Device for entity authentication using quantum random numbers and entity authentication method thereof

The calculation sequence is generated by quantum random number sequence for entity identification, which solves the problems of high computing time consumption and easy-to-break encryption algorithms in the prior art, and realizes efficient and secure entity identification.

CN119892361BActive Publication Date: 2025-08-01ANHUI GUOKE QUANTUM NETWORK CO LTD +1
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202510378153.8
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2025-03-28
Publication Date
2025-08-01
Estimated Expiration
2045-03-28

AI Technical Summary

Technical Problem

The existing entity identification mechanism has the risk of high computing time consumption and easy encryption algorithms to be cracked, affecting system performance and security.

Method used

Quantum random number sequences are used for entity identification, and quantum random number sequences are generated and distributed by cryptographs through quantum key distribution networks or quantum key routing machines. The claiming party and the verification party share the same sequence, and the verification sequence is generated based on the quantum random number to identify.

Benefits of technology

It significantly reduces the calculation time, eliminates the risk of being cracked, and enhances the security and reliability of entity identification.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN119892361B_ABST
    Figure CN119892361B_ABST
Patent Text Reader

Abstract

This application relates to quantum communication technology and discloses a device for entity authentication using quantum random numbers and an entity authentication method thereof. The entity authentication method of this application includes generating a first verification sequence, wherein the first verification sequence is obtained based on a quantum random number sequence, and the quantum random number sequence is shared by the claimant and the verifier through QKDN or QKR; sending the first verification sequence to the verifier, thereby authenticating the claimant entity, wherein the verifier verifies the first verification sequence using a second verification sequence generated based on the quantum random number sequence. By using the quantum random number sequence to generate a verification sequence for entity authentication, this application avoids the complexity of traditional encryption and decryption operations, significantly reduces the calculation time, avoids the risk of being cracked, and enhances the security and reliability of entity authentication.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This application relates to quantum communication technology, and particularly to an apparatus and method for entity authentication using quantum random numbers. Background Art

[0002] In a real-time communication system, entity authentication, as a basic security service, plays a crucial role. Its core purpose is to verify whether an entity is the identity it claims to be. Specifically, in a one-way authentication scenario, entity A plays the role of the claimant, while entity B is the verifier; correspondingly, in a two-way authentication scenario, entity A and entity B are both the claimant and the verifier to each other. In the authentication process, both parties generate and exchange a standardized message, namely a token. One-way authentication involves at least one token exchange, while two-way authentication requires at least two token exchanges. If the authentication mechanism is initiated by sending a challenge, an additional transmission is required.

[0003] Currently, the mechanisms for entity authentication mainly include the following methods: the authentication mechanism using symmetric encryption algorithms, the authentication mechanism based on digital signature technology, and the authentication mechanism using cryptographic hash functions. The common feature of these mechanisms is that entity A and entity B jointly possess a secret key KAB, and based on this key, they encrypt and decrypt the specified data to verify the identity of the entity.

[0004] However, this entity authentication mechanism has certain limitations. On the one hand, the encryption and decryption operations consume a certain amount of time, which may affect the performance of the system; on the other hand, there is a risk that the encryption algorithm itself can be cracked, thus posing a potential threat to the security of the system. Summary of the Invention

[0005] This application aims to provide an apparatus and method for entity authentication using quantum random numbers. This method avoids the complexity of traditional encryption and decryption operations, thus significantly reducing the calculation time. At the same time, it effectively eliminates the risk of being cracked, enhancing the security and reliability.

[0006] To solve the above technical problems, at least one embodiment of this application provides an entity authentication method, applicable to the claimant, including: generating a first verification sequence, where the first verification sequence is obtained based on a quantum random number sequence, and the quantum random number sequence is shared by the claimant and the verifier through QKDN or QKR; sending the first verification sequence to the verifier, thereby authenticating the claimant, where the verifier verifies the first verification sequence based on a second verification sequence generated based on the quantum random number sequence.

[0007] At least one embodiment of the present application provides an entity authentication method, which is applicable to a verifier and includes: obtaining a first verification sequence from a claimant, where the first verification sequence is generated by the claimant based on a quantum random number sequence, and the quantum random number sequence is shared by the claimant and the verifier through QKDN or QKR; generating a second verification sequence to verify the first verification sequence, where the second verification sequence is obtained based on the quantum random number sequence.

[0008] At least one embodiment of the present application provides an entity authentication method, which is applicable to a claimant and includes: receiving a verification notice from a verifier, where the verification notice instructs the claimant to obtain a quantum random number sequence from QKDN or QKR; generating a first verification sequence, where the first verification sequence is obtained based on a quantum random number sequence, and the quantum random number sequence is shared by the claimant and the verifier through QKDN or QKR; sending the first verification sequence to the verifier, so as to authenticate the claimant, where the verifier verifies the first verification sequence with a second verification sequence generated based on the quantum random number sequence.

[0009] At least one embodiment of the present application provides an entity authentication method, which is applicable to a verifier and includes: sending a verification notice, where the verification notice instructs the claimant to obtain a quantum random number sequence from QKDN or QKR; obtaining a first verification sequence from the claimant, where the first verification sequence is generated by the claimant based on a quantum random number sequence, and the quantum random number sequence is shared by the claimant and the verifier through QKDN or QKR; generating a second verification sequence to verify the first verification sequence, where the second verification sequence is obtained based on the quantum random number sequence.

[0010] At least one embodiment of the present application provides an entity authentication method, which is applicable to a claimant and includes: generating a first verification sequence, where the first verification sequence is obtained based on a quantum random number sequence, and the quantum random number sequence is shared by the claimant and the verifier through QKDN or QKR; sending the first verification sequence to the verifier, so as to authenticate the claimant, where the verifier verifies the first verification sequence with a second verification sequence generated based on the quantum random number sequence; receiving a third verification sequence, so as to authenticate the verifier, where the claimant verifies the third verification sequence with a fourth verification sequence generated based on the quantum random number sequence, and the third verification sequence is obtained by the verifier based on the quantum random number sequence.

