corresponding border base station in the basic service area, forwards the quantum security key to the receiving end border base station by the border base station, forwards the quantum security key to the receiving end access base station by the receiving end border base station, and then forwards the quantum security key to the corresponding receiving end by the receiving end access base station when the receiving end does not belong to the basic service area according to the receiving end network access identification information.

[0022] The paired session key between the sending end and the access base station is a quantum random number key.

[0023] The network access identification includes network location information and device identification information.

[0024] In the scheme of the present application, for the quantum security terminals deployed in the same basic service area, the quantum security key distributed by the key center is used to encrypt the communication data to ensure the security of the communication. Between the basic service areas, the quantum security key is relayed by the border base station, and the symmetric quantum key is distributed between the basic service areas by the QKD key distribution channel to encrypt the relayed quantum security key. This process ensures the security of the cross-service area communication and makes the network topology highly adaptable. The end-to-end encrypted communication between the quantum security terminals is realized, and the privacy of the user data is effectively protected. BRIEF DESCRIPTION OF DRAWINGS

[0025] Figure 1 The structure of the basic service area in the embodiment of the present application is shown in the figure;

[0026] Figure 2 The timing diagram of the quantum security terminal communication in the same basic service area in the embodiment of the present application is shown in the figure;

[0027] Figure 3 The timing diagram of the quantum security terminal communication between the basic service areas in the embodiment of the present application is shown in the figure. DETAILED DESCRIPTION

[0028] In order to make the purpose, technical scheme and advantages of the present application clearer, the present application will be described in further detail below with reference to the drawings. Obviously, the described embodiments are only part of the embodiments of the present application, not all the embodiments. Based on the embodiments in the present application, all other embodiments obtained by those skilled in the art without creative labor fall within the scope of protection of the present application.

[0029] Embodiment: A quantum secure communication method integrating QKD and global quantum security, comprising the following steps:

[0030] According to the network topology, a communication connection is established for quantum secure devices belonging to the same basic service area, wherein, as shown in Figure 1 The quantum secure devices belonging to the same basic service area include quantum secure terminals, access base stations, key centers and boundary base stations, the quantum secure terminals access the access base stations, the key centers are in communication connection with the access base stations, and the access base stations are in communication connection with the boundary base stations;

[0031] One basic service area is one physical coverage area, which contains a certain number of quantum secure terminals, one or more access base stations, one key center and at least one boundary base station;

[0032] The quantum secure terminals serve as user devices, which are used to process user data and encrypt the communication data according to quantum secure keys; wherein the quantum secure keys are quantum random numbers generated by quantum true random number generators (QRNG); the access base stations serve as a bridge connecting the quantum secure terminals, the key centers and the boundary base stations, and are responsible for managing the access of the terminals, the relay and forwarding of the keys; the key centers are responsible for generating and managing quantum keys; the boundary base stations are located at the edge of the basic service area, and are used to relay quantum secure keys between the basic service areas;

[0033] A QKD key distribution channel and a classical communication channel are established between two basic service areas in need of communication, wherein the QKD key distribution channel connects the boundary base stations of the two basic service areas respectively, and symmetric quantum keys are distributed to the two boundary base stations through the QKD key distribution channel;

[0034] Specifically, optical fibers or other suitable quantum channels can be used to connect the two boundary base stations; QKD devices are installed on the two boundary base stations, which can perform key distribution through quantum channels; the QKD devices are configured to realize the functions of key generation, transmission and reception;

[0035] As shown in Figure 2 When the quantum secure terminals belonging to the same basic service area communicate with each other, the communication data encrypted by quantum secure keys is sent through a local network; and the quantum secure keys used to encrypt the communication data are relayed to the receiving end by the access base stations; the encryption of the communication data by the quantum secure keys can provide theoretical security that cannot be cracked. The randomness of the quantum key and the quantum non-cloning theorem guarantee the absolute security of the key;

[0036] As shown in Figure 3As shown, when the quantum secure terminal communicates between the basic service areas, the sending end encrypts data using its own quantum secure key, and sends the encrypted ciphertext to the receiving end through the classical communication channel between the basic service areas; meanwhile, the sending end forwards the quantum secure key used for encryption after encryption to the corresponding access base station, which forwards it to the sending end after decryption; the sending end encrypts the quantum secure key again and forwards it to the receiving end, wherein the key used by the boundary base station to encrypt the quantum secure key is a symmetric quantum key distributed through the QKD key distribution channel and successfully verified.

