A method, device, equipment and storage medium for generating a vehicle-ground communication key
By automatically identifying and generating keys in the CTCS-3 train control system using wireless and quantum communication networks, the problem of easy cracking of key generation and manual distribution in vehicle-to-ground communication is solved, and efficient and reliable key management is achieved.
Patent Information
- Application Number
- CN202510279770.2
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2025-03-11
- Publication Date
- 2025-08-01
- Estimated Expiration
- 2045-03-11
AI Technical Summary
In the existing CTCS-3 train control system, the generation of vehicle-local communication keys has the risk of long-term validity and malicious cracking after the key is generated. There is a hidden danger of leakage during the manual distribution process, and the maintenance work is huge.
After the identification key expires through the wireless communication network, initial key data is generated and quantum preparation is performed. The quantum communication network is used for key exchange to realize automated key generation and secure distribution between the on-board equipment and the wireless occlusion center.
It improves the efficiency and reliability of key generation, reduces manual intervention, reduces key maintenance workload, and enhances communication security.
Smart Images

Figure CN119788280B_ABST
Abstract
Description
Technical Field
[0001] The embodiments of the present application relate to the field of communication technologies, and in particular, to the field of vehicle-ground secure communication technologies. Specifically, the embodiments of the present application relate to a method, device, equipment, and storage medium for generating vehicle-ground communication keys. Background Art
[0002] The CTCS-3 (Chinese Train Control System Level 3) train control system is the core control system of China's railway signal system, mainly composed of a Radio Block Centre (RBC) and on-vehicle equipment (Automatic Train Protection, ATP). The RBC sends a movement authority to the ATP through a wireless communication network, and the ATP calculates a speed control curve based on this to control the safe operation of the train.
[0003] Currently, for the vehicle-ground wireless communication of the CTCS-3 train control system in China, two information security measures are mainly adopted. One is that the communication between the ATP and the RBC uses the 3DES encryption algorithm, and the other is that certain technical management measures are taken for the authentication key KMAC (Keccak Message Authentication Code) used by the ATP and the RBC to run the 3DES (Triple Data Encryption Standard) algorithm. From the current KMAC key management measures, although relevant management methods have been formulated by relevant institutions, there are still certain problems in terms of key security and maintainability: for example, although one key per vehicle is adopted, the key is valid for a long time after generation, and there is a possibility of being maliciously cracked; after the KMAC key is generated, although an encryption software is used to encrypt the KMAC, the distribution method of the KMAC strongly depends on manual operation, and there is a hidden danger of being leaked by personnel during the distribution process; the key needs to be manually written to the RBC device and the ATP device. Against the background of a large number of train control devices across the country, the workload of key maintenance is huge, and there is also a possibility of incorrect writing. Summary of the Invention
[0004] The present application provides a method, device, equipment, and storage medium for generating vehicle-ground communication keys to improve the efficiency and reliability of key generation.
[0005] According to one aspect of the present application, a method for generating vehicle-ground communication keys is provided. The method is configured in the on-vehicle equipment of the train control system; the train control system further includes a Radio Block Centre; the on-vehicle equipment and the Radio Block Centre are connected by a wireless communication network and a quantum communication network; the method includes:
[0006] When it is recognized that the current message authentication key has expired, key request data is sent to the radio block center through the wireless communication network;
[0007] When receiving the key response data returned by the radio block center through the wireless communication network, initial key data of a preset number of bits is generated based on binary coding;
[0008] Quantum preparation is performed on the initial key data to obtain real-time quantum data, and the real-time quantum data is sent to the radio block center through the quantum communication network;
[0009] When receiving the quantum measurement data sent by the radio block center through the wireless communication network, a target message authentication key is determined according to the real-time quantum data and the quantum measurement data; wherein, the quantum measurement data is determined by the radio block center according to the real-time quantum data.
[0010] According to another aspect of the present application, a method for generating a vehicle-ground communication key is provided. This method is configured in the radio block center of the train control system; the train control system further includes on-vehicle equipment; the on-vehicle equipment and the radio block center are connected by a wireless communication network and a quantum communication network; this method includes:
[0011] When receiving the key request data sent by the on-vehicle equipment through the wireless communication network, key response data is determined according to the key request data, and the key response data is sent to the on-vehicle equipment through the wireless communication network;
[0012] When receiving the real-time quantum data sent by the on-vehicle equipment through the quantum communication network, quantum measurement and recording are performed on the real-time quantum data to obtain target key data; wherein, the real-time quantum data is obtained by the on-vehicle equipment performing quantum preparation on initial key data; the initial key data is generated by the on-vehicle equipment based on binary coding;
[0013] When the target key data meets the key generation condition, a target message authentication key and quantum measurement data of the target message authentication key are determined from the target key data, and the quantum measurement data is sent to the on-vehicle equipment through the wireless communication network.
[0014] According to another aspect of the present application, a device for generating a vehicle-ground communication key is provided. This device is configured in the on-vehicle equipment of the train control system; the train control system further includes a radio block center; the on-vehicle equipment and the radio block center are connected by a wireless communication network and a quantum communication network; this device includes:
[0015] A key request module, configured to send key request data to the radio block center via the wireless communication network when it is recognized that the current message authentication key has expired;
[0016] A data generation module, configured to generate initial key data of a preset number of bits based on binary coding when receiving key response data returned by the radio block center via the wireless communication network;
[0017] A quantum preparation module, configured to perform quantum preparation on the initial key data to obtain real-time quantum data, and send the real-time quantum data to the radio block center via the quantum communication network;
[0018] A first key generation module, configured to determine the target message authentication key according to the real-time quantum data and the quantum measurement data when receiving the quantum measurement data sent by the radio block center via the wireless communication network; wherein, the quantum measurement data is determined by the radio block center according to the real-time quantum data.
[0019] According to another aspect of the present application, there is provided a vehicle-ground communication key generation device, which is configured in the radio block center of the train control system; the train control system further includes on-vehicle equipment; the on-vehicle equipment and the radio block center are connected by a wireless communication network and a quantum communication network; the device includes:
[0020] A key response module, configured to determine key response data according to the key request data when receiving the key request data, and send the key response data to the on-vehicle equipment via the wireless communication network;
[0021] A quantum measurement module, configured to perform quantum measurement and record on the real-time quantum data when receiving the real-time quantum data sent by the on-vehicle equipment via the quantum communication network to obtain target key data; wherein, the real-time quantum data is obtained by the on-vehicle equipment performing quantum preparation on initial key data; the initial key data is generated by the on-vehicle equipment based on binary coding;
[0022] A second key generation module, configured to determine the target message authentication key and the quantum measurement data of the target message authentication key from the target key data when the target key data meets the key generation condition, and send the quantum measurement data to the on-vehicle equipment via the wireless communication network.