[0011] At least one embodiment of the present application provides an entity authentication method, which is applicable to a verifier and includes: obtaining a first verification sequence from a claimant, where the first verification sequence is generated by the claimant based on a quantum random number sequence, and the quantum random number sequence is shared by the claimant and the verifier through QKDN or QKR; generating a second verification sequence to verify the first verification sequence, where the second verification sequence is obtained based on the quantum random number sequence; sending a third verification sequence to authenticate the verifier, where the fourth verification sequence generated by the claimant based on the quantum random number sequence is used to verify the third verification sequence, and the third verification sequence is obtained by the verifier based on the quantum random number sequence.

[0012] At least one embodiment of the present application provides an entity authentication method, which is applicable to a claimant and includes: receiving a verification notice from a verifier, where the verification notice instructs the claimant to obtain a quantum random number sequence from QKDN or QKR; generating a first verification sequence, where the first verification sequence is obtained based on a quantum random number sequence, and the quantum random number sequence is shared by the claimant and the verifier through QKDN or QKR; sending the first verification sequence to the verifier to authenticate the claimant, where the second verification sequence generated by the verifier based on the quantum random number sequence is used to verify the first verification sequence; receiving a third verification sequence to authenticate the verifier, where the fourth verification sequence generated by the claimant based on the quantum random number sequence is used to verify the third verification sequence, and the third verification sequence is obtained by the verifier based on the quantum random number sequence.

[0013] At least one embodiment of the present application provides an entity authentication method, which is applicable to a verifier and includes: sending a verification notice, where the verification notice instructs the claimant to obtain a quantum random number sequence from QKDN or QKR; obtaining a first verification sequence from a claimant, where the first verification sequence is generated by the claimant based on a quantum random number sequence, and the quantum random number sequence is shared by the claimant and the verifier through QKDN or QKR; generating a second verification sequence to verify the first verification sequence, where the second verification sequence is obtained based on the quantum random number sequence; sending a third verification sequence to authenticate the verifier, where the fourth verification sequence generated by the claimant based on the quantum random number sequence is used to verify the third verification sequence, and the third verification sequence is obtained by the verifier based on the quantum random number sequence.

[0014] At least one embodiment of the present application provides a device for entity authentication using quantum random numbers, including: at least one processor; and a memory communicatively connected to the at least one processor, wherein the memory stores instructions executable by the at least one processor, and the instructions are executed by the at least one processor to enable the at least one processor to execute the above-mentioned entity authentication method.

[0015] At least one embodiment of the present application provides a computer-readable storage medium storing a computer program, which implements the above-mentioned entity authentication method when executed by a processor.

[0016] At least one embodiment of the present application provides a system for entity authentication using quantum random numbers, the system including: the above-mentioned device for entity authentication using quantum random numbers, wherein the device includes a claimant device and a verifier device; a quantum key distribution network or a QKR device, wherein the quantum key distribution network or the QKR device is used to generate and distribute a quantum random number sequence to ensure that the claimant and the verifier share the same sequence.

[0017] Compared with the prior art, in the present application, the claimant generates a first check sequence based on the quantum random number sequence and sends it to the verifier. After receiving the first check sequence, the verifier generates a second check sequence based on the quantum random number sequence shared by both parties to verify the first check sequence, thereby completing the entity authentication of the claimant. By using the quantum random number sequence to generate the check sequence for entity authentication, the present application avoids the complexity of traditional encryption and decryption operations, significantly reduces the calculation time, effectively eliminates the risk of being cracked, and enhances the security and reliability of entity authentication. Description of the Drawings

[0018] One or more embodiments are exemplarily illustrated by the pictures in the corresponding drawings. These exemplary illustrations do not limit the embodiments. Elements with the same reference numerals in the drawings are represented as similar elements, unless otherwise stated, and the drawings in the drawings do not constitute a proportional limitation.

[0019] Figure 1 It is a schematic structural diagram of a system for entity authentication using quantum random numbers provided by an embodiment of the present application;

[0020] Figure 2 It is a schematic structural diagram of a device for entity authentication using quantum random numbers provided by an embodiment of the present application;

[0021] Figure 3 It is a flowchart of an entity authentication method provided by an embodiment of the present application;

[0022] Figure 4 It is a schematic diagram of a verification sequence involved in an entity authentication method provided by an embodiment of the present application;

[0023] Figure 5 It is a schematic diagram of an interception method of a verification sequence involved in an entity authentication method provided by another embodiment of the present application;

[0024] Figure 6 It is a schematic diagram of an interception method of a verification sequence involved in an entity authentication method provided by another embodiment of the present application;

[0025] Figure 7 It is a flowchart of an entity authentication method provided by another embodiment of the present application;

[0026] Figure 8 It is a flowchart of an entity authentication method provided by another embodiment of the present application;

[0027] Figure 9 It is a flowchart of an entity authentication method provided by another embodiment of the present application;

[0028] Figure 10 It is a flowchart of an entity authentication method provided by another embodiment of the present application. Detailed implementation manners

[0029] To make the objectives, technical solutions and advantages of the embodiments of the present application clearer, the following will elaborate on each embodiment of the present application in conjunction with the accompanying drawings. However, those of ordinary skill in the art can understand that in each embodiment of the present application, many technical details are presented for the reader to better understand the present application. However, even without these technical details and various changes and modifications based on the following embodiments, the technical solutions claimed in the present application can still be implemented. The following division of each embodiment is for convenience of description and should not constitute any limitation on the specific implementation manner of the present application. Each embodiment can be combined and cross-referenced with each other on the premise of not being contradictory.

[0030] It should be noted that the terms "first", "second", etc. in the specification, claims and drawings of the present application are used to distinguish similar objects and do not necessarily need to describe a specific order or sequence. It should be understood that such used data can be interchanged under appropriate circumstances so that the embodiments of the present application described herein can be implemented in an order other than those illustrated or described herein. In addition, the terms "include" and "have" and any variations thereof are intended to cover non-exclusive inclusion. For example, a process, method, system, product or device that includes a series of steps or units does not necessarily need to be limited to those steps or units clearly listed, but may include other steps or units not clearly listed or inherent to these processes, methods, products or devices.

[0031] Regarding the technical problems that the encryption and decryption operations of the current entity authentication mechanism may affect the system performance, and there is a risk that the encryption algorithm may be cracked, thus posing a potential threat to the security of the system, etc., the embodiments of the present application provide a system for entity authentication using quantum random numbers, such as Figure 1 shown. The system includes: a Quantum Key Distribution Network (QKDN) or a Quantum Key Route (QKR). The QKDN or QKR device is used to generate and distribute (or provide) a quantum random number sequence to ensure that the claimant and the verifier share the same sequence. In addition, based on generating or providing a quantum random number sequence with a high entropy value, the QKDN or QKR securely distributes the quantum random number sequence to the claimant device and the verifier device through a quantum channel.

