A personal application level global quantum secure encryption proxy gateway and communication system

By providing quantum-secure communication services to general-purpose terminals through a personal application-level full-domain quantum-secure encryption proxy gateway, the problem of quantum transformation of terminal devices in the process of promoting full-domain quantum security protection is solved, and a smooth transition between quantum-secure encrypted communication and public network business communication is achieved, ensuring the security of data transmission and normal access.

CN119892356BActive Publication Date: 2025-12-30MATRICTIME DIGITAL TECH CO LTD
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202510047541.8
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2025-01-13
Publication Date
2025-12-30
Estimated Expiration
2045-01-13

AI Technical Summary

Technical Problem

In the process of promoting full-domain quantum security protection, when terminal devices need to meet the access requirements of both secure and insecure services, how can we achieve a smooth transition between quantum-secure encrypted communication and public network service communication without quantum-modifying the terminal devices, especially when terminal device upgrades are uneven, and enable effective service communication between users with different encryption levels?

Method used

This invention provides a personal application-level full-domain quantum-safe encryption proxy gateway, including a security proxy module, an interaction module, a transceiver module, and a quantum encryption module. Through these modules, it provides quantum-safe communication services to terminal applications on general-purpose terminals. It utilizes national cryptographic/commercial cryptographic symmetric encryption algorithms and the quantum encryption module to access a full-domain quantum-safe network, realizes quantum encryption and decryption of data, and communicates with business applications protected by full-domain quantum security through traditional networks.

Benefits of technology

Without quantum-modifying general-purpose terminals, quantum-secure communication services are provided to ensure the security of sensitive business data transmission without affecting the public network access of general-purpose terminals, thus achieving a balance between quantum-level security and normal access.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN119892356B_ABST
    Figure CN119892356B_ABST
Patent Text Reader

Abstract

The application discloses a personal application level global quantum security encryption proxy gateway and a communication system. Only the terminal application of a general terminal which needs to interact with a business application protected by global quantum security can establish a secure session with a security proxy module in the personal application level global quantum security encryption proxy gateway and determine a session key through negotiation, so that the personal application level global quantum security encryption proxy gateway can provide quantum security service for the general terminal based on specific applications, instead of protecting all business applications on the general terminal by quantum security, thereby avoiding affecting normal access of the general terminal to public network services. Moreover, the business data is encrypted and interacted by using a national secret / commercial secret symmetric encryption algorithm based on the established secure session and the negotiated session key, so that the security and confidentiality of the business data in the transmission process are ensured.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This application relates to the fields of information security and quantum encryption technology, and in particular to a personal application-level full-domain quantum secure encryption proxy gateway and communication system. Background Technology

[0002] With the rapid development of information technology, data security and privacy protection have become core issues in today's society. Full-domain quantum security protection has emerged to address this need, aiming to treat the entire business application device as a highly secure privacy zone through quantum encryption, ensuring that all business data entering and leaving the device is strictly protected by quantum-secure encryption devices. The proposal of this technical framework marks a new quantum era in data security protection, providing strong technical support for addressing increasingly complex cyberattacks and data breach risks.

[0003] However, in practical applications, full-domain quantum security protection faces some significant challenges. First, terminal devices typically need to accommodate both secure and insecure access requirements. For example, personal devices need to access not only business applications protecting data assets with full-domain quantum security, but also applications for daily information exchange with other individuals or businesses. However, considering that not all business applications accessed by the terminal device employ full-domain quantum security protection, directly upgrading the terminal device to a full-domain quantum-secure terminal to ensure encrypted communication would prevent it from communicating with applications not protected by full-domain quantum security, thus impacting some of the user's normal business activities.

[0004] Furthermore, there is a significant transitional phase in the promotion and widespread adoption of full-domain quantum security protection. Due to limitations such as the cost, time, and user acceptance of technology upgrades, it is impossible for all terminal devices to be upgraded to full-domain quantum security protection simultaneously. Therefore, for a period of time, some terminal devices will inevitably have been upgraded to full-domain quantum security protection, while others will not. This uneven upgrade situation poses a significant challenge to achieving effective business communication between users with different encryption levels.

[0005] In conclusion, how to achieve a universal terminal that can meet the requirements of quantum-secure encrypted communication while also enabling smooth public network business communication, while ensuring data security, has become a key issue that urgently needs to be addressed in the field of quantum-secure encrypted communication. Summary of the Invention

[0006] This application provides a personal application-level full-domain quantum-safe encrypted proxy gateway and communication system, which enables a general-purpose terminal to meet the requirements of quantum-safe encrypted communication and to successfully conduct public network business communication while ensuring data security.

[0007] In a first aspect, this application provides a personal application-level full-domain quantum-secure encryption proxy gateway. This gateway is used to provide quantum-secure communication services to a terminal application installed on a general-purpose terminal when it interacts with a business application protected by full-domain quantum security in a full-domain quantum-secure network. The personal application-level full-domain quantum-secure encryption proxy gateway includes the following modules: a security proxy module, an interaction module, a transceiver module, and a quantum encryption module; the interaction module is connected to the security proxy module, the transceiver module, and the quantum encryption module, respectively.

[0008] The security proxy module is used to establish a secure session with the terminal application and negotiate and determine a session key; based on the session key, it uses a pre-agreed national cryptographic / commercial cryptographic symmetric encryption algorithm with the terminal application to encrypt and interact with business data; wherein, the business data includes first business data sent by the terminal application to the business application protected by full-domain quantum security, and second business data sent by the business application protected by full-domain quantum security to the terminal application;

[0009] The interaction module is used to enable data transfer between different modules and to verify the security of the transferred data.

[0010] The quantum encryption module is configured to request access to the access base station in the global quantum security network, so that the personal application-level global quantum security encryption proxy gateway has the permission to communicate with the business application protected by global quantum security; and to receive first business data transmitted by the interaction module, obtain a first key to perform quantum encryption processing on the first business data, and perform quantum encryption processing on the first key based on a pre-saved symmetric key paired with the access base station; and to receive quantum-encrypted second business data and a quantum-encrypted second key transmitted by the interaction module; to perform quantum decryption on the quantum-encrypted second key based on the symmetric key; to perform quantum decryption processing on the quantum-encrypted second business data based on the second key; and to transmit the second business data to the security proxy module through the interaction module.

[0011] The transceiver module is configured to: receive the quantum-encrypted first service data and the quantum-encrypted first key through the interaction module; send the quantum-encrypted first service data to the service application protected by global quantum security through a traditional network, and relay the quantum-encrypted first key to the service application protected by global quantum security through the global quantum security network; receive the quantum-encrypted second service data sent by the service application protected by global quantum security through the traditional network, and the quantum-encrypted second key relayed through the global quantum security network; and transmit the quantum-encrypted second service data and the quantum-encrypted second key to the quantum encryption module through the interaction module.

