Information encryption method and device, electronic equipment, storage medium and program product

By using multiple iterations of the quantum key group and random number processing, and by utilizing the polarization state measurement and key destruction mechanism of the quantum key system, the problem of rapid cracking of symmetric and asymmetric encryption methods under quantum computing is solved, thus achieving high security in information transmission.

CN119835041BActive Publication Date: 2025-11-04CHINA MOBILE INTERNET CO LTD +1
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202411973303.1
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2024-12-30
Publication Date
2025-11-04
Estimated Expiration
2044-12-30

AI Technical Summary

Technical Problem

Existing symmetric and asymmetric encryption methods are vulnerable to rapid cracking when facing the threat of quantum computing, which compromises information security during data transmission.

Method used

By using the number of quantum keys in the quantum key group and the generated random string encryption value, a target quantum key is extracted from the quantum key group, and sensitive information is encrypted using the target quantum key. Combined with the polarization state measurement and multiple iteration generation mechanism of the quantum key system, and utilizing random number XOR processing and key destruction mechanism, information security is improved.

Benefits of technology

By iterating through quantum key groups and processing random numbers, the security of information transmission is improved, the risk of quantum computing attacks is reduced, and the information is ensured to be uneavesdroppable and unbreakable during transmission.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN119835041B_ABST
    Figure CN119835041B_ABST
Patent Text Reader

Abstract

The application discloses an information encryption method and device, electronic equipment, a storage medium and a program product, and belongs to the technical field of information security, and aims to improve information security. The method comprises the following steps: extracting a target quantum key from a quantum key group according to the number of quantum keys in the quantum key group and a generated random string encryption value; and sending the target quantum key to a terminal device, so that the terminal device encrypts sensitive information to be encrypted according to the target quantum key, and obtains encrypted information.
Need to check novelty before this filing date? Find Prior Art

Description

TECHNICAL FIELD

[0001] The application belongs to the technical field of information security, and particularly relates to an information encryption method and device, electronic equipment, a storage medium and a program product. BACKGROUND

[0002] With the rapid development of the Internet era, the number of information users is increasing day by day. In the process of using APP software, personal sensitive information is at risk of being stolen. The current symmetric and asymmetric encryption methods are relatively old. With the deepening of quantum computing research, the emergence of large-scale quantum computers, many commonly used password systems will be quickly cracked. Therefore, the current encryption algorithm is at risk of being cracked by computing, which leads to the risk of modifying, imitating or replaying the transmitted information content in the data transmission process, threatening the security of communication. SUMMARY

[0003] The embodiments of the application provide an information encryption method and device, electronic equipment, a storage medium and a program product, which can solve the problem of threatening the security of communication.

[0004] In a first aspect, the embodiments of the application provide an information encryption method, which comprises: extracting a target quantum key from a quantum key group according to the number of quantum keys in the quantum key group and a generated random string encryption value; and sending the target quantum key to a terminal device, so that the terminal device encrypts sensitive information to be encrypted according to the target quantum key to obtain encrypted information.

[0005] In a second aspect, the embodiments of the application provide an information encryption method, which comprises: receiving a target quantum key sent by a server, wherein the target quantum key is extracted from a quantum key group by the server according to the number of quantum keys in the quantum key group and a generated random string encryption value; and encrypting sensitive information to be encrypted by using the target quantum key to obtain encrypted information.

[0006] In a third aspect, the embodiments of the application provide an information encryption device, which comprises: a working module configured to extract a target quantum key from a quantum key group according to the number of quantum keys in the quantum key group and a generated random string encryption value; and a sending module configured to send the target quantum key to a terminal device, so that the terminal device encrypts sensitive information to be encrypted according to the target quantum key to obtain encrypted information.

[0007] In a fourth aspect, an information encryption apparatus is provided. The apparatus includes a receiving module configured to receive a target quantum key sent by a server, wherein the target quantum key is extracted from a quantum key group according to a number of quantum keys in the quantum key group and a generated random string encryption value; and a processing module configured to encrypt sensitive information to be encrypted by using the target quantum key to obtain encrypted information.

[0008] In a fifth aspect, an electronic device is provided. The electronic device includes a processor, a memory, and a program or instructions stored in the memory and executable on the processor. When the program or instructions are executed by the processor, the steps of the method according to the first aspect or the steps of the method according to the second aspect are implemented.

[0009] In a sixth aspect, a readable storage medium is provided. The readable storage medium stores a program or instructions. When the program or instructions are executed by a processor, the steps of the method according to the first aspect or the steps of the method according to the second aspect are implemented.

[0010] In a seventh aspect, a computer program product is provided. The computer program product includes a computer program stored on a non-transitory computer-readable storage medium. The computer program includes program instructions that, when executed by a computer, cause the computer to perform the steps of the method according to the first aspect or the steps of the method according to the second aspect.

[0011] In the embodiments of the present application, the target quantum key is extracted from the quantum key group according to the number of quantum keys in the quantum key group and the generated random string encryption value, and the target quantum key is sent to a terminal device to enable the terminal device to encrypt sensitive information to be encrypted according to the target quantum key to obtain encrypted information, thereby improving the security of information. BRIEF DESCRIPTION OF DRAWINGS

[0012] Figure 1 is a flowchart of an information encryption method provided by the embodiments of the present application;

[0013] Figure 2 is a schematic diagram of a quantum key system provided by the embodiments of the present application;

[0014] Figure 3 is a schematic diagram of terminal information processing provided by the embodiments of the present application;

[0015] Figure 4 is a schematic diagram of server information processing provided by the embodiments of the present application;

[0016] Figure 5is a flowchart of another information encryption method provided by an embodiment of the present application;

[0017] Figure 6 is a flowchart of an information interaction process provided by an embodiment of the present application;

[0018] Figure 7 is a structural diagram of an information encryption device provided by an embodiment of the present application;

[0019] Figure 8 is a structural diagram of another information encryption device provided by an embodiment of the present application;

[0020] Figure 9 is a structural diagram of an electronic device provided by an embodiment of the present application. DETAILED DESCRIPTION

[0021] The technical solutions in the embodiments of the present application will be clearly and completely described below with reference to the drawings in the embodiments of the present application. Obviously, the described embodiments are some but not all of the embodiments of the present application. Based on the embodiments in the present application, all other embodiments obtained by those of ordinary skill in the art without creative work fall within the scope of the present application.