[0037] The sending end encrypts data using the quantum secure key, ensuring the security of the data in the transmission process; the boundary base station encrypts the quantum secure key using the symmetric quantum key distributed through the QKD key distribution channel and successfully verified, further enhancing the security of the key in the transmission process; although the data is transmitted through the classical communication channel, the end-to-end secure communication is achieved because the quantum secure key is used for encryption; the quantum secure key is securely relayed through the access base station and the boundary base station, ensuring the security of the key in the cross-service area transmission process;

[0038] In a specific scheme, the process of distributing a symmetric quantum key to the two boundary base stations through the QKD key distribution channel includes:

[0039] The sending end sends a series of polarized photons to the receiving end through the QKD key distribution channel, wherein each photon represents a bit of the key;

[0040] The receiving end measures each received photon using its own randomly selected basis state;

[0041] The sending end and the receiving end perform a verification process, and the part that passes the verification is retained as the distributed symmetric quantum key.

[0042] The step of performing a verification process between the sending end and the receiving end includes:

[0043] The sending end and the receiving end compare their respective selected basis states through the classical communication channel, and in the comparison process, the information corresponding to the part with consistent basis states is used as the key.

[0044] For example, the sending end A generates a series of polarized photons, and the polarization state of each photon represents a key bit (0 or 1);

[0045] The sending end A randomly selects two polarization bases (e.g., horizontal / vertical and + / x) to send the photons.

[0046] After receiving the photons, the receiving end B randomly selects its own measurement basis (horizontal / vertical and + / x) to measure the polarization state of each photon;

[0047] After the communication is completed, the sending end discloses the basis state used when sending each photon to the receiving end B through a classical communication channel;

[0048] The receiving end B compares its measurement basis with the measurement basis of the sending end A, and only retains the measurement results of the photons whose measurement basis is consistent with the basis state sent by the sending end A;

[0049] The process of relaying the quantum secure key for encryption by the access base station to the receiving end comprises:

[0050] The sending end encrypts the quantum secure key for encrypting data by using the paired session key between the sending end and the access base station to form key relay data ciphertext, and sends the key relay data ciphertext and the key index of the session key to the corresponding access base station;

[0051] The access base station determines the corresponding session key according to the key index, and decrypts the key relay data ciphertext to obtain the quantum secure key;

[0052] When the receiving end belongs to the access base station itself according to the network access identification information of the receiving end, the access base station forwards the quantum secure key to the receiving end; when the receiving end belongs to the same basic service area but does not belong to the access base station itself according to the network access identification information of the receiving end, the access base station forwards the quantum secure key to the access base station to which the receiving end belongs, and then forwards the quantum secure key to the receiving end by the access base station; when the receiving end does not belong to the basic service area according to the network access identification information of the receiving end, the access base station forwards the quantum secure key to the corresponding border base station in the basic service area, forwards the quantum secure key to the border base station of the receiving end by the border base station, forwards the quantum secure key to the access base station of the receiving end by the border base station of the receiving end, and then forwards the quantum secure key to the corresponding receiving end by the access base station of the receiving end.

[0053] The paired session key between the sending end and the access base station is a quantum random number key, which is generated by a quantum random number generator and has true randomness, so that the security of encryption is higher.

[0054] The network access identification comprises network location information and device identification information, and the corresponding quantum secure device can be quickly located by the network location information and the device identification information.

[0055] Examples:

[0056] Suppose that there are two places A and B, and there are many enterprises and users in the two places, and quantum secure communication is to be realized between the two places and inside the two places.