[0012] Secondly, this application also provides a proxy-based full-domain quantum-secure encrypted communication system, the system including a general terminal, a personal application-level full-domain quantum-secure encrypted proxy gateway as described above, a public network application device, and a business application device protected by full-domain quantum security;

[0013] For the terminal application in the general terminal that interacts with the public network application device, the terminal application directly interacts with the public network application device to exchange business data.

[0014] For terminal applications in the general terminal that interact with business application devices protected by global quantum security, the terminal applications interact with the business application devices protected by global quantum security through the quantum security services provided by the personal application-level global quantum security encryption proxy gateway.

[0015] The beneficial effects of this application are as follows:

[0016] 1. Through a personal application-level full-domain quantum-secure encrypted proxy gateway, quantum-secure communication services can be provided between terminal applications installed on general-purpose terminals and protected business applications in a full-domain quantum-secure network without requiring quantum-modification of general-purpose terminals. This feature ensures that the transmission of sensitive business data can achieve quantum-level security even in traditional network environments.

[0017] 2. Only terminal applications in the general-purpose terminal that need to interact with business applications protected by full-domain quantum security will establish a secure session with the security proxy module in the personal application-level full-domain quantum security encryption proxy gateway and negotiate and determine the session key. This allows the personal application-level full-domain quantum security encryption proxy gateway to provide quantum security services to the general-purpose terminal based on specific applications, rather than providing quantum security protection for all business applications on the general-purpose terminal, thus avoiding interference with the general-purpose terminal's normal access to public network services. Furthermore, based on the established secure session and the negotiated session key, national / commercial cryptographic symmetric encryption algorithms are used to encrypt and interact with business data, ensuring the security and confidentiality of the business data during transmission. Attached Figure Description

[0018] To more clearly illustrate the technical solutions in the embodiments of this application, the accompanying drawings used in the description of the embodiments will be briefly introduced below. Obviously, the accompanying drawings described below are only some embodiments of this application. For those skilled in the art, other drawings can be obtained based on these drawings without creative effort.

[0019] Figure 1 A schematic diagram of the structure of a personal application-level full-domain quantum-secure encrypted proxy gateway provided in this application embodiment;

[0020] Figure 2 A schematic diagram illustrating the workflow of a specific personal application-level global quantum-secure encrypted proxy gateway provided in this application embodiment;

[0021] Figure 3 This application provides a system architecture diagram for a proxy-based global quantum secure encrypted communication. Detailed Implementation

[0022] To make the objectives, technical solutions, and advantages of this application clearer, the application will be further described in detail below with reference to the accompanying drawings. Obviously, the described embodiments are only some embodiments of this application, and not all embodiments. Based on the embodiments in this application, all other embodiments obtained by those skilled in the art without creative effort are within the scope of protection of this application.

[0023] A globally secure quantum network can support secure and efficient quantum communication between any quantum-safe terminals connected to the network, regardless of their geographical location. A core aspect of this network is the use of access base stations as communication hubs to connect quantum-safe terminals to the network, and the implementation of key relay between terminals connected to the network.

[0024] During the access process, when a quantum-safe terminal connects to an access base station, the base station assigns it a network access identifier—a unique identifier for the entire global quantum security network. This identifier carries information about the country, operator, region, cell, access base station, and the terminal itself. With this identifier, the terminal can be identified within the global quantum security network within the timeframe it possesses this identifier. Subsequently, the quantum-safe terminal can request services and resources from the global quantum security network through the access base station.

[0025] During key relay, the encryption terminal transmits the key through the encryption terminal's access base station, via the global quantum secure network, to the decryption terminal's access base station. The decryption terminal then forwards the key to the decryption terminal via the access base station, thus ensuring a symmetric quantum secure key between the encryption and decryption terminals, enabling encryption and decryption communication. This global quantum secure network also includes a key center, which primarily distributes keys—i.e., quantum keys—to quantum secure terminals connected to the network.

[0026] In the aforementioned global quantum secure network, the two ends that communicate directly, such as between a quantum secure terminal and an access base station, or between two access base stations, use a symmetric encryption method based on one-time pad encryption with true random numbers. This symmetric encryption method requires that only the two ends that communicate directly possess a unique true random number symmetric key to ensure the privacy of the communication.

[0027] However, in practical applications, full-domain quantum security protection faces some significant challenges. First, terminal devices typically need to accommodate both secure and insecure access requirements. For example, personal devices need to access not only business applications protecting data assets with full-domain quantum security, but also applications for daily information exchange with other individuals or businesses. However, considering that not all business applications accessed by the terminal device employ full-domain quantum security protection, directly upgrading the terminal device to a full-domain quantum-secure terminal to ensure encrypted communication would prevent it from communicating with applications not protected by full-domain quantum security, thus impacting some of the user's normal business activities.

[0028] Furthermore, there is a significant transitional phase in the promotion and widespread adoption of full-domain quantum security protection. Due to limitations such as the cost, time, and user acceptance of technology upgrades, it is impossible for all terminal devices to be upgraded to full-domain quantum security protection simultaneously. Therefore, for a period of time, some terminal devices will inevitably have been upgraded to full-domain quantum security protection, while others will not. This uneven upgrade situation poses a significant challenge to achieving effective business communication between users with different encryption levels.

[0029] Based on this, this application provides a personal application-level full-domain quantum-safe encrypted proxy gateway and communication system, so as to enable a general-purpose terminal to meet the requirements of quantum-safe encrypted communication and to successfully conduct public network business communication while ensuring data security.

[0030] Example 1:

[0031] Figure 1 This is a schematic diagram of a personal application-level full-domain quantum-secure encryption proxy gateway 100 provided in an embodiment of this application. The personal application-level full-domain quantum-secure encryption proxy gateway 100 is used to provide quantum-secure communication services to terminal applications installed on general-purpose terminals when interacting with business applications protected by full-domain quantum security in a full-domain quantum-secure network. The personal application-level full-domain quantum-secure encryption proxy gateway 100 includes the following modules: a security proxy module 110, an interaction module 120, a transceiver module 130, and a quantum encryption module 140; the interaction module 120 is connected to the security proxy module 110, the transceiver module 130, and the quantum encryption module 140 respectively.

