Key processing method and device for quantum key distribution, storage medium, computer program product, chip and computing equipment
By keeping key synchronization between quantum key cloud service nodes and pushing key components in the private network, the problem of high deployment cost of QKD devices is solved, and the security and economic benefits of key transmission are achieved.
Patent Information
- Application Number
- CN202411964520.4
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2024-12-30
- Publication Date
- 2025-05-06
AI Technical Summary
When using quantum key distribution (QKD) devices and networks, each communication node needs to deploy QKD devices and access optical fibers, resulting in high costs and insufficient reuse of resources.
By keeping the keys between at least two quantum key cloud service nodes synchronized and responding to the request of the cryptographic application, the key is split into components and pushed in the private network, and the cryptographic application is spliced into a complete key.
It reduces the deployment cost and resource waste of QKD devices, and realizes the security and economic benefits of key transmission.
Smart Images

Figure CN119945669A_ABST
Abstract
Description
Technical Field
[0001] The present application relates to the technical field of quantum key distribution, and in particular to a key processing method, device and storage medium, computer program product, chip and computing device for quantum key distribution. Background Art
[0002] Quantum Key Distribution (QKD) is a secure way to transmit keys, which can send keys between two distant communication terminals. In the process of confidential communication, keys are needed to encrypt and decrypt information, and the security of the keys ensures the security of the information.
[0003] QKD requires optical fiber as a transmission medium during key generation and transmission, so China has specially built an inter-city quantum trunk line for inter-city quantum key synchronization. Both parties using the quantum key can complete the transmission and synchronization of the key by connecting the QKD device to the quantum trunk line.
[0004] Currently, when using quantum key distribution QKD devices and quantum key distribution QKD networks, each communication node needs to deploy QKD devices and access optical fibers to complete the synchronization and transmission of quantum keys. Taking banks as an example, because the key synchronization objects may be customers, branches, or even ATM machines, the large-scale deployment of QKD devices will result in high costs. Summary of the invention
[0005] The embodiments of the present application provide a key processing method, apparatus and storage medium, computer program product, chip and computing device for quantum key distribution, so as to reduce the cost of deploying a large number of QKD devices while ensuring the security of key transmission.
[0006] The present application embodiment adopts the following technical solutions:
[0007] In a first aspect, an embodiment of the present application provides a key processing method for quantum key distribution, wherein the method comprises:
[0008] Maintain key synchronization between at least two quantum key cloud service nodes;
[0009] In response to a cryptographic use request from a cryptographic application, each of the quantum key cloud service nodes pushes key components to the cryptographic application respectively, so as to splice the key components into a complete key in the cryptographic application.
[0010] In some embodiments, in response to the cryptographic application's cryptographic use request, each of the quantum key cloud service nodes pushes a key component to the cryptographic application, including:
[0011] In response to a cryptographic use request from a cryptographic application, the key to be sent is split into key components according to the symmetric key synchronization result between the at least two quantum key cloud service nodes, and the quantum key cloud service nodes push the pre-negotiated key components to the cryptographic application one by one.
[0012] In some embodiments, the quantum key cloud service node includes multiple QKD devices deployed in key management nodes that are connected to the QKD network, and the key management system inside the quantum key cloud service node is connected to the QKD device.
[0013] In some embodiments, the method further includes: each of the quantum key cloud service nodes pushes a key component of a preset length to the cryptographic application through an internal private network.
[0014] In some embodiments, there is a negotiation mechanism between the quantum key cloud service nodes to ensure that the key components pushed by each quantum key cloud service node are different, and the key components pushed by multiple quantum key cloud service nodes are spliced to obtain a complete key.
[0015] In some embodiments, the quantum key cloud service node is also used to provide key distribution and key update services for multiple cryptographic applications.
[0016] In some embodiments, the quantum key cloud service node is also used to manage symmetric keys according to cryptographic applications and / or cryptographic application nodes.
[0017] In some embodiments, the quantum key cloud service node is also used to provide redundant access or capacity expansion for the QKD device.