[0022] The terms "first", "second", and the like in the specification and claims of the present application are used to distinguish similar objects, and are not used to describe a specific order or sequence. It should be understood that the data used in this way can be interchanged under appropriate circumstances, so that the embodiments of the present application can be implemented in an order other than those illustrated or described herein, and the objects distinguished by "first", "second", etc. are usually a class, not limited to the number of objects, for example, the first object can be one or more. In addition, "and / or" in the specification and claims indicates at least one of the connected objects, and the character " / ", generally indicates that the front and rear associated objects are in an "or" relationship.

[0023] The information encryption method, device, electronic device, storage medium and program product provided by the embodiments of the present application will be described in detail below with reference to the drawings and specific embodiments and their application scenarios.

[0024] Figure 1 An information encryption method provided by one embodiment of the present application is shown, which can be executed by a server. In other words, the method can be executed by software or hardware installed on the server, and the method includes the following steps:

[0025] Step 102: According to the number of quantum keys in the quantum key group and the generated random string encryption value, a target quantum key is extracted from the quantum key group.

[0026] In the embodiment of the present application, the target quantum key is extracted from the quantum key group by the server according to the number of quantum keys in the quantum key group and the generated random string encrypted value. Specifically, the application of the terminal device can access the mobile authentication SDK capability, thereby enabling the terminal device of the user to obtain the number. After the mobile terminal obtains the basic user information such as the mobile phone number, device number, and device machine IP, the message can be temporarily saved.

[0027] The terminal device (also referred to as a mobile authentication function server) initiates a quantum encryption request to the server (also referred to as a quantum key server) in turn, and the server obtains a quantum key from a quantum key system. The quantum key is based on the indivisibility and unclonability of quantum, uses the polarization state fluctuation of photons and the principle of measurement basis of photons, generates multiple groups of quantum bit data, randomly selects a test basis, discloses part of the bit segment, and finally intercepts a segment of the disclosed data for comparison. If the comparison result is the same, the undisclosed part can be used as a common key. If the comparison result is different, it means that there is a hacker to eavesdrop on the data, and the communication is invalid.

[0028] In the embodiment of the present application, a quantum key system is provided, as shown in Figure 2 The quantum key system integrates a quantum key distribution system (QKM) and an electronic code machine (ECM), wherein the quantum key distribution system (QKM) obtains quantum random numbers from the electronic code machine (ECM) to generate a quantum encryption key (QEK). The above process is iterated multiple times, and the electronic code machine (ECM) generates a quantum encryption key group (QEKG). As shown in Table 1 below, the QKM randomly selects two groups of polarization orthogonal bases ( and (represented by ) and (represented by ) ) to coordinate the transmission of single photons. If the polarization bases of the sending end and the polarization bases of the receiver are the same, the correct key value is obtained. If they are different, the random distribution will be allocated to a certain receiver.

[0029] Table 1

[0030]

[0031] In an implementation, before the target quantum key is extracted from the quantum key group according to the number of quantum keys in the quantum key group and the generated random string encryption value, the method further includes: receiving single photon information sent by the quantum key system through a preselected polarization basis; converting the single photon information into photon information bits according to single photon polarization measurement, and sending the photon information bits to the quantum key system; receiving single photon information polarization states of the single photon information sent by the quantum key system; comparing bit values of corresponding single photon information polarization states and photon information bits through the quantum key system and the server, and taking a non-disclosed part in the same bit value as a quantum key, thereby forming the quantum key group.

[0032] Specifically, the iterative generation process of the quantum key group is as follows: the quantum key system randomly selects a set of polarization bases, modulates single photon information according to the polarization bases, and assumes that the single photon information is (100111010); the server randomly selects a set of polarization bases to receive the single photon information, converts the single photon information into a set of photon information bits according to single photon polarization measurement, and assumes that the photon information bits are (100010011), and transmits the photon information bits to the quantum key system through a channel. Meanwhile, the quantum key system also discloses single photon information polarization states to the server. The quantum key system and the server select corresponding single photon information polarization states and photon information bits, select a bit value to publish, and if there is a difference in the sequence, it indicates that there is a phenomenon of eavesdropping and tampering, and the key acquisition is failed. If there is no difference, the non-disclosed part in the same bit value can be used as the final key value. As shown in the following table, the final generated key fragment is 011.

[0033] Table 2

[0034]

[0035] In an implementation, after the bit values of the corresponding single photon information polarization states and the photon information bits are compared by the quantum key system and the server, the method further includes: when the proportion of quantum keys that fail in the comparison exceeds a threshold value, regenerating the quantum key group; and performing exclusive OR processing on the quantum keys through a generated quantum key random number.

[0036] In order to further improve the security of the key, the embodiments of the application add a multiple iteration mechanism to the key generation rule on the basis of the quantum key generation principle, in order to avoid the waste of resources caused by multiple retries after a failed key acquisition. The failed polarization states are controlled in the multiple iteration mechanism, as follows:

[0037] ={ ... }

[0038] wherein represent quantum keys with a risk of eavesdropping due to a failure in polarization state comparison, a threshold value is set :

[0039] >

[0040] When the threshold value is exceeded, it is proved that the quantum key group has a high risk, and the quantum key group is discarded and a new quantum key group is generated.

[0041] After the quantum key is compared with the polarization state for multiple times, a quantum key group is generated and returned to the server of the business party for storage. In order to ensure the confidentiality of the storage, a quantum key random number is generated by a random number machine , and an exclusive or operation is performed on the random number to prevent the risk of theft in the machine storage cache, as follows:

[0042] ={ ... }

[0043] In this way, after the server obtains the quantum key group, a target quantum key can be extracted from the quantum key group according to the number of quantum keys in the quantum key group and the encrypted value of the generated random string.

[0044] A plurality of quantum key groups are generated by using the polarization state measurement basis of the quantum key, the failure rate of key matching is controlled, a related threshold value is set, and the quantum key groups with a high failure rate are removed. Meanwhile, an exclusive or operation is performed on the quantum key by using a plurality of random numbers, so that even if the data in the cache is leaked, a hacker cannot obtain the specific value of the quantum key.

[0045] Step 104: sending the target quantum key to the terminal device, so that the terminal device encrypts the sensitive information to be encrypted according to the target quantum key to obtain encrypted information.

