A Quantum-Secure Key Management Method and System Based on Homomorphic Encryption
By adopting a quantum secure key management method based on homomorphic encryption in the key management system, the existing system's lack of dynamics and security is solved, and the accurate prediction of key requirements and the security of keys throughout the life cycle are achieved.
Patent Information
- Application Number
- CN202510345654.6
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2025-03-24
- Publication Date
- 2025-05-30
- Estimated Expiration
- 2045-03-24
AI Technical Summary
The existing key management systems have shortcomings in terms of dynamics and security, and are difficult to accurately capture seasonal and trend changes, and have failed to fully utilize the quantum entanglement characteristics for eavesdropping detection. Moreover, homomorphic encryption is not widely used in key management, especially when combining quantum technology, how to ensure the security of the entire life cycle of the key is still a challenge.
The quantum security key management method based on homomorphic encryption is adopted. By initializing the quantum key pool, configuring multi-dimensional quantum state encoding parameters, collecting and preprocessing historical key usage data, building a key demand prediction model, generating a multi-dimensional quantum state as an initial key allocation scheme, and transmitting the encrypted key through the quantum channel for verification.
The prediction accuracy of the key demand prediction model is improved, the seasonality and trend changes of key demand are captured, the security of the key throughout the life cycle is realized, and the security of the key is ensured through the encrypted transmission of the quantum channel.
Smart Images

Figure CN119865317B_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the field of network security technology, and particularly to a quantum-secure key management method and system based on homomorphic encryption. Background Art
[0002] With the rapid development of quantum computing technology, traditional encryption algorithms are facing the potential threat of being cracked, which has promoted the research and development of quantum-secure key management systems. Modern key management methods usually rely on classical encryption algorithms such as RSA and AES, but these methods may no longer be secure in the face of quantum computing. At the same time, quantum key distribution has been proven to provide theoretically absolute security, but its practical application is limited by transmission distance and cost. Therefore, researchers have begun to explore key management methods that combine homomorphic encryption and quantum technology in order to achieve secure key distribution and management without leaking information.
[0003] However, the existing key management has deficiencies in terms of dynamics and security. First, the traditional key demand prediction model lacks accurate capture of seasonality and trends, resulting in low key distribution efficiency. Second, the existing key transmission and verification mechanisms lack the utilization of quantum states and fail to fully utilize the quantum entanglement property to detect eavesdropping behavior. In addition, the application of homomorphic encryption in key management has not been widespread, especially when combined with quantum technology, and how to ensure the security of keys throughout their life cycle remains a challenge. Summary of the Invention
[0004] In view of the above existing problems, the present invention is proposed.
[0005] Therefore, the present invention provides a quantum-secure key management method based on homomorphic encryption to solve the problem of key life cycle management.
[0006] To solve the above technical problems, the present invention provides the following technical solutions:
[0007] In a first aspect, the present invention provides a quantum-secure key management method based on homomorphic encryption, which includes initializing a quantum key pool, configuring multi-dimensional quantum state encoding parameters, collecting and preprocessing the usage data of historical keys, constructing a key demand prediction model based on the preprocessed usage data, and outputting a predicted key demand quantity; generating a multi-dimensional quantum state as an initial key distribution scheme based on the predicted key demand quantity, encoding the multi-dimensional quantum state using the multi-dimensional quantum state encoding parameters to generate a high-dimensional quantum state, and converting the key format to be stored in the quantum key pool, and allocating keys to each node of the quantum key pool according to the predicted key demand quantity; monitoring the key usage situation of each node in the quantum key pool in real time, collecting feedback information, generating a visualization report, generating a new key distribution scheme based on the key demand prediction model and storing it in the quantum key pool; extracting the keys of the new key distribution scheme from the quantum key pool, encrypting the keys of the new key distribution scheme using homomorphic encryption, transmitting the encrypted keys through a quantum channel, decrypting the received encrypted keys by the receiving party to restore the original keys, and verifying the received keys using the multi-dimensional quantum state encoding parameters.
[0008] As a preferred solution of the quantum-secure key management method based on homomorphic encryption according to the present invention, wherein: the multi-dimensional quantum state encoding parameters refer to the photon polarization state, photon phase, and photon time characteristics;
[0009] The usage data is the key time period, the number of key usages, the key usage change rate, and the average key quantity;
[0010] The preprocessing is to remove outliers, perform normalization processing, and feature engineering.
[0011] As a preferred solution of the quantum-secure key management method based on homomorphic encryption according to the present invention, wherein: the specific steps of constructing a key demand prediction model based on the preprocessed usage data and outputting a predicted key demand quantity are as follows,
[0012] Select the SARIMA model as the basic framework of the key demand prediction model;
[0013] Define the input of the key demand prediction model as the usage data and the output as the predicted key demand quantity;
[0014] Divide the preprocessed usage data into a training set and a test set;
[0015] Draw ACF and PACF graphs through statsmodels, view the time series data of the usage data in the ACF and PACF graphs, and obtain the non-seasonal parameters of the key demand prediction model;
[0016] On the ACF and PACF graphs, focus on the time series data of the key usage change rate to obtain the seasonal parameters of the key demand prediction model;
[0017] Train the key demand prediction model using the training set, and adjust the non-seasonal parameters and seasonal parameters to optimize the key demand prediction model;
[0018] Verify the prediction ability of the key demand prediction model using the test set;
[0019] Predict the future key time period according to the trained key demand prediction model to generate the predicted key demand quantity.
[0020] As a preferred solution of the quantum-secure key management method based on homomorphic encryption according to the present invention, wherein: encoding the multi-dimensional quantum state using the multi-dimensional quantum state encoding parameters to generate a high-dimensional quantum state, and converting the key format and storing it in the quantum key pool. The specific steps are as follows.
[0021] Generate quantum states with different polarization states by changing the polarization direction of photons through the photon polarization state;
[0022] Generate quantum states with different phase angles by setting the photon phase angle through the photon phase;
[0023] Generate time-characteristic-based quantum states by controlling the photon propagation time through the photon time characteristic;
[0024] Combine the different quantum states generated based on the photon polarization state, photon phase, and photon time characteristic into a high-dimensional quantum state;
[0025] Convert the high-dimensional quantum state into a binary key through a mapping rule, and convert the binary key into an AES key and an RSA key respectively;
[0026] Further encrypt the converted AES key and RSA key using Paillier homomorphic encryption and store them in the quantum key pool.