[0018] In some embodiments, the method further comprises:
[0019] The key UID is synchronized between the at least two quantum key cloud service nodes to push a key associated with the key UID to the cryptographic application.
[0020] In a second aspect, an embodiment of the present application further provides a key processing device for quantum key distribution, wherein the device comprises:
[0021] A maintaining module, used to maintain key synchronization between at least two quantum key cloud service nodes;
[0022] A response module is used to respond to a cryptographic use request of a cryptographic application, and each of the quantum key cloud service nodes pushes key components to the cryptographic application respectively, so as to splice the key components into a complete key in the cryptographic application.
[0023] In a third aspect, an embodiment of the present application further provides a computer-readable storage medium, which stores one or more programs. When the one or more programs are executed by an electronic device including multiple application programs, the electronic device executes the above method.
[0024] In a fourth aspect, an embodiment of the present application further provides a computer program product, comprising instructions, which, when executed individually or collectively by at least one processor of a computing device, enable the computing device to execute a method according to any one of the above items.
[0025] In a fifth aspect, an embodiment of the present application further provides a chip, wherein the chip is configured to execute any of the methods described above.
[0026] In a sixth aspect, an embodiment of the present application also provides a computing device, comprising the above-mentioned chip.
[0027] At least one of the above technical solutions adopted in the embodiments of the present application can achieve the following beneficial effects: maintaining key synchronization between at least two quantum key cloud service nodes, and by responding to the password use request of the cryptographic application, each of the quantum key cloud service nodes pushes key components to the cryptographic application respectively, so as to splice the key components into a complete key in the cryptographic application. Through the above method, the cost problem in the process of technology promotion and use is reduced, and institutions and companies only need to complete QKD access at some nodes and use a private network to transmit key components to complete the previous key transmission and synchronization tasks, which has significant economic benefits.
[0028] In addition, it reduces the cost problem in the process of technology promotion and use. In the past, when using QKD equipment, as many devices as access points needed to be deployed and as many fiber access points opened, which was very costly. Through the above method, institutions and companies only need to complete QKD access at some nodes and use a private network to transmit key components, thus completing the previous key transmission and synchronization tasks, which has significant economic benefits. BRIEF DESCRIPTION OF THE DRAWINGS
[0029] The drawings described herein are used to provide a further understanding of the present application and constitute a part of the present application. The illustrative embodiments of the present application and their descriptions are used to explain the present application and do not constitute an improper limitation on the present application. In the drawings:
[0030] Figure 1 This is a flow chart of a key processing method for quantum key distribution in an embodiment of the present application;
[0031] Figure 2 This is a schematic diagram of the structure of a key processing device for quantum key distribution in an embodiment of the present application;
[0032] FIG3( a ) is a schematic diagram of a spine-leaf architecture of a key processing method for quantum key distribution in an embodiment of the present application;
[0033] FIG3( b) is a schematic diagram of the implementation principle of the key processing method for quantum key distribution in an embodiment of the present application;
[0034] FIG3( c ) is a schematic diagram of an actual use example of the key processing method for quantum key distribution in an embodiment of the present application;
[0035] Figure 4 This is a schematic diagram of the structure of an electronic device in an embodiment of the present application. DETAILED DESCRIPTION
[0036] In order to make the purpose, technical solution and advantages of the present application clearer, the technical solution of the present application will be clearly and completely described below in combination with the specific embodiments of the present application and the corresponding drawings. Obviously, the described embodiments are only part of the embodiments of the present application, not all of the embodiments. Based on the embodiments in the present application, all other embodiments obtained by ordinary technicians in this field without making creative work are within the scope of protection of the present application.
[0037] Currently, when using quantum key distribution QKD equipment and quantum key distribution QKD networks, each communication node needs to deploy QKD equipment and access optical fiber to complete the synchronization and transmission of quantum keys. If a large number of nodes have key synchronization requirements, deploying QKD equipment will incur extremely high costs, and the entire communication network does not reuse the internal private networks of companies and institutions, resulting in a waste of resources.
[0038] In response to the above shortcomings, the cost problem of QKD technology application is solved while ensuring the security of key transmission process. At the same time, the company and institution’s own intranet is reused to improve resource utilization.