[0046] Specifically, after the terminal device requests the quantum key from the server, the server can send the extracted target quantum key to the terminal device, so that the terminal device encrypts the sensitive information to be encrypted according to the target quantum key to obtain encrypted information.

[0047] The information encryption method provided by the embodiment of the application extracts a target quantum key from the quantum key group according to the number of quantum keys in the quantum key group and a generated random string encryption value; the target quantum key is sent to a terminal device, so that the terminal device encrypts sensitive information to be encrypted according to the target quantum key, and obtains encrypted information; a certain number of quantum key sets are obtained from a quantum key system, and then server caching is performed, and the terminal device is delivered, wherein a random string encryption value hash value is used for random extraction disturbance, and finally a suitable quantum key is selected for encryption, the safety of information transmission in the whole process is realized, and the safety of information can be improved.

[0048] In an implementation manner, before the step of obtaining the quantum key set according to the number of quantum keys in the quantum key group and the generated random string encryption value, the method further includes: receiving a signature value, encrypted data and encrypted ciphertext sent by the terminal device, wherein the encrypted data and the encrypted ciphertext are generated by the terminal device according to a random number and a data set, the data set is generated by the terminal device by splicing a timestamp and a server sent credential, and the signature value is obtained by the terminal device by signing related information in a data transmission process.

[0049] Specifically, after obtaining the key set, the server returns a credential to the terminal device , as shown in the figure. Figure 3 The terminal device stores the credential and splices the credential with a timestamp to form a data set , as follows:

[0050] ={ || }

[0051] The terminal device signs related data in a transmission process by using a private key of an SM2 algorithm, and the related data includes an Ip request end , a request end Mac device number , a user service number code , a single transaction serial number , and a timestamp . The signature value is mainly used for checking information. A client side initiates a digest. After the server receives the information, the signature value is checked to confirm that the information comes from the client side and not from an unknown request end. The following formula is used:

[0052] Sign= ( || || || || )

[0053] SDK terminal device pre-embedded server SM2 public key , the terminal device is used for transmitting a user data set , using SM4 algorithm, taking Rand as the key for symmetric encryption, generating encrypted data SC, the formula is as follows:

[0054] SC= (Rand )

[0055] After obtaining the SC value, using the SM2 algorithm, using the server public key Asymmetric encryption of random number Rand, get encrypted ciphertext SR, the formula is as follows:

[0056] SR=Enc( (Rand ))

[0057] The terminal device obtains the server public key, SC, SR and other related information after obtaining SC and SR values, and summarizes them into a data packet Req={ , SC, SR}, and transmits it to the server through https. The server can receive the signature value, encrypted data and encrypted ciphertext sent by the terminal device.

[0058] In an implementation mode, the target quantum key is extracted from the quantum key group according to the number of quantum keys in the quantum key group and the generated random string encryption value, comprising: verifying the signature value, in the case of passing verification, decrypting the ciphertext to obtain the random number; decrypting the encrypted data to obtain the data set; parsing the data set to obtain the voucher; in the case of successfully verifying the voucher, according to the number of quantum keys in the quantum key group and the generated random string encryption value, extracting the target quantum key from the quantum key group.

[0059] Figure 4 A server information processing flowchart provided by an embodiment of the application is shown, as shown in Figure 4 After receiving the data packet Req packet, the server parses the data packet and uses the SM2 algorithm to verify the signature value || || || || ) data, and after verifying the signature value, the encrypted ciphertext SR parameter is decrypted by SM2 to obtain the Rand parameter, the formula is as follows:

[0060] Rand=Dec( (SR ))

[0061] After obtaining the Rand parameter, the server uses the SM4 symmetric algorithm to decrypt the encrypted data SC, thus obtaining the data set. The formula is as follows:

[0062] = (Rand SC)

[0063] Obtain the data set Then, the server performs parsing to obtain the credentials. The server can verify the credentials. Once the information is verified, it can extract the target quantum key from the quantum key group based on the number of quantum keys in the quantum key group and the generated random string encryption value.

[0064] In one implementation, the step of extracting a target quantum key from the quantum key group based on the number of quantum keys in the quantum key group and the generated random string encryption value includes: using the hash value obtained by hashing the generated random string as the random string encryption value; performing a modulo operation on the number of quantum keys in the quantum key group using the random string encryption value, and extracting the corresponding quantum key from the quantum key group as the target quantum key based on the obtained modulo value.

[0065] To further enhance the security and reliability of encryption, the server generates a 32-bit non-repeating random string. Based on this random string, a hash function is performed to obtain the encrypted random string value. Then, the random number is extracted from the key set, and the array is modulo-calculated using the following formula:

[0066] Num= ) mod

[0067] in, ) represents a random number The encrypted value of the random string. This represents the number of quantum keys in the entire quantum key pool, and Num represents the number of the selected quantum key.

[0068] After obtaining the modulus parameter, the Num-th target quantum key is extracted and returned to the client along with a random string. Simultaneously, the server uses the randomly generated string as a cached key-value pair corresponding to the target quantum key. Implement caching.

[0069] In the sending the target quantum key to the terminal device, so that the terminal device encrypts the sensitive information to be encrypted according to the target quantum key to obtain encrypted information, the method further includes: receiving the encrypted information sent by the terminal device; and decrypting the encrypted information by using the target quantum key to obtain the sensitive information.

[0070] Specifically, after receiving the target quantum key, the terminal device can encrypt the sensitive information by using the target quantum key to obtain encrypted information, and then send the encrypted information to the server. After receiving the encrypted information, the server can obtain the corresponding target quantum key from the cache according to the random string , and perform quantum key decryption of the encrypted information by using SM4 to obtain the sensitive information.

[0071] In an implementation manner, after the sending the target quantum key to the terminal device, so that the terminal device encrypts the sensitive information to be encrypted according to the target quantum key to obtain encrypted information, the method further includes: destroying the used target quantum key.

[0072] Meanwhile, in order to maintain the uncertainty of the key group and avoid the possibility that the key is used multiple times or stored for a long time and then stolen by an external party, a key destruction mechanism is arranged in the quantum key group. After obtaining the quantum key, the server destroys the target quantum key in the quantum key group after the encryption and decryption process.