[0032] Among them, the QKDN distributes the quantum random number sequence to the devices for entity authentication using quantum random numbers through a Key Management Terminal (KMT). Different Quantum Key Distribution (QKD) local area networks are interconnected through the QKD backbone network, and different key management terminals maintain quantum keys through a Key Management Service (KMS); the QKDN ensures the security of the entity authentication process by generating truly random numbers and prevents being cracked; in addition, the QKDN can achieve end-to-end key distribution in a multi-user scenario, is suitable for key distribution of multi-user devices within a domain, and provides reliable and secure guarantees for entity authentication; by distributing keys through a quantum channel, the QKDN improves the key distribution efficiency, especially in a multi-user environment, and can effectively support large-scale and distributed key distribution requirements.

[0033] Among them, the QKR can directly distribute the quantum random number sequence to the devices for entity authentication using quantum random numbers. The QKR accesses the QKD through Quantum Key Management (QKM), can provide services such as secure, elastic, and highly available quantum key production and distribution management for business applications, meet the key guarantee and key life cycle management requirements of various cryptographic applications, can achieve the fusion and docking of satellite and fiber optic quantum key distribution networks, provide a secure isolation function between different business networks, and provide multiple key service modes for users.

[0034] A device for entity authentication using quantum random numbers, wherein the device includes a claimant device and a verifier device. The claimant device and the verifier device are respectively connected to different device nodes of QKR. The device nodes of different QKR are paired through a dynamic end-to-end key method, and the same quantum random number sequence can be negotiated by sharing a key pool and the same offset value; or, the claimant device and the verifier device are respectively connected to different KMT nodes in QKDN, and different KMT device nodes use the key management service mode to complete pairing through a session mechanism, provide the same quantum random number sequence to the verifier device through the key application interface of the claimant device, and use the key consistency check callback method to ensure that the quantum random number sequences of both parties are exactly the same. At the same time, a communication connection is established between the claimant device and the verifier device. The claimant device and the verifier device not only support identity authentication and pairing to ensure the legality of both communication parties, but also can calculate the digest value of the quantum random number sequence and compare the digest values of both parties to ensure the consistency and integrity of the data.

[0035] Among them, the device for entity authentication using quantum random numbers, such as Figure 2 shown, includes: at least one processor; and a memory communicatively connected to the at least one processor, wherein the memory stores instructions executable by the at least one processor, and the instructions are executed by the at least one processor to enable the at least one processor to execute the entity authentication method provided by the embodiments of the present application (which will be elaborated in detail later in this article and will not be elaborated here), and the entity authentication method includes one-way authentication and two-way authentication. The one-way authentication includes one-pass and two-pass, and the two-way authentication includes two-pass and three-pass.

[0036] Among them, the memory and the processor are connected by a bus. The bus can include any number of interconnected buses and bridges, and the bus connects various circuits of one or more processors and the memory together. The bus can also connect various other circuits such as peripheral devices, voltage regulators, and power management circuits, which are well known in the art, so they will not be further described herein. The bus interface provides an interface between the bus and the transceiver. The transceiver can be an element or multiple elements, such as multiple receivers and transmitters, and provides a unit for communicating with various other devices on the transmission medium. The data processed by the processor is transmitted over the wireless medium through the antenna. Further, the antenna also receives data and transmits the data to the processor. The processor is responsible for managing the bus and general processing, and can also provide various functions, including timing, peripheral interface, voltage regulation, power management, and other control functions. The memory can be used to store the data used by the processor when performing operations.

[0037] Meanwhile, the embodiment of the present application also provides a computer-readable storage medium, which can be built into a device that uses quantum random numbers for entity authentication and is used to store a computer program. When the computer program is executed by a processor, it implements the entity authentication method provided by the embodiment of the present application (which will be elaborated in detail later and will not be repeated here). The entity authentication method includes one-way authentication and two-way authentication. The one-way authentication includes one-pass and two-pass, and the two-way authentication includes two-pass and three-pass.

[0038] Those skilled in the art can understand that all or part of the steps of implementing the above embodiments or the methods in the following embodiments can be completed by a program instructing relevant hardware. The program is stored in a storage medium and includes several instructions to enable a device (which can be a single-chip microcomputer, a chip, etc.) or a processor to execute all or part of the steps of the methods in various embodiments of the present application. The foregoing storage medium includes: various media such as USB flash drives, mobile hard disks, read-only memories (ROM, Read-Only Memory), random access memories (RAM, Random Access Memory), magnetic disks, or optical discs that can store program codes.

[0039] Through the above manner of the present application, a system for entity authentication using quantum random numbers and a device for entity authentication using quantum random numbers are built. Thus, entity authentication based on quantum random numbers can be carried out based on this system or device, avoiding the complexity of traditional encryption and decryption operations, significantly reducing the calculation time, effectively eliminating the risk of being cracked, and enhancing the security and reliability of entity authentication.

[0040] Under the above software and hardware operating environment, aiming at the technical problems that the encryption and decryption operations in the current entity authentication mechanism may affect the system performance and the encryption algorithm has the risk of being cracked, the embodiment of the present application provides an entity authentication method. The entity authentication method includes one-way authentication and two-way authentication. The one-way authentication includes one-pass and two-pass, and the two-way authentication includes two-pass and three-pass. It is executed by the processor of the device for entity authentication using quantum random numbers. By using a quantum random number sequence to generate a verification sequence for entity authentication, the complexity of traditional encryption and decryption operations is avoided, the risk of being cracked is eliminated, and the performance and security of the system are improved. To facilitate understanding of the entity authentication method provided by the embodiment of the present application, the following will be based on one-pass of one-way authentication and, at the same time, combined with its different implementation processes, to illustrate two-pass of one-way authentication, two-pass and three-pass of two-way authentication.

[0041] The first part is one-way authentication. The one-way authentication on the claimant device side and the verifier device side will be elaborated in sequence later.

