Data management method and system based on quantum key cloud
By dividing the quantum key cloud into a private cloud server and a public cloud server, the problem of the inability to meet the user's encrypted data storage needs in the existing technology is solved, and high-security data storage is achieved.
Patent Information
- Application Number
- CN202411994366.5
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2024-12-31
- Publication Date
- 2025-05-02
AI Technical Summary
The existing quantum key cloud technology cannot meet users' encrypted data storage needs, and there is a risk of information leakage.
Quantum key cloud is divided into private cloud servers and public cloud servers. Private cloud servers are used to store quantum keys and encrypted and decrypted data, and public cloud servers are used to store encrypted data. This hierarchical structure meets users' encryption and storage needs.
There is no need to return encrypted data to the user side to store, which avoids the risk of information leakage and improves the security of data storage.
Smart Images

Figure CN119921946A_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the field of quantum communication technology, and in particular to a data management method and system based on a quantum key cloud. Background Art
[0002] The sharing of multi-user information has become a common application scenario for the Internet and future quantum network industries. The quantum key cloud makes the "one-to-many" and "many-to-many" modes of quantum communication possible. It is the most important catalyst and booster for the industrialization of quantum communication, accelerating the large-scale application of quantum communication.
[0003] Quantum devices reconstruct the intermediate support platform for various application industries. The quantum key cloud completes a series of configurations including scheduling, trusted relay, routing, and management, cascading, authentication, and interfaces of the entire key network through its own algorithms. For example, in the prior art, the Chinese invention patent with publication number CN112134695A discloses a distributed quantum key management system and method. The solution creates different encryption and decryption strategies for quantum keys for different applications of mobile terminals, stores quantum keys in cloud servers, and monitors the status of quantum keys in real time.
[0004] As the number of users or terminals requesting to use quantum keys increases, the services and management of quantum key clouds have become more diverse and complex, and it is urgent to meet the needs of users to store encrypted data. However, the existing quantum key cloud technology cannot meet the encrypted data storage needs of users, and there is a potential risk of information leakage in the process of returning encrypted data to the user end for storage. Summary of the invention
[0005] In order to solve the problem that the existing quantum key cloud technology cannot meet the needs of users for storing encrypted data, the present invention provides a data management method and system based on quantum key cloud.
[0006] To achieve the above purpose, the technical solution adopted by the present invention is as follows:
[0007] A data management method based on a quantum key cloud, wherein the quantum key cloud is divided into a private cloud server and a public cloud server; wherein the private cloud server is used to store quantum keys and encryption and decryption data; the quantum keys are generated by N quantum key distribution (QKD) systems, and the QKD system includes a sender and a receiver, N≥1; and the public cloud server is used to store encrypted data;
[0008] The method comprises the following steps:
[0009] S1: The user sends an encrypted service request to the private cloud server;
[0010] S2: The private cloud server determines whether it receives multiple encryption service requests at the same time;
[0011] If yes, execute step S3;
[0012] If not, execute step S4;
[0013] S3: The private cloud server classifies and sorts the received multiple encrypted service requests by security level to obtain the request execution order;
[0014] S4: The private cloud server determines whether the remaining quantum key quantity meets the total quantum key demand of the encryption service request;
[0015] If yes, execute step S5;
[0016] If not, perform quantum key expansion and re-execute step S4;
[0017] S5: The private cloud server processes each encrypted service request in sequence according to the request execution order, and obtains the encrypted data of each request;
[0018] S6: The private cloud server sends the encrypted data to the public cloud server for storage.
[0019] In the above solution, by dividing the quantum key cloud into a private cloud server for encrypting data and a public cloud server for storing encrypted data, the encryption and storage requirements of the user side can be met at the same time. There is no need to return the encrypted data to the user side for storage to avoid increasing the risk of information leakage, thereby improving the security of data storage.
[0020] Preferably, before the user terminal sends an encrypted service request to the private cloud server, multi-factor authentication is also performed.
[0021] Preferably, the multi-factor authentication includes any two of knowledge factor authentication, ownership factor authentication and biometric factor authentication.
[0022] Preferably, the encryption service request includes plaintext data and quantum key demand.
[0023] Preferably, in step S3, the encryption service request is classified into security levels according to the quantum key requirement; wherein, the encryption service request with a higher quantum key requirement has a higher corresponding security level.
[0024] Preferably, the request execution order is from high to low security levels.
[0025] Preferably, in step S4, quantum key expansion is achieved by encrypting the remaining quantum key to obtain a new key.
[0026] Preferably, in step S6, the private cloud server divides the encrypted data into multiple parts, and stores them in different physical or logical locations of the public cloud server, and forms a file index table according to the storage location of each part of the data.
[0027] Preferably, when the private cloud server receives a data request from the user, the private cloud server sends a corresponding file index table to the public cloud server; the public cloud server obtains the stored data according to the file index table, reassembles the encrypted data and sends it to the private cloud server; the encrypted data is decrypted by the private cloud server to obtain plaintext data and then sent to the user.