[0073] In an implementation manner, after the extracting the target quantum key from the quantum key group according to the number of quantum keys in the quantum key group and the encrypted value of the generated random string, the method further includes: in a case where the number of quantum keys remaining in the quantum key group after destroying the target quantum key is less than a number threshold, destroying the quantum key group; and in a case where the time counting after obtaining the quantum key group exceeds a time threshold, destroying the quantum key group.

[0074] The key destruction mechanism is arranged in the embodiment of the application, and a minimum number of keys and an expiration time are further arranged. When the number of keys remaining after the destruction of the key group is N, and N , the entire key group is destroyed and a new key group is generated. After obtaining the quantum key group, the server starts to count time, and the time is T. When the time T , a timeout destruction mechanism is triggered, the time of the entire key group is too long, and the entire key group is destroyed and updated.

[0075] The time wheel destruction mechanism is used to destroy the used target quantum key, and the unused quantum key that exceeds the time limit is cleared in time. After the clearing, the quantum key is updated, the uncertainty of the key group key is maintained, and the possibility of being cracked is further reduced.

[0076] Figure 5 Another information encryption method provided by the embodiment of the application is shown, the method is executed by a terminal device, and the method includes the following steps.

[0077] Step 502: receiving a target quantum key sent by a server.

[0078] Specifically, after the server extracts the quantum key from the key group, the target quantum key can be sent to the terminal device, and the terminal device can receive the target quantum key sent by the server. The target quantum key is extracted from the quantum key group according to the number of quantum keys in the quantum key group and a generated random string encryption value.

[0079] Step 504: encrypting sensitive information to be encrypted by using the target quantum key to obtain encrypted information.

[0080] Specifically, after the terminal device receives the target quantum key, the SM4 algorithm is used to encrypt the user sensitive message to be transmitted to form encrypted information , and the encrypted information is transmitted to the server through https.

[0081] = Enc( ( ))

[0082] Wherein represents the encrypted information after the client encryption, and the encrypted information is transmitted to the server through https.

[0083] After the server receives and the like, the corresponding target quantum key is obtained from the cache by using a random string, and SM4 quantum key decryption is performed on .

[0084] The information encryption method provided by the embodiment of the application comprises the following steps: receiving a target quantum key sent by a server, wherein the target quantum key is extracted from a quantum key group according to a number of quantum keys in the quantum key group and a random string encryption value generated by the server; and encrypting sensitive information to be encrypted by using the target quantum key to obtain encrypted information, and finally selecting a suitable quantum key to encrypt the sensitive information by using a random string encryption value hash value for random extraction and disturbance, so that the security of information in the whole process is ensured and the security of the information is improved.

[0085] In an implementation manner, the random string encryption value is a hash value obtained by performing hash processing on the generated random string by the server.

[0086] In order to further improve the security and reliability of the encryption, the server generates a 32-bit non-repeated random string, performs hash processing on the generated random string to obtain a random string encryption value, and then performs random number extraction on the quantum key group, and performs modulo processing on the array according to the following formula:

[0087] Num= ) mod

[0088] wherein, represents the random number random string encryption value, represents the number of quantum keys in the whole quantum key group, and Num represents the number of the extracted quantum key.

[0089] After the modulo value parameter is obtained, the Numth target quantum key is extracted, and the target quantum key and the random string are returned to the client, and the server caches the corresponding target quantum key by using the randomly generated string as a cache key value.

[0090] In an implementation manner, before the target quantum key sent by the server is received, the following steps are further included: splicing a timestamp and a server sending credential to generate a data set; signing relevant information in a data transmission process to obtain a signature value; generating encrypted data corresponding to the data set and encrypted ciphertext corresponding to the random number according to the random number and the data set; and sending the signature value, the encrypted data and the encrypted ciphertext to the server, so that the server extracts the target quantum key from the quantum key group in a case where the server successfully checks the signature value, the encrypted data and the encrypted ciphertext.

[0091] Specifically, as Figure 3As shown, specifically, the server returns the voucher to the terminal device after obtaining the key group The terminal device stores the voucher and splices the timestamp to form a data set As follows:

[0092] ={ || }

[0093] The terminal device will transmit the relevant data in the transmission process, including the IP request end transmitted by the client SDK Request end Mac device number User service number code Single transaction serial number Timestamp The signature value obtained by signing the above relevant information by the SM2 algorithm private key is mainly used for checking information. The client side initiates a digest, and the server receives the information and checks the signature value to confirm that the information comes from the client side, rather than from an unknown request end, as follows:

[0094] Sign= ( || || || || )

[0095] In one implementation, the method further includes: performing symmetric encryption on the data set by using the random number to obtain the encrypted data; and performing asymmetric encryption on the random number to obtain the encrypted ciphertext.

[0096] Specifically, the SDK terminal device pre-buries the server SM2 public key The server generates a random number Rand using a random number machine, and the terminal device uses the SM4 algorithm to perform symmetric encryption on the transmitted user data set using Rand as the key to generate encrypted data SC, as follows:

[0097] SC= (Rand )

[0098] After obtaining the SC value, the SM2 algorithm is used to perform asymmetric encryption on the random number Rand using the server public key to obtain the encrypted ciphertext SR, as follows:

[0099] SR=Enc( (Rand ))

[0100] The terminal device, after obtaining the SC and SR values, aggregates the server public key and related information such as SC and SR into a data packet Req={SC, SR}, and transmits the data packet to the server through https.

[0101] An information interaction process provided by an embodiment of the present application is shown. As shown in FIG. 1, a server requests a quantum key system for quantum key distribution, the quantum key system obtains a random number, generates a quantum key, generates a quantum key group through multiple iterations, and distributes the quantum key group to the server. After obtaining the key group, the server returns a credential to a terminal device. The terminal device signs related information by using a server private key SC, randomly generates a random number R, and performs symmetric encryption on R and the credential information by using an SM4 block encryption algorithm. Then, the terminal device encrypts the random number R by using an SM2 algorithm and an authentication server public key PS. After the server performs non-block decryption of SM2 and symmetric decryption of SM4, the server obtains the credential and verifies the validity of the credential, and distributes a target quantum key and a random string. After the related information is returned to the terminal device, the terminal device encrypts user sensitive information by using the SM4 algorithm and the quantum key, transmits the encrypted information to the server, the server obtains the target quantum key according to the random string, and decrypts the encrypted information. Figure 6 Figure 6 In an embodiment of the present application, the role of generating a quantum key group is mainly to obtain an entire data set based on the principle of quantum polarization state and measurement through a request of a quantum key system once. One-time calling connection can reduce frequent calling of the quantum system, and generation of a random string and hashization and modulus operation can make each request use the quantum key evenly, so that the risk of cracking due to fixed use of a specific key value is avoided, and security is further improved.