[0032] The security proxy module 110 is used to establish a secure session with the terminal application and negotiate and determine a session key; based on the session key, it uses a pre-agreed national cryptographic / commercial cryptographic symmetric encryption algorithm with the terminal application to encrypt and interact with business data; wherein, the business data includes first business data sent by the terminal application to the business application protected by full-domain quantum security, and second business data sent by the business application protected by full-domain quantum security to the terminal application;

[0033] The interaction module 120 is used to realize the transmission of data between different modules, and to verify the security of the transmitted data;

[0034] The quantum encryption module 140 is configured to request access to the access base station in the global quantum security network, so that the personal application-level global quantum security encryption proxy gateway 100 has the permission to communicate with the business application protected by global quantum security; and to receive first business data transmitted by the interaction module 120, obtain a first key to perform quantum encryption processing on the first business data, and perform quantum encryption processing on the first key based on a pre-saved symmetric key paired with the access base station; and to receive quantum-encrypted second business data and a quantum-encrypted second key transmitted by the interaction module 120; to perform quantum decryption on the quantum-encrypted second key based on the symmetric key; to perform quantum decryption processing on the quantum-encrypted second business data based on the second key; and to transmit the second business data to the security proxy module 110 through the interaction module 120.

[0035] The transceiver module 130 is configured to receive, via the interaction module 120, the quantum-encrypted first service data and the quantum-encrypted first key; send the quantum-encrypted first service data to the service application protected by global quantum security via a conventional network, and relay the quantum-encrypted first key to the service application protected by global quantum security via the global quantum security network; receive, via the conventional network, the quantum-encrypted second service data sent by the service application protected by global quantum security, and the quantum-encrypted second key relayed via the global quantum security network; and transmit the quantum-encrypted second service data and the quantum-encrypted second key to the quantum encryption module 140 via the interaction module 120.

[0036] To enable a general-purpose terminal to perform quantum-secure encrypted communication without affecting its public network services, this application provides a personal application-level full-domain quantum-secure encrypted proxy gateway 100 (hereinafter referred to as "proxy gateway 100"). By connecting the proxy gateway 100 to the general-purpose terminal, it is possible to provide quantum-secure services to the general-purpose terminal when it needs to access business applications protected by full-domain quantum security, without quantum-modifying the terminal, and to ensure that the terminal's normal access to public network services is not affected. The general-purpose terminal refers to terminal devices not protected by full-domain quantum security, such as smartphones and computers. The proxy gateway 100 includes a security proxy module 110, an interaction module 120, a transceiver module 130, a quantum encryption module 140, and a quantum key module. The interaction module 120 is connected to the security proxy module 110, the transceiver module 130, and the quantum encryption module 140, respectively. The quantum encryption module 140 is connected to the quantum key module. The functions of each module in the proxy gateway 100 are described below:

[0037] A. Interactive Module 120.

[0038] The interaction module 120 plays a crucial role in the proxy gateway 100. Its core responsibility is to isolate and protect the different modules within the proxy gateway 100, ensuring the security of data transmitted within the proxy gateway 100 and the stable operation of the system. It prevents external networks from directly threatening the data in the quantum encryption module 140 and the security proxy module 110 through the transceiver module 130 of the proxy gateway 100. In particular, the interaction module 120 isolates the quantum encryption module 140 from other modules, preventing unauthorized data access and thus protecting the core functions and data security of the quantum encryption module 140.

[0039] Based on this, the interaction module 120 is responsible for transmitting data between different modules within the proxy gateway 100. This includes receiving first service data from the security proxy module 110 and then passing it to the quantum encryption module 140 for quantum encryption processing; or receiving quantum-encrypted first service data from the quantum encryption module 140 and then passing it to the transceiver module 130 for transmission; or receiving quantum-encrypted second service data from the transceiver module 130 and then passing it to the quantum encryption module 140 for quantum decryption processing; or receiving second service data from the quantum encryption module 140 and then passing it to the security proxy module 110, etc.

[0040] During data transmission, the interaction module 120 performs security checks on the data, such as verifying its integrity and compliance, to ensure overall data quality and transmission security, and prevent the injection of malicious data. For example, by comparing the hash value or checksum of the data, the interaction module 120 can detect whether any form of tampering or damage has occurred during transmission, thereby verifying the integrity of the data. As another example, the interaction module 120 can perform compliance verification on the data. This typically involves checking whether the data's format, scope, type, etc., conform to expected standards, thereby verifying the compliance of the data.

[0041] In one possible implementation, the interaction module 120 is specifically used to send the data to be quantum encrypted to the quantum encryption module 140 for quantum encryption processing if it is determined that the data type of the data to be quantum encrypted meets the pre-configured quantum-safe encryption and forwarding requirements.

[0042] When the interaction module 120 receives data (denoted as the data to be quantum-encrypted) that needs to be transmitted to the quantum encryption module 140 for quantum encryption, it can check the data type of the data to be quantum-encrypted. To accurately determine the data type, the interaction module 120 typically relies on the header information of the data to be quantum-encrypted. The header is the beginning of a data packet and contains important information about the packet content, such as data type, data length, and checksum. By parsing this header information, the interaction module 120 can quickly and accurately determine the data type of the data to be quantum-encrypted. Next, the interaction module 120 will determine whether the data meets the quantum-safe encryption and forwarding requirements according to pre-configured rules. These quantum-safe encryption and forwarding requirements can include allowed data types and / or prohibited data types. For example, certain highly sensitive data types can be explicitly listed as prohibited from being sent out, while some normal business data types are listed as data types that must be quantum-encrypted. If the interaction module 120 determines that the data to be quantum-encrypted does not meet the quantum-safe encryption and forwarding requirements, the interaction module 120 can refuse to transmit the data. If the interaction module 120 determines that the data to be quantum encrypted meets the requirements for quantum security encryption and forwarding, the interaction module 120 can send the data to be quantum encrypted to the quantum encryption module 140 for quantum encryption processing.

[0043] In one possible implementation, the interaction module 120 is specifically configured to send the data to be quantum decrypted to the quantum encryption module 140 for quantum decryption processing if it is determined that the encryption protocol of the data to be quantum decrypted satisfies a pre-configured quantum-safe encrypted communication protocol.

[0044] To prevent forged messages from entering the quantum encryption module 140 through the transceiver module 130 and thus affecting the security of the proxy gateway 100, in this application, when the interaction module 120 receives data (denoted as the data to be quantum decrypted) that needs to be transmitted to the quantum encryption module 140 for quantum decryption, it can check the encryption protocol of the data to be quantum decrypted. The encryption protocol refers to the encryption technology and standards used during data transmission or storage; it determines how the data is encrypted and how it should be decrypted. The interaction module 120 identifies the encryption protocol by reading the metadata or a specific protocol identifier in the data header. If the encryption protocol of the data to be quantum decrypted does not meet the pre-configured quantum-safe encrypted communication protocol, the interaction module 120 can refuse to transmit the data. If the encryption protocol of the data to be quantum decrypted meets the pre-configured quantum-safe encrypted communication protocol, the interaction module 120 can send the data to be quantum decrypted to the quantum encryption module 140 for quantum decryption processing.

