Data transmission method and device and data transmission system

By using true random numbers as key sequence numbers in rail vehicle communication and using preset keys for encrypted communication, the high cost and high security risks of networking and key transmission methods in existing quantum key technology are solved, and the secure distribution of quantum keys and the security improvement of vehicle-to-ground communication is achieved.

CN119945786AActive Publication Date: 2025-05-06CRRC TANGSHAN CO LTD

Patent Information

Application Number
CN202510111963.7
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-01-23
Publication Date
2025-05-06
Estimated Expiration
2045-01-23

AI Technical Summary

Technical Problem

Among the existing quantum key technologies, networking and key transmission methods have a large transformation range of traditional systems, and the economic costs are high. The networking and key transmission methods applicable to traditional encryption methods are not suitable for quantum key technology, and the transmission security risks are relatively high.

Method used

Provided is a data transmission method, by generating a true random number as a key sequence number and using a preset key for encrypted communication, to realize the secure distribution of quantum keys between the vehicle and the ground. The method includes generating and sending a first key sequence number, generating and sending a random digital tag encrypted by the first key, receiving and verifying feedback and generating a second key sequence number for encrypting communication.

Benefits of technology

It realizes the secure distribution of quantum keys in vehicle-to-ground communication application scenarios, improves vehicle-to-ground transmission security, and reduces the range of changes to existing systems and reduces unnecessary overhead.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN119945786A_ABST
    Figure CN119945786A_ABST
Patent Text Reader

Abstract

The embodiment of the invention provides a data transmission method and device and a data transmission system, and relates to the technical field of network security. The method comprises the steps that ground terminal equipment generates a true random number as a first secret key serial number and sends the first secret key serial number to vehicle-mounted terminal equipment, the ground terminal equipment and the vehicle-mounted terminal equipment are configured with the same preset secret keys, and a secret key corresponding to the first secret key serial number in the preset secret keys serves as the first secret key; generating a random digital tag encrypted through the first key, and sending the random digital tag to the vehicle-mounted terminal equipment; and after decryption loading feedback of the vehicle-mounted terminal equipment on the random digital tag is received, generating a true random number as a second secret key serial number, sending the second secret key serial number to the vehicle-mounted terminal equipment, taking a secret key corresponding to the second secret key serial number in the preset secret keys as a second secret key, and performing encryption communication with the vehicle-mounted terminal equipment by using the second secret key. According to the invention, secure distribution of quantum keys in a train-ground communication application scene can be realized, and the train-ground transmission security is improved.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present application relates to the field of network security technology, and in particular, to a data transmission method and device, and a data transmission system. Background Art

[0002] With the continuous improvement of informatization and intelligence levels, rail vehicles have increasingly higher requirements for communication security, and traditional encryption methods can no longer meet the growing security needs.

[0003] Quantum key distribution technology is based on the basic principles of quantum mechanics. It uses the uncertainty and non-cloning of quantum states to achieve unconditional and secure transmission of keys, thus providing a revolutionary security guarantee for rail vehicle communications. In rail vehicle communication networks, quantum key distribution technology can effectively prevent security threats such as hacker attacks, information leakage, and malicious tampering, and ensure the stability and reliability of train control systems, passenger service systems, and emergency rescue communications. In addition, with the rapid development of my country's rail transit industry, the requirements for rail vehicle communication security are becoming increasingly stringent. The application of quantum key distribution technology will help improve the overall safety level of my country's rail transit and lay a solid foundation for the sustainable development of my country's rail transit industry.

[0004] However, the networking and key transmission methods in the existing quantum key technology require a large transformation of the traditional system and have a high economic cost; while the networking and key transmission methods applicable to traditional encryption methods are no longer applicable to quantum key technology and have a high transmission security risk. Therefore, a networking and key transmission method is needed that can effectively prevent potential transmission security risks and achieve system security upgrades at a lower cost. Summary of the invention

[0005] In order to solve one of the above-mentioned technical defects, a data transmission method and device, and a data transmission system are provided in the embodiments of the present application.

[0006] According to a first aspect of an embodiment of the present application, a data transmission method is provided, which is applied to a ground terminal device; the method comprises:

[0007] Generate a true random number as the first key serial number and send it to the vehicle-mounted terminal device. The ground terminal device and the vehicle-mounted terminal device are configured with the same preset key, and the key corresponding to the first key serial number in the preset key is used as the first key;

[0008] Generate a random digital label encrypted by a first key and send it to the vehicle terminal device;

[0009] After receiving the decryption loading feedback of the random digital tag from the vehicle-mounted terminal device, a true random number is generated as the second key serial number and sent to the vehicle-mounted terminal device, and the key corresponding to the second key serial number in the preset key is used as the second key, and the second key is used to perform encrypted communication with the vehicle-mounted terminal device.