[0102] In an embodiment of the present application, the role of generating a quantum key group is mainly to obtain an entire data set based on the principle of quantum polarization state and measurement through a request of a quantum key system once. One-time calling connection can reduce frequent calling of the quantum system, and generation of a random string and hashization and modulus operation can make each request use the quantum key evenly, so that the risk of cracking due to fixed use of a specific key value is avoided, and security is further improved.

[0103] ​The embodiment of the application uses a quantum key system to generate a quantum key group, uses a randomly generated character string for formal analysis, and cooperates with digital envelope encryption to solidify information transmission security. In order to avoid the fixed quantum key being obtained by hackers through network technology in the storage and transmission process. The quantum key distribution system generates a quantum key group through multiple iterations. In the storage process, the system integrates a quantum key distribution machine (QKM) to further optimize quantum key distribution (QKD), further cooperates with the national secret algorithm SM2 and SM4, thereby resisting quantum computing attacks. After quantum key generation iteration and multiple polarization base selection, a quantum key combination is formed, as shown below:

[0104] ={ ... }

[0105] The embodiment of the application generates a quantum key random number through a random number machine after the quantum key system generates a quantum key group , and prevents the risk of theft in the machine storage cache through random number XOR processing, as shown below:

[0106] ={ ... }

[0107] After the terminal device obtains the credential and the random character string, when requesting a quantum key from the server, the server will select the target quantum key according to the hash value, and then transmit the XOR processed quantum key result to the terminal device. The terminal device extracts the target quantum key and performs encryption processing on the sensitive information to obtain encrypted information, and then transmits it to the server. The server extracts the terminal device for decryption. In the transmission process, the attacker cannot identify the internal conversion rule, and even if he gets the encrypted information in the network transmission, he cannot extract the key.

[0108] In comparison with the traditional asymmetric encryption algorithm RSA and the symmetric algorithm AES, the encryption and decryption of the SM2 and SM4 national secret algorithms take almost the same time, while the encryption and decryption of RSA obviously increase with the increase of encrypted data. The growth of the encryption and decryption time of the national secret algorithm is relatively flat compared with RSA. Compared with the traditional RSA+quantum key encryption combination, the performance is more advantageous.

[0109] It should be noted that the information encryption method provided in the embodiments of the present application can be executed by an information encryption device, or a control module in the information encryption device for executing the information encryption method. In the embodiments of the present application, the information encryption device is taken as an example to illustrate the information encryption device provided in the embodiments of the present application.

[0110] Figure 7 FIG. 7 is a structural schematic diagram of an information encryption device according to an embodiment of the present application. As shown in FIG. 7, the information encryption device 700 includes a working module 710 and a sending module 720. Figure 7

[0111] The working module 710 is configured to extract a target quantum key from a quantum key group according to a number of quantum keys in the quantum key group and a generated random string encryption value.The sending module 720 is configured to send the target quantum key to a terminal device, so that the terminal device encrypts sensitive information to be encrypted according to the target quantum key to obtain encrypted information.

[0112] In an implementation manner, the working module 710 is further configured to receive a signature value, encrypted data and encrypted ciphertext sent by the terminal device, wherein the encrypted data and the encrypted ciphertext are generated by the terminal device according to a random number and a data set, the data set is generated by the terminal device by splicing a time stamp and a server sent credential, and the signature value is obtained by the terminal device by signing relevant information in a data transmission process.

[0113] In an implementation manner, the working module 710 is configured to verify the signature value, decrypt the encrypted ciphertext to obtain the random number in a case where the verification is passed, decrypt the encrypted data to obtain the data set, analyze the data set to obtain the credential, and extract a target quantum key from a quantum key group according to a number of quantum keys in the quantum key group and a generated random string encryption value in a case where the credential is verified successfully.

[0114] In an implementation manner, the working module 710 is configured to obtain a hash value by performing hash processing on the generated random string as the random string encryption value, perform modulo processing on the number of quantum keys in the quantum key group through the random string encryption value, and extract a corresponding quantum key from the quantum key group as the target quantum key according to a obtained modulus value.

[0115] In an implementation manner, the working module 710 is further configured to receive the encrypted information sent by the terminal device, and decrypt the encrypted information through the target quantum key to obtain the sensitive information.

[0116] In an implementation manner, the working module 710 is further configured to destroy the used target quantum key.

[0117] In an implementation manner, the working module 710 is further configured to, in a case where the number of quantum keys remaining in the quantum key group after destroying the target quantum key is less than a number threshold, destroy the quantum key group; and in a case where a time threshold is exceeded in timing after obtaining the quantum key group, destroy the quantum key group.

[0118] In an implementation manner, the working module 710 is configured to receive single-photon information sent by a quantum key system through a preselected polarization basis; convert the single-photon information into photon information bits according to single-photon polarization measurement; send the photon information bits to the quantum key system; receive single-photon information polarization states of the single-photon information sent by the quantum key system; compare corresponding single-photon information polarization states and bit values of the photon information bits through the quantum key system and the server; and take a part not disclosed in the same bit value as a quantum key, thereby forming the quantum key group.

[0119] In an implementation manner, the working module 710 is further configured to, in a case where a proportion of quantum keys that fail in comparison exceeds a threshold, regenerate a quantum key group; and perform exclusive OR processing on the quantum keys through a generated quantum key random number.

[0120] The information encryption apparatus in the embodiments of the present application can be an apparatus, a component in a terminal, an integrated circuit, or a chip. The apparatus can be a mobile electronic device or a non-mobile electronic device. Exemplarily, the mobile electronic device can be a mobile phone, a tablet computer, a notebook computer, a palm computer, a vehicle-mounted electronic device, a wearable device, an ultra-mobile personal computer (UMPC), a netbook, or a personal digital assistant (PDA), etc., and the non-mobile electronic device can be a server, a network attached storage (NAS), a personal computer (PC), a television (TV), a teller machine, or a self-service machine, etc., and the embodiments of the present application are not limited in this regard.