[0042] For example, a device that uses quantum random numbers for entity authentication is a claimant device (abbreviated as "claimant"). In some embodiments, the entity authentication method involves a one-way authentication transfer. At this time, its flowchart is as Figure 3 shown and includes the following steps.

[0043] Step 301: Generate a first check sequence. Among them, the first check sequence is obtained based on a quantum random number sequence, and the quantum random number sequence is shared by the claimant and the verifier through QKDN or QKR.

[0044] Step 304: Send the first check sequence to the verifier, thereby authenticating the claimant entity. Among them, the verifier verifies the first check sequence based on a second check sequence generated based on the quantum random number sequence.

[0045] Through the above method of the present application, in the one-way authentication transfer authentication mechanism, the claimant initiates this process and is authenticated by the verifier, that is, the claimant generates a first check sequence based on the quantum random number sequence and sends it to the verifier. After receiving the first check sequence, the verifier generates a second check sequence based on the quantum random number sequence shared by both parties to verify the first check sequence, thereby completing the one-way entity authentication of the claimant. For the problems that the encryption and decryption operations in the traditional entity authentication mechanism may affect the system performance and the encryption algorithm is easily cracked, this one-way authentication transfer authentication mechanism uses the high entropy and uniqueness of the quantum random number sequence to achieve lightweight authentication without encryption operations, solves the problems that the traditional entity authentication depends on the encryption algorithm resulting in large computational overhead and the pseudo-random numbers are easily predicted, and improves the security and performance of the system. For better understanding by those skilled in the art Figure 3 of the entity authentication method shown below, the steps will be further described.

[0046] In step 301, a first check sequence is generated. This can be achieved in the following way: obtain a quantum random number sequence from QKDN or QKR; intercept several data segments of a specified length from the quantum random number sequence according to a preset interception rule as the first check sequence.

[0047] In some examples, a quantum random number sequence can be obtained from QKDN or QKR. The specific process is as follows: The claiming party applies for an identity identifier from QKDN or QKR and sends the identity identifier to the verifying party. Among them, the verifying party generates a verification configuration file based on the identity identifier and shares the verification configuration file with the claiming party. The verification configuration file at least includes a preset interception rule, the identity identifier of the claiming party, and the identity identifier of the claiming party; the identity identifier of the claiming party is submitted to QKDN or QKR to obtain a quantum random number sequence. Among them, QKDN or QKR pairs the identity identifier of the claiming party and the identity identifier of the claiming party. If the pairing is successful, a quantum random number sequence is generated and distributed to the claiming party and the verifying party through a quantum channel.

[0048] That is to say: First, the claiming party applies for an identity identifier IDA from QKDN or QKR and simultaneously applies for the identity identifier IDB of the verifying party. After obtaining IDA, the claiming party applies for identity authentication configuration from the verifying party based on this identifier. The verifying party generates a verification configuration file in JSON format according to the identity identifier of the claiming party and the identity identifier of the verifying party and sends it to the claiming party by offline or postal means. The claiming party then logs in to the background system, imports the configuration file, and stores it in the system hard disk. The verification configuration file should at least include a preset interception rule, the identity identifier IDA of the claiming party, and the identity identifier IDB of the claiming party.

[0049] Second, after the claiming party obtains the identity identifier IDB of the claiming party, it uploads IDB through the distribution application interface of QKDN or QKR, and the device of QKDN or QKR completes the pairing of the claiming party and the verifying party. After the pairing is successful, the claiming party applies to QKDN or QKR to negotiate and distribute a quantum random number sequence with the verifying party. After QKDN or QKR generates a quantum random number sequence, it distributes the same random number content of K bytes in length to the claiming party and the verifying party in a callback manner through a quantum channel, where K is a positive integer. At this point, the claiming party and the verifying party obtain the same quantum random number sequence that is only shared by the two parties. This application realizes end-to-end security through the identity identifier and the verification configuration file, ensuring that both parties safely obtain and synchronize the quantum random number.

[0050] Finally, after the claiming party and the verifying party obtain the quantum random number sequence through the quantum channel, it further includes requesting QKDN or QKR to perform a consistency check. Among them, QKDN or QKR performs a consistency check on the digest value of the quantum random number sequence through the consistency check interface. If the consistency check passes, it notifies the claiming party and the verifying party to save the quantum random number sequence and the digest value.

[0051] After receiving the quantum random number sequence, the claimant calls the consistency check interface of QKDN or QKR and requests the QKDN or QKR device to calculate the digest value of the quantum random number sequence. Subsequently, QKDN or QKR notifies the verifier to call the same consistency check interface to verify the quantum random number sequence of the verifier in a callback manner. After QKDN or QKR devices complete the verification of the quantum random number series of the claimant and the verifier, they respectively notify both parties that the digest values of the quantum random number sequences are exactly the same, and return the digest values to the claimant and the verifier. Thus, the claimant and the verifier complete the negotiation process of the quantum random number sequence of the same binary. At the same time, the claimant and the verifier respectively save the values of the distributed quantum random number sequence and their digest values in memory. In this way, this application uses the comparison of the digest values of the quantum random number sequence to ensure data integrity and prevent the quantum random number from being tampered with or affected by noise during the distribution process.

[0052] In some examples, several data segments of a specified length are intercepted from the quantum random number sequence according to a preset interception rule as the first check sequence. This can be achieved in the following ways. The preset interception rule includes a first interception rule, a second interception rule, and a third interception rule. According to the first interception rule, a first random number segment of a first length is sequentially intercepted from the quantum random number sequence as the first check sequence. Or according to the second interception rule, a second random number segment of a second length and a second random number segment of a third length are sequentially intercepted from the quantum random number sequence. The second random number segment is XORed with the timestamp to obtain a fourth random number segment. The second random number segment and the fourth random number segment are concatenated as the first check sequence. Or according to the third interception rule, the quantum random number sequence block belonging to itself in the quantum random number sequence is obtained, and a fifth random number segment of a fifth length is sequentially intercepted from the quantum random number sequence block as the first check sequence, where the quantum random number sequence is divided into multiple blocks and distributed to the claimant and the verifier respectively. It should be noted that the preset interception rule includes at least the cursor start position and the intercepted sequential length. For the claimant, the first check sequence can be generated in the following three ways.