[0027] As a preferred solution of the quantum-secure key management method based on homomorphic encryption according to the present invention, wherein: real-time monitor the key usage situation of each node in the quantum key pool, collect feedback information, generate a visualization report, generate a new key allocation plan based on the key demand prediction model, and store it in the quantum key pool. The specific steps are as follows.
[0028] Deploy Prometheus to monitor each node of the key management center and obtain new key usage data;
[0029] Configure Kafka to collect the key usage feedback of each node;
[0030] Check the available key quantity in the quantum key pool through an SQL query statement;
[0031] Generate a visualization report by using Grafana in combination with new key usage data, key usage feedback, and the number of available keys, and connect to Prometheus for real-time monitoring;
[0032] Real-time predict the key requirements through a Python script in combination with a key requirement prediction model, and generate a new key allocation plan;
[0033] Use an SSH tunnel to transfer and store the keys in the new key allocation plan to each node in the quantum key pool.
[0034] As a preferred solution of the quantum secure key management method based on homomorphic encryption described in the present invention, wherein: encrypt the keys in the new key allocation plan by using homomorphic encryption, transmit the encrypted keys through a quantum channel, and the receiving party decrypts the encrypted keys after receiving them to restore the original keys. The specific steps are as follows:
[0035] The sender uses Paillier homomorphic encryption to generate a pair of public and private keys;
[0036] Convert the keys in the new key allocation plan into binary numbers;
[0037] Encrypt the binary numbers by using the public key to generate encrypted ciphertext;
[0038] The sender transmits the encrypted ciphertext to the receiving party through quantum communication;
[0039] After receiving the encrypted ciphertext, the receiving party decrypts it by using the private key to restore the original keys.
[0040] As a preferred solution of the quantum secure key management method based on homomorphic encryption described in the present invention, wherein: verify the received keys by using multi-dimensional quantum state encoding parameters. The specific steps are as follows:
[0041] The receiving party uses a quantum photon detector to receive a high-dimensional quantum state and measures the high-dimensional quantum state according to the multi-dimensional quantum state encoding parameters;
[0042] Compare the measured high-dimensional quantum state with the decrypted keys to check for consistency;
[0043] If the measurement result is consistent with the decrypted keys, the keys can be used;
[0044] If the measurement result is inconsistent with the decrypted keys, trigger a security alarm and reject the use of the keys;
[0045] The keys expire after use and are destroyed by physical destruction.
[0046] Second aspect, the present invention provides a quantum-secure key management system based on homomorphic encryption, including a construction module, an encoding module, a monitoring module, and a verification module; the construction module is used to initialize a quantum key pool, configure multi-dimensional quantum state encoding parameters, collect usage data of historical keys and preprocess them, and based on the preprocessed usage data, construct a key demand prediction model and output a predicted key demand quantity; the encoding module is used to generate a multi-dimensional quantum state as an initial key distribution scheme based on the predicted key demand quantity, encode the multi-dimensional quantum state using the multi-dimensional quantum state encoding parameters to generate a high-dimensional quantum state, and convert the key format and store it in the quantum key pool, and allocate keys to each node of the quantum key pool according to the predicted key demand quantity; the monitoring module is used to monitor the key usage situation of each node in the quantum key pool in real time, collect feedback information, generate a visualization report, generate a new key distribution scheme based on the key demand prediction model and store it in the quantum key pool; the verification module is used to extract the key of the new key distribution scheme from the quantum key pool, encrypt the key of the new key distribution scheme using homomorphic encryption, transmit the encrypted key through a quantum channel, the receiving party decrypts the received encrypted key to recover the original key, and verify the received key using the multi-dimensional quantum state encoding parameters.
[0047] Third aspect, the present invention provides a computer device, including a memory and a processor, where the memory stores a computer program, and: when the computer program is executed by the processor, any step of the quantum-secure key management method based on homomorphic encryption as described in the first aspect of the present invention is implemented.
[0048] Fourth aspect, the present invention provides a computer-readable storage medium, on which a computer program is stored, and: when the computer program is executed by the processor, any step of the quantum-secure key management method based on homomorphic encryption as described in the first aspect of the present invention is implemented.
[0049] The beneficial effects of the present invention are as follows: By selecting the SARIMA model as the basic framework of the key demand prediction model, defining a clear input-output relationship, and dividing the preprocessed usage data into a training set and a test set, the present invention realizes an accurate modeling of the key usage situation, not only improves the prediction accuracy of the key demand prediction model, but also can capture the seasonality and trend changes of the key demand. By drawing the ACF and PACF graphs using statsmodels and analyzing the non-seasonal and seasonal parameters, the key demand prediction model can adapt to the complexity and periodicity of the key usage pattern, which is crucial for predicting future key demands. Through repeated adjustment and verification of the training set and the test set, the generalization ability and prediction reliability of the key demand prediction model are ensured. Description of the Drawings
[0050] To more clearly illustrate the technical solutions of the embodiments of the present invention, the following will briefly introduce the drawings required for the description of the embodiments. Obviously, the drawings in the following description are only some embodiments of the present invention. For those of ordinary skill in the art, without creative efforts, other drawings can be obtained based on these drawings.
[0051] Figure 1 It is a flowchart of the quantum secure key management method based on homomorphic encryption in Embodiment 1.
[0052] Figure 2 It is a module diagram of the quantum secure key management system based on homomorphic encryption in Embodiment 1. Detailed implementation manners
[0053] To make the above objects, features, and advantages of the present invention more obvious and understandable, the following will make a detailed description of the specific implementation manners of the present invention in conjunction with the drawings of the specification.
[0054] In the following description, many specific details are set forth to fully understand the present invention. However, the present invention can also be implemented in other ways different from those described herein. Those skilled in the art can make similar generalizations without departing from the connotation of the present invention. Therefore, the present invention is not limited by the specific embodiments disclosed below.
[0055] Secondly, the so-called "one embodiment" or "embodiment" herein refers to a specific feature, structure, or characteristic that can be included in at least one implementation manner of the present invention. The "in one embodiment" that appears in different places in this specification does not all refer to the same embodiment, nor is it a separate or alternative embodiment that mutually excludes other embodiments.