[0121] The information encryption apparatus in the embodiments of the present application can be an apparatus with an operating system. The operating system can be an Android operating system, an ios operating system, or other possible operating systems, and the embodiments of the present application are not limited in this regard.

[0122] The information encryption device provided by the embodiments of the present application can realize Figures 1 to 4 The method embodiments realize various processes, and thus details are not repeated here.

[0123] Figure 8 is a structural schematic diagram of the information encryption device according to the embodiments of the present application. As shown in Figure 8 The information encryption device 800 includes a receiving module 810 and a processing module 820.

[0124] The receiving module 810 is configured to receive a target quantum key sent by a server, wherein the target quantum key is extracted from a quantum key group by the server according to a number of quantum keys in the quantum key group and a random string encryption value generated by the server. The processing module 820 is configured to encrypt sensitive information to be encrypted by using the target quantum key to obtain encrypted information.

[0125] In an implementation manner, the random string encryption value is a hash value obtained by performing hash processing on the generated random string by the server.

[0126] In an implementation manner, the processing module 820 is further configured to splice a timestamp and the server-sent credential to generate a data set, sign related information in a data transmission process to obtain a signature value, generate encrypted data corresponding to the data set and encrypted ciphertext corresponding to a random number according to the random number and the data set, and send the signature value, the encrypted data and the encrypted ciphertext to the server, so that the server extracts the target quantum key from the quantum key group in a case where verification is successful according to the signature value, the encrypted data and the encrypted ciphertext.

[0127] In an implementation manner, the processing module 820 is configured to perform symmetric encryption on the data set by using the random number to obtain the encrypted data, and perform asymmetric encryption on the random number to obtain the encrypted ciphertext.

[0128] The information encryption apparatus in the embodiments of the present application can be an apparatus, or a component, an integrated circuit, or a chip in a terminal. The apparatus can be a mobile electronic device or a non-mobile electronic device. Exemplarily, the mobile electronic device can be a mobile phone, a tablet computer, a notebook computer, a palm computer, a vehicle-mounted electronic device, a wearable device, an ultra-mobile personal computer (UMPC), a netbook, or a personal digital assistant (PDA), etc., and the non-mobile electronic device can be a server, a network attached storage (NAS), a personal computer (PC), a television (TV), a teller machine, or a self-service machine, etc., and the embodiments of the present application are not limited in this regard.

[0129] The information encryption apparatus in the embodiments of the present application can be an apparatus with an operating system. The operating system can be an Android operating system, an ios operating system, or other possible operating systems, and the embodiments of the present application are not limited in this regard.

[0130] The information encryption apparatus provided in the embodiments of the present application can implement Figure 3 and Figure 5 The processes implemented by the method embodiments are not repeated here to avoid repetition.

[0131] As shown in Figure 9 , the embodiments of the present application further provide an electronic device 900, which includes a processor 901 and a memory 902, and the memory 902 has stored programs or instructions executable on the processor 901, and the programs or instructions are executed by the processor 901 to implement the following: extracting a target quantum key from a quantum key group according to a number of quantum keys in the quantum key group and a generated random string encryption value; and sending the target quantum key to a terminal device, so that the terminal device encrypts sensitive information to be encrypted according to the target quantum key to obtain encrypted information.

[0132] In an implementation manner, before the extracting a target quantum key from a quantum key group according to a number of quantum keys in the quantum key group and a generated random string encryption value, a signature value, encrypted data, and encrypted ciphertext sent by the terminal device are received, wherein the encrypted data and the encrypted ciphertext are generated by the terminal device according to a random number and a data set, the data set is generated by the terminal device by splicing a time stamp and a credential sent by the server, and the signature value is obtained by the terminal device by signing relevant information in a data transmission process.

[0133] In an implementation, the signature value is verified, and in the case of verification success, the encrypted ciphertext is decrypted to obtain the random number; the encrypted data is decrypted to obtain the data set; the data set is parsed to obtain the credential;

[0134] In the case of successful verification of the credential, a target quantum key is extracted from a quantum key group according to a number of quantum keys in the quantum key group and a generated random string encryption value.

[0135] In an implementation, a hash value obtained by performing hash processing on the generated random string is used as the random string encryption value; the number of quantum keys in the quantum key group is processed by taking a modulus of the random string encryption value, and a corresponding quantum key is extracted from the quantum key group as the target quantum key according to a modulus value obtained.

[0136] In an implementation, after the target quantum key is sent to a terminal device to enable the terminal device to encrypt sensitive information to be encrypted according to the target quantum key to obtain encrypted information, the encrypted information sent by the terminal device is received; the encrypted information is decrypted by using the target quantum key to obtain the sensitive information.

[0137] In an implementation, after the target quantum key is sent to a terminal device to enable the terminal device to encrypt sensitive information to be encrypted according to the target quantum key to obtain encrypted information, the target quantum key used is destroyed.

[0138] In an implementation, after the target quantum key is extracted from the quantum key group according to the number of quantum keys in the quantum key group and the generated random string encryption value, in the case that the number of quantum keys remaining in the quantum key group after the target quantum key is destroyed is less than a number threshold, the quantum key group is destroyed; after the quantum key group is obtained, timing is performed, and in the case that a timing time exceeds a time threshold, the quantum key group is destroyed.

[0139] In an implementation, before the target quantum key is extracted from the quantum key group according to the number of quantum keys in the quantum key group and the random string encryption value generated by the server, the method further includes: receiving single photon information sent by the quantum key system through a preselected polarization basis; converting the single photon information into photon information bits according to single photon polarization measurement, and sending the photon information bits to the quantum key system; receiving single photon information polarizations of the single photon information sent by the quantum key system; comparing corresponding single photon information polarizations and bit values of the photon information bits by the quantum key system and the server, taking a non-disclosed part of the same bit value as a quantum key, and further forming the quantum key group.

[0140] In an implementation, after the comparing corresponding single photon information polarizations and bit values of the photon information bits by the quantum key system and the server, the method further includes: when a proportion of quantum keys that fail in the comparison exceeds a threshold, regenerating a quantum key group; and performing XOR processing on the quantum keys by a quantum key random number generated.