[0053] Method 1, direct interception method (first interception rule). As Figure 4 and Figure 5 shown, starting from the index start position of the quantum random number sequence (such as Figure 4 O), a random number segment E1 of length K is sequentially intercepted and used as the check sequence.

[0054] Method 2, interception method combined with timestamp (second interception rule). As Figure 4 and Figure 6As shown, starting from the cursor start position of the quantum random number sequence, a random number segment X1 with a length of K and a random number segment Y1 with a length of M are sequentially obtained; the random number segment Y1 is XOR processed with the binary sequence corresponding to the current time of the claimant to obtain a sequence Z1; subsequently, the random number segment X1 is concatenated with the sequence Z1 to form a verification sequence E1. By introducing a timestamp, the uniqueness of the verification sequence is further ensured.

[0055] In view of the fact that in Method 1 and Method 2, the claimant and the verifier share the same quantum random number sequence at two points, and fixed-length random numbers are sequentially intercepted as identity identifiers and put into the messages sent to the other party. However, there is a problem with this. The claimant may send two or more messages to the verifier continuously. For example, at a certain moment, the claimant sends a message to the verifier. Before the claimant receives the feedback information from the verifier, the claimant generates and sends another message to the verifier. This may cause the claimant and the verifier to intercept and use the same random number, not only causing confusion in the identity identifier, but also the receiving party being unable to determine whether the message is sent by the real other party or a replay attack sent by an attacker. To avoid the above problems, Method 3 can be adopted.

[0056] Method 3, the quantum random number sequence block interception method (the third interception rule). After the claimant and the verifier generate the same quantum random number sequence, this random number sequence is divided into blocks according to a specified size, for example, 1024B as a block. In this way, the quantum random number sequence is divided into multiple blocks and numbered. Then these quantum random number sequence blocks are assigned to the claimant and the verifier, requiring that one quantum random number sequence block can only be assigned to the claimant or the verifier, and cannot be assigned to both the claimant and the verifier at the same time. Thus, the claimant sequentially intercepts and uses the quantum random numbers from the random number block with the smallest label belonging to itself. After all the quantum random numbers in this quantum random number sequence block are used, the next random number block belonging to the claimant is used. Similarly, after the verifier receives the message sent by the claimant, it makes a judgment based on the quantum random numbers in the quantum random number sequence block belonging to the claimant. The process of the verifier sending and the claimant receiving is the same as the above process. Through Method 3, the risk of identity confusion and replay attack caused by the claimant and the verifier sending the same quantum random number sequence is avoided.

[0057] It should also be noted that how to assign the quantum random number sequence blocks to the claimant and the verifier, and at the same time, both the claimant and the verifier need to know which ones are their own and which ones are the other party's. The possible solutions include but are not limited to the following methods.

[0058] 1. Designated method. This method requires a central management node for unified management and distribution, and the result is informed to the claimant and the verifier through a certain management signaling.

[0059] 2. Autonomous. This approach requires no central management node; instead, the claimant and verifier generate their own quantum random number through negotiation. For example, at the very beginning, or when activating a new quantum random number sequence block, the claimant selects the first quantum random number from that block and sends it to the verifier. Upon receiving this message, the verifier defines the quantum random number sequence block as the claimant's subordinate data block and intercepts the second quantum random number from that block and sends it to the claimant, indicating that both parties have reached a consensus. Subsequently, the claimant can use this quantum random number sequence block as its subordinate quantum random number sequence block when sending messages. If a collision occurs—that is, the claimant and verifier both activate the same quantum random number sequence block and send it to each other simultaneously—the claimant, upon receiving the quantum random number from the verifier, discovers that the verifier has selected the same quantum random number sequence block. It will then randomly delay and initiate again. The verifier will do the same, until one party is certain that the other party has first occupied the quantum random number sequence block.

[0060] In all three methods described above, the length and starting position of the index are pre-programmed into a shared verification configuration file. After each random number segment is intercepted, the cursor position is synchronously moved down by the same distance as the intercepted length. This ensures that each sent verification sequence is used only once, avoiding security risks associated with reuse.

[0061] In step 304, the first check sequence is sent to the verifier. This can be achieved by sending the first check sequence to the verifier via an application layer request, wherein the request includes a field for identifying the first check sequence to be checked, and the value of the field is the data processed after the first check sequence. Optionally, in some embodiments, the first check sequence is sent to the verifier via an HTTP request, wherein the HTTP request header key value is Authorization and the value content is the compressed first check sequence.

[0062] Because the verification sequence is binary data, the claimant encodes the first verification sequence using the Base64 algorithm, converting it into a string (denoted as tokenA). The claimant then places tokenA as a token in the HTTP request header to be sent to the verifier. Specifically, the key in the HTTP request header is "Authorization," and the corresponding value is the tokenA string. The claimant sends the data to the verifier's IP address via an HTTP packet. The HTTP packet's header contains authentication information, while the body carries service-related verification information and business content.

[0063] So far, through the above steps, the claimant has completed the generation of the verification sequence and provided the verification sequence to the verifier for the one-way authentication of the claimant by the verifier. This application realizes lightweight authentication without encryption operations through the high entropy and uniqueness of the quantum random number sequence, achieves end-to-end security based on the identity identifier and the verification profile, presets the standardized process of the interception rule when generating the verification sequence to ensure the consistency between both parties, further generates a composite token through the exclusive OR of timestamps to verify the timeliness, and finally standardizes the transmission through the application layer protocol, effectively reducing the deployment cost. Through the above process, lightweight authentication without encryption operations is realized, solving the problems that traditional entity authentication depends on encryption algorithms, resulting in large computational overhead and the easy predictability of pseudo-random numbers.

[0064] In the case of clarifying the one-pass authentication mechanism of one-way authentication, the two-pass authentication mechanism of one-way authentication will be described next. In the two-pass manner of one-way authentication, the verifier B initiates this process and authenticates the claimant A, that is, the verifier sends a notice instructing the claimant to obtain a quantum random number sequence, and then the claimant generates a first verification sequence based on the quantum random number sequence and sends it to the verifier. After receiving the first verification sequence, the verifier generates a second verification sequence based on the quantum random number sequence shared by both parties to verify the first verification sequence, thus completing the one-way entity authentication of the claimant. As Figure 7 shown, the process of two-pass one-way authentication of the transfer method 2 is realized through the following steps.