[0056] Embodiment 1, referring to Figure 1 and Figure 2 , is the first embodiment of the present invention. This embodiment provides a quantum secure key management method based on homomorphic encryption, including the following steps:
[0057] S1. Initialize the quantum key pool, configure multi-dimensional quantum state encoding parameters, collect and preprocess the usage data of historical keys, and based on the preprocessed usage data, construct a key demand prediction model and output the predicted key demand quantity.
[0058] Furthermore, the multi-dimensional quantum state encoding parameters refer to the photon polarization state, photon phase, and photon time characteristics;
[0059] Specifically, a series of photon polarization states are defined to encode quantum information. For example, horizontal polarization, vertical polarization, diagonal polarization, etc. Each photon polarization state can serve as a basis state of a qubit. In actual operations, photon polarization states are manipulated through polarization filters or wave plates to ensure stability and repeatability;
[0060] The phase difference of photons is used to distinguish different quantum states. The phase can be encoded as various phase angles such as 0 degrees, 90 degrees, 180 degrees, etc. A phase modulator (such as a Pockels cell) is used to change the photon phase to ensure the accurate transmission and detection of phase information;
[0061] Quantum information is encoded through time difference or time delay. For example, photons arriving at different times can represent different quantum states;
[0062] Optical delay lines or fiber optic delay lines are used to control the photon time characteristics of the arrival time of photons to ensure the accuracy and stability of time encoding;
[0063] The data used are the key time period, the number of key usages, the key usage change rate, and the average key quantity;
[0064] Among them, the key time period is to determine the scope of historical data. For example, historical data for the past year or historical data for the past three months. All key usage records for the historical key time period are extracted from the database or log file;
[0065] The number of key usages is to calculate the total number of times the key is used within this time period, which may include each communication, each encryption operation, etc. The occurrence times of each event are counted;
[0066] The usage change rate is to analyze how the key usage frequency changes over time. It may be by calculating the usage frequency daily, weekly, or monthly. Time series analysis tools (such as FFT or trend analysis) are used to identify seasonal or periodic changes in the usage frequency;
[0067] The average key quantity is to calculate the average number of keys used in each event. This involves detailed recording of each usage event and calculating the average number of keys used per event;
[0068] The preprocessing is to remove outliers, standardize, and perform feature engineering;
[0069] Specifically, obvious error data or outliers are identified and removed, such as data where the number of key usages suddenly exceeds or is lower than the normal range. Statistical methods such as Z-score, IQR (interquartile range) are used to identify outliers, and then they are removed manually or automatically;
[0070] Convert data with different dimensions to a unified scale, usually between 0 and 1 or -1 and 1. Common methods include min-max normalization or Z-score normalization. After processing, the mean and variance of the data will be unified;
[0071] Create new features or combine existing features to better reveal data patterns. For example, create features for time windows or convert time series data to frequency domain features;
[0072] Based on the preprocessed data, create or extract new features to enhance the predictive ability of the data;
[0073] Analyze the key time period and the number of key usages, and create sliding window features, such as the daily average usage in the past 7 days, the weekly average usage in the past month, etc.;
[0074] On the rate of change of key usage frequency, further analyze its change trend by calculating the moving average (such as a 3-day moving average) or using more complex time series analysis methods;
[0075] For the average key quantity, aggregate different time periods and calculate more meaningful statistics, such as the total usage, maximum usage, minimum usage, median, etc. within a certain time period;
[0076] Use Fourier transform or periodic decomposition methods to analyze the rate of change of key usage frequency and identify whether there are periodic usage patterns such as weekly or monthly;
[0077] Combine existing features to create new features, such as multiplying the number of key usages by the average key quantity to estimate the total key consumption, or creating special flag features according to different business scenarios (such as holiday effects);
[0078] Select the SARIMA model (Seasonal Autoregressive Integrated Moving Average model) as the basic framework for the key demand prediction model;
[0079] Define the input of the key demand prediction model as usage data and the output as the predicted key demand quantity;
[0080] Divide the preprocessed usage data into a training set and a test set. Usually, 80% is used for training and 20% is used for testing, ensuring that the test set contains at least one complete seasonal cycle;
[0081] Plot the ACF and PACF diagrams through statsmodels, view the time series data of the data used in the ACF and PACF diagrams, and obtain the non-seasonal parameters (p, d, q) of the key demand prediction model. Among them, p is the non-seasonal autoregressive parameter, which indicates how many past observations are used in the key demand prediction model to predict the current value. d is the non-seasonal differencing parameter, which represents how many differencing operations are performed to make the time series data stationary. q is the non-seasonal moving average parameter, which indicates how many past error terms are considered in the key demand prediction model for prediction;
[0082] Specifically, use a time series analysis tool (such as statsmodels in Python) to plot the ACF diagram and observe at which lags the autocorrelation is significant;
[0083] If there is significant autocorrelation at lag k (i.e., outside the confidence interval), it is possible that q ≥ k. Observe how the autocorrelation decreases as lag increases. Here, k represents a specific number of time steps or delays. The specific value of k depends on the time resolution of the data. For example, if the data is recorded daily, k = 1 represents a one-day delay. If it is recorded hourly, k = 1 represents an hour delay. In time series analysis, lag refers to the time step or delay. For example, if observing a time series today, then lag 1 refers to yesterday, and lag 2 refers to the day before yesterday;