[0141] Alternatively, the program or instructions, when executed by the processor 901, implement: receiving a target quantum key sent by a server, wherein the target quantum key is extracted from a quantum key group by the server according to the number of quantum keys in the quantum key group and a random string encryption value generated by the server; and encrypting sensitive information to be encrypted by the target quantum key to obtain encrypted information.

[0142] In an implementation, the random string encryption value is a hash value obtained by performing hash processing on a generated random string by the server.

[0143] In an implementation, before the target quantum key sent by the server is received, a timestamp and a server sending credential are spliced to generate a data set; related information in a data transmission process is signed to obtain a signature value; encryption data corresponding to the data set and encryption ciphertext corresponding to a random number are generated according to the random number and the data set; and the signature value, the encryption data, and the encryption ciphertext are sent to the server, so that the server extracts the target quantum key from the quantum key group in a case where verification is successful according to the signature value, the encryption data, and the encryption ciphertext.

[0144] In an implementation, the data set is symmetrically encrypted by the random number to obtain the encryption data; and the random number is asymmetrically encrypted to obtain the encryption ciphertext.

[0145] The specific implementation steps can refer to the steps of the above-mentioned information encryption method embodiments, and the same technical effects can be achieved. To avoid repetition, details are not described here.

[0146] It should be noted that the electronic device in the embodiments of the present application includes a server, a terminal or other devices in addition to the terminal.

[0147] The above electronic device structure does not constitute a limitation on the electronic device, and the electronic device can include more or fewer components than the illustration, or combine certain components, or different component arrangements. For example, the input unit can include a graphics processing unit (GPU) and a microphone, and the display unit can be configured with a display panel in the form of a liquid crystal display, an organic light-emitting diode, etc. The user input unit includes at least one of a touch panel and other input devices. The touch panel is also called a touch screen. Other input devices can include, but are not limited to, a physical keyboard, function keys (such as volume control buttons, switch buttons, etc.), trackballs, mice, joysticks, and the like, and details are not described here.

[0148] The memory can be used to store software programs and various data. The memory can mainly include a first storage area storing programs or instructions and a second storage area storing data, wherein the first storage area can store an operating system, application programs or instructions required by at least one function (such as a sound playing function, an image playing function, etc.), and the like. In addition, the memory can include a volatile memory or a non-volatile memory, or the memory can include both volatile and non-volatile memories. The non-volatile memory can be a Read-Only Memory (ROM), a Programmable ROM (PROM), an Erasable PROM (EPROM), an Electrically EPROM (EEPROM), or a flash memory. The volatile memory can be a Random Access Memory (RAM), a Static RAM (SRAM), a Dynamic RAM (DRAM), a Synchronous DRAM (SDRAM), a Double Data Rate SDRAM (DDR SDRAM), an Enhanced SDRAM (ESDRAM), a Synchlink DRAM (SLDRAM), and a Direct Rambus RAM (DRRAM).

[0149] The processor can include one or more processing units; optionally, the processor integrates an application processor and a modem processor, wherein the application processor mainly processes operations related to an operating system, a user interface, and an application program, and the modem processor mainly processes wireless communication signals, such as a baseband processor. It can be understood that the above-mentioned modem processor can also not be integrated into the processor.

[0150] The embodiment of the present application further provides a readable storage medium, and the readable storage medium stores programs or instructions, the programs or instructions are executed by a processor to realize various processes of the above-mentioned information encryption method embodiment, and the same technical effects can be achieved, and thus details are not described herein again.

[0151] The processor is the processor in the electronic device in the above-mentioned embodiment. The readable storage medium includes a computer readable storage medium, such as a ROM, a RAM, a magnetic disc, or an optical disc.

[0152] The embodiment of the present application further provides a computer program product, which comprises a computer program stored on a non-transitory computer readable storage medium, the computer program comprising program instructions, which, when executed by a computer, cause the computer to perform the processes of the above-mentioned information encryption method embodiment and achieve the same technical effects. To avoid repetition, details are not described herein.

[0153] It should be noted that, in this document, the terms "comprising", "including", or any other variant thereof are intended to cover a non-exclusive inclusion, such that processes, methods, articles, or apparatuses that comprise a list of elements not only include those elements, but also include other elements that are not expressly listed, or other elements that are inherent in such processes, methods, articles, or apparatuses. Without more limitations, an element defined by the statement "comprising a" does not exclude the presence of additional identical elements in the process, method, article, or apparatus that includes the element. In addition, it should be pointed out that the scope of the methods and apparatuses in the embodiments of the present application is not limited to performing functions in the order shown or discussed, but can also include performing functions in a substantially simultaneous manner or in reverse order, for example, the described method can be performed in an order different from that described, and various steps can also be added, omitted, or combined. In addition, features described with reference to certain examples can be combined in other examples.

[0154] From the above description of the embodiments, those skilled in the art can clearly understand that the above-mentioned embodiment method can be realized by means of software and a necessary general hardware platform, of course, it can also be realized by hardware, but in many cases the former is a better embodiment. Based on such understanding, the technical solutions of the present application can be embodied in the form of a computer software product, which is stored in a storage medium (such as ROM / RAM, magnetic disk, optical disk), and includes a plurality of instructions for causing a terminal (which can be a mobile phone, computer, server, or network device, etc.) to execute the method described in each embodiment of the present application.

[0155] The embodiments of the present application are described above in combination with the drawings, but the present application is not limited to the above-mentioned specific embodiments, the above-mentioned specific embodiments are only illustrative, not restrictive, and those skilled in the art can make many forms under the inspiration of the present application without departing from the scope of the present application and the protection scope of the claims.

Claims

1. An information encryption method characterized by, Applied to a server, comprising: extracting a target quantum key from a quantum key group according to the number of quantum keys in the quantum key group and a generated random string encryption value; sending the target quantum key to a terminal device to enable the terminal device to encrypt sensitive information to be encrypted according to the target quantum key to obtain encrypted information; before the extracting, further comprising: receiving single photon information sent by a quantum key system through a preselected polarization basis; converting the single photon information into photon information bits according to single photon polarization measurement, and sending the photon information bits to the quantum key system; receiving single photon information polarization states of the single photon information sent by the quantum key system; comparing corresponding single photon information polarization states and bit values of the photon information bits through the quantum key system and the server, taking a non-disclosed part in the same bit value as a quantum key, and further forming the quantum key group.