[0023] According to another aspect of the present application, there is provided an electronic device, the electronic device includes:
[0024] One or more processors;
[0025] A memory for storing one or more programs;
[0026] When the one or more programs are executed by the one or more processors, the one or more processors implement any one of the vehicle - to - ground communication key generation methods provided by the embodiments of the present application.
[0027] According to another aspect of the present application, there is provided a computer - readable storage medium, on which a computer program is stored, and when the program is executed by a processor, it implements any one of the vehicle - to - ground communication key generation methods provided by the embodiments of the present application.
[0028] According to another aspect of the present application, there is provided a computer program product, including a computer program, and when the computer program is executed by a processor, it implements any one of the vehicle - to - ground communication key generation methods provided by the embodiments of the present application.
[0029] In the present application, when it is recognized that the current message authentication key has expired, key request data is sent to the radio block center through a wireless communication network; when receiving the key response data returned by the radio block center through the wireless communication network, initial key data of a preset number of bits is generated based on binary coding; the initial key data is subjected to quantum preparation to obtain real - time quantum data, and the real - time quantum data is sent to the radio block center through a quantum communication network; when receiving the quantum measurement data sent by the radio block center through the wireless communication network, a target message authentication key is determined according to the real - time quantum data and the quantum measurement data, where the quantum measurement data is determined by the radio block center according to the real - time quantum data. The above - mentioned technical solution enables the on - vehicle device to automatically identify whether the key has expired, and in the case of expiration, combines the quantum key distribution technology to realize the generation and secure distribution of keys between the on - vehicle device and the radio block center, without manual programming, reducing the maintenance workload of train control keys, and helping to improve the efficiency and reliability of key generation. Description of the Drawings
[0030] Figure 1 is a flowchart of a vehicle - to - ground communication key generation method provided by Embodiment 1 of the present application;
[0031] Figure 2 is a flowchart of a vehicle - to - ground communication key generation method provided by Embodiment 2 of the present application;
[0032] Figure 3 is a schematic structural diagram of a vehicle - to - ground communication key generation device provided by Embodiment 3 of the present application;
[0033] Figure 4 is a schematic structural diagram of a vehicle - to - ground communication key generation device provided by Embodiment 4 of the present application;
[0034] Figure 5 It is a schematic structural diagram of an electronic device for implementing the vehicle-ground communication key generation method according to the embodiments of the present application. Detailed implementation manners
[0035] In order to enable those skilled in the art of the present technology to better understand the solutions of the present application, the technical solutions in the embodiments of the present application will be clearly and completely described below in conjunction with the accompanying drawings in the embodiments of the present application. Obviously, the described embodiments are only a part of the embodiments of the present application, rather than all the embodiments. Based on the embodiments in the present application, all other embodiments obtained by those of ordinary skill in the art without creative efforts shall fall within the protection scope of the present application.
[0036] It should be noted that the terms "first", "second", etc. in the description and claims of the present application and the above-mentioned drawings are used to distinguish similar objects, and do not necessarily need to be used to describe a specific order or sequence. It should be understood that such data used in appropriate cases can be interchanged so that the embodiments of the present application described herein can be implemented in an order other than those illustrated or described herein. In addition, the terms "comprising" and "having" and any variations thereof are intended to cover non-exclusive inclusion. For example, a process, method, system, product or device including a series of steps or units does not necessarily have to be limited to those steps or units clearly listed, but may include other steps or units not clearly listed or inherent to these processes, methods, products or devices.
[0037] In addition, it should also be noted that in the technical solutions of the present application, the collection, storage, use, processing, transmission, provision, disclosure and other processing of relevant data such as key request data and key response data comply with the provisions of relevant laws and regulations and do not violate public order and good customs.
[0038] Embodiment 1
[0039] Figure 1 It is a flowchart of a vehicle-ground communication key generation method provided according to Embodiment 1 of the present application. This embodiment is applicable to the situation of generating a message authentication key between an RBC and an ATP, and can be executed by a vehicle-ground communication key generation device. The vehicle-ground communication key generation device can be implemented in the form of hardware and / or software, and the vehicle-ground communication key generation device can be configured in a computer device, such as an on-vehicle device of a train control system; the train control system also includes a radio block center; the on-vehicle device and the radio block center are connected by a wireless communication network and a quantum communication network. As Figure 1 shown, the method includes:
[0040] S110. When it is recognized that the current message authentication key has expired, send key request data to the radio block center through the wireless communication network.
[0041] In this embodiment, the current message authentication key refers to the KMAC key locally stored in the vehicle-mounted device. The wireless communication network is a type of network that transmits data via radio waves. It does not rely on physical media (such as cables or optical fibers), but transmits data through radio frequency signals; it should be noted that the wireless communication network in this application specifically refers to the vehicle-ground GSM-R (Global System for Mobile Communications – Railway) two-way wireless communication network. The radio block center refers to the central management unit or server in the wireless communication network for key management, communication security, etc.; it is responsible for managing security tasks such as key generation, distribution, and storage to ensure the security of wireless communication. The key request data refers to the key message containing user data, which is used to verify the relevant authentication data of the vehicle-mounted device; this key message may include the device type number, message type, direction flag, device ID (Identity), the type of quantum network interface supported by the vehicle-mounted device, etc.
[0042] In an alternative embodiment, when it is recognized that the message authentication key is not locally stored, the key request data is also sent to the radio block center via the wireless communication network.
[0043] Exemplarily, when the ATP uses the existing GSM-R channel to call the RBC to establish a secure connection and finds that the KMAC key is not locally stored or the KMAC key has expired, it sends the key request data to the radio block center via the wireless communication network.
[0044] It should be noted that the validity period of the key is preset and can be flexibly configured according to the needs of the user.
[0045] S120. When receiving the key response data returned by the radio block center via the wireless communication network, generate the initial key data with a preset number of bits based on binary encoding.