[0045] B. Security Agent Module 110.

[0046] The security proxy module 110 serves as a bridge for data exchange between the proxy gateway 100 and the general-purpose terminal. It is responsible for receiving requests from the general-purpose terminal to access the full-domain quantum security business application, forwarding these requests to other modules within the proxy gateway 100 for full-domain quantum security protection processing, and simultaneously returning the business data from the full-domain quantum security business application to the general-purpose terminal.

[0047] For example, before interacting with the terminal application installed on the general-purpose terminal, the security proxy module 110 first needs to establish a secure session to identify the terminal application in the general-purpose terminal that requires the proxy gateway 100 to provide quantum security services, and to ensure the security of data transmission between the proxy gateway 100 and the terminal application. Simultaneously, the security proxy module 110 will also negotiate with the terminal application the session key and national / commercial cryptographic symmetric encryption algorithm required for subsequent business data transmission to ensure the confidentiality and integrity of the data.

[0048] In one possible implementation, the session key can be negotiated and determined by manually filling or configuring it in the general terminal and the proxy gateway 100.

[0049] In another possible implementation, the security proxy module 110 is specifically configured to receive a secure session establishment request sent by the terminal application; wherein the secure session establishment request indicates that the terminal application wishes to interact with the business application protected by full-domain quantum security; send a secure session establishment response carrying a digital certificate to the terminal application, so that the terminal application verifies the identity legitimacy of the personal application-level full-domain quantum security encryption proxy gateway 100 based on the digital certificate; wherein the digital certificate includes the following information: a pre-configured public key of the security proxy module 110, the certificate authority signature of the digital certificate, and the validity period; receive a session key and identity authentication information encrypted and sent by the terminal application based on the public key; wherein the identity authentication information includes the application digital certificate, username, and password of the terminal application; decrypt the encrypted session key and identity authentication information based on the session key; and, if the terminal application is determined to be legitimate based on the identity authentication information, determine to provide quantum secure communication services to the terminal application and save the session key.

[0050] During the establishment of a secure session, the security proxy module 110 first receives a secure session establishment request from the terminal application. This secure session establishment request is a clear indication that the terminal application wishes to interact with a business application protected by global quantum security.

[0051] Upon receiving the security establishment request, the security proxy module 110 can obtain a pre-saved digital certificate and then send a secure session establishment response carrying the digital certificate to the terminal application. The digital certificate serves as proof of identity for the security proxy module 110, ensuring that the terminal application can verify the legitimacy of the proxy gateway 100. The digital certificate includes the following information: the pre-configured public key of the security proxy module 110, the certificate authority signature of the digital certificate, and the validity period of the digital certificate. The public key is used to protect the confidentiality of the session key. The certificate authority signature of the digital certificate proves the authenticity and validity of the digital certificate, preventing forgery. The validity period indicates the duration of the digital certificate's validity, ensuring that the digital certificate is no longer used after expiration.

[0052] Upon receiving the secure session establishment response carrying the digital certificate, the terminal application parses the response to obtain the digital certificate. Then, based on the digital certificate, it verifies the legitimacy of the proxy gateway 100. If the proxy gateway 100 is deemed illegitimate, the application rejects the response; if the proxy gateway 100 is deemed legitimate, it obtains authentication information and generates a session key. This authentication information, used to verify the legitimacy of the terminal application, includes the application's digital certificate, username, and password. Based on this public key, the authentication information and session key are encrypted and sent to the secure proxy module 110 of the proxy gateway 100.

[0053] The terminal application can send the identity authentication information and session key to the security proxy module 110 simultaneously, or it can send them to the security proxy module 110 asynchronously; no specific limitation is made here.

[0054] Upon receiving encrypted authentication information and an encrypted session key from the terminal application, the security proxy module 110 obtains a pre-configured private key. Using this private key, it decrypts the encrypted authentication information and session key to obtain the plaintext of the session key and authentication information. The security proxy module 110 then verifies the legitimacy of the terminal application based on the decrypted authentication information. If the terminal application is deemed illegitimate based on this authentication information, it refuses to respond to the application; if the terminal application is deemed legitimate, it provides quantum-secure communication services to the application and saves the session key for use in subsequent communications, thus establishing a secure and reliable communication channel between the proxy gateway 100 and the terminal application.

[0055] Based on the above embodiments, the security proxy module 110 and the terminal application can establish a secure session and negotiate and determine a session key. Subsequently, the security proxy module 110 and the terminal application can use the session key to perform encrypted transmission of business data using a pre-agreed national cryptographic / commercial cryptographic symmetric encryption algorithm. The national cryptographic / commercial cryptographic symmetric encryption algorithm refers to national cryptographic algorithms (such as SM1, SM2, SM3, SM4, SM7, SM9, etc.) or commercial cryptographic algorithms (such as AES, DES, etc.).

[0056] For example, when a terminal application needs to send data (first business data) to a business application protected by full-domain quantum security, the terminal application encrypts the first business data using a pre-agreed national / commercial cryptographic symmetric encryption algorithm based on the session key, and transmits the classically encrypted first business data to the security proxy module 110 of the proxy gateway 100. Upon receiving the classically encrypted first business data, the security proxy module 110 decrypts it using the pre-agreed national / commercial cryptographic symmetric encryption algorithm based on the session key to obtain the first business data. The security proxy module 110 then securely sends the first business data to the desired business application protected by full-domain quantum security through other modules of the proxy gateway 100 (such as the transceiver module 130, the quantum encryption module 140, the interaction module 120, etc.).

[0057] In another example, the security proxy module 110 of the proxy gateway 100 obtains the service data (denoted as the second service data) sent by the service application protected by full-domain quantum security to the terminal application through the interaction module 120 of the proxy gateway 100. The security proxy module 110 encrypts the second service data using a pre-agreed national / commercial cryptographic symmetric encryption algorithm based on the session key, and transmits the classically encrypted second service data to the terminal application. Upon receiving the classically encrypted second service data, the terminal application decrypts the classically encrypted second service data using the pre-agreed national / commercial cryptographic symmetric encryption algorithm based on the session key to obtain the second service data.

[0058] C. Quantum encryption module 140.

[0059] The quantum encryption module 140 is a core component of the proxy gateway 100 that ensures the security of data during network transmission. It is primarily responsible for the following key tasks:

[0060] I. Network Communication and Access Permission Acquisition

[0061] The quantum encryption module 140 is first responsible for communicating with the access base station in the global quantum security network. This step is crucial because it involves requesting access to the global quantum security network and obtaining communication permissions within it. Only after successfully obtaining communication permissions can the quantum encryption module 140 ensure that subsequent access to business applications protected by global quantum security can proceed smoothly. For example, after the proxy gateway 100 is powered on, the quantum encryption module 140 automatically initiates an access authentication process with the access base station, requesting access to the global quantum security network.