[0039] The technical solutions provided by various embodiments of the present application are described in detail below in conjunction with the accompanying drawings.
[0040] The present application embodiment provides a key processing method for quantum key distribution, such as Figure 1 As shown, a schematic flow chart of a key processing method for quantum key distribution in an embodiment of the present application is provided, and the key processing method for quantum key distribution at least includes the following steps S110 to S120:
[0041] Step S110, maintaining key synchronization between at least two quantum key cloud service nodes.
[0042] Based on the technical characteristics of QKD, at least two quantum key cloud service nodes can achieve key synchronization, that is, the at least two quantum key cloud service nodes have exactly the same key at all times. Of course, at least two quantum key cloud service nodes can also be expanded to n quantum key cloud service nodes, which is closely related to the actual needs of institutions and enterprises and the number of data centers, and is not specifically limited in the embodiments of this application.
[0043] Specifically, QKD equipment, optical fiber and quantum key management system are deployed in n data centers (or key management nodes) in institutions and enterprises, and connected to the QKD network, and these n nodes are defined as quantum key cloud service nodes QKSN. The above QKD equipment, optical fiber and quantum key management system are common and well-known in the relevant technology, and will not be repeated here.
[0044] As shown in Figure 3(b), each quantum key cloud service node QKSN is interconnected, and the communication between the user and the quantum key cloud service node QKSN is based on the key management module in QKSN. The quantum key cloud service node QKSN consists of a QKD device and a key management server, which is used to communicate and receive the keys generated in the storage QKD. The quantum key cloud service node QKSN consists of a QKD device and a key management server, which is used to communicate and receive the keys generated in the storage QKD.
[0045] Step S120, in response to a cryptographic use request of a cryptographic application, each of the quantum key cloud service nodes pushes key components to the cryptographic application respectively, so as to splice the key components into a complete key in the cryptographic application.
[0046] The key management system deployed in the quantum key cloud service node QKSN is connected to the QKD device for application, so QKSN can realize the functions of obtaining keys, storing keys and sending keys. Each QKSN splits the key into key components, and then transmits them to the cryptographic application separately. The method of completing the key synthesis by the application side solves the security problem of using dedicated lines for key transmission in a simple and efficient way.
[0047] As shown in Figure 3(b), the QKSN nodes maintain key synchronization between multiple QKSN nodes through quantum communication trunks. When the cryptographic applications within the organization and the company need to use keys, they apply to all n QKSN nodes within the organization to obtain keys through dedicated lines. The QKSN nodes push key components of specific lengths to the cryptographic applications through dedicated lines. There is a negotiation mechanism between the QKSN nodes to ensure that the key components pushed by each node are different, and the key components pushed by n nodes can be spliced to form a complete key. Cryptographic applications include but are not limited to customers, branches, etc.
[0048] As shown in Figure 3(a), the quantum key cloud service node QKSN adopts the spine-leaf architecture commonly used in data centers, which is a two-layer network topology. Compared with the traditional three-layer network architecture, the quantum key cloud service node QKSN brings multiple advantages to the data center infrastructure, such as scalability, reduced latency and improved performance. Spine is the spine and leaf is the sub-leaf.
[0049] As shown in Figure 3(c), the quantum key cloud service nodes QKSN constitute the total key center, and the keys between them are synchronized. Taking a bank as an example, the head office department deploys the quantum key cloud service node QKSN, and when the branch applies for use, the key component is transmitted in the intranet. PQC is related to actual business.
[0050] The method of maintaining key synchronization between at least two quantum key cloud service nodes is adopted, and the QKSN node splits the key into components and distributes them to the cryptographic application, which then completes the synthesis of the components. This solves the problem in related technologies that each communication node needs to deploy QKD equipment and access optical fiber to complete quantum key synchronization and transmission. If a large number of nodes have key synchronization requirements, deploying QKD equipment will result in extremely high costs.
[0051] Since any eavesdropping on the quantum key distribution process may change the quantum state itself, causing a high bit error rate, thus making the eavesdropping discovered. Generally speaking, the transmission of quantum states in the QKD process is achieved by encoding, transmitting, and measuring photons. Therefore, if the key result obtained by the above method is adopted, it has a higher security.