[0046] In this embodiment, the key response data is generated by the radio block center, which is used to respond to the key request data and reply with a key message containing user data to verify the relevant authentication data of the radio block center; this key response data may include the device type number, message type, device ID, the type of quantum network interface supported by the radio block center, etc. Binary encoding refers to a method of converting information into a binary (0 and 1) representation form; in computer and communication systems, data is usually transmitted and stored in binary encoding. The initial key data refers to randomly generated binary data with a preset number of bits; exemplarily, randomly generate key data with a length of 32768 bits.
[0047] In an alternative embodiment, when receiving the key response data returned by the radio block center via the wireless communication network, a quantum communication interface for key response data feedback is activated, and subsequent quantum network communication is implemented using this quantum communication interface.
[0048] S130. Perform quantum preparation on the initial key data to obtain real-time quantum data, and send the real-time quantum data to the radio block center via the quantum communication network.
[0049] In this embodiment, the real-time quantum data refers to the quantum bit data and the quantum preparation bases used that are generated or transmitted in real time during quantum communication; these data can be used in processes such as encryption and key exchange, and due to the special properties of quantum bits (such as superposition and entanglement), stronger security can be provided; the real-time quantum data can include at least one of quantum key data and a set of quantum preparation bases, etc.; among them, the quantum key data refers to the quantum bit data that is generated or transmitted in real time during quantum communication; the set of quantum preparation bases refers to the quantum preparation bases used to produce quantum bit data during quantum communication. The quantum communication network refers to a network that uses the principles of quantum mechanics (such as quantum entanglement and quantum superposition) for data transmission; it can provide higher security than traditional communication, especially for key exchange and data encryption processes; the quantum communication network can be used to protect the communication content from being eavesdropped or tampered with.
[0050] Optionally, according to the candidate quantum preparation bases in the quantum key distribution protocol, perform quantum preparation on the value of each bit in the initial key data in sequence to obtain quantum key data, and send the quantum key data to the radio block center via the quantum communication network; record in sequence the candidate quantum preparation bases used for performing quantum preparation on the value of each bit in the initial key data to obtain a set of quantum preparation bases.
[0051] In this embodiment, the quantum key distribution protocol refers to a method that uses the principles of quantum mechanics to ensure the security of a shared key between two communication parties; in quantum key distribution, quantum states are used to transmit information between the two communication parties, and the confidentiality of the communication content is ensured through quantum measurement. The candidate quantum preparation bases refer to a set of ground states that can be used to prepare quantum states; for example, in the preparation process of quantum bits, different quantum ground states can be selected to represent information; the candidate quantum preparation bases refer to a set of different ground states that can be selected during the execution of the protocol; the value of each bit (0 or 1) will be used to prepare the quantum state according to these candidate bases. Quantum preparation refers to converting the initial key data into a quantum state according to the selected quantum preparation bases according to specific rules; simply put, it is to determine the corresponding quantum state according to each bit (0 or 1) and transmit these quantum states to the receiver.
[0052] Further, according to the candidate quantum preparation bases in the quantum key distribution protocol, the value of each bit in the initial key data is quantum-prepared in sequence to obtain quantum key data. Specifically, for each bit in the initial key data, a target quantum preparation base is determined from the candidate quantum preparation bases. The candidate quantum preparation bases include a horizontal polarization state straight base, a vertical polarization state straight base, a diagonal polarization state diagonal base, and an anti-diagonal polarization state diagonal base. Using the target quantum preparation base, the value of this bit is converted into a polarization state to obtain the quantum key data.
[0053] In this embodiment, the horizontal polarization state straight base represents the state of the quantum state in the horizontal polarization direction. The vertical polarization state straight base represents the state of the quantum state in the vertical polarization direction. The diagonal polarization state diagonal base represents the polarization state of the quantum state along the diagonal (45 degrees and 135 degrees). The anti-diagonal polarization state diagonal base represents the polarization state of the quantum state along the anti-diagonal (-45 degrees and +45 degrees). The polarization state is a quantum property of a quantum photon, representing the state in which the photon vibrates in a certain specific direction. Different polarization states (such as horizontal polarization, vertical polarization, diagonal polarization, and anti-diagonal polarization) are used to represent different quantum bit states in quantum key distribution. Through these polarization states, quantum key distribution can transmit encrypted information.
[0054] Exemplarily, the initial key data is encoded on 4 polarization states of two sets of conjugate bases of photons: the horizontal polarization state |H> straight base, the vertical polarization state |V> straight base; the 45° polarization state |D> diagonal base, the 135° polarization state |A> diagonal base. At the same time, the protocol defines the correspondence between the 4 polarization states and the encoded information as: |H> or |A> represents binary 0b0, |V> or |D> represents binary 0b1. ATP randomly selects one base from each of the two sets of bases, such as the straight basis vectors and the diagonal basis vectors, for preparation, encodes the initial key data bit by bit 0 and 1 into the corresponding polarization state of a single photon to obtain the quantum key data, and sends it to RBC through the quantum channel. At the same time, ATP records the selected preparation bases to obtain the set of quantum preparation bases.
[0055] S140. When receiving the quantum measurement data sent by the radio block center through the wireless communication network, determine the target message authentication key according to the real-time quantum data and the quantum measurement data. The quantum measurement data is determined by the radio block center according to the real-time quantum data.
[0056] In this embodiment, the quantum measurement data refers to the data obtained through the quantum measurement process. The quantum measurement data may include the number of quantum states and the set of quantum measurement bases. The number of quantum states refers to the number of quantum states received by the radio block center when measuring the target message authentication key. The set of quantum measurement bases refers to the set composed of the quantum measurement bases used in the quantum measurement process by the radio block center. The target message authentication key refers to the finally obtained KMAC key.
[0057] Optionally, determining the target message authentication key based on real-time quantum data and quantum measurement data may be to screen out key data with the number of quantum states from the quantum key data of the real-time quantum data to obtain candidate key data; perform quantum measurement on the candidate key data according to the quantum measurement basis set and the quantum preparation basis set of the real-time quantum data to obtain the target message authentication key.
[0058] Exemplarily, the ATP restores the correct target message authentication key according to the received number of quantum states and quantum measurement basis set, in combination with the locally selected quantum preparation basis set and quantum key data, based on the principle of a simple quantum protocol.