[0084] Similarly, use a time series analysis tool to plot the PACF diagram and observe the partial autocorrelation;
[0085] If there is significant partial autocorrelation at lag k, it is possible that p ≥ k. Especially when the PACF drops rapidly to 0 after a certain lag, this usually indicates the order of the AR part;
[0086] Check the stationarity of the time series data in the data used through the ADF or KPSS test. If the time series data in the data used shows a trend or non-stationarity, differencing is required until the time series data in the data used is stationary. The number of differencing operations is the value of the non-seasonal parameter d;
[0087] On the ACF and PACF plots, focus on the time series data of the key usage change rate, especially the autocorrelation and partial autocorrelation at multiples of m, to obtain the seasonal parameters (P, D, Q, m) of the key demand prediction model. Here, P is the seasonal regression parameter, representing the order of the seasonal autoregressive part, that is, how many past values of seasonal cycles are considered to predict the current value. D is the seasonal differencing parameter, which is the number of times the seasonal component is differenced. Usually, 0 or 1 time is sufficient to make the seasonal component stationary. Q is the seasonal moving average parameter, which represents the order of the seasonal moving average part. Focus on the autocorrelation at multiples of the seasonal cycle in the ACF plot. m is the seasonal cycle (for example, one week or one month);
[0088] Specifically, analyze the time series plot of the key usage change rate, look for obvious periodic patterns such as weekly or monthly peaks, and determine m as the length of the cycle (for example, if there is an obvious weekly periodicity, m = 7);
[0089] On the ACF and PACF plots, focus on the autocorrelation and partial autocorrelation at multiples of m. If there is significant autocorrelation at multiples of the cycle m, it may be that Q ≥ 1. If there is significant partial autocorrelation at multiples of the cycle m, it may be that P ≥ 1;
[0090] If the seasonal component causes the time series data of the usage data to be non-stationary, seasonal differencing may be required. Usually, 0 or 1 time of seasonal differencing is sufficient to determine the value of D;
[0091] Use the training set to train the key demand prediction model and adjust the non-seasonal parameters and seasonal parameters to optimize the key demand prediction model;
[0092] Specifically, according to the results of the ACF and PACF plots, set an initial key demand prediction model (i.e., the SARIMA(p, d, q)(P, D, Q, m) model);
[0093] Use the training set to fit the key demand prediction model through software or programming libraries (such as statsmodels in Python). Input the training set, and the key demand prediction model will automatically calculate the parameter estimates;
[0094] Try different combinations of p, d, q, P, D, Q values and observe the performance of the key demand prediction model fitting;
[0095] Conduct multiple iterations, gradually fine-tune the parameters to ensure that the key demand prediction model performs well on the training set and avoid overfitting;
[0096] Use the test set to verify the prediction ability of the key demand prediction model, and calculate error metrics such as MAE and RMSE to evaluate the accuracy of the key demand prediction model. The expressions are:
[0097] ;
[0098] ;
[0099] Among them, MAE is the mean absolute error, is the root mean square error, is the number of samples in the test set, that is, the total number of observed values of the key demand prediction model, is the actual value of the i-th observed value, that is, the true key demand at the i-th time point in the test set, represents the predicted value of the i-th observed value, that is, the prediction of the key demand prediction model for the key demand at the i-th time point, is the absolute value function, which represents the absolute difference between the predicted value and the actual value, ensuring that the error is non-negative. i is the index of the observed value, used to iterate through each observed value in the test set, is the square of the prediction error. By squaring the error, large errors will be amplified, thus having a greater impact on the overall error;
[0100] Compare the values of MAE and RMSE. The smaller the value, the closer the prediction of the key demand prediction model is to the actual situation;
[0101] If the value of MAE or RMSE is very low, such as close to 0, this means that the prediction of the key demand prediction model is very close to the actual value, and the accuracy of the key demand prediction model is high;
[0102] Predict the future key time period according to the trained key demand prediction model to generate the predicted key demand. The expression is:
[0103] ;
[0104] Among them, is the predicted key demand, is the key time length, used to consider the impact of the time scale on the prediction, is the key usage change rate, using and to reflect the complexity of the periodic change, The tangent function is used here to simulate the non-linear effect of the frequency change, is the tangent function, is the pi, with an approximate value of 3.1415926, is the number of key usages, used as part of the denominator to adjust the predicted key demand, considering the logarithmic relationship of the past usage times, is the average key quantity, and the cube root is used to smooth its impact because the average quantity may have large fluctuations;
[0105] It should be noted that by initializing the quantum key pool and configuring multi-dimensional quantum state encoding parameters, combined with the preprocessing of historical key usage data, an accurate key demand prediction model is constructed, enabling the identification of the seasonality and trends of key usage, optimizing the generation and distribution of keys. The preprocessing ensures the quality of the data, provides stable and reliable input, enhances the accuracy of the prediction. The key demand prediction model captures the complex dynamics of key demand through the adjustment of non-seasonal and seasonal parameters, and the generated prediction expression takes into account the interaction of time, usage change rate, and usage volume.
[0106] S2. Generate multi-dimensional quantum states as the initial key distribution scheme based on the predicted key demand quantity. Use the multi-dimensional quantum state encoding parameters to encode the multi-dimensional quantum states to generate high-dimensional quantum states, and convert the key format and store it in the quantum key pool. Allocate keys to each node of the quantum key pool according to the predicted key demand quantity.