[0052] Since each byte of the key generated by QKD has two numbers (i.e., two polarization states of photons), it is generally generated continuously over time, the length grows infinitely, and each node is synchronized. For example, 01001 can be considered as a string of 5-byte keys generated by QKD. The keys generated by QKD can be applied to a wide range of scenarios. Therefore, the quantum key cloud service node QKSN is used to solve the problem of high cost of QKD technology in related technologies.
[0053] Preferably, since a quantum communication trunk line is used to maintain synchronization, the quantum key users can complete the transmission and synchronization of the key by connecting the QKD device to the quantum trunk line.
[0054] In one embodiment of the present application, in response to a cryptographic use request from a cryptographic application, each of the quantum key cloud service nodes pushes key components to the cryptographic application respectively, including: in response to the cryptographic use request from the cryptographic application, splitting the key to be sent into key components according to the symmetric key synchronization result between the at least two quantum key cloud service nodes, and pushing the pre-negotiated key components to the cryptographic application one by one by the quantum key cloud service nodes.
[0055] When cryptographic applications within an organization or company need to use keys, they apply to all n QKSN nodes within the organization to obtain keys through a dedicated line. The QKSN nodes push key components of specific lengths to the cryptographic applications through the dedicated line. There is a negotiation mechanism between the QKSN nodes to ensure that the key components pushed by each node are different, and the key components pushed by n nodes can be spliced to form a complete key.
[0056] In one embodiment of the present application, the quantum key cloud service node includes multiple QKD devices deployed in key management nodes that are connected to the QKD network, and the key management system inside the quantum key cloud service node is connected to the QKD device.
[0057] The cryptographic application nodes synthesize the final key through a consensus-based key synthesis method, based on which the secure key issuance behavior centered on the quantum key cloud service node can be realized. The QKSN node supports key distribution and update services for multiple applications, supports the management of symmetric keys by application and application node, and supports redundant access to QKD devices and system expansion.
[0058] In one embodiment of the present application, the method further includes: each of the quantum key cloud service nodes pushes a key component of a preset length to the cryptographic application through an internal private network.
[0059] During the transmission of key components, the internal private network of the organization and the company can be used, which improves resource reuse and reduces the cost of technology promotion and use.
[0060] In one embodiment of the present application, there is a negotiation mechanism between the quantum key cloud service nodes to ensure that the key components pushed by each quantum key cloud service node are different, and the key components pushed by multiple quantum key cloud service nodes are spliced to obtain a complete key.
[0061] For example, if the quantum key cloud service node QKSN includes QKSN1, QKSN2, and QKSN3, there is a negotiation mechanism between the quantum key cloud service nodes, and each QKSN1, QKSN2, and QKSN3 can transmit 1 / 3 of the key component respectively, and then the key components pushed by multiple quantum key cloud service nodes are spliced to obtain a complete key. The above is only an example and is not intended to limit the scope of protection in the embodiments of the present application.
[0062] In one embodiment of the present application, the quantum key cloud service node is also used to provide key distribution and key update services for multiple cryptographic applications.
[0063] The quantum key cloud service node QKSN, due to the technical characteristics of QKD, n QKSNs can achieve key synchronization, that is, the n quantum key cloud service nodes have exactly the same key at all times.
[0064] In one embodiment of the present application, the quantum key cloud service node is also used to manage symmetric keys according to cryptographic applications and / or cryptographic application nodes.
[0065] The key management system deployed in the quantum key cloud service node QKSN is connected to the QKD device for application, so QKSN can realize the functions of obtaining keys, storing keys and sending keys.
[0066] In one embodiment of the present application, the quantum key cloud service node is also used to provide redundant access or capacity expansion for the QKD device.
[0067] The quantum key cloud service node QKSN provides the possibility of redundancy and expansion of QKD equipment. The QKSN node pushes key components of specific length to the cryptographic application through a dedicated line. There is a negotiation mechanism between QKSN nodes to ensure that the key components pushed by each node are different, and the key components pushed by n nodes can be spliced to form a complete key. This constitutes a redundancy or expansion solution.