[0059] Further, performing quantum measurement on the candidate key data according to the quantum measurement basis set and the quantum preparation basis set of the real-time quantum data to obtain the target message authentication key may be to perform a consistency comparison between the quantum measurement basis set and the quantum preparation basis set of the real-time quantum data to determine the target measurement basis set and the number of quantum bits corresponding to each measurement basis in the target measurement basis set; taking the number of quantum bits corresponding to each measurement basis in the target measurement basis set as the quantum measurement target, and performing quantum measurement on the candidate key data according to the target measurement basis set to obtain the target message authentication key.
[0060] In this embodiment, the number of quantum bits corresponding to each measurement basis in the target measurement basis set refers to the number of quantum bits corresponding to the target message authentication key confirmed by the RBC in the candidate key data.
[0061] In an alternative embodiment, after determining the target message authentication key, key confirmation data is sent to the radio block center.
[0062] In this embodiment, the key confirmation data refers to the relevant data sent by the ATP to the RBC for confirming the successful generation of the key; this data may include the device type number of the on-vehicle device, message type, device ID, etc.
[0063] In an alternative embodiment, a timer is also set during the generation process of the target message authentication key; this timer is used to detect unacceptable delays during the generation and distribution of the KMAC key, and the timer is started before the on-vehicle device sends the key request data and ends after the on-vehicle device sends the key confirmation data. The specific value of the timer can be flexibly configured according to the quality of the wireless communication network.
[0064] Further, after the generation and distribution of the target message authentication key between the on-vehicle device and the radio block center are completed, both the vehicle and the ground use this target message authentication key for subsequent full connection establishment and wireless data communication.
[0065] In the embodiment of the present application, when it is recognized that the current message authentication key has expired, key request data is sent to the radio block center through a wireless communication network; when the key response data returned by the radio block center through the wireless communication network is received, initial key data of a preset number of bits is generated based on binary coding; quantum preparation is performed on the initial key data to obtain real-time quantum data, and the real-time quantum data is sent to the radio block center through a quantum communication network; when the quantum measurement data sent by the radio block center is received through the wireless communication network, a target message authentication key is determined according to the real-time quantum data and the quantum measurement data; wherein, the quantum measurement data is determined by the radio block center according to the real-time quantum data. In the above technical solution, the in-vehicle device automatically identifies whether the key has expired, and in the case of expiration, combined with the quantum key distribution technology, the generation and secure distribution of the key between the in-vehicle device and the radio block center are realized, without manual programming, reducing the maintenance workload of the train control key, and helping to improve the efficiency and reliability of key generation.
[0066] Embodiment 2
[0067] Figure 2 FIG. is a flowchart of a method for generating a vehicle-ground communication key according to Embodiment 2 of the present application. This embodiment is applicable to the situation of generating a message authentication key between the RBC and the ATP, and can be executed by a vehicle-ground communication key generation device. The vehicle-ground communication key generation device can be implemented in the form of hardware and / or software, and the vehicle-ground communication key generation device can be configured in a computer device, such as a radio block center in a train control system; the train control system further includes an in-vehicle device; the in-vehicle device and the radio block center are connected by a wireless communication network and a quantum communication network. As Figure 2 shown, the method includes:
[0068] S210. When the key request data sent by the in-vehicle device is received through the wireless communication network, determine the key response data according to the key request data, and send the key response data to the in-vehicle device through the wireless communication network.
[0069] In this embodiment, the key response data is generated by the radio block center, used to respond to the key request data, and reply with a key message containing user data for verifying the relevant authentication data of the radio block center; the key response data may include the device type number, message type, device ID, supported quantum network interface type, etc. of the radio block center.
[0070] Exemplarily, when the RBC receives the key request data, according to the quantum network interface type specified in the key request data, the local same-type quantum interface is enabled, and the agreed-upon same-type quantum interface is replied in the key response data.
[0071] S220. When receiving real-time quantum data sent by a vehicle-mounted device through a quantum communication network, perform quantum measurement on the real-time quantum data and record it to obtain target key data. The real-time quantum data is obtained by the vehicle-mounted device through quantum preparation of initial key data, and the initial key data is generated by the vehicle-mounted device based on binary coding.
[0072] In this embodiment, quantum measurement refers to the process of measuring a quantum system. In quantum communication, when measuring a quantum state, the value of a qubit will collapse to a definite state. For example, when a photon transmitted through quantum communication undergoes quantum measurement, according to different measurement bases, the polarization state of the photon may become a certain specific state, and the measurement result is usually a binary value (such as 0 or 1). The target key data refers to the key data obtained after quantum measurement and recording.
[0073] Optionally, performing quantum measurement on the real-time quantum data and recording it to obtain target key data may be to determine a target quantum measurement basis from candidate quantum measurement bases in a quantum key distribution protocol. The candidate quantum measurement bases include a horizontal polarization state straight basis, a vertical polarization state straight basis, a diagonal polarization state diagonal basis, and an anti-diagonal polarization state diagonal basis. Use the target quantum measurement basis to perform quantum measurement on the real-time quantum data and record it to obtain target key data.
[0074] S230. When the target key data meets the key generation condition, determine a target message authentication key and quantum measurement data of the target message authentication key from the target key data, and send the quantum measurement data to the vehicle-mounted device through a wireless communication network.
[0075] In this embodiment, the key generation condition is artificially preset according to the actual situation or empirical value. For example, this condition may be that the number of bits of the target key data is a bit number threshold.
[0076] Exemplarily, after the RBC receives the quantum state (real-time quantum data) of the photon sent by the ATP from the quantum channel, it randomly selects a set of measurement bases from two sets of bases such as the straight basis and the diagonal basis for measurement, and records the selected measurement basis, measurement result, and number of measurement bits until 192 bits of correct received data are measured. These 192 bits of data are the KMAC keys used for vehicle-ground wireless communication between the ATP and the RBC.
[0077] In an optional implementation manner, a timer is also set during the generation process of the target message authentication key. The timer is used to detect an unacceptable delay during the generation and distribution of the KMAC key. The timer is started before the vehicle-mounted device sends key request data and ends after the vehicle-mounted device sends key confirmation data. The specific value of the timer can be flexibly configured according to the quality of the wireless communication network.
[0078] Further, after the target message authentication key of the on-vehicle device and the radio block center is produced and distributed, both the vehicle and the ground use the target message authentication key for subsequent full connection establishment and wireless data communication.