[0065] Step 701: Receive the verification notice from the verifier, where the verification notice instructs the claimant to obtain a quantum random number sequence from the QKDN or QKR.

[0066] Step 704, generate a first verification sequence, where the first verification sequence is obtained based on the quantum random number sequence, and the quantum random number sequence is shared by the claimant and the verifier through the QKDN or QKR.

[0067] Step 707, send the first verification sequence to the verifier, thereby authenticating the claimant entity, where the verifier verifies the first verification sequence with the second verification sequence generated based on the quantum random number sequence.

[0068] Through the above method of this application, the two-pass authentication mechanism of one-way authentication: the claimant obtains the verification notice sent by the verifier, where the verification notice is used to instruct the claimant to obtain a quantum random number sequence from the QKDN or QKR; after obtaining the instruction of the verification notice, the claimant obtains the quantum random number sequence from the QKDN or QKR. In this way, through two passes, the security of the system is increased, while maintaining the high entropy and uniqueness of the quantum random number sequence, and further reducing the risk of being cracked.

[0069] Similarly, for example, a device that uses a quantum random number sequence for entity authentication is a verifier device (abbreviated as "verifier"). In some embodiments, the entity authentication method: one-way authentication in a single transfer, and its flowchart is as follows Figure 8 shown, including the following steps.

[0070] Step 801: Obtain a first verification sequence from the claimant. The first verification sequence is generated by the claimant based on a quantum random number sequence, and the quantum random number sequence is shared by the claimant and the verifier through QKDN or QKR.

[0071] Step 804: Generate a second verification sequence to verify the first verification sequence, where the second verification sequence is obtained based on the quantum random number sequence.

[0072] Through the above method of the present application, the one-way authentication single-transfer authentication mechanism: after receiving the first verification sequence generated by the claimant based on the quantum random number sequence, the verifier generates a second verification sequence based on the quantum random number sequence shared by both parties to verify the first verification sequence, thereby completing the entity authentication of the claimant. In this way, lightweight authentication without encryption operations is achieved through the high entropy and uniqueness of the quantum random number sequence, solving the problem of large computational overhead caused by traditional entity authentication relying on encryption algorithms.

[0073] In step 801, obtain the first verification sequence from the claimant. This can be achieved in the following way: the claimant obtains a protocol packet sent by the claimant, which is an HTTP request sent through the TCP protocol. The verifier obtains the tokenA whose Key value is the value corresponding to Authorization from the request header, which is the compressed verification sequence. The verification sequence can be obtained by decompressing tokenA through the Base64 algorithm, and this verification sequence is binary data.

[0074] In step 804, generate a second verification sequence to verify the first verification sequence. It can be the following way: intercept several data segments of a specified length from the quantum random number sequence as the second verification sequence according to a preset interception rule, and verify the first verification sequence based on the second verification sequence. The preset interception rule is determined based on a verification configuration file, and the verification configuration file is generated according to the authentication configuration of the claimant. Among them, the above verification configuration file, preset interception rule, and the starting position of the cursor included in the preset interception rule and the intercepted sequential length have been described in step 301 and step 304, and will not be elaborated here one by one.

[0075] For intercepting several data segments of a specified length from a quantum random number sequence as a second verification sequence according to a preset intercepting rule, it can be implemented as follows: The preset intercepting rule includes a first intercepting rule, a second intercepting rule, and a third intercepting rule; According to the first intercepting rule, intercept a sixth random number segment of a first length from the quantum random number sequence, and compare whether the sixth random number segment is the same as the first verification sequence; Or, according to the second intercepting rule, intercept a seventh random number segment of a second length and an eighth random number segment of a third length from the quantum random number sequence in sequence; When the seventh random number segment is the same as the first verification sequence, perform an exclusive OR calculation on the eighth random number segment and the first verification sequence to obtain a time sequence, and compare whether the difference between the time sequence and the current time does not exceed a threshold; Or according to the third intercepting rule, obtain a quantum random number sequence block belonging to itself in the quantum random number sequence, sequentially intercept a ninth random number segment of a fifth length from the quantum random number sequence block, and compare whether the ninth random number segment is the same as the first verification sequence, where the quantum random number sequence is divided into multiple blocks and distributed to the claimant and the verifier respectively.

[0076] Among them, according to the first intercepting rule, the verifier directly intercepts the second verification sequence from the quantum random number sequence, and the specific implementation is as follows: The verifier starts from the starting position of the index of the quantum random number sequence, intercepts a random number segment E2 with a length of K, and uses it as the second verification sequence, and compares it with the first verification sequence sent by the claimant. If the two are the same, the authentication of the claimant is completed.

[0077] Among them, according to the second intercepting rule, the verifier starts from the starting position of the index of the quantum random number sequence, and sequentially obtains a random number segment X2 with a length of K and a random number segment Y2 with a length of M. Perform an exclusive OR operation on the random number segment Y2 and the last M bits of the first verification sequence to obtain a sequence Z2 (that is, the binary sequence corresponding to the current time of the claimant). The verifier first compares whether the random number segment X2 is the same as the first K bits of the first verification sequence; if they are the same, then continue to compare whether the difference between the sequence Z2 and the current time of the verifier is less than a preset threshold. If the conditions are met, the authentication of the claimant is completed.

[0078] Among them, according to the third intercepting rule, after receiving the message sent by the claimant, the verifier makes a judgment based on the quantum random numbers in the quantum random number sequence block belonging to the claimant. Subsequently, when the verifier uses the quantum random number sequence, it sequentially intercepts and uses the quantum random numbers from the quantum random number sequence block with the smallest label belonging to itself.

[0079] The selection of the first truncation rule, the second truncation rule, or the third truncation rule depends on the capabilities and environment of the claimant and the verifier. The truncation length of the above sequence and the starting position of the index are written in advance in the verification configuration file shared by both parties, that is, the truncation rules of the claimant and the verifier should be exactly the same. In addition, among the above three methods of generating the check sequence, after each random number segment is truncated, the position of the cursor is synchronously moved down by a distance equal to the truncation length. In this way, it can be ensured that each sent check sequence is only used once and there is no risk of being cracked.