[0068] In one embodiment of the present application, the method further includes: synchronizing the key UID between the at least two quantum key cloud service nodes to push a key associated with the key UID to the cryptographic application.
[0069] When concatenating keys, if an organization or company deploys two QKSN nodes, called QKSN1 and QKSN2, it is assumed that the key length is k.
[0070] Set QKSN1 to send the first half of the component to all branches, denoted as k1, and QKSN2 to send the second half of the component to all branches, denoted as k2; QKSN1 regularly updates the application key according to the key management strategy, and sends k1 and the hash value H1 of k1 to the cryptographic application that needs to use the key.
[0071] After receiving k1, the cryptographic application replies to QKSN1 to confirm receipt of the k1 component. After receiving the reply from the cryptographic application, QKSN1 notifies QKSN2 to apply the updated key UID. After obtaining the UID, QKSN2 sends the second half of the key k2 corresponding to the UID and the hash value H2 of k2 to the cryptographic application.
[0072] After receiving component k2, the cryptographic application synthesizes the final key, calculates the hash value H of its own synthesized key, and compares it with the received hash values H1 and H2 of k1 to verify the correctness of the key. If it is correct, it replies to QKSN2. After QKSN2 receives the reply, that is, the cryptographic application synthesized key verification success message, it notifies QKSN1 that the key component distribution is successful. This completes this round of key distribution process.
[0073] The present application also provides a key processing device 200 for quantum key distribution, such as Figure 2 As shown, a schematic diagram of the structure of a key processing device for quantum key distribution in an embodiment of the present application is provided. The key processing device 200 for quantum key distribution at least includes: a holding module 210 and a response module 220, wherein:
[0074] In one embodiment of the present application, the maintaining module 210 is specifically used to maintain key synchronization between at least two quantum key cloud service nodes.
[0075] Based on the technical characteristics of QKD, at least two quantum key cloud service nodes can achieve key synchronization, that is, the at least two quantum key cloud service nodes have exactly the same key at all times. Of course, at least two quantum key cloud service nodes can also be expanded to n quantum key cloud service nodes, which is closely related to the actual needs of institutions and enterprises and the number of data centers, and is not specifically limited in the embodiments of this application.
[0076] Specifically, QKD equipment, optical fiber and quantum key management system are deployed in n data centers (or key management nodes) in institutions and enterprises, and connected to the QKD network, and these n nodes are defined as quantum key cloud service nodes QKSN. The above QKD equipment, optical fiber and quantum key management system are common and well-known in the relevant technology, and will not be repeated here.
[0077] In one embodiment of the present application, the response module 220 is specifically used to: in response to a cryptographic use request of a cryptographic application, each of the quantum key cloud service nodes pushes key components to the cryptographic application respectively, so as to splice the key components into a complete key in the cryptographic application.
[0078] The key management system deployed in the quantum key cloud service node QKSN is connected to the QKD device for application, so QKSN can realize the functions of obtaining keys, storing keys and sending keys.
[0079] As shown in Figure 3, the QKSN nodes maintain key synchronization between multiple QKSN nodes through quantum communication trunks. When the cryptographic applications within the organization and the company need to use keys, they apply to all n QKSN nodes within the organization to obtain keys through dedicated lines. The QKSN nodes push key components of specific lengths to the cryptographic applications through dedicated lines. There is a negotiation mechanism between QKSN nodes to ensure that the key components pushed by each node are different, and the key components pushed by n nodes can form a complete key through splicing.
[0080] In one embodiment of the present application, the response module 220 is also used to
[0081] In response to a cryptographic use request from a cryptographic application, the key to be sent is split into key components according to the symmetric key synchronization result between the at least two quantum key cloud service nodes, and the quantum key cloud service nodes push the pre-negotiated key components to the cryptographic application one by one.
[0082] In one embodiment of the present application, the quantum key cloud service node includes multiple QKD devices deployed in key management nodes that are connected to the QKD network, and the key management system inside the quantum key cloud service node is connected to the QKD device.