[0057] First, a QKD key distribution node is built between locations A and B respectively, and QKD keys are distributed to the communication nodes in the two locations. There is a QKD key distribution channel and a classical communication channel between the two locations. The QKD key distribution channel is used to transmit photons, and the classical communication channel is used for classical network communication.

[0058] Sending photons:

[0059] Site A sends a series of polarized photons to Site B via the QKD key distribution channel, where each photon represents a bit of the key.

[0060] Measuring photons:

[0061] Site B uses its own randomly chosen basis state to measure each received photon. If the measurement basis chosen by Site B matches the basis state used by Site A when sending, Site B can accurately measure the photon's polarization and identify the bit value. If the chosen basis state is inconsistent, the measurement result will be random.

[0062] Public ground state comparison:

[0063] Sites A and B compare their chosen basis states over a classical communication channel, but keep the measurement results private. Only if the basis states match is that bit retained as part of the key; any mismatched base states are discarded.

[0064] Through this process, a symmetric quantum security key pool is established between A and B, which can provide quantum security keys for quantum security encryption transmission between A and B.

[0065] Secondly, a global quantum security network will be built in locations A and B. A global quantum security network includes access base stations, key centers, border base stations and other operation and maintenance systems.

[0066] The global quantum security boundary base station is used to realize secure communication between the global quantum security network, that is, communication between A and B, while the access base station is used to control and manage the access of each terminal to the quantum security network. The key center is used to provide quantum security keys for terminal devices accessing this quantum security network.

[0067] The border base station uses the session key distributed by QKD to locations A and B as a quantum security key pool to realize key relay between locations A and B.

[0068] The border base stations at locations A and B access the key pool distributed by QKD to perform key consistency detection and synchronization, ensuring consistent key usage on both sides. Once the border base stations at locations A and B have synchronized the QKD-distributed keys, they will have the session key and can then relay the key.

[0069] Then, all user terminals, business systems, Internet of Things devices, etc. that need to perform quantum secure communication access the access base station of the global quantum secure service through the global quantum secure terminal.

[0070] The global quantum secure terminal, as a user data encryption and decryption device, can be used with user equipment in different situations and locations for quantum secure encryption communication. The terminal device is mobile and can use quantum secure encryption communication anywhere where the network is accessible.

[0071] At this point, after completing authentication and authorization, any terminal device that has joined the quantum secure service can perform quantum secure communication with other quantum secure terminals, regardless of whether the two terminals have symmetric quantum secure keys.

[0072] At the same time, the global quantum secure terminal has a device isolation function, which not only protects data transmission security but also protects devices from network attacks. In this way, information is fully protected throughout the information exchange process.

[0073] Finally, when the quantum secure key of a user terminal is insufficient, it can request a key supplement from the access base station. The access base station allocates a key center to the terminal. The key center has a quantum secure key generation function and can generate quantum secure keys for the terminal and distribute them to the terminal.

[0074] When user a in place A needs to perform quantum secure communication with user c in place A, since user a and user c are both connected to the same global quantum secure network, their keys are distributed by the key center of the global quantum secure network. Therefore, user a and user c can directly perform quantum secure communication based on the global quantum secure network. The key relay is directly provided by the global quantum secure network in place A.

[0075] When user a in place A needs to perform quantum secure communication with user b in place B, first, user a encrypts the data using his own quantum secure key to obtain ciphertext and sends it to the network. The ciphertext directly reaches user b through the network. Second, user a informs the access base station of the global quantum secure network of the encrypted key. The access base station retrieves the encrypted key and forwards it to the border base station. The border base station encrypts the encrypted key using the quantum key distributed by QKD and sends it to the border base station in place B. The border base station in place B receives the relay key message from the border base station in place A, decrypts the encrypted key using the quantum key distributed by QKD, and then forwards the encrypted key to the access base station in place B. The access base station in place B encrypts the encrypted key using the global quantum secure key according to the destination and sends it to user b. User b obtains the key and ciphertext and decrypts to obtain the plaintext.