[0062] It should be noted that when the quantum encryption module 140 successfully connects to the access base station in the global quantum security network, the quantum encryption module 140 will store the symmetric key paired with the access base station. Similarly, the access base station will also store the symmetric key paired with the proxy gateway 100 to facilitate providing key relay services to the proxy gateway 100 in the future.

[0063] In one example, the quantum encryption module 140 is further configured to generate a successful access notification message upon receiving a response message indicating successful access from the access base station; and send the successful access notification message to the security proxy module 110 via the interaction module 120.

[0064] The security proxy module 110 is specifically used to establish a secure session with the terminal application and negotiate and determine the session key upon receiving the successful access notification message.

[0065] In this application, after the proxy gateway 100 successfully connects to the global quantum security network, it notifies the security proxy module 110 of the successful connection, indicating that the security proxy module 110 can establish a secure session with the terminal application normally. For example, upon receiving a response message from the access base station indicating successful connection, the quantum encryption module 140 can generate a successful access notification message and then send this message to the interaction module 120, which in turn transmits the message to the security proxy module 110. Once the security proxy module 110 receives the successful access notification message, it indicates that it can establish a secure session with the terminal application normally. Therefore, the security proxy module 110 can establish a secure session with the terminal application and negotiate and determine the session key.

[0066] In one possible implementation, considering the possibility that the access base station may be offline or access authentication may fail, causing the proxy gateway 100 to fail to connect to the global quantum security network, the quantum encryption module 140, upon determining that the proxy gateway 100 has failed to connect to the global quantum security network, can generate a failure access notification message to notify the security proxy module 110 that the current proxy gateway 100 has failed to connect. When the security proxy module 110 receives a security session establishment request from the terminal application, it directly rejects it. For example, if the quantum encryption module 140 does not receive a response message from the access base station indicating successful access, it can generate a failure access notification message and then send the failure access notification message to the interaction module 120, which then transmits the failure access notification message to the security proxy module 110. Once the security proxy module 110 receives the failure access notification message, it indicates that it cannot yet provide quantum security services to the terminal application. Therefore, when the security proxy module 110 receives a security session establishment request initiated by the terminal application, it rejects the security session establishment request.

[0067] II. Provide quantum encryption processing.

[0068] For the first service data sent by the terminal application to the device which is protected by quantum security, the quantum encryption module 140 can perform quantum encryption processing on the first service data so that the first service data is transmitted in the form of quantum encryption during subsequent network transmission. This ensures that even if the data is intercepted during transmission, it cannot be easily decrypted, thereby ensuring the security of the data.

[0069] For example, based on the above embodiment, the quantum encryption module 140 can receive the first service data transmitted by the security proxy module 110 through the interaction module 120. For this first service data, the quantum encryption module 140 can obtain a key (denoted as the first key) used for quantum encryption of the first service data, and then perform quantum encryption processing on the first service data based on the first key to obtain the quantum-encrypted first service data. Simultaneously, the quantum encryption module 140 also obtains a pre-saved symmetric key paired with the access base station connected to the proxy gateway 100. Based on this symmetric key, the first key is quantum-encrypted to obtain the quantum-encrypted first key. This provides double protection; even if the first key is intercepted during transmission, an attacker cannot directly obtain the real key information.

[0070] III. Provides quantum decryption processing.

[0071] Corresponding to quantum encryption processing, quantum decryption processing is another important function of the quantum encryption module 140. For quantum-encrypted second service data transmitted under full quantum security protection, the quantum encryption module 140 can perform quantum decryption processing to recover the original second service data. For example, when the quantum encryption module 140 receives the quantum-encrypted second service data through the interaction module 120, it obtains the key (denoted as the second key) used to decrypt the quantum-encrypted second service data. Then, based on the second key, it performs quantum decryption on the quantum-encrypted second service data, thereby recovering the original second service data. The second service data is then transmitted to the security proxy module 110 through the interaction module 120.

[0072] The second key is relayed from a service application protected by global quantum security via a global quantum security network. To ensure the security of this second key during its transmission from the access base station to the proxy gateway 100, the access base station, upon obtaining the second key, performs quantum encryption on it based on a symmetric key paired with the proxy gateway 100 to obtain a quantum-encrypted second key. This quantum-encrypted second key is then sent to the proxy gateway 100. Therefore, the quantum encryption module 140 of the proxy gateway 100 can receive the quantum-encrypted second key from its transceiver module 130 via the interaction module 120. Then, based on the symmetric key paired with the access base station, it decrypts the quantum-encrypted second key to obtain the second key.

[0073] In one possible implementation, the quantum encryption module 140 may include a quantum encryption / decryption processing submodule and a quantum key submodule. The quantum encryption / decryption processing submodule is connected to both the interaction module 120 and the quantum key submodule. The quantum key submodule primarily serves as an area for storing and managing keys, and provides quantum keys to the quantum encryption / decryption processing submodule when needed. The quantum encryption / decryption processing submodule is used to request access to the access base station in the global quantum security network, so that the proxy gateway 100 has the authority to communicate with service applications protected by global quantum security; and to receive first service data transmitted by the interaction module 120, obtain a first key from the quantum key submodule, perform quantum encryption processing on the first service data based on the first key, and perform quantum encryption processing on the first key based on the symmetric key obtained from the quantum key submodule and paired with the access base station; and to receive quantum-encrypted second service data and quantum-encrypted second key transmitted by the interaction module 120; perform quantum decryption on the quantum-encrypted second key based on the symmetric key obtained from the quantum key submodule and paired with the access base station; perform quantum decryption processing on the quantum-encrypted second service data based on the second key; and transmit the second service data to the security proxy module 110 through the interaction module 120.

[0074] D. Transceiver module 130.

[0075] The transceiver module 130 is a key module in the proxy gateway 100 responsible for communicating with external networks (including traditional networks and global quantum-secure networks). The following describes the transceiver scenarios of the transceiver module 130:

[0076] Scenario 1: Sending scenario.

[0077] In this scenario, the transceiver module 130 is mainly responsible for sending data to business applications protected by full-domain quantum security via an external network.

[0078] For example, the transceiver module 130 can receive the quantum-encrypted first service data and its corresponding destination address transmitted by the quantum encryption module 140 through the interaction module 120 of the proxy gateway 100. Then, through a traditional network, the quantum-encrypted first service data is sent to the service application protected by global quantum security according to the destination address.