[0083] In one embodiment of the present application, it further includes: a division module for
[0084] Each of the quantum key cloud service nodes pushes a key component of a preset length to the cryptographic application through an internal private network.
[0085] In one embodiment of the present application, there is a negotiation mechanism between the quantum key cloud service nodes to ensure that the key components pushed by each quantum key cloud service node are different, and the key components pushed by multiple quantum key cloud service nodes are spliced to obtain a complete key.
[0086] In one embodiment of the present application, the quantum key cloud service node is also used to provide key distribution and key update services for multiple cryptographic applications.
[0087] In one embodiment of the present application, the quantum key cloud service node is also used to manage symmetric keys according to cryptographic applications and / or cryptographic application nodes.
[0088] In one embodiment of the present application, the quantum key cloud service node is also used to provide redundant access or capacity expansion for the QKD device.
[0089] In one embodiment of the present application, it further includes: a key merging module for
[0090] The key UID is synchronized between the at least two quantum key cloud service nodes to push a key associated with the key UID to the cryptographic application.
[0091] It can be understood that the above-mentioned key processing device for quantum key distribution can implement the various steps of the key processing method for quantum key distribution provided in the aforementioned embodiments, and the relevant explanations on the key processing method for quantum key distribution are applicable to the key processing device for quantum key distribution, which will not be repeated here.
[0092] In an embodiment of the present application, a computer-readable storage medium is provided, on which instructions are stored. When the instructions are executed individually or collectively by at least one processor of a computing device, the computing device is caused to execute the method described.
[0093] In an embodiment of the present application, a computer program product is provided, comprising instructions, which, when executed individually or collectively by at least one processor of a computing device, cause the computing device to perform the method.
[0094] A chip is provided in an embodiment of the present application, and the chip is configured to execute the method described.
[0095] A computing device is provided in an embodiment of the present application, including the chip.
[0096] Figure 4 This is a schematic diagram of the structure of an electronic device according to an embodiment of the present application. Figure 4 At the hardware level, the electronic device includes a processor, and optionally also includes an internal bus, a network interface, and a memory. The memory may include a memory, such as a high-speed random access memory (RAM), and may also include a non-volatile memory (non-volatile memory), such as at least one disk storage. Of course, the electronic device may also include hardware required for other services.
[0097] The processor, network interface and memory can be interconnected through an internal bus, which can be an ISA (Industry Standard Architecture) bus, a PCI (Peripheral Component Interconnect) bus or an EISA (Extended Industry Standard Architecture) bus. The bus can be divided into an address bus, a data bus, a control bus, etc. For ease of representation, Figure 4Only one bidirectional arrow is used in the diagram, but this does not mean that there is only one bus or only one type of bus.
[0098] The memory is used to store the program. Specifically, the program may include a program code, and the program code includes a computer operation instruction. The memory may include a memory and a non-volatile memory, and provides instructions and data to the processor.
[0099] The processor reads the corresponding computer program from the non-volatile memory into the memory and then runs it, forming a key processing device for quantum key distribution at the logical level. The processor executes the program stored in the memory and is specifically used to perform the following operations:
[0100] Maintain key synchronization between at least two quantum key cloud service nodes;
[0101] In response to a cryptographic use request from a cryptographic application, each of the quantum key cloud service nodes pushes key components to the cryptographic application respectively, so as to splice the key components into a complete key in the cryptographic application.
[0102] The above application Figure 1The method performed by the key processing device for quantum key distribution disclosed in the illustrated embodiment can be applied to a processor or implemented by a processor. The processor may be an integrated circuit chip with signal processing capabilities. In the implementation process, each step of the above method can be completed by an integrated logic circuit of hardware in the processor or an instruction in the form of software. The above processor may be a general-purpose processor, including a central processing unit (CPU), a network processor (NP), etc.; it may also be a digital signal processor (DSP), an application-specific integrated circuit (ASIC), a field-programmable gate array (FPGA) or other programmable logic devices, discrete gates or transistor logic devices, discrete hardware components. The methods, steps and logic block diagrams disclosed in the embodiments of the present application can be implemented or executed. The general-purpose processor may be a microprocessor or the processor may also be any conventional processor, etc. The steps of the method disclosed in conjunction with the embodiments of the present application can be directly embodied as being executed by a hardware decoding processor, or executed by a combination of hardware and software modules in a decoding processor. The software module can be located in a storage medium mature in the art such as a random access memory, a flash memory, a read-only memory, a programmable read-only memory, or an electrically erasable programmable memory, a register, etc. The storage medium is located in the memory, and the processor reads the information in the memory and completes the steps of the above method in combination with its hardware.