[0107] Furthermore, determine the number of generated quantum states according to the predicted key demand quantity. For example, if the predicted key demand quantity is expected to be 1000 keys in the future, at least 1000 multi-dimensional quantum states are generated;
[0108] Generate quantum states with different polarization states by changing the polarization direction of photons through the photon polarization state;
[0109] Specifically, use a polarization filter or wave plate (such as a half-wave plate or a quarter-wave plate), define a set of horizontal polarization, vertical polarization, diagonal polarization, and circular polarization of polarization states to control the photon polarization state, and change the polarization direction of photons by rotating the wave plate. For example, a wave plate can change the horizontal polarization to vertical polarization or diagonal polarization, and each polarization state can represent one of the basic states of the quantum state, ensuring that the generated polarization states are diverse enough;
[0110] Generate quantum states with different phase angles by setting the photon phase angle through the photon phase;
[0111] Specifically, use a phase modulator (such as a Pockels cell) or a phase shifter to change the photon phase, set different phase angles, such as 0 degrees, 90 degrees, 180 degrees, and other angles. Each phase angle corresponds to a specific quantum state. By applying an electric field to change the refractive index of photons, the photon phase is changed, adding an additional dimension to the generated quantum states;
[0112] Generate time-based quantum states by controlling the photon propagation time through the photon time characteristics;
[0113] Specifically, an optical delay line or a fiber optic delay line is used to control the propagation time of photons, generating a time difference. The arrivals at different times can represent different quantum states. For example, a photon arriving at time t 1 and t 2 represent different quantum states respectively. By precisely controlling the optical path length, the arrival time of the photon at the detector is adjusted to ensure that the time difference is sufficiently obvious to distinguish different quantum states;
[0114] Combining different quantum states generated based on the polarization state, phase, and time characteristics of photons into a high-dimensional quantum state;
[0115] Specifically, different quantum states generated by combining the polarization state, phase, and time characteristics of photons are high-dimensional quantum states. For example, a three-dimensional quantum state may be composed of a photon polarization state (such as horizontal or vertical polarization), a photon phase (such as a 0-degree or 90-degree phase angle), and a photon time characteristic (such as arrival time t 1 or t 2 ). The combination of each quantum state needs to ensure that all characteristics are measured simultaneously in the same quantum to maintain the superposition state of the quantum state, and the combination of high-dimensional quantum states is achieved through the direct combination or tensor product of these characteristics;
[0116] Converting the high-dimensional quantum state into a binary key through a mapping rule, and respectively converting the binary key into an AES key and an RSA key;
[0117] Using Paillier homomorphic encryption to further encrypt the converted AES key and RSA key and store them in the quantum key pool;
[0118] Specifically, first, design a mapping table that maps each high-dimensional quantum state (such as a quantum state composed of photon polarization state, photon phase, and photon time characteristic) to a specific binary sequence; for example: polarization H, phase 0°, time t 1 may be mapped to the binary sequence "000";
[0119] polarization V, phase 90°, time t 2 , may be mapped to "001";
[0120] The mapping can be continued until all possible combinations of quantum states correspond to a unique binary sequence;
[0121] When measuring a high-dimensional quantum state, according to the measurement result (such as obtaining polarization H, phase 0°, time t 1 ), find the corresponding binary sequence through the mapping table;
[0122] Concatenate these binary sequences to form a complete binary key. For example, if multiple quantum states are measured, the resulting binary sequence might be "000101011".
[0123] And convert the binary key into a key format recognizable by a computer, which refers to the key format required by a certain symmetric or asymmetric encryption algorithm. For example, in AES symmetric encryption, keys of 128 bits, 192 bits, or 256 bits are usually used. This means the binary sequence needs to be adjusted or extended to these lengths. For example, AES-128 requires a 16-byte (128-bit) key.
[0124] In RSA asymmetric encryption, the key is based on large prime numbers and usually requires converting the binary key into a large integer or a part used to generate the public and private keys.
[0125] If the length of the binary sequence does not match the target key length, it can be adjusted by padding or truncating. For example, padding a shorter binary key to 128 bits.
[0126] For AES symmetric encryption, the binary string can be directly converted into the required byte array.
[0127] For RSA asymmetric encryption, it may be necessary to convert the binary sequence into large integers and then use these integers to generate part of the key pair (such as the public key's )
[0128] For example: If there is a binary key "1010101010101010", for AES-128, it may only need to be extended or directly used (if the length is already 128 bits).
[0129] For RSA, it may be necessary to convert this binary number into a large integer and then use it to generate the key pair.
[0130] Use Paillier homomorphic encryption to encrypt the binary key or the key after converting the AES key format and RSA key format to prevent unauthorized access.
[0131] Specifically, use Paillier homomorphic encryption to generate a new pair of public and private keys as the key.
[0132] Assume the AES key exists in a 128-bit binary form and is regarded as an integer. Paillier homomorphic encryption is suitable for encrypting integers.
[0133] The public key of the RSA key contains the modulus and the public key exponent, both of which are large integers. The private key contains the modulus and the private key exponent, also large integers.
[0134] Encrypt the AES key integer with the public key of Paillier homomorphic encryption. For example, if the AES key is "1010101010101010", convert it to the corresponding integer, and then perform public key encryption using Paillier homomorphic encryption to obtain a ciphertext encrypted by Paillier homomorphic encryption;
[0135] Encrypt each part of the RSA key independently. Specifically, encrypt the public key exponent with the public key of Paillier homomorphic encryption to obtain a ciphertext, and encrypt the public key exponent (if it is the public key) or the private key exponent (if it is the private key) with the public key of Paillier homomorphic encryption to obtain another ciphertext;
[0136] And store these ciphertexts encrypted by Paillier homomorphic encryption in the quantum key pool. Each key (a part of AES or RSA) now exists in an encrypted form;
[0137] It should be noted that through prediction-based quantum state generation and multi-dimensional encoding, high-dimensional quantum states are created for key distribution, ensuring the complexity and security of the keys. Utilizing the polarization, phase, and time characteristics of photons, the dimension and difficulty of cracking the keys are increased. Convert the high-dimensional quantum states into AES and RSA formats, and use Paillier homomorphic encryption to protect the storage, achieving secure storage and distribution under the threat of quantum computing.
[0138] S3. Monitor the key usage of each node in the quantum key pool in real time, collect feedback information, generate a visualization report, and generate a new key distribution plan based on the key demand prediction model and store it in the quantum key pool.