[0079] The destination address is transmitted to the security proxy module 110 of the proxy gateway 100 when the terminal application transmits the first service data. The security proxy module 110 then transmits the destination address and the first service data to the quantum encryption module 140 through the interaction module 120.

[0080] As another example, the transceiver module 130 can also receive the quantum-encrypted first key transmitted by the quantum encryption module 140 through the interaction module 120. This quantum-encrypted first key is then relayed to the access base station via a global quantum security network.

[0081] Scenario 2: Receiving scenario.

[0082] In addition to transmitting data, the transceiver module 130 is also used to receive data. The transceiver module 130 can receive quantum-encrypted second service data sent by a service application protected by global quantum security via a conventional network, and receive the quantum-encrypted second key relayed from the service application by the access base station via the global quantum security network. Once the quantum-encrypted second service data is obtained, the transceiver module 130 can transmit the quantum-encrypted second service data to the quantum encryption module 140 for subsequent quantum decryption processing via the interaction module 120. Similarly, once the quantum-encrypted second key is obtained, the transceiver module 130 can transmit the quantum-encrypted second key to the quantum encryption module 140 via the interaction module 120, so that the quantum encryption module 140 can perform subsequent quantum decryption processing based on the quantum-encrypted second key.

[0083] The beneficial effects of this application are as follows:

[0084] 1. Through the personal application-level full-domain quantum-secure encryption proxy gateway 100, quantum-secure communication services can be provided between terminal applications installed on general-purpose terminals and protected business applications in a full-domain quantum-secure network without quantum-modifying general-purpose terminals. This feature ensures that the transmission of sensitive business data can achieve quantum-level security even in traditional network environments.

[0085] 2. Only terminal applications in the general-purpose terminal that need to interact with business applications protected by full-domain quantum security will establish a secure session with the security proxy module 110 in the personal application-level full-domain quantum security encryption proxy gateway 100 and negotiate and determine the session key. This allows the personal application-level full-domain quantum security encryption proxy gateway 100 to provide quantum security services to the general-purpose terminal based on specific applications, rather than providing quantum security protection for all business applications on the general-purpose terminal, thus avoiding interference with the general-purpose terminal's normal access to public network services. Furthermore, based on the established secure session and the negotiated session key, national cryptographic / commercial cryptographic symmetric encryption algorithms are used to encrypt and interact with business data, ensuring the security and confidentiality of the business data during transmission.

[0086] 3. The interaction module 120 in this personal application-level full-domain quantum security encryption proxy gateway 100 isolates and protects different modules within the proxy gateway 100, ensuring the security of data transmitted within the proxy gateway 100 and the stable operation of the system. This prevents external networks from directly threatening the data in the quantum encryption module 140 and the security proxy module 110 through the transceiver module 130 of the proxy gateway 100. In particular, the interaction module 120 isolates the quantum encryption module 140 from other modules, preventing unauthorized data access and thus protecting the core functions and data security of the quantum encryption module 140.

[0087] 4. The quantum encryption module 140 in the personal application-level full-domain quantum-secure encryption proxy gateway 100 obtains the permission to communicate with business applications protected by full-domain quantum security by requesting access to the access base station in the full-domain quantum-secure network. Simultaneously, the quantum encryption module 140 can also provide quantum encryption and decryption processing, thereby ensuring the secure transmission of business data within the quantum-secure network.

[0088] Example 2:

[0089] The workflow of the personal application-level full-domain quantum-secure encryption proxy gateway provided in this application will be described below through specific embodiments. Figure 2 This application provides a schematic diagram of the workflow of a specific personal application-level full-domain quantum-secure encryption proxy gateway. The workflow mainly includes an access phase, a session establishment phase, and a communication phase, with each phase comprising:

[0090] Phase 1: Access Phase.

[0091] S201: After the proxy gateway is powered on, its quantum encryption and decryption processing submodule will automatically initiate an access authentication process to the access base station and request access to the global quantum security network.

[0092] S202: Upon receiving a response message from the access base station indicating successful access, the quantum encryption / decryption processing submodule generates a successful access notification message and sends it to the interaction module of the proxy gateway.

[0093] S203: If the interaction module determines that the successful access notification message has passed the security verification, it will send the successful access notification message to the security proxy module of the proxy gateway.

[0094] S204: Upon receiving the successful access notification message, the security agent module determines that a secure session can be established with the terminal application on the general terminal.

[0095] In one possible implementation, if the quantum encryption module does not receive a response message from the access base station indicating successful access, it can generate a failed access notification message and then send this message to the interaction module. The interaction module then forwards the message to the security proxy module. Upon receiving the failed access notification message, the security proxy module recognizes that it cannot yet provide quantum-secure services to the terminal application. Therefore, if the security proxy module receives a secure session establishment request from the terminal application, it will reject the request.

[0096] Phase Two: Session Establishment Phase.

[0097] S301: When a terminal application on a general terminal needs to access a business application protected by global quantum security, it sends a security session establishment request to the security proxy module of the proxy gateway.

[0098] S302: After receiving the security establishment request, the security agent module can obtain the pre-saved digital certificate and then send the security session establishment response carrying the digital certificate to the terminal application.

[0099] The digital certificate serves as authentication for the security proxy module, ensuring that end applications can verify the legitimacy of the proxy gateway. This digital certificate includes the following information: the pre-configured public key of the security proxy module, the certificate authority signature of the digital certificate, and the validity period of the digital certificate. The public key is used to protect the confidentiality of the session key. The certificate authority signature of the digital certificate proves the authenticity and validity of the digital certificate, preventing forgery. The validity period indicates the duration of the digital certificate's validity, ensuring that it is no longer used after expiration.

[0100] S303: After receiving the secure session establishment response carrying the digital certificate, the terminal application verifies the identity and legitimacy of the proxy gateway based on the digital certificate.

[0101] S304: If the identity of the proxy gateway is confirmed to be legitimate, obtain the identity authentication information and generate a session key. Based on the public key, encrypt the identity authentication information and session key and send them to the security proxy module of the proxy gateway.

[0102] The identity authentication information is used to verify the legitimacy of the terminal application, and it includes the application's digital certificate, username, and password.

[0103] In one possible implementation, if the terminal application determines, based on the digital certificate, that the proxy gateway's identity is illegitimate, it will refuse to respond.

[0104] S305: When the security proxy module receives the encrypted authentication information and encrypted session key sent by the terminal application, it obtains the pre-configured private key, and decrypts the encrypted authentication information and encrypted session key according to the private key to obtain the plaintext of the session key and authentication information.

[0105] S306: The security proxy module will verify the legitimacy of the terminal application based on the decrypted identity authentication information.

[0106] S307: If the terminal application is determined to be legitimate based on the identity authentication information, the security proxy module determines to provide quantum secure communication services for the terminal application and saves the session key.