[0080] Through the above method of the present application, the one-way authentication one-time transfer authentication mechanism: the verifier performs one-way entity authentication on the claimant. In this authentication mechanism, the claimant initiates this process and is authenticated by the verifier. Both parties achieve lightweight authentication without encryption operations through the high entropy and uniqueness of the quantum random number sequence, solving the problems of large computational overhead caused by traditional entity authentication relying on encryption algorithms and the easy predictability of pseudo-random numbers.

[0081] In the case of clarifying the one-way authentication one-time transfer authentication mechanism, the two-way transfer authentication mechanism of one-way authentication will be described next. For the verifier, the entity authentication method: two-way transfer of one-way authentication, including: sending a verification notice, where the verification notice instructs the claimant to obtain a quantum random number sequence from QKDN or QKR; obtaining a first check sequence from the claimant, where the first check sequence is generated by the claimant based on the quantum random number sequence, and the quantum random number sequence is shared by the claimant and the verifier through QKDN or QKR; generating a second check sequence to verify the first check sequence, where the second check sequence is obtained based on the quantum random number sequence.

[0082] Through the above method of the present application, the two-way transfer authentication mechanism of one-way authentication: the claimant obtains the verification notice sent by the verifier, where the verification notice is used to instruct the claimant to obtain a quantum random number sequence from QKDN or QKR; after obtaining the instruction of the verification notice, the claimant obtains a quantum random number sequence from QKDN or QKR. In this way, through two transfers, the security of the system is increased, and at the same time, the high entropy and uniqueness of the quantum random number sequence are maintained, further reducing the risk of being cracked.

[0083] The second part is two-way authentication. Subsequently, the two-way authentication on the claimant device and the verifier device side will be elaborated in turn.

[0084] For example, the device using the quantum random number sequence for entity authentication is the claimant device (abbreviated as "claimant"). In some embodiments, the entity authentication method: two-way transfer of two-way authentication, and its flowchart is as Figure 9 shown, including the following steps.

[0085] Step 901: Generate a first verification sequence, where the first verification sequence is obtained based on a quantum random number sequence, and the quantum random number sequence is shared by the claimant and the verifier via QKDN or QKR.

[0086] Step 904: Send the first verification sequence to the verifier to authenticate the claimant entity, where the verifier verifies the first verification sequence against a second verification sequence generated based on the quantum random number sequence.

[0087] Step 907: Receive a third verification sequence to authenticate the verifier entity, where the claimant verifies the third verification sequence against a fourth verification sequence generated based on the quantum random number sequence, and the third verification sequence is obtained by the verifier based on the quantum random number sequence.

[0088] By the above method of the present application, the entity authentication method: for the two-way authentication with two transmissions, after the verifier authenticates the claimant entity, the claimant will generate a verification sequence for the verifier and perform entity authentication. This two-way authentication mechanism further improves the effectiveness of authentication and ensures the reliable verification of the identities of both parties. The following will be described in combination with its different implementation processes.

[0089] In addition, the descriptions of the corresponding features in Steps 901, 904, and 907 have been similarly recorded in the foregoing embodiments, and will not be elaborated here one by one. With the two-transmission authentication mechanism of two-way authentication being clear, the three-transmission authentication mechanism of two-way authentication will be described next, including: receiving a verification notice from the verifier, where the verification notice instructs the claimant to obtain a quantum random number sequence from QKDN or QKR; generating a first verification sequence, where the first verification sequence is obtained based on the quantum random number sequence, and the quantum random number sequence is shared by the claimant and the verifier via QKDN or QKR; sending the first verification sequence to the verifier to authenticate the claimant entity, where the verifier verifies the first verification sequence against a second verification sequence generated based on the quantum random number sequence; receiving a third verification sequence to authenticate the verifier entity, where the claimant verifies the third verification sequence against a fourth verification sequence generated based on the quantum random number sequence, and the third verification sequence is obtained by the verifier based on the quantum random number sequence.

[0090] Similarly, for example, the device using quantum random numbers for entity authentication is the verifier device (abbreviated as "verifier"). In some embodiments, the entity authentication method: two-way authentication with two transmissions, and its flowchart at this time is as Figure 10 shown, including the following steps.

[0091] Step 1001: Obtain a first verification sequence from the claimant, where the first verification sequence is generated by the claimant based on a quantum random number sequence, and the quantum random number sequence is shared by the claimant and the verifier via QKDN or QKR.

[0092] Step 1004, generate a second verification sequence to verify the first verification sequence, where the second verification sequence is obtained based on a quantum random number sequence.

[0093] Step 1007, send a third verification sequence to the entity authentication verifier, where the claimant verifies the third verification sequence with a fourth verification sequence generated based on a quantum random number sequence, and the third verification sequence is obtained by the verifier based on a quantum random number sequence.

[0094] Through the above method of the present application, for the entity authentication method: in the two-way authentication with two transmissions, after the verifier authenticates the claimant, the claimant will generate a verification sequence for the verifier and conduct entity authentication. This two-way authentication mechanism further improves the effectiveness of authentication and ensures the reliable verification of the identities of both parties. The following will be described in combination with its different implementation processes.

[0095] Specifically, the descriptions of the corresponding features of steps 1001, 1004, and 1007 have been recorded in the foregoing embodiments, and will not be elaborated here one by one. With the two-transmission authentication mechanism of two-way authentication being clear, the three-transmission authentication mechanism of two-way authentication will be described next, including: sending a verification notice, where the verification notice instructs the claimant to obtain a quantum random number sequence from QKDN or QKR; obtaining a first verification sequence from the claimant, where the first verification sequence is generated by the claimant based on a quantum random number sequence, and the quantum random number sequence is shared by the claimant and the verifier through QKDN or QKR; generating a second verification sequence to verify the first verification sequence, where the second verification sequence is obtained based on a quantum random number sequence; sending a third verification sequence to the entity authentication verifier, where the claimant verifies the third verification sequence with a fourth verification sequence generated based on a quantum random number sequence, and the third verification sequence is obtained by the verifier based on a quantum random number sequence.

[0096] In summary, the entity authentication methods on the claimant and verifier sides of the present application can further be combined with serial numbers, timestamps, random numbers, etc. to generate a mixed verification sequence, so as to support delay attacks. Through the above embodiments of the present application, one-way authentication or two-way authentication is performed. The advantages are that no encryption and decryption operations are required, reducing the time for encryption and decryption calculations; moreover, the random number sent each time is only used once, and there is no risk of being cracked; the random number sequence simultaneously has the characteristics of a serial number, a random number, and an identifier.