[0103] The electronic device may also perform Figure 1 A method for executing a key processing device for quantum key distribution in a Figure 1 The functions of the illustrated embodiment will not be described in detail in the embodiments of the present application.
[0104] The present application also provides a computer-readable storage medium, which stores one or more programs, wherein the one or more programs include instructions, which, when executed by an electronic device including multiple application programs, enable the electronic device to execute Figure 1 The method performed by the key processing device for quantum key distribution in the illustrated embodiment is specifically used to perform:
[0105] Maintain key synchronization between at least two quantum key cloud service nodes;
[0106] In response to a cryptographic use request from a cryptographic application, each of the quantum key cloud service nodes pushes key components to the cryptographic application respectively, so as to splice the key components into a complete key in the cryptographic application.
[0107] Those skilled in the art will appreciate that embodiments of the present invention may be provided as methods, systems, or computer program products. Therefore, the present invention may take the form of a complete hardware embodiment, a complete software embodiment, or an embodiment combining software and hardware. Moreover, the present invention may take the form of a computer program product implemented on one or more computer-usable storage media (including but not limited to disk storage, CD-ROM, optical storage, etc.) containing computer-usable program code.
[0108] The present invention is described with reference to flowcharts and / or block diagrams of methods, devices (systems), and computer program products according to embodiments of the present invention. It should be understood that each process and / or block in the flowchart and / or block diagram, as well as the combination of processes and / or blocks in the flowchart and / or block diagram, can be implemented by computer program instructions. These computer program instructions can be provided to a processor of a general-purpose computer, a special-purpose computer, an embedded processor, or other programmable data processing device to produce a machine, so that the instructions executed by the processor of the computer or other programmable data processing device generate instructions for implementing the processes in the flowchart and / or block diagram. Figure 1 A process or multiple processes and / or boxes Figure 1 A device that provides the functions specified in a block or multiple blocks.
[0109] These computer program instructions may also be stored in a computer-readable memory capable of directing a computer or other programmable data processing device to operate in a specific manner, so that the instructions stored in the computer-readable memory produce an article of manufacture comprising an instruction device, which implements the process Figure 1 A process or multiple processes and / or boxes Figure 1 A function specified in one or more boxes.
[0110] These computer program instructions can also be loaded onto a computer or other programmable data processing device so that a series of operating steps are executed on the computer or other programmable device to produce a computer-implemented process, thereby providing instructions for implementing the process. Figure 1 A process or multiple processes and / or boxes Figure 1 The steps for the functions specified in one or more boxes.
[0111] In a typical configuration, a computing device includes one or more processors (CPU), input / output interfaces, network interfaces, and memory.
[0112] The memory may include non-permanent storage in a computer-readable medium, random access memory (RAM) and / or non-volatile memory in the form of read-only memory (ROM) or flash RAM. The memory is an example of a computer-readable medium.
[0113] Computer readable media include permanent and non-permanent, removable and non-removable media that can be implemented by any method or technology to store information. Information can be computer readable instructions, data structures, program modules or other data. Examples of computer storage media include, but are not limited to, phase change memory (PRAM), static random access memory (SRAM), dynamic random access memory (DRAM), other types of random access memory (RAM), read-only memory (ROM), electrically erasable programmable read-only memory (EEPROM), flash memory or other memory technology, compact disk read-only memory (CD-ROM), digital versatile disk (DVD) or other optical storage, magnetic cassettes, magnetic tape magnetic disk storage or other magnetic storage devices or any other non-transmission media that can be used to store information that can be accessed by a computing device. As defined herein, computer readable media does not include temporary computer readable media (transitory media), such as modulated data signals and carrier waves.