[0028] A data management system based on quantum key cloud, used to implement the data management method based on quantum key cloud, comprising a user terminal, a private cloud server and a public cloud server;
[0029] The user terminal is connected to the private cloud server via a quantum channel, and the private cloud server is connected to the public cloud server via a quantum channel.
[0030] Beneficial technical effects of the present invention:
[0031] The present invention provides a data management method and system based on a quantum key cloud. By dividing the quantum key cloud into a private cloud server for encrypting data and a public cloud server for storing encrypted data, the encryption and storage requirements of the user end are met at the same time. There is no need to return the encrypted data to the user end for storage to avoid increasing the risk of information leakage, thereby improving the security of data storage. BRIEF DESCRIPTION OF THE DRAWINGS
[0032] Figure 1 It is a structural block diagram of the connection between the QKD system and the private cloud server in the present invention;
[0033] Figure 2 Flow chart of the implementation steps of the technical solution of the present invention
[0034] Figure 3 It is a schematic diagram of module connection of the present invention. DETAILED DESCRIPTION
[0035] In order to make the purpose, technical solutions and advantages of the present invention more clearly understood, the present invention is further described in detail below in conjunction with embodiments, but the scope of protection claimed in the present invention is not limited to the following specific embodiments.
[0036] Example 1
[0037] like Figure 1-2As shown, a data management method based on a quantum key cloud is used to divide the quantum key cloud into a private cloud server and a public cloud server; wherein the private cloud server is used to store quantum keys and encrypt and decrypt data; the quantum keys are generated by N quantum key distribution (Quantum Key Distribution, QKD) systems, and the QKD system includes a sender and a receiver, N≥1; the public cloud server is used to store encrypted data;
[0038] The method comprises the following steps:
[0039] S1: The user sends an encrypted service request to the private cloud server;
[0040] S2: The private cloud server determines whether it receives multiple encryption service requests at the same time;
[0041] If yes, execute step S3;
[0042] If not, execute step S4;
[0043] S3: The private cloud server classifies and sorts the received multiple encrypted service requests by security level to obtain the request execution order;
[0044] S4: The private cloud server determines whether the remaining quantum key quantity meets the total quantum key demand of the encryption service request;
[0045] If yes, execute step S5;
[0046] If not, perform quantum key expansion and re-execute step S4;
[0047] S5: The private cloud server processes each encrypted service request in sequence according to the request execution order, and obtains the encrypted data of each request;
[0048] S6: The private cloud server sends the encrypted data to the public cloud server for storage.
[0049] During the specific implementation process, the quantum key cloud is divided into a private cloud server for encrypting data and a public cloud server for storing encrypted data, which can meet the encryption and storage needs of the user side at the same time. There is no need to return the encrypted data to the user side for storage to avoid increasing the risk of information leakage, thereby improving the security of data storage.
[0050] Example 2
[0051] A data management method based on quantum key cloud, which divides the quantum key cloud into a private cloud server and a public cloud server; wherein,
[0052] The private cloud server is used to store quantum keys and encrypt and decrypt data;
[0053] The public cloud server is used to store encrypted data;
[0054] The method comprises the following steps:
[0055] S1: The user sends an encrypted service request to the private cloud server;
[0056] S2: The private cloud server determines whether it receives multiple encryption service requests at the same time;
[0057] If yes, execute step S3;
[0058] If not, execute step S4;
[0059] S3: The private cloud server classifies and sorts the received multiple encrypted service requests by security level to obtain the request execution order;
[0060] S4: The private cloud server determines whether the remaining quantum key quantity meets the total quantum key demand of the encryption service request;
[0061] If yes, execute step S5;
[0062] If not, perform quantum key expansion and re-execute step S4;
[0063] S5: The private cloud server processes each encrypted service request in sequence according to the request execution order, and obtains the encrypted data of each request;
[0064] S6: The private cloud server sends the encrypted data to the public cloud server for storage.
[0065] More specifically, before the user sends an encrypted service request to the private cloud server, multi-factor authentication is also performed.
[0066] More specifically, the multi-factor authentication includes any two of knowledge factor authentication, ownership factor authentication, and biometric factor authentication.
[0067] During the specific implementation process, the user logs in to the private cloud server and performs preliminary identity authentication with a username and password. If the user's behavior pattern (such as login time, geographic location, etc.) is abnormal, further facial recognition biometric authentication is required; if the user logs in from an unverified new device, a one-time verification code will be sent to the user's preset secure email address or mobile phone number, and the user needs to enter the verification code.
[0068] More specifically, the encryption service request includes plaintext data and quantum key demand.
[0069] More specifically, in step S3, the security level of the encryption service request is divided according to the quantum key requirement; wherein, the encryption service request with a higher quantum key requirement has a higher corresponding security level.