[0079] When receiving the key request data sent by the on-vehicle device through the wireless communication network according to an embodiment of the present application, key response data is determined according to the key request data, and the key response data is sent to the on-vehicle device through the wireless communication network; when receiving the real-time quantum data sent by the on-vehicle device through the quantum communication network, quantum measurement is performed on the real-time quantum data and recorded to obtain target key data; wherein, the real-time quantum data is obtained by the on-vehicle device performing quantum preparation on the initial key data; the initial key data is generated by the on-vehicle device based on binary coding; when the target key data meets the key generation condition, the target message authentication key and the quantum measurement data of the target message authentication key are determined from the target key data, and the quantum measurement data is sent to the on-vehicle device through the wireless communication network. According to the above technical solution, the on-vehicle device automatically identifies whether the key has expired, and in the case of expiration, combined with the quantum key distribution technology, the generation and secure distribution of the key between the on-vehicle device and the radio block center are realized, without manual programming, reducing the maintenance workload of the train control key, and helping to improve the efficiency and reliability of key generation.
[0080] Embodiment III
[0081] Figure 3 is a schematic structural diagram of a vehicle-ground communication key generation device provided according to Embodiment III of the present application, which is applicable to the situation of message authentication key generation between the RBC and the ATP. The vehicle-ground communication key generation device can be implemented in the form of hardware and / or software, and the vehicle-ground communication key generation device can be configured in a computer device, such as an on-vehicle device of a train control system; the train control system further includes a radio block center; the on-vehicle device and the radio block center are connected by a wireless communication network and a quantum communication network. As Figure 3 shown, the device includes:
[0082] A key request module 310, configured to send key request data to the radio block center through the wireless communication network when it is recognized that the current message authentication key has expired;
[0083] A data generation module 320, configured to generate initial key data with a preset number of bits based on binary coding when receiving the key response data returned by the radio block center through the wireless communication network;
[0084] A quantum preparation module 330, configured to perform quantum preparation on the initial key data to obtain real-time quantum data, and send the real-time quantum data to the radio block center through the quantum communication network;
[0085] The first key generation module 340 is configured to determine a target message authentication key according to real-time quantum data and quantum measurement data when receiving the quantum measurement data sent by the radio block center through the wireless communication network; wherein, the quantum measurement data is determined by the radio block center according to the real-time quantum data.
[0086] In the embodiment of the present application, when it is recognized that the current message authentication key has expired, key request data is sent to the radio block center through the wireless communication network; when receiving the key response data returned by the radio block center through the wireless communication network, based on binary coding, initial key data with a preset number of bits is generated; the initial key data is subjected to quantum preparation to obtain real-time quantum data, and the real-time quantum data is sent to the radio block center through the quantum communication network; when receiving the quantum measurement data sent by the radio block center through the wireless communication network, a target message authentication key is determined according to the real-time quantum data and the quantum measurement data; wherein, the quantum measurement data is determined by the radio block center according to the real-time quantum data. The above technical solution enables the on-vehicle device to automatically identify whether the key has expired, and in the case of expiration, combines the quantum key distribution technology to realize the generation and secure distribution of keys between the on-vehicle device and the radio block center, without manual programming, reducing the maintenance workload of the train control key and helping to improve the efficiency and reliability of key generation.
[0087] Optionally, the real-time quantum data includes quantum key data and a quantum preparation basis set; correspondingly, the quantum preparation module 330 includes:
[0088] A quantum preparation unit, configured to perform quantum preparation on the value of each bit in the initial key data in sequence according to the candidate quantum preparation bases in the quantum key distribution protocol to obtain quantum key data, and send the quantum key data to the radio block center through the quantum communication network;
[0089] A data recording unit, configured to record in sequence the candidate quantum preparation bases used for performing quantum preparation on the value of each bit in the initial key data to obtain a quantum preparation basis set.
[0090] Optionally, the quantum preparation unit is specifically configured to:
[0091] For each bit in the initial key data, determine a target quantum preparation basis from the candidate quantum preparation bases; wherein, the candidate quantum preparation bases include a horizontal polarization state straight basis, a vertical polarization state straight basis, a diagonal polarization state diagonal basis, and an anti-diagonal polarization state diagonal basis;
[0092] Use the target quantum preparation basis to convert the value of this bit into a polarization state to obtain quantum key data.
[0093] Optionally, the quantum measurement data includes the number of quantum states and the set of quantum measurement bases; correspondingly, the first key generation module 340 includes:
[0094] A data screening unit, configured to screen out the key data of the number of quantum states from the quantum key data of the real-time quantum data to obtain candidate key data;
[0095] A quantum measurement unit, configured to perform quantum measurement on the candidate key data according to the set of quantum measurement bases and the set of quantum preparation bases of the real-time quantum data to obtain a target message authentication key.
[0096] Optionally, the quantum measurement unit is specifically configured to:
[0097] Perform a consistency comparison between the set of quantum measurement bases and the set of quantum preparation bases of the real-time quantum data to determine the target measurement base set and the number of quantum bits corresponding to each measurement base in the target measurement base set;
[0098] Using the number of quantum bits corresponding to each measurement base in the target measurement base set as the quantum measurement target, perform quantum measurement on the candidate key data according to the target measurement base set to obtain a target message authentication key.
[0099] The vehicle-ground communication key generation device provided by the embodiments of the present application can execute the vehicle-ground communication key generation method provided by any embodiment of the present application, and has the corresponding functional modules and beneficial effects for executing each vehicle-ground communication key generation method.
[0100] Embodiment 4
[0101] Figure 4 It is a schematic structural diagram of a vehicle-ground communication key generation device provided by Embodiment 4 of the present application, which is applicable to the situation of generating a message authentication key between an RBC and an ATP. The vehicle-ground communication key generation device can be implemented in the form of hardware and / or software, and the vehicle-ground communication key generation device can be configured in a computer device, such as a radio block center in a train control system; the train control system further includes on-vehicle equipment; the on-vehicle equipment and the radio block center are connected by a wireless communication network and a quantum communication network. As Figure 4 shown, the device includes:
[0102] A key response module 410, configured to determine key response data according to the key request data when receiving the key request data, and send the key response data to the on-vehicle equipment through the wireless communication network;
[0103] A quantum measurement module 420, configured to perform quantum measurement and record on real-time quantum data when receiving the real-time quantum data sent by a vehicle-mounted device through a quantum communication network, so as to obtain target key data; wherein, the real-time quantum data is obtained by the vehicle-mounted device performing quantum preparation on initial key data; and the initial key data is generated by the vehicle-mounted device based on binary coding.