[0139] Furthermore, deploy Prometheus to monitor each node of the key management center and obtain new key usage data;
[0140] Specifically, deploy the Prometheus node exporter on each node, configure it to expose key usage data such as usage frequency and remaining key quantity, set up the Prometheus server to pull the key usage data at an hourly or other appropriate frequency to ensure capturing the latest usage situation;
[0141] The node exporter exposes the latest key usage data to Prometheus through the HTTP API. The Prometheus configuration file defines how to scrape the key usage data and sets alert rules, such as alarming when the key usage reaches a certain threshold;
[0142] Configure Kafka to collect the key usage feedback of each node;
[0143] Specifically, deploy a Kafka cluster in the monitoring key management center, configure clients or scripts on each node, and set an inventory threshold. When the key usage reaches the set inventory threshold (such as when the inventory is less than 10%), send feedback data to Kafka. The sender of Kafka is used to collect this feedback data to ensure that the feedback data can be transmitted in real time. The Kafka receiver (which may be another service or script) receives the feedback data, processes the feedback data, and provides real-time usage data for dynamically adjusting key allocation;
[0144] Check the number of available keys in the quantum key pool through SQL query statements;
[0145] Specifically, use a predefined SQL query statement (such as SELECT COUNT(*) FROM key_pool WHERE status = 'available') to query the database regularly or on demand to check the current status of the quantum key pool. The query result will show the number and type of currently available keys to ensure that there are enough keys in the quantum key pool to meet the demand;
[0146] Use Grafana to generate a visualization report by combining new key usage data, key usage feedback, and the number of available keys, and connect to Prometheus for real-time monitoring;
[0147] Specifically, create a new Grafana dashboard or add new charts and panels to an existing dashboard, use the Prometheus query language (PromQL) to query and display new key usage data. For example, charts can be created to show the key usage trend of each node. The charts can include time series graphs showing key usage frequency, single-value panels showing the current number of available keys, and alert panels showing alerts when key usage reaches certain thresholds. Kafka feedback data can be imported into a database or logging system, and these key usage feedbacks can be integrated through Grafana plugins (such as Grafana Loki or plugins of Grafana Enterprise) or custom data sources. For example, create a panel to show the latest key usage feedback, such as which nodes reported key shortages or abnormal usage. Configure Grafana to connect to the database (if the number of available keys from the SQL query is stored in the database), or if the number of available keys has been imported through Prometheus, directly use PromQL to query the number of available keys. Create a panel specifically to show the current status of the quantum key pool, showing the number and type of available keys (i.e., the number of available keys), set the Grafana panel to automatically refresh regularly to ensure that the report continuously reflects the latest monitoring data, and alerts can also be configured to send notifications when specific conditions are met (such as when the number of keys is below a certain value);
[0148] The key requirements are predicted in real time through a Python script combined with a key requirement prediction model to generate a new key distribution plan;
[0149] Specifically, the Python script extracts the latest data from Prometheus, combines it with the key requirement prediction model for prediction. Based on the predicted key requirements, the Python script calculates the key changes required for each node and generates a new key distribution plan (including adjusting the existing key distribution or generating new keys to ensure that the key supply for each node matches the predicted demand). The script may involve data preprocessing, loading the key requirement prediction model, and performing the prediction;
[0150] Use an SSH tunnel to transfer the keys in the new key distribution plan to each node of the quantum key pool;
[0151] Specifically, use an SSH tunnel to securely transfer the keys in the new key distribution plan to each node that needs to be adjusted in the quantum key pool. The key plan for implementing the new key distribution is to add new keys to the node or recycle keys from the node through a script or manual operation, ensuring the security of the keys during the transmission process. SSH provides an encrypted channel;
[0152] It should be noted that through real-time monitoring and feedback mechanisms, combined with the use of Prometheus, Kafka, and Grafana, precise monitoring and analysis of the usage of the quantum key pool have been achieved. Based on the dynamically adjusted key requirement prediction model, a new distribution plan is generated through a Python script, ensuring the timeliness and accuracy of the key supply.
[0153] S4. Extract the keys of the new key distribution plan from the quantum key pool, encrypt the keys of the new key distribution plan using homomorphic encryption, transmit the encrypted keys through a quantum channel, and after the receiver receives the encrypted keys, decrypt them to restore the original keys, and verify the received keys using multi-dimensional quantum state encoding parameters.
[0154] Furthermore, the sender uses Paillier homomorphic encryption to generate a pair of public and private keys;
[0155] Specifically, the sender uses Paillier homomorphic encryption to select two very large prime numbers a and b as the basis for the public and private keys;
[0156] The public key is calculated through the formula, and the expression is:
[0157] ;
[0158] where, is the public key, is the initial prime number, is an auxiliary prime number;
[0159] Then the private key is calculated, and the expression is:
[0160] ;
[0161] ;
[0162] where, is the main parameter of the private key, representing the least common multiple of the initial prime number minus one and the auxiliary prime number minus one, is the least common multiple, is the secondary parameter of the private key, is the auxiliary function defined by Paillier homomorphic encryption, which is used to calculate the private key parameters and is ultimately used in decryption, is a generator, usually c + 1 or other suitable numbers, is the generator According to After taking the power of the main parameter of the private key and then taking the modulus of the public key The square of, is the modulo operation;
[0163] Convert the key in the new key distribution scheme into binary digits;
[0164] Encrypt the binary digits using the public key to generate an encrypted ciphertext;
[0165] Specifically, convert the key in the new key distribution scheme into a series of binary digits;
[0166] Use the public key Encrypt a series of binary digits, and for each key, generate a random number as the encrypted ciphertext;
[0167] The sender transmits the encrypted ciphertext to the receiver through quantum communication;
[0168] Specifically, the sender and the receiver establish a secure communication channel through quantum key distribution (QKD), which involves generating and exchanging a new shared key for subsequent communication verification;
[0169] The encrypted ciphertext is transmitted through this quantum communication. Utilizing the property of quantum entanglement, any attempt to eavesdrop will cause a change in the quantum state and thus be detected;
[0170] After receiving the encrypted ciphertext, the receiver uses the private key to decrypt it and recover the original key;
[0171] Specifically, after receiving the encrypted ciphertext, the receiver passes through the auxiliary function defined by Paillier homomorphic encryption in the private key Decrypt it to restore the original key format, such as binary;
[0172] The receiving party uses a quantum photon detector to receive the high-dimensional quantum state and measures the high-dimensional quantum state according to the multi-dimensional quantum state encoding parameters;
[0173] Specifically, the receiving party uses a dedicated quantum receiving device (such as a quantum photon detector) to receive the high-dimensional quantum state transmitted through the quantum channel;
[0174] According to the multi-dimensional quantum state encoding parameters (photon polarization state, photon phase, and photon time characteristics), precisely measure each quantum state. For example, measure the polarization angle, phase change, and arrival time of the photon to reconstruct these high-dimensional quantum states;
[0175] Compare the measured high-dimensional quantum state with the decrypted key to check for consistency;
[0176] Specifically, convert the measured high-dimensional quantum state into the corresponding binary or other key format, and then compare it with the decrypted key. This comparison can be a bit-by-bit comparison to ensure that each bit matches. If there is any mismatch, it may indicate a transmission error or a eavesdropping attack;
[0177] If the measurement result is consistent with the decrypted key, the key can be used;
[0178] Specifically, if the measurement result is exactly the same as the decrypted key, the key management center marks the key as available, records the time when the key verification passed and which node or task it is used for, and allows it to be used for encryption or decryption operations;
[0179] If the measurement result is inconsistent with the decrypted key, trigger a security alert and reject the use of the key;
[0180] Specifically, if an inconsistency is found, the key management center immediately triggers a security alert (including notifying the security team, recording it in the log, or automatically starting a security protocol such as re-requesting the key), records the event, rejects the use of this key, and prevents possible security risks;
[0181] The key expires after use and is destroyed physically to ensure that the key cannot be recovered;
[0182] Specifically, when the key reaches its predetermined usage period or a specific condition is triggered (such as the key usage frequency reaching a certain threshold), the key management center marks it as expired. By using physical destruction methods, such as destroying the hardware device storing the key (such as physically damaging a dongle), or in a digital environment, physical destruction may include smashing the hard drive, etc., to ensure that the key cannot be recovered;
[0183] It should be noted that by extracting from the quantum key pool, protecting the key using Paillier homomorphic encryption, and transmitting it through the quantum channel, the absolute security of the key during transmission is ensured. The receiving party uses quantum state measurement and comparison to verify the consistency of the key, achieving efficient key verification, preventing eavesdropping and tampering. After the key expires, it is physically destroyed, completely eliminating the risk of key leakage.