2. The method of claim 1, wherein, before the extracting, further comprising: receiving a signature value, encrypted data and encrypted ciphertext sent by the terminal device, wherein the encrypted data and the encrypted ciphertext are generated by the terminal device according to a random number and a data set, the data set is generated by the terminal device by splicing a timestamp and a credential sent by the server, and the signature value is obtained by the terminal device signing relevant information in a data transmission process.

3. The method of claim 2, wherein, the extracting, comprising: verifying the signature value, and in the case of passing the verification, decrypting the encrypted ciphertext to obtain the random number; decrypting the encrypted data to obtain the data set; parsing the data set to obtain the credential; in the case of successfully verifying the credential, extracting a target quantum key from the quantum key group according to the number of quantum keys in the quantum key group and a generated random string encryption value.

4. The method of claim 3, wherein, the extracting, comprising: taking a hash value obtained by performing hash processing on the generated random string as the random string encryption value; performing modulo processing on the number of quantum keys in the quantum key group through the random string encryption value, and extracting a corresponding quantum key from the quantum key group as the target quantum key according to the obtained modulus value.

5. The method of claim 1, wherein, after the sending, further comprising: receiving the encrypted information sent by the terminal device; decrypting the encrypted information through the target quantum key to obtain the sensitive information.

6. The method of claim 1, wherein, The method further includes, after the target quantum key is sent to the terminal device, causing the terminal device to encrypt sensitive information to be encrypted according to the target quantum key, to obtain encrypted information. The used target quantum key is destroyed.

7. The method of claim 1, wherein, The method further includes, after the target quantum key is extracted from the quantum key group according to the number of quantum keys in the quantum key group and a generated random string encryption value: In a case where the number of quantum keys remaining in the quantum key group after the target quantum key is destroyed is less than a number threshold, the quantum key group is destroyed. In a case where a timing time exceeds a time threshold after the quantum key group is obtained, the quantum key group is destroyed.

8. The method of claim 1, wherein, The method further includes, after the bit value of the corresponding single-photon information polarization state and the photon information bit is compared by the quantum key system and the server: In a case where a proportion of quantum keys that fail to pass the comparison exceeds a threshold, a quantum key group is regenerated; The quantum key is processed by exclusive OR with the generated quantum key random number.

9. An information encryption method characterized by, The application is applied to a terminal device and includes: A target quantum key sent by a server is received, wherein the target quantum key is extracted from a quantum key group by the server according to the number of quantum keys in the quantum key group and a generated random string encryption value. The quantum key group is formed by the server by comparing the bit value of the corresponding single-photon information polarization state and the photon information bit through a quantum key system and the server, and by taking a non-disclosed part in the same bit value as a quantum key. The single-photon information polarization state of a single photon is received by the server from the quantum key system. The photon information bit is generated by the server according to single-photon polarization measurement. The single-photon information is received by the server from the quantum key system through a preselected polarization basis.

10. The method of claim 9, wherein, Sensitive information to be encrypted is encrypted by the target quantum key, to obtain encrypted information.

11. The method of claim 9, wherein, The random string encryption value is a hash value obtained by the server by performing hash processing on a generated random string. Before the target quantum key sent by the server is received, the method further includes: A timestamp and a server sending credential are spliced to generate a data set; A signature value is obtained by signing related information in a data transmission process; According to a random number and the data set, encrypted data corresponding to the data set and encrypted ciphertext corresponding to the random number are generated; 12. The method of claim 11, wherein, The signature value, the encrypted data, and the encrypted ciphertext are sent to the server, to cause the server to extract the target quantum key from the quantum key group in a case where verification is successful according to the signature value, the encrypted data, and the encrypted ciphertext. According to a random number and the data set, encrypted data corresponding to the data set and encrypted ciphertext corresponding to the random number are generated, including: The data set is symmetrically encrypted by the random number, to obtain the encrypted data; 13. An information encryption device characterized by comprising: The random number is asymmetrically encrypted, to obtain the encrypted ciphertext. The application is applied to a server and includes: The working module is configured to extract a target quantum key from a quantum key group according to a number of quantum keys in the quantum key group and a generated random string encryption value; The sending module is configured to send the target quantum key to a terminal device, so that the terminal device encrypts sensitive information to be encrypted according to the target quantum key to obtain encrypted information; The working module is further configured to receive single-photon information sent by a quantum key system through a preselected polarization basis, convert the single-photon information into photon information bits according to single-photon polarization measurement, send the photon information bits to the quantum key system, receive single-photon information polarization states of the single-photon information sent by the quantum key system, compare corresponding single-photon information polarization states and bit values of the photon information bits through the quantum key system and the server, and take a non-disclosed part in the same bit value as a quantum key to form the quantum key group.

14. An information encryption device characterized by comprising: Applied to a terminal device, comprising: The receiving module is configured to receive a target quantum key sent by a server, wherein the target quantum key is extracted from a quantum key group by the server according to a number of quantum keys in the quantum key group and a generated random string encryption value; The quantum key group is formed by the server by comparing corresponding single-photon information polarization states and bit values of photon information bits through a quantum key system and the server, and taking a non-disclosed part in the same bit value as a quantum key; The single-photon information polarization state of the single photon is received by the server from the quantum key system; The photon information bits are generated by the server according to single-photon polarization measurement conversion of single-photon information; The single-photon information is received by the server from the quantum key system through a preselected polarization basis; The processing module is configured to encrypt sensitive information to be encrypted through the target quantum key to obtain encrypted information.

15. An electronic device, comprising: The readable storage medium stores programs or instructions, and the programs or instructions are executed by the processor to implement the steps of the information encryption method according to any one of claims 1-8 or the steps of the information encryption method according to any one of claims 9-12.

16. A readable storage medium, characterized by, The readable storage medium stores programs or instructions, and the programs or instructions are executed by the processor to implement the steps of the information encryption method according to any one of claims 1-8 or the steps of the information encryption method according to any one of claims 9-12.

17. A computer program product, comprising a computer program stored on a non-transitory computer-readable storage medium, the computer program comprising program instructions that, when executed by a computer, cause the computer to perform the steps of the information encryption method according to any one of claims 1-8 or the steps of the information encryption method according to any one of claims 9-12.

Citation Information

Patent Citations

  • Data transmission method and device based on quantum communication

    CN107483192A

  • PSK generation method and apparatus, user equipment, server, and storage medium

    CN108964912A