[0070] More specifically, the request execution order is from high to low security levels.
[0071] During the specific implementation process, security levels are divided and encryption service requests are executed in order from high to low security levels, and quantum keys are reasonably allocated to handle multiple encryption service requests received simultaneously.
[0072] More specifically, in step S4, the remaining quantum key is encrypted to obtain a new key to achieve quantum key expansion.
[0073] In the specific implementation process, the remaining quantum key is encrypted according to the Advanced Encryption Standard (AES) encryption algorithm to obtain a new key, thereby improving the key utilization rate and reducing the key resource consumption.
[0074] More specifically, in step S6, the private cloud server divides the encrypted data into multiple parts and stores them in different physical or logical locations of the public cloud server, and forms a file index table according to the storage location of each part of the data.
[0075] More specifically, when the private cloud server receives a data request from the user, the private cloud server sends the corresponding file index table to the public cloud server; the public cloud server obtains the stored data according to the file index table, reassembles the encrypted data and sends it to the private cloud server; the private cloud server decrypts the encrypted data to obtain plaintext data and sends it to the user.
[0076] In the specific implementation process, it also includes comparing the hash values calculated before and after data encryption to determine whether the data has been tampered with.
[0077] Example 3
[0078] like Figure 3 As shown, a data management system based on quantum key cloud is used to implement the data management method based on quantum key cloud, including a user terminal, a private cloud server and a public cloud server;
[0079] The user terminal is connected to the private cloud server via a quantum channel, and the private cloud server is connected to the public cloud server via a quantum channel.
[0080] According to the disclosure and teaching of the above description, those skilled in the art to which the present invention belongs may also make changes and modifications to the above embodiments. Therefore, the present invention is not limited to the specific embodiments disclosed and described above, and some modifications and changes to the invention should also fall within the scope of protection of the claims of the present invention. In addition, although some specific terms are used in this specification, these terms are only for the convenience of description and do not constitute any limitation to the present invention.
Claims
1. A data management method based on quantum key cloud, characterized in that: The quantum key cloud is divided into a private cloud server and a public cloud server; wherein the private cloud server is used to store quantum keys and encryption and decryption data; the quantum key is generated by N QKD systems, and the QKD system includes a sender and a receiver, N≥1; the public cloud server is used to store encrypted data; The method comprises the following steps: S1: The user sends an encrypted service request to the private cloud server; S2: The private cloud server determines whether it receives multiple encryption service requests at the same time; If yes, execute step S3; If not, execute step S4; S3: The private cloud server classifies and sorts the received multiple encrypted service requests by security level to obtain the request execution order; S4: The private cloud server determines whether the remaining quantum key quantity meets the total quantum key demand of the encryption service request; If yes, execute step S5; If not, perform quantum key expansion and re-execute step S4; S5: The private cloud server processes each encrypted service request in sequence according to the request execution order, and obtains the encrypted data of each request; S6: The private cloud server sends the encrypted data to the public cloud server for storage.
2. According to claim 1, a data management method based on quantum key cloud is characterized in that: Before the user sends an encrypted service request to the private cloud server, multi-factor authentication is also included.
3. A data management method based on quantum key cloud according to claim 2, characterized in that: The multi-factor authentication includes any two of knowledge factor authentication, ownership factor authentication and biometric factor authentication.
4. According to a data management method based on quantum key cloud according to claim 1, it is characterized in that: The encryption service request includes plaintext data and quantum key demand.
5. A data management method based on quantum key cloud according to claim 4, characterized in that: In step S3, the encryption service request is classified into security levels according to the quantum key requirement; wherein, the encryption service request with a higher quantum key requirement has a higher corresponding security level.
6. A data management method based on quantum key cloud according to claim 5, characterized in that: The request execution order is from high to low security level.
7. The data management method based on quantum key cloud according to claim 1 is characterized in that: In step S4, the remaining quantum key is encrypted to obtain a new key to achieve quantum key expansion.
8. The data management method based on quantum key cloud according to claim 1 is characterized in that: In step S6, the private cloud server divides the encrypted data into multiple parts and stores them in different physical or logical locations of the public cloud server, and forms a file index table according to the storage location of each part of the data.
9. A data management method based on quantum key cloud according to claim 8, characterized in that: When the private cloud server receives a data request from the user, the private cloud server sends the corresponding file index table to the public cloud server; The public cloud server obtains the stored data according to the file index table, reassembles the encrypted data and sends it to the private cloud server; the private cloud server decrypts the encrypted data to obtain the plaintext data and sends it to the user end.
10. A data management system according to any one of claims 1 to 9, characterized in that: Including user end, private cloud server and public cloud server; The user terminal is connected to the private cloud server via a quantum channel, and the private cloud server is connected to the public cloud server via a quantum channel.
Citation Information
Patent Citations
Cloud platform management method and system based on quantum key distribution technology
CN112134695A