[0114] It should also be noted that the terms "include", "comprises" or any other variations thereof are intended to cover non-exclusive inclusion, so that a process, method, commodity or device including a series of elements includes not only those elements, but also other elements not explicitly listed, or also includes elements inherent to such process, method, commodity or device. In the absence of more restrictions, the elements defined by the sentence "comprises a ..." do not exclude the existence of other identical elements in the process, method, commodity or device including the elements.
[0115] Those skilled in the art will appreciate that the embodiments of the present application may be provided as methods, systems or computer program products. Therefore, the present application may adopt the form of a complete hardware embodiment, a complete software embodiment or an embodiment in combination with software and hardware. Moreover, the present application may adopt the form of a computer program product implemented on one or more computer-usable storage media (including but not limited to disk storage, CD-ROM, optical storage, etc.) that contain computer-usable program code.
[0116] The above is only an embodiment of the present application and is not intended to limit the present application. For those skilled in the art, the present application may have various changes and variations. Any modification, equivalent replacement, improvement, etc. made within the spirit and principle of the present application should be included in the scope of the claims of the present application.
Claims
1. A key processing method for quantum key distribution, wherein: The method comprises: Maintain key synchronization between at least two quantum key cloud service nodes; In response to a cryptographic use request from a cryptographic application, each of the quantum key cloud service nodes pushes key components to the cryptographic application respectively, so as to splice the key components into a complete key in the cryptographic application.
2. The method of claim 1, wherein: In response to the cryptographic application's cryptographic use request, each of the quantum key cloud service nodes pushes a key component to the cryptographic application, including: In response to a cryptographic use request from a cryptographic application, the key to be sent is split into key components according to the symmetric key synchronization result between the at least two quantum key cloud service nodes, and the quantum key cloud service nodes push the pre-negotiated key components to the cryptographic application one by one.
3. The method of claim 2, wherein: The quantum key cloud service node includes multiple QKD devices deployed in key management nodes that are connected to the QKD network, and the key management system inside the quantum key cloud service node is connected to the QKD device.
4. The method according to claim 2, further comprising: Each of the quantum key cloud service nodes pushes a key component of a preset length to the cryptographic application through an internal private network.
5. The method of claim 1, wherein: There is a negotiation mechanism between the quantum key cloud service nodes to ensure that the key components pushed by each quantum key cloud service node are different, and the key components pushed by multiple quantum key cloud service nodes are spliced to obtain a complete key.
6. The method of claim 1, wherein: The quantum key cloud service node is also used to provide key distribution and key update services for multiple cryptographic applications.
7. The method of claim 1, wherein: The quantum key cloud service node is also used to manage symmetric keys according to cryptographic applications and / or cryptographic application nodes.
8. The method of claim 3, wherein: The quantum key cloud service node is also used to provide redundant access or capacity expansion for the QKD device.
9. The method of claim 1, further comprising: The key UID is synchronized between the at least two quantum key cloud service nodes to push a key associated with the key UID to the cryptographic application.
10. A key processing device for quantum key distribution, wherein: The device comprises: A maintaining module, used to maintain key synchronization between at least two quantum key cloud service nodes; A response module is used to respond to a cryptographic use request of a cryptographic application, and each of the quantum key cloud service nodes pushes key components to the cryptographic application respectively, so as to splice the key components into a complete key in the cryptographic application.
11. A computer-readable storage medium storing instructions, characterized in that: When the instructions are executed individually or collectively by at least one processor of a computing device, the computing device is caused to perform the method according to any one of claims 1 to 9.
12. A computer program product comprising instructions, characterized in that When the instructions are executed individually or collectively by at least one processor of a computing device, the computing device is caused to perform the method according to any one of claims 1 to 9.
13. A chip, characterized in that: The chip is configured to perform the method according to any one of claims 1 to 9.
14. A computing device, characterized in that Comprising the chip as claimed in claim 13.
Citation Information
Cited By
Communication method, electronic equipment and computer readable storage medium
CN120811693A