[0107] Phase 3: Communication Phase.

[0108] For sending scenarios:

[0109] S401: The terminal application uses a session key and a national cryptographic / commercial cryptographic symmetric encryption algorithm to encrypt the first business data, and sends the classically encrypted first business data to the security proxy module of the proxy gateway.

[0110] S402: The security agent module uses a pre-agreed national cryptographic / commercial cryptographic symmetric encryption algorithm based on the session key to decrypt the first business data after it has been encrypted in a classic way, so as to obtain the first business data.

[0111] S403: The security agent module transmits the first business data to the interaction module.

[0112] S404: The interaction module determines whether the data type of the first business data meets the requirements for quantum-safe encryption and forwarding.

[0113] S405: If the interaction module determines that the data type of the first service data meets the requirements for quantum-safe encryption and forwarding, it forwards the first service data to the quantum encryption module.

[0114] S406: The quantum encryption / decryption processing submodule receives the service data from the terminal application, obtains the first key from the quantum key submodule for quantum encryption of the first service data, and then performs quantum encryption processing on the first service data based on the first key to obtain the quantum-encrypted first service data.

[0115] S407: The quantum encryption / decryption processing submodule obtains the symmetric key paired with the access base station from the quantum key submodule, and performs quantum encryption processing on the first key based on the symmetric key to obtain the quantum-encrypted first key.

[0116] S408: The quantum encryption / decryption processing submodule sends the quantum-encrypted first business data and its corresponding destination address, as well as the quantum-encrypted first key, to the interaction module.

[0117] S409: The interaction module forwards the quantum-encrypted first business data and its corresponding destination address, as well as the quantum-encrypted first key, to the transceiver module of the proxy gateway.

[0118] S410: Upon receiving the first quantum-encrypted service data and its corresponding destination address, the transceiver module transmits the first quantum-encrypted service data to the service application protected by global quantum security via a traditional network, according to the destination address.

[0119] S411: Upon receiving the quantum-encrypted first key, the transceiver module transmits the quantum-encrypted first key to the access base station for relay through the global quantum security network, so that the first key can be relayed to the business application protected by global quantum security.

[0120] For receiving scenarios:

[0121] S501: When the transceiver module receives quantum-encrypted second service data sent by a service application protected by full-domain quantum security through a traditional network, it transmits the quantum-encrypted second service data to the interaction module and executes S503.

[0122] S502: When the transceiver module receives the quantum-encrypted second key from the access base station through the global quantum security network, it transmits the quantum-encrypted second key to the interaction module.

[0123] S503: The interaction module checks whether the encryption protocol of the data to be quantum decrypted meets the pre-configured quantum-safe encrypted communication protocol.

[0124] The data to be quantum decrypted includes quantum-encrypted second business data and quantum-encrypted second key.

[0125] S504: If it is determined that the encryption protocol of the data to be quantum decrypted meets the pre-configured quantum-safe encrypted communication protocol, the interaction module sends the data to be quantum decrypted to the quantum encryption and decryption processing submodule for quantum decryption processing.

[0126] In one possible implementation, if the encryption protocol of the data to be quantum decrypted does not meet the pre-configured quantum-safe encrypted communication protocol, the interaction module may refuse to transmit the data to be quantum decrypted.

[0127] S505: For the quantum-encrypted second key received by the quantum encryption / decryption processing submodule, the quantum encryption / decryption processing submodule can obtain the symmetric key paired with the access base station from the quantum key submodule, and decrypt the quantum-encrypted second key based on the symmetric key to obtain the second key.

[0128] S506: For the quantum-encrypted second service data received by the quantum encryption / decryption processing submodule, the quantum encryption / decryption processing submodule obtains the second key, and based on the second key, decrypts the quantum-encrypted second service data to obtain the second service data.

[0129] S507: The quantum encryption / decryption processing submodule transmits the second business data to the interaction module.

[0130] S508: The interaction module performs a security verification on the second business data.

[0131] S509: If the interaction module determines that the second business data has passed the security verification, it will transfer the second business data to the security proxy module.

[0132] S510: The security proxy module uses a session key and a national cryptographic / commercial cryptographic symmetric encryption algorithm to encrypt the second business data, and then sends the classically encrypted second business data to the terminal application.

[0133] S511: The terminal application uses the session key and a national cryptographic / commercial cryptographic symmetric encryption algorithm to decrypt the received classically encrypted second service data to obtain the second service data.

[0134] Example 3:

[0135] Based on the same inventive concept, this application also provides a proxy-based global quantum-secure encrypted communication system. Figure 3 This application provides a system architecture diagram for a proxy-based full-domain quantum-secure encrypted communication system, which includes a general terminal 31, a personal application-level full-domain quantum-secure encrypted proxy gateway 32 as in any of the above embodiments, a public network application device 33, and a business application device 34 protected by full-domain quantum security.

[0136] For the terminal application in the general terminal 31 that interacts with the public network application device 33, the terminal application 31 directly interacts with the public network application device 33 for business data.

[0137] For the terminal application in the general terminal 31 that interacts with the business application device 34 protected by global quantum security, the terminal application interacts with the business application device 34 protected by global quantum security through the quantum security service provided by the personal application-level global quantum security encryption proxy gateway 32.

[0138] After processing by the personal application-level full-domain quantum-secure encryption proxy gateway 32, when a general-purpose terminal needs to access a business application device 34 protected by full-domain quantum security, it will first access the personal application-level full-domain quantum-secure encryption proxy gateway 32. Communication between the general-purpose terminal 31 and the personal application-level full-domain quantum-secure encryption proxy gateway 32 uses national cryptographic / commercial cryptographic symmetric encryption. After being decrypted by the personal application-level full-domain quantum-secure encryption proxy gateway 32 using national cryptographic / commercial cryptographic methods, the communication is converted to quantum-secure encryption to access the business application device 34 protected by full-domain quantum security. In other words, the first business data sent by the terminal application on the general-purpose terminal 31 to the business application device 34 protected by full-domain quantum security is processed by the personal application-level full-domain quantum-secure encryption proxy gateway 32 and converted into quantum-encrypted data for transmission over the network.

[0139] Similarly, the second business data, quantum-encrypted, sent by the business application device 34 protected by full-domain quantum security to the terminal application of the general terminal 31, can also be first sent to the personal application-level full-domain quantum security encryption proxy gateway 32 for decryption, and then the decrypted second business data is sent to the terminal application through national cryptographic / commercial cryptographic symmetric encryption communication.

[0140] If the general terminal 31 interacts with the public network application device 33, the terminal application in the general terminal 31 that interacts with the public network application device 33 can directly establish a connection with the public network application device 33 and interact with the public network application service on the public network application device using public network encryption or unencryption.