[0184] This embodiment also provides a quantum-secure key management system based on homomorphic encryption, including: a construction module, an encoding module, a monitoring module, and a verification module; The construction module is used to initialize the quantum key pool, configure multi-dimensional quantum state encoding parameters, collect and preprocess the usage data of historical keys, and based on the preprocessed usage data, construct a key demand prediction model and output the predicted key demand; The encoding module is used to generate a multi-dimensional quantum state as an initial key distribution scheme based on the predicted key demand, encode the multi-dimensional quantum state using the multi-dimensional quantum state encoding parameters to generate a high-dimensional quantum state, and store the key in the quantum key pool after converting the key format. Allocate keys to each node of the quantum key pool according to the predicted key demand; The monitoring module is used to monitor the key usage of each node in the quantum key pool in real time, collect feedback information, generate a visualization report, generate a new key distribution scheme based on the key demand prediction model and store it in the quantum key pool; The verification module is used to extract the key of the new key distribution scheme from the quantum key pool, encrypt the key of the new key distribution scheme using homomorphic encryption, transmit the encrypted key through the quantum channel, and the receiving party decrypts the received encrypted key to restore the original key and verify the received key using the multi-dimensional quantum state encoding parameters.
[0185] This embodiment also provides a computer device applicable to the situation of the quantum-secure key management method based on homomorphic encryption, including: a memory and a processor; The memory is used to store computer-executable instructions, and the processor is used to execute the computer-executable instructions to implement the quantum-secure key management method based on homomorphic encryption as proposed in the above embodiment.
[0186] The computer device may be a terminal, which includes a processor, a memory, a communication interface, a display screen, and an input device connected through a system bus. Among them, the processor of the computer device is used to provide computing and control capabilities. The memory of the computer device includes a non-volatile storage medium and an internal memory. The non-volatile storage medium stores an operating system and computer programs. The internal memory provides an environment for the operation of the operating system and computer programs in the non-volatile storage medium. The communication interface of the computer device is used to communicate with external terminals in a wired or wireless manner, and the wireless manner can be achieved through WIFI, a carrier network, NFC (Near Field Communication), or other technologies. The display screen of the computer device can be a liquid crystal display screen or an electronic ink display screen, and the input device of the computer device can be a touch layer covering the display screen, or buttons, trackballs, or touchpads provided on the housing of the computer device, or an external keyboard, touchpad, or mouse, etc.
[0187] This embodiment also provides a storage medium, on which a computer program is stored. When the program is executed by a processor, it implements the quantum secure key management method based on homomorphic encryption proposed in the above embodiment; the storage medium can be implemented by any type of volatile or non-volatile storage device or a combination thereof, such as static random access memory (Static Random Access Memory, abbreviated as SRAM), electrically erasable programmable read-only memory (Electrically Erasable Programmable Read-Only Memory, abbreviated as EEPROM), erasable programmable read-only memory (Erasable Programmable Read Only Memory, abbreviated as EPROM), programmable read-only memory (Programmable Red-Only Memory, abbreviated as PROM), read-only memory (Read-Only Memory, abbreviated as ROM), magnetic memory, flash memory, a magnetic disk, or an optical disc.
[0188] In summary, the present invention selects the SARIMA model as the basic framework of the key demand prediction model, defines clear input-output relationships, and divides the preprocessed usage data into a training set and a test set, achieving an accurate modeling of the key usage situation. It not only improves the prediction accuracy of the key demand prediction model but also captures the seasonality and trend changes of the key demand. By plotting the ACF and PACF graphs using statsmodels and analyzing the non-seasonal and seasonal parameters, the key demand prediction model can adapt to the complexity and periodicity of the key usage pattern, which is crucial for predicting future key demands. Through repeated adjustment and verification of the training set and the test set, the generalization ability and prediction reliability of the key demand prediction model are ensured.
[0189] It should be noted that the above embodiments are only used to illustrate the technical solutions of the present invention and not to limit them. Although the present invention has been described in detail with reference to the preferred embodiments, those of ordinary skill in the art should understand that the technical solutions of the present invention can be modified or equivalently replaced without departing from the spirit and scope of the technical solutions of the present invention, and they should all be covered within the scope of the claims of the present invention.
Claims
1. A quantum secure key management method based on homomorphic encryption, characterized in that: include, Initialize the quantum key pool, configure the multi-dimensional quantum state encoding parameters, collect and preprocess the usage data of historical keys, build a key demand prediction model based on the preprocessed usage data, and output the predicted key demand. The expression for the predicted key demand is: ; in, To predict the key demand, is the key time length, is the key usage change rate, is the tangent function, is the circumference of a circle, is the number of times the key is used, is the average amount of key; Based on the predicted key demand, a multi-dimensional quantum state is generated as the initial key distribution scheme, and the multi-dimensional quantum state is encoded using the multi-dimensional quantum state encoding parameters to generate a high-dimensional quantum state, and the key format is converted and stored in the quantum key pool, and the key is distributed to each node of the quantum key pool according to the predicted key demand; Monitor the key usage of each node in the quantum key pool in real time, collect feedback information, generate visual reports, generate new key distribution plans based on the key demand prediction model and store them in the quantum key pool; Extract the key of the new key distribution scheme from the quantum key pool, encrypt the key of the new key distribution scheme using homomorphic encryption, transmit the encrypted key through the quantum channel, and the receiver decrypts the encrypted key after receiving it to restore the original key, and verifies the received key using multi-dimensional quantum state encoding parameters; The multi-dimensional quantum state encoding parameters refer to the photon polarization state, photon phase and photon time characteristics; The usage data includes key time period, key usage times, key usage change rate and key average amount; The preprocessing includes removing outliers, standardization and feature engineering.