[0104] A second key generation module 430, configured to determine a target message authentication key and quantum measurement data of the target message authentication key from the target key data when the target key data meets the key generation condition, and send the quantum measurement data to the vehicle-mounted device through a wireless communication network.
[0105] In the embodiment of the present application, when receiving key request data sent by a vehicle-mounted device through a wireless communication network, key response data is determined according to the key request data, and the key response data is sent to the vehicle-mounted device through the wireless communication network; when receiving real-time quantum data sent by the vehicle-mounted device through the quantum communication network, quantum measurement and recording are performed on the real-time quantum data to obtain target key data; wherein, the real-time quantum data is obtained by the vehicle-mounted device performing quantum preparation on initial key data; and the initial key data is generated by the vehicle-mounted device based on binary coding; when the target key data meets the key generation condition, a target message authentication key and quantum measurement data of the target message authentication key are determined from the target key data, and the quantum measurement data is sent to the vehicle-mounted device through the wireless communication network. In the above technical solution, the vehicle-mounted device automatically identifies whether the key has expired, and in the case of expiration, combined with the quantum key distribution technology, the generation and secure distribution of the key between the vehicle-mounted device and the radio block center are realized, without manual programming, reducing the maintenance workload of the train control key, and helping to improve the efficiency and reliability of key generation.
[0106] Optionally, the quantum measurement module 420 is specifically configured to:
[0107] Determine a target quantum measurement basis from candidate quantum measurement bases in a quantum key distribution protocol; wherein, the candidate quantum measurement bases include a horizontal polarization state straight basis, a vertical polarization state straight basis, a diagonal polarization state diagonal basis, and an anti-diagonal polarization state diagonal basis;
[0108] Perform quantum measurement and record on the real-time quantum data by using the target quantum measurement basis to obtain target key data.
[0109] The vehicle-ground communication key generation device provided in the embodiment of the present application can execute the vehicle-ground communication key generation method provided in any embodiment of the present application, and has corresponding functional modules and beneficial effects for executing each vehicle-ground communication key generation method.
[0110] According to an embodiment of the present application, the present application further provides an electronic device, a readable storage medium, and a computer program product.
[0111] Embodiment 5
[0112] Figure 5 FIG. 510 is a schematic structural diagram of an electronic device 510 for implementing the vehicle-ground communication key generation method according to the embodiments of the present application. The electronic device is intended to represent various forms of digital computers, such as, a laptop computer, a desktop computer, a workbench, a personal digital assistant, a server, a blade server, a mainframe computer, and other suitable computers. The electronic device can also represent various forms of mobile devices, such as, a personal digital processor, a cellular phone, a smart phone, a wearable device (such as a helmet, glasses, a watch, etc.) and other similar computing devices. The components shown herein, their connections and relationships, and their functions are only examples and are not intended to limit the implementation of the present application described and / or claimed herein.
[0113] As Figure 5 shown, the electronic device 510 includes at least one processor 511, and a memory communicatively connected to the at least one processor 511, such as a read-only memory (ROM) 512, a random access memory (RAM) 513, etc. Among them, the memory stores a computer program executable by the at least one processor. The processor 511 can perform various appropriate actions and processes according to the computer program stored in the read-only memory (ROM) 512 or the computer program loaded from the storage unit 518 into the random access memory (RAM) 513. In the RAM 513, various programs and data required for the operation of the electronic device 510 can also be stored. The processor 511, the ROM 512, and the RAM 513 are connected to each other through a bus 514. The input / output (I / O) interface 515 is also connected to the bus 514.
[0114] Multiple components in the electronic device 510 are connected to the I / O interface 515, including: an input unit 516, such as a keyboard, a mouse, etc.; an output unit 517, such as various types of displays, speakers, etc.; a storage unit 518, such as a magnetic disk, an optical disk, etc.; and a communication unit 519, such as a network card, a modem, a wireless communication transceiver, etc. The communication unit 519 allows the electronic device 510 to exchange information / data with other devices through a computer network such as the Internet and / or various telecommunication networks.
[0115] The processor 511 can be various general-purpose and / or special-purpose processing components with processing and computing capabilities. Some examples of the processor 511 include, but are not limited to, a central processing unit (CPU), a graphics processing unit (GPU), various dedicated artificial intelligence (AI) computing chips, various processors running machine learning model algorithms, a digital signal processor (DSP), and any suitable processor, controller, microcontroller, etc. The processor 511 executes the various methods and processes described above, such as the vehicle-ground communication key generation method.
[0116] In some embodiments, the vehicle-ground communication key generation method can be implemented as a computer program tangibly embodied in a computer-readable storage medium, such as the storage unit 518. In some embodiments, part or all of the computer program can be loaded and / or installed onto the electronic device 510 via the ROM 512 and / or the communication unit 519. When the computer program is loaded into the RAM 513 and executed by the processor 511, one or more steps of the vehicle-ground communication key generation method described above can be executed. Alternatively, in other embodiments, the processor 511 can be configured for the vehicle-ground communication key generation method by any other suitable means (e.g., by means of firmware).
[0117] Various embodiments of the systems and techniques described above in this document can be implemented in digital electronic circuit systems, integrated circuit systems, field-programmable gate arrays (FPGA), application-specific integrated circuits (ASIC), application-specific standard products (ASSP), systems-on-chip (SOC), complex programmable logic devices (CPLD), computer hardware, firmware, software, and / or combinations thereof. These various embodiments can include: implemented in one or more computer programs that can be executed and / or interpreted on a programmable system including at least one programmable processor, which can be a dedicated or general-purpose programmable processor that can receive data and instructions from a storage system, at least one input device, and at least one output device, and transmit the data and instructions to the storage system, the at least one input device, and the at least one output device.
[0118] The computer program for implementing the method of the present application can be written in any combination of one or more programming languages. These computer programs can be provided to the processor of a general-purpose computer, a special-purpose computer, or other programmable vehicle-ground communication key generation devices, such that when the computer program is executed by the processor, the functions / operations specified in the flowcharts and / or block diagrams are implemented. The computer program can be executed entirely on the machine, partially on the machine, as a stand-alone software package partially on the machine and partially on a remote machine, or entirely on a remote machine or server.