[0076] Obviously, many modifications and variations of the present application are possible in light of the above teachings. It is, therefore, to be understood that within the scope of the appended claims and their equivalents, the application can be practiced otherwise than as specifically described.

Claims

1. A quantum secure communication method of QKD and global quantum security fusion, characterized in that, The method comprises the following steps: According to the network topology, a communication connection is established for quantum security devices belonging to the same basic service area, wherein the quantum security devices belonging to the same basic service area include quantum security terminals, access base stations, key centers and boundary base stations, the quantum security terminals access the access base stations, the key centers are in communication connection with the access base stations, and the access base stations are in communication connection with the boundary base stations; A QKD key distribution channel and a classical communication channel are established between two basic service areas in need of communication, wherein the QKD key distribution channel connects the boundary base stations of the two basic service areas, respectively, and symmetric quantum keys are distributed to the two boundary base stations through the QKD key distribution channel; When the quantum security terminals belonging to the same basic service area communicate with each other, the communication data encrypted by the quantum security keys is sent through a local network, and the quantum security keys used for encrypting the communication data are relayed to the receiving end by the access base station; When the quantum security terminals in different basic service areas communicate with each other, the sending end encrypts data by using its own quantum security key, and the ciphertext obtained by the encryption is sent to the receiving end through the classical communication channel between the basic service areas; meanwhile, the quantum security key used for encryption is encrypted and forwarded to the corresponding access base station, decrypted by the access base station and then forwarded to the boundary base station of the sending end, and finally encrypted by the boundary base station and forwarded to the boundary base station of the receiving end, wherein the key used by the boundary base station to encrypt the quantum security key is the symmetric quantum key distributed through the QKD key distribution channel and successfully verified.

2. The method of claim 1, wherein, The process of distributing symmetric quantum keys to the two boundary base stations through the QKD key distribution channel comprises the following steps: The sending end sends a series of polarized photons to the receiving end through the QKD key distribution channel, wherein each photon represents a bit of the key; The receiving end measures each received photon by using a randomly selected basis state of itself; A verification process is performed between the sending end and the receiving end, and the part consistent with the verification is reserved as the distributed symmetric quantum key.

3. The method of claim 2, wherein, The step of performing the verification process between the sending end and the receiving end comprises the following steps: The sending end and the receiving end compare the basis states selected by themselves through the classical communication channel, and in the comparison process, the information corresponding to the part with consistent basis states is taken as the key.

4. The method of claim 1, wherein, The process of relaying the quantum security key used for encrypting the communication data to the receiving end by the access base station comprises the following steps: The sending end encrypts the quantum security key used for encrypting the data by using the paired session key between the sending end and the access base station to form key relay data ciphertext, and sends the key relay data ciphertext and the key index of the session key to the corresponding access base station; The access base station determines the corresponding session key according to the key index, decrypts the key relay data ciphertext to obtain the quantum security key, and relays the quantum security key to the receiving end. The access base station forwards the quantum secure key to the receiving end when the receiving end belongs to the access base station according to the receiving end network access identification information; forwards the quantum secure key to the access base station to which the receiving end belongs when the receiving end belongs to the same basic service area but does not belong to the access base station according to the receiving end network access identification information, and then forwards the quantum secure key to the receiving end by the access base station; forwards the quantum secure key to the corresponding border base station in the basic service area when the receiving end does not belong to the basic service area according to the receiving end network access identification information, forwards the quantum secure key to the receiving end border base station by the border base station, forwards the quantum secure key to the receiving end access base station by the receiving end border base station, and then forwards the quantum secure key to the corresponding receiving end by the receiving end access base station.

5. The method of claim 4, wherein, The paired session key between the sending end and the access base station is a quantum random number key.

6. The method of claim 4, wherein, The network access identification includes network location information and device identification information.

Citation Information

Patent Citations

  • Quantum secure communication method and device based on network access identifier, equipment and medium

    CN116346331A

  • Quantum security wide area network networking method

    CN117749364A