2. The quantum secure key management method based on homomorphic encryption according to claim 1, characterized in that: The key demand prediction model is constructed based on the preprocessed usage data to output the predicted key demand. The specific steps are: Select the SARIMA model as the basic framework of the key demand prediction model; Define the key demand prediction model with usage data as input and predicted key demand as output; Divide the preprocessed usage data into a training set and a test set; Use statsmodels to plot ACF and PACF graphs, view the time series data of the data used in the ACF and PACF graphs, and obtain the non-seasonal parameters of the key demand prediction model; On the ACF and PACF graphs, focus on the time series data of the key usage change rate and obtain the seasonal parameters of the key demand prediction model; Use the training set to train the key demand prediction model, and adjust the non-seasonal parameters and seasonal parameters to optimize the key demand prediction model; Use the test set to verify the prediction ability of the key demand prediction model; The future key time period is predicted based on the trained key demand prediction model to generate the predicted key demand.
3. The quantum secure key management method based on homomorphic encryption as claimed in claim 2, characterized in that: The method of using multi-dimensional quantum state encoding parameters to encode multi-dimensional quantum states to generate high-dimensional quantum states, and converting the key format to be stored in a quantum key pool, specifically comprises the following steps: By changing the polarization direction of photons through the polarization state of photons, quantum states of different polarization states are generated; The photon phase angle is set by the photon phase to generate quantum states with different phase angles; Controlling the photon propagation time through the photon time characteristics generates a quantum state based on the time characteristics; Combining different quantum states generated based on photon polarization state, photon phase and photon time characteristics into a high-dimensional quantum state; Convert the high-dimensional quantum state into a binary key through a mapping rule, and convert the binary key into an AES key and an RSA key respectively; The converted AES keys and RSA keys are further encrypted using Paillier homomorphic encryption and stored in the quantum key pool.
4. The quantum secure key management method based on homomorphic encryption as claimed in claim 3, characterized in that: The specific steps of real-time monitoring of the key usage of each node in the quantum key pool, collecting feedback information, generating a visual report, generating a new key distribution scheme based on the key demand prediction model and storing it in the quantum key pool are as follows: Deploy Prometheus to monitor each node of the key management center and obtain new key usage data; Configure Kafka to collect key usage feedback from each node; Check the number of available keys in the quantum key pool through SQL query statements; Use Grafana to generate visualization reports combining new key usage data, key usage feedback, and the number of available keys, and connect to Prometheus for real-time monitoring; Use Python scripts combined with key demand prediction models to predict key demand in real time and generate new key distribution plans; The keys in the new key distribution scheme are transmitted and stored in each node in the quantum key pool using SSH tunnel.
5. The quantum secure key management method based on homomorphic encryption according to claim 4, characterized in that: The key of the new key distribution scheme is encrypted using homomorphic encryption, and the encrypted key is transmitted through the quantum channel. After receiving the encrypted key, the receiver decrypts it and recovers the original key. The specific steps are: The sender uses Paillier homomorphic encryption to generate a pair of public and private keys; Converting the keys in the new key distribution scheme into binary numbers; Use the public key to encrypt the binary number and generate encrypted ciphertext; The sender transmits the encrypted ciphertext to the receiver through quantum communication; After receiving the encrypted ciphertext, the receiver uses the private key to decrypt it and recover the original key.
6. The quantum secure key management method based on homomorphic encryption according to claim 5, characterized in that: The method of using the multi-dimensional quantum state encoding parameters to verify the received key comprises the following specific steps: The receiver uses a quantum photon detector to receive the high-dimensional quantum state and measures the high-dimensional quantum state according to the multi-dimensional quantum state encoding parameters; Compare the measured high-dimensional quantum state with the decrypted key to check the consistency; If the measurement result is consistent with the decrypted key, the key can be used; If the measurement result is inconsistent with the decrypted key, a security alarm is triggered and the key is refused to be used; The key expires after use and is destroyed by physical destruction.
7. A quantum secure key management system based on homomorphic encryption, based on the quantum secure key management method based on homomorphic encryption according to any one of claims 1 to 6, characterized in that: Including, building module, encoding module, monitoring module and verification module; The construction module is used to initialize the quantum key pool, configure multi-dimensional quantum state encoding parameters, collect and pre-process the usage data of historical keys, build a key demand prediction model based on the pre-processed usage data, and output the predicted key demand; The encoding module is used to generate a multidimensional quantum state as an initial key distribution scheme based on the predicted key demand, encode the multidimensional quantum state using the multidimensional quantum state encoding parameter to generate a high-dimensional quantum state, convert the key format and store it in the quantum key pool, and distribute the key to each node of the quantum key pool according to the predicted key demand; The monitoring module is used to monitor the key usage of each node in the quantum key pool in real time, collect feedback information, generate a visual report, generate a new key distribution plan based on the key demand prediction model and store it in the quantum key pool; The verification module is used to extract the key of the new key distribution scheme from the quantum key pool, encrypt the key of the new key distribution scheme using homomorphic encryption, transmit the encrypted key through the quantum channel, and the receiver decrypts the encrypted key after receiving it to restore the original key, and verify the received key using multi-dimensional quantum state encoding parameters.
8. A computer device comprising a memory and a processor, wherein the memory stores a computer program, wherein: When the processor executes the computer program, the steps of the quantum secure key management method based on homomorphic encryption are implemented in any one of claims 1 to 6.
9. A computer-readable storage medium having a computer program stored thereon, characterized in that: When the computer program is executed by a processor, the steps of the quantum secure key management method based on homomorphic encryption according to any one of claims 1 to 6 are implemented.
Citation Information
Patent Citations
Quantum homomorphic encryption and decryption method based on multi-valued single quantum state
CN113922944A
Quantum key encryption communication method and system based on virtual private network
CN119583167A