[0119] In the context of this application, a computer-readable storage medium can be a tangible medium that can contain or store a computer program for use by or in connection with an instruction execution system, apparatus, or device. The computer-readable storage medium can include, but is not limited to, electronic, magnetic, optical, electromagnetic, infrared, or semiconductor systems, apparatus, or devices, or any suitable combination of the foregoing. Alternatively, the computer-readable storage medium can be a machine-readable signal medium. More specific examples of a machine-readable storage medium would include an electrical connection based on one or more wires, a portable computer diskette, a hard disk, a random access memory (RAM), a read-only memory (ROM), an erasable programmable read-only memory (EPROM or Flash memory), an optical fiber, a portable compact disc read-only memory (CD-ROM), an optical storage device, a magnetic storage device, or any suitable combination of the foregoing.
[0120] To provide for interaction with a user, the systems and techniques described herein can be implemented on an electronic device having: a display device (e.g., a CRT (cathode ray tube) or LCD (liquid crystal display) monitor) for displaying information to the user; and a keyboard and a pointing device (e.g., a mouse or a trackball) by which the user can provide input to the electronic device. Other kinds of devices can also be used to provide for interaction with the user; for example, feedback provided to the user can be any form of sensory feedback (e.g., visual feedback, auditory feedback, or tactile feedback); and input from the user can be received in any form (including acoustic, speech, or tactile input).
[0121] The systems and techniques described herein can be implemented in a computing system that includes backend components (e.g., as a data server), or a computing system that includes middleware components (e.g., an application server), or a computing system that includes frontend components (e.g., a user computer having a graphical user interface or a web browser through which the user can interact with an implementation of the systems and techniques described herein), or a computing system that includes any combination of such backend components, middleware components, or frontend components. The components of the system can be interconnected by any form or medium of digital data communication (e.g., a communication network). Examples of a communication network include: a local area network (LAN), a wide area network (WAN), a blockchain network, and the Internet.
[0122] A computing system may include a client and a server. The client and the server are generally far from each other and usually interact via a communication network. The client-server relationship is created by computer programs running on respective computers and having a client-server relationship with each other. The server can be a cloud server, also known as a cloud computing server or a cloud host, which is a host product in the cloud computing service system, solving the defects of difficult management and weak business scalability existing in traditional physical hosts and VPS services.
[0123] It should be understood that various forms of processes shown above can be used, with steps reordered, added or deleted. For example, the steps recited in this application can be executed in parallel, sequentially, or in a different order, as long as the desired results of the technical solution of this application can be achieved, and no limitations are imposed herein.
[0124] The above specific embodiments do not constitute a limitation on the protection scope of this application. Those skilled in the art should understand that various modifications, combinations, sub-combinations, and substitutions can be made according to design requirements and other factors. Any modifications, equivalent substitutions, and improvements made within the spirit and principles of this application shall be included within the protection scope of this application.
Claims
1. A method for generating a vehicle-ground communication key, characterized in that, On-vehicle equipment configured in a train control system; the train control system further includes a radio block center; the on-vehicle equipment is connected to the radio block center through a wireless communication network and a quantum communication network; the method includes: When it is recognized that the current message authentication key has expired, send key request data to the radio block center through the wireless communication network; When receiving the key response data returned by the radio block center through the wireless communication network, start the quantum communication interface for feedback of the key response data, and generate initial key data of a preset number of bits based on binary coding; wherein, the quantum communication interface is used for the quantum communication network connection between the on-vehicle equipment and the radio block center; Perform quantum preparation on the initial key data to obtain real-time quantum data; the real-time quantum data includes quantum key data and a quantum preparation basis set; and send the quantum key data of the real-time quantum data to the radio block center through the quantum communication interface, including: According to the candidate quantum preparation bases in the quantum key distribution protocol, sequentially perform quantum preparation on the value of each bit in the initial key data to obtain quantum key data, and send the quantum key data to the radio block center through the wireless communication network; Sequentially record the candidate quantum preparation bases used for performing quantum preparation on the value of each bit in the initial key data to obtain a quantum preparation basis set; When receiving the quantum measurement data sent by the radio block center through the wireless communication network, screen out the key data of the quantum state quantity from the quantum key data of the real-time quantum data to obtain candidate key data; the quantum measurement data includes the quantum state quantity and a quantum measurement basis set; Perform quantum measurement on the candidate key data according to the quantum measurement basis set and the quantum preparation basis set of the real-time quantum data to obtain a target message authentication key; wherein, the quantum measurement data is determined by the radio block center according to the real-time quantum data, including: Perform quantum measurement and recording on the quantum key data by the radio block center to obtain target key data; When the target key data meets the key generation condition, determine the target message authentication key and the quantum measurement data of the target message authentication key from the target key data by the radio block center.
2. The method according to claim 1, characterized in that, According to the candidate quantum preparation bases in the quantum key distribution protocol, sequentially perform quantum preparation on the value of each bit in the initial key data to obtain quantum key data, including: For each bit in the initial key data, determine a target quantum preparation basis from the candidate quantum preparation bases; wherein, the candidate quantum preparation bases include a horizontal polarization state straight basis, a vertical polarization state straight basis, a diagonal polarization state diagonal basis, and an anti-diagonal polarization state diagonal basis; Use the target quantum preparation basis to convert the value of this bit into a polarization state to obtain quantum key data.
3. The method according to claim 1, characterized in that, The performing quantum measurement on the candidate key data according to the quantum measurement basis set and the quantum preparation basis set of the real-time quantum data to obtain a target message authentication key includes: Perform a consistency comparison between the set of quantum measurement bases and the set of quantum preparation bases of the real-time quantum data to determine the target measurement basis set and the number of quantum bits corresponding to each measurement basis in the target measurement basis set; Using the number of quantum bits corresponding to each measurement basis in the target measurement basis set as the quantum measurement target, perform quantum measurement on the candidate key data according to the target measurement basis set to obtain the target message authentication key.