[0097] The step division of the above various methods is only for clear description. During implementation, they can be combined into one step or some steps can be split into multiple steps. As long as the same logical relationship is included, it is within the protection scope of the present application; making insignificant modifications to the algorithm or process or introducing insignificant designs, but not changing the core design of its algorithm and process are all within the protection scope of this application.

[0098] Those of ordinary skill in the art can understand that the above embodiments are specific examples for implementing the present application, and in actual applications, various changes can be made to them in form and details without departing from the spirit and scope of the present application.

Claims

1. An entity authentication method, applicable to a claimant, characterized in that, Including: Generating a first verification sequence, wherein the first verification sequence is obtained based on a quantum random number sequence, and the quantum random number sequence is shared by the claimant and the verifier through QKDN or QKR; Sending the first verification sequence to the verifier for the verifier entity to authenticate the claimant, wherein the verifier verifies the first verification sequence based on a second verification sequence generated based on the quantum random number sequence; The generating of the first verification sequence includes: Obtaining the quantum random number sequence from the QKDN or the QKR; Intercepting several data segments of a specified length from the quantum random number sequence according to a preset intercepting rule as the first verification sequence; wherein the preset intercepting rule at least includes the starting position of the cursor and the intercepting length, and after each intercepting of a random number segment, the position of the cursor moves down synchronously by a distance equal to the intercepting length; Wherein, obtaining the quantum random number sequence from the QKDN or the QKR includes: Applying for an identity identifier to the QKDN or the QKR; Sending the identity identifier to the verifier, wherein the verifier generates a verification configuration file based on the identity identifier and shares the verification configuration file with the claimant, and the verification configuration file at least includes the preset intercepting rule, the identity identifier of the claimant and the identity identifier of the verifier; Submitting the identity identifier of the claimant to the QKDN or the QKR to obtain the quantum random number sequence, wherein the QKDN or the QKR pairs the identity identifier of the claimant and the identity identifier of the verifier, and generates the quantum random number sequence in the case of successful pairing, and distributes the quantum random number sequence to the claimant and the verifier through a quantum channel.

2. The entity authentication method according to claim 1, wherein After obtaining the quantum random number sequence through the quantum channel, it further includes: Requesting the QKDN or the QKR to perform consistency verification, wherein the QKDN or the QKR performs consistency verification on the digest value of the quantum random number sequence through a consistency verification interface, and if the consistency verification passes, notifies the claimant and the verifier to save the quantum random number sequence and the digest value.

3. The entity authentication method according to claim 1, wherein The preset intercepting rule includes a first intercepting rule, a second intercepting rule and a third intercepting rule. Intercepting several data segments of a specified length from the quantum random number sequence according to the preset intercepting rule as the first verification sequence includes: According to the first intercepting rule, sequentially intercepting a first random number segment of a first length from the quantum random number sequence as the first verification sequence; or, According to the second intercepting rule, sequentially intercepting a second random number segment of a second length and a second random number segment of a third length from the quantum random number sequence, performing an exclusive OR operation on the second random number segment and a time stamp to obtain a fourth random number segment, and splicing the second random number segment and the fourth random number segment as the first verification sequence; or, According to the third truncation rule, obtain the quantum random number sequence block belonging to itself in the quantum random number sequence, and sequentially truncate the fifth random number segment with the fifth length from the quantum random number sequence block as the first verification sequence, wherein the quantum random number sequence is divided into multiple blocks and distributed to the claimant and the verifier respectively.

4. The entity authentication method according to claim 1, wherein Before generating the first verification sequence, it further includes: Receiving a verification notice from the verifier, wherein the verification notice instructs the claimant to obtain the quantum random number sequence from the QKDN or the QKR.

5. The entity authentication method according to claim 1, characterized in that Sending the first verification sequence to the verifier includes: Sending the first verification sequence to the verifier through an application layer request, wherein the application layer request contains a field for identifying and verifying the first verification sequence, and the value of the field is the data obtained after processing the first verification sequence.

6. The entity authentication method according to claim 5, characterized in that Sending the first verification sequence to the verifier through an application layer request includes: Sending the first verification sequence to the verifier through an HTTP request, wherein in the request header of the HTTP request, the Key value is Authorization and the value content is the compressed first verification sequence.

7. The entity authentication method according to claim 1, characterized in that After sending the first verification sequence to the verifier, it further includes: Receiving a third verification sequence to authenticate the verifier, wherein the claimant verifies the third verification sequence based on the fourth verification sequence generated based on the quantum random number sequence, and the third verification sequence is obtained by the verifier based on the quantum random number sequence.

8. An entity authentication method, applicable to the verifier, characterized in that, It includes: Accepting the identity identifier sent by the claimant, generating a verification configuration file based on the identity identifier, and sharing the verification configuration file with the claimant. The verification configuration file at least includes a preset truncation rule, the identity identifier of the claimant, and the identity identifier of the verifier, for the claimant to submit the identity identifier of the claimant to the QKDN or the QKR to obtain the quantum random number sequence, wherein the QKDN or the QKR pairs the identity identifier of the claimant and the identity identifier of the verifier, and generates the quantum random number sequence in the case of successful pairing, and distributes the quantum random number sequence to the claimant and the verifier through a quantum channel; Obtaining the first verification sequence from the claimant, wherein the first verification sequence is generated by the claimant based on the quantum random number sequence, and the quantum random number sequence is shared by the claimant and the verifier through the QKDN or the QKR; Generating a second verification sequence to verify the first verification sequence, wherein the second verification sequence is obtained based on the quantum random number sequence.

9. An apparatus for entity authentication using quantum random numbers, characterized in that, It includes: At least one processor; And, A memory communicatively connected to the at least one processor, wherein the memory stores instructions executable by the at least one processor, and the instructions are executed by the at least one processor to enable the at least one processor to execute the entity authentication method according to any one of claims 1 to 7 and / or the entity authentication method according to claim 8.

10. A computer-readable storage medium storing a computer program, characterized in that, When the computer program is executed by a processor, it implements the entity authentication method according to any one of claims 1 to 7 and / or the entity authentication method according to claim 8.

Citation Information

Patent Citations

  • Method and system for dynamic verification

    CN103763104A

  • Identity authentication method based on quantum key

    CN115913521A