[0141] Based on this, a single device can access both quantum security services and public network services, with near-end encryption protected by national cryptographic / commercial cryptographic encryption.

[0142] It should be noted that the principle by which this personal application-level full-domain quantum secure encryption proxy gateway solves the problem is the same as the principle by which it solves the technical problem in the above-mentioned device embodiments, and the repetitions will not be repeated.

Claims

1. A personal application level global quantum secure encryption proxy gateway, characterized in that, The personal application level global quantum security encryption proxy gateway is used for providing quantum security communication service for a terminal application installed on a general terminal when the terminal application interacts with a service application protected by global quantum security in a global quantum security network, and comprises the following modules: a security proxy module, an interaction module, a transceiver module, and a quantum encryption module; the interaction module is connected with the security proxy module, the transceiver module, and the quantum encryption module respectively; The security proxy module is used for establishing a secure session with the terminal application, negotiating and determining a session key, and encrypting interactive service data with the terminal application by using a pre-agreed national secret / commercial secret symmetric encryption algorithm based on the session key; the service data includes first service data sent by the terminal application to the service application protected by global quantum security and second service data sent by the service application protected by global quantum security to the terminal application; The interaction module is used for realizing data transmission between different modules and checking the security of the transmitted data; The quantum encryption module is used for requesting access to an access base station in the global quantum security network, so that the personal application level global quantum security encryption proxy gateway has the permission to communicate with the service application protected by global quantum security, receiving the first service data transmitted by the interaction module, obtaining a first key to perform quantum encryption processing on the first service data, performing quantum encryption processing on the first key based on a pre-saved symmetric key paired with the access base station, receiving the quantum-encrypted second service data and the quantum-encrypted second key transmitted by the interaction module, performing quantum decryption on the quantum-encrypted second key based on the symmetric key, performing quantum decryption processing on the quantum-encrypted second service data based on the second key, and transmitting the second service data to the security proxy module through the interaction module; The transceiver module is used for receiving the quantum-encrypted first service data and the quantum-encrypted first key through the interaction module, sending the quantum-encrypted first service data to the service application protected by global quantum security through a traditional network, relaying the quantum-encrypted first key to the service application protected by global quantum security through the global quantum security network, receiving quantum-encrypted second service data sent by the service application protected by global quantum security through the traditional network and the quantum-encrypted second key relayed through the global quantum security network, and transmitting the quantum-encrypted second service data and the quantum-encrypted second key to the quantum encryption module through the interaction module.

2. The personal application-level global quantum secure encryption proxy gateway of claim 1, wherein, The security agent module is specifically configured to receive a security session establishment request sent by the terminal application; the security session establishment request is used to represent that the terminal application hopes to interact with the service application protected by global quantum security; send a security session establishment response carrying a digital certificate to the terminal application, so that the terminal application verifies the identity legality of the personal application level global quantum security encryption agent gateway based on the digital certificate; the digital certificate includes the following information: a pre-configured public key of the security agent module, a certificate authority signature of the digital certificate, and a validity period; receive the session key and identity authentication information encrypted and sent by the terminal application based on the public key; the identity authentication information includes the application digital certificate of the terminal application, the username, and the password; decrypt the encrypted session key and identity authentication information based on the session key; in the case of determining that the terminal application is legal based on the identity authentication information, determine to provide quantum security communication services for the terminal application, and save the session key.

3. The personal application-level global quantum secure encryption proxy gateway of claim 1, wherein, The quantum encryption module is further configured to generate a successful access notification message in the case of receiving the response message representing successful access sent by the access base station; and send the successful access notification message to the security agent module through the interaction module. The security agent module is specifically configured to establish a security session with the terminal application and negotiate a session key in the case of receiving the successful access notification message.

4. The personal application-level global quantum secure encryption proxy gateway of claim 1, wherein, The security agent module is specifically configured to receive the first service data encrypted by the terminal application; decrypt the first service data encrypted by the terminal application based on the session key through the SM / CM symmetric encryption algorithm to obtain the first service data; and receive the second service data through the interaction module; encrypt the second service data based on the session key through the SM / CM symmetric encryption algorithm and send the second service data encrypted by the terminal application to the terminal application.

5. The personal application-level global quantum secure encryption proxy gateway of claim 1, wherein, The interaction module is specifically configured to send the data to be quantum encrypted to the quantum encryption module for quantum encryption processing if it is determined that the data type of the data to be quantum encrypted to be transmitted meets the pre-configured quantum security encryption and forwarding requirements.

6. The personal application-level global quantum secure encryption proxy gateway of claim 1, wherein, The interaction module is specifically configured to send the data to be quantum decrypted to the quantum encryption module for quantum decryption processing if it is determined that the encryption protocol of the data to be quantum decrypted meets the pre-configured quantum security encryption communication protocol.

7. The personal application-level global quantum secure encryption proxy gateway of claim 1, wherein, The quantum encryption module includes a quantum encryption and decryption processing submodule and a quantum key submodule; the quantum encryption and decryption processing submodule is connected with the interaction module and the quantum key submodule respectively; The quantum key submodule is used to store and manage quantum keys and provide the quantum encryption and decryption processing submodule with keys required for quantum encryption and decryption processing. The quantum encryption and decryption processing submodule is configured to request access to an access base station in the global quantum security network, so that the personal application-level global quantum security encryption proxy gateway has the permission to communicate with the service application protected by the global quantum security; receive the first service data transmitted by the interaction module, obtain the first key from the quantum key submodule, perform quantum encryption processing on the first service data based on the first key, and perform quantum encryption processing on the first key based on the symmetric key stored in the quantum key submodule; receive the quantum-encrypted second service data and the quantum-encrypted second key transmitted by the interaction module; perform quantum decryption on the quantum-encrypted second key based on the symmetric key stored in the quantum key submodule; perform quantum decryption processing on the quantum-encrypted second service data based on the second key; and transmit the second service data to the security proxy module through the interaction module.

8. A proxy-based global quantum-secure encrypted communication system, characterized in that, The system comprises a general terminal, the personal application-level global quantum security encryption proxy gateway according to any one of claims 1-7, a public network application device, and a service application device protected by the global quantum security. For a terminal application in the general terminal that interacts with the public network application device, the terminal application directly interacts with the public network application device for service data. For a terminal application in the general terminal that interacts with the service application device protected by the global quantum security, the terminal application interacts with the service application device protected by the global quantum security for service data through the quantum security service provided by the personal application-level global quantum security encryption proxy gateway.

Citation Information

Patent Citations

  • Communication method and system based on quantum Ukey

    CN107769913A

  • Negotiation method of point-to-point communication key center

    CN119299082A