4. A method for generating a vehicle-ground communication key, characterized in that, A radio block center configured in the train control system; the train control system further includes on-vehicle equipment; the on-vehicle equipment is connected to the radio block center through a wireless communication network and a quantum communication network; the method includes: When receiving the key request data sent by the on-vehicle equipment through the wireless communication network, start the local quantum interface of the same type according to the quantum network interface type in the key request data; and determine the key response data according to the key request data, and send the key response data to the on-vehicle equipment through the wireless communication network, and reply the quantum interface type agreed by both parties in the key response data; wherein, the quantum interface is used for the quantum communication network connection between the on-vehicle equipment and the radio block center; When receiving the quantum key data of the real-time quantum data sent by the on-vehicle equipment through the quantum communication network, perform quantum measurement and recording on the quantum key data to obtain the target key data; wherein, the real-time quantum data is obtained by the on-vehicle equipment through quantum preparation of the initial key data; the initial key data is generated by the on-vehicle equipment based on binary coding; the real-time quantum data includes quantum key data and a set of quantum preparation bases; the quantum key data is determined by the on-vehicle equipment according to the candidate quantum preparation bases in the quantum key distribution protocol and sequentially performing quantum preparation on the value of each bit in the initial key data; When the target key data meets the key generation condition, determine the target message authentication key and the quantum measurement data of the target message authentication key from the target key data; the quantum measurement data includes the number of quantum states and the set of quantum measurement bases; and send the quantum measurement data to the on-vehicle equipment through the wireless communication network, so that when the on-vehicle equipment receives the quantum measurement data sent by the radio block center through the wireless communication network, filter out the key data with the number of quantum states from the quantum key data of the real-time quantum data to obtain the candidate key data, and perform quantum measurement on the candidate key data according to the set of quantum measurement bases and the set of quantum preparation bases of the real-time quantum data to obtain the target message authentication key.
5. The method according to claim 4, characterized in that, Performing quantum measurement and recording on the real-time quantum data to obtain the target key data includes: Determine the target quantum measurement basis from the candidate quantum measurement bases in the quantum key distribution protocol; wherein, the candidate quantum measurement bases include the horizontal polarization state straight basis, the vertical polarization state straight basis, the diagonal polarization state diagonal basis, and the anti-diagonal polarization state diagonal basis; Using the target quantum measurement basis, perform quantum measurement on the real-time quantum data and record it to obtain target key data.
6. A vehicle-ground communication key generation device, characterized in that, An on-vehicle device configured in a train control system; the train control system further includes a radio block center; the on-vehicle device and the radio block center are connected by a wireless communication network and a quantum communication network; the device includes: A key request module, configured to send key request data to the radio block center through the wireless communication network when it is recognized that the current message authentication key has expired. A data generation module, configured to, when receiving key response data returned by the radio block center through the wireless communication network, activate the quantum communication interface for key response data feedback, and generate initial key data of a preset number of bits based on binary coding; the quantum communication interface is used for the quantum communication network connection between the on-vehicle device and the radio block center. A quantum preparation module, configured to perform quantum preparation on the initial key data to obtain real-time quantum data, and send the quantum key data of the real-time quantum data to the radio block center through the quantum communication interface; the real-time quantum data includes quantum key data and a quantum preparation basis set. A first key generation module, configured to, when receiving quantum measurement data sent by the radio block center through the wireless communication network, determine a target message authentication key according to the real-time quantum data and the quantum measurement data; wherein, the quantum measurement data includes the number of quantum states and a quantum measurement basis set; the quantum measurement data is determined by the radio block center according to the real-time quantum data, including: Performing quantum measurement on the quantum key data by the radio block center and recording it to obtain target key data. When the target key data meets the key generation condition, determining, by the radio block center, a target message authentication key and the quantum measurement data of the target message authentication key from the target key data. Wherein, the quantum preparation module includes: A quantum preparation unit, configured to perform quantum preparation on the value of each bit in the initial key data in sequence according to the candidate quantum preparation bases in the quantum key distribution protocol to obtain quantum key data, and send the quantum key data to the radio block center through the quantum communication network. A data recording unit, configured to record the candidate quantum preparation bases used for performing quantum preparation on the value of each bit in the initial key data in sequence to obtain a quantum preparation basis set. Wherein, the first key generation module includes: A data screening unit, configured to screen out the key data of the number of quantum states from the quantum key data of the real-time quantum data to obtain candidate key data. A quantum measurement unit, configured to perform quantum measurement on the candidate key data according to the quantum measurement basis set and the quantum preparation basis set of the real-time quantum data to obtain a target message authentication key.
7. A vehicle-ground communication key generation device, characterized in that, A radio block center configured in a train control system; the train control system further includes an on-vehicle device; the on-vehicle device and the radio block center are connected by a wireless communication network and a quantum communication network; the device includes: A key response module, configured to, when receiving key request data, start a local quantum interface of the same type according to the quantum network interface type in the key request data; and determine key response data according to the key request data, and send the key response data to the vehicle-mounted device through the wireless communication network, and reply the quantum interface type agreed upon by both parties in the key response data; wherein the quantum interface is used for the quantum communication network connection between the vehicle-mounted device and the radio block center; A quantum measurement module, configured to, when receiving the quantum key data of the real-time quantum data sent by the vehicle-mounted device through the quantum communication network, perform quantum measurement and record on the quantum key data to obtain target key data; wherein the real-time quantum data is obtained by the vehicle-mounted device through quantum preparation of initial key data; the initial key data is generated by the vehicle-mounted device based on binary coding; the real-time quantum data includes quantum key data and a quantum preparation basis set; the quantum key data is determined by the vehicle-mounted device according to the candidate quantum preparation bases in the quantum key distribution protocol, and sequentially performing quantum preparation on the value of each bit in the initial key data; A second key generation module, configured to, when the target key data meets the key generation condition, determine a target message authentication key and the quantum measurement data of the target message authentication key from the target key data, the quantum measurement data including the number of quantum states and a quantum measurement basis set; and send the quantum measurement data to the vehicle-mounted device through the wireless communication network, so that when the vehicle-mounted device receives the quantum measurement data sent by the radio block center through the wireless communication network, filter out the key data of the number of quantum states from the quantum key data of the real-time quantum data to obtain candidate key data, and perform quantum measurement on the candidate key data according to the quantum measurement basis set and the quantum preparation basis set of the real-time quantum data to obtain the target message authentication key.
8. An electronic device, characterized in that, Comprising: One or more processors; A memory for storing one or more programs; When the one or more programs are executed by the one or more processors, the one or more processors implement the vehicle-ground communication key generation method according to any one of claims 1-5.
9. A computer-readable storage medium having a computer program stored thereon, characterized in that, When the program is executed by the processor, it implements the vehicle-ground communication key generation method according to any one of claims 1-5.
10. A computer program product, comprising a computer program, the computer program implementing the vehicle-ground communication key generation method according to any one of claims 1-5 when executed by a processor.
Citation Information
Patent Citations
Key management method for train-ground secure communication protocol of CTCS-3 level train control system
CN109474909A
Quantum key distribution method and system
CN114817940A