[0010] In an optional embodiment of the present application, after receiving the decryption loading feedback of the random digital tag by the vehicle terminal device, a true random number is generated as the second key serial number and sent to the vehicle terminal device, and the key corresponding to the second key serial number in the preset key is used as the second key, and the step of using the second key to perform encrypted communication with the vehicle terminal device also includes:

[0011] The decrypted loading feedback includes the hash algorithm calculation value of the vehicle terminal device identity information and the random digital tag, and the vehicle terminal device identity information is verified. If the verification passes, a second key is generated and used to perform encrypted communication with the vehicle terminal device.

[0012] In an optional embodiment of the present application, it also includes:

[0013] When receiving a key charging request from the vehicle-mounted terminal device, wirelessly charge the key to the vehicle-mounted terminal device.

[0014] According to a second aspect of an embodiment of the present application, a data transmission method is provided, which is applied to a vehicle-mounted terminal device, and the method includes:

[0015] Receiving a first key serial number sent by the ground terminal device, the vehicle-mounted terminal device and the ground terminal device are configured with the same pre-set key, and using a key corresponding to the first key serial number in the pre-set key as the first key;

[0016] Receive a random digital label encrypted by a first key from a ground terminal device, decrypt and load the random digital label, store it in a static random access memory, and send a decryption and loading feedback to the ground terminal device;

[0017] Receive the second key serial number sent by the ground terminal device, use the key corresponding to the second key serial number in the preset key as the second key, and use the second key to perform encrypted communication with the ground terminal device.

[0018] In an optional embodiment of the present application, the steps of receiving a random digital tag encrypted by a first key sent by the vehicle-mounted terminal device, decrypting the random digital tag and loading it, and sending a decrypted loading feedback to the ground terminal device also include:

[0019] The identity information of the vehicle-mounted terminal device and the random digital tag are calculated using a hash algorithm, and the value of the hash algorithm is encrypted using a first key and sent to the ground terminal device.

[0020] In an optional embodiment of the present application, it also includes:

[0021] When the number of preset keys is lower than the set number, a key charging request is sent to the ground terminal device;

[0022] Receive the key sent by the ground terminal device in response to the key injection request.

[0023] According to a third aspect of an embodiment of the present application, there is provided a data transmission device, comprising a processor and a memory storing program instructions, wherein the processor is configured to execute a data transmission method as described in any one of the first and second aspects of the embodiment of the present application when running the program instructions.

[0024] According to a fourth aspect of an embodiment of the present application, a data transmission system is provided, including:

[0025] Ground terminal equipment, including ground data center, quantum key management platform, and communication encryption module;

[0026] The vehicle-mounted terminal device is connected to the ground terminal device for communication; and

[0027] For example, the data transmission device according to the third aspect of the embodiment of the present application is installed in a ground terminal device and a vehicle-mounted terminal device.

[0028] In an optional embodiment of the present application, it also includes:

[0029] The quantum key service center stores the identity information of the vehicle-mounted terminal device, is connected to the ground terminal device for communication, and is used to verify the identity information of the vehicle-mounted terminal device received by the ground terminal device according to the request sent by the ground terminal device; and stores the key for injecting the key into the vehicle-mounted terminal device through the ground terminal device according to the request sent by the ground terminal device.

[0030] In an optional embodiment of the present application, it also includes:

[0031] The quantum encryption device production terminal is connected to the quantum key service center for communication, is used to produce keys, and sends keys to the quantum key service center based on the request received from the quantum key service center.

[0032] By adopting the data transmission method provided in the embodiment of the present application, both the vehicle and the ground use the same serial number key as the business key, and the serial number is a true random number, which can realize the secure distribution of quantum keys in vehicle-to-ground communication application scenarios and improve the security of vehicle-to-ground transmission. At the same time, based on the networking scheme to which this method can be applied, it can reduce the extent of changes to the existing system and reduce unnecessary overhead. BRIEF DESCRIPTION OF THE DRAWINGS

[0033] The drawings described herein are used to provide a further understanding of the present application and constitute a part of the present application. The illustrative embodiments of the present application and their descriptions are used to explain the present application and do not constitute an improper limitation on the present application. In the drawings:

[0034] Figure 1 is a schematic diagram of a data transmission system provided in an embodiment of the present application;

[0035] Figure 2 is a schematic diagram of a data transmission method provided in an embodiment of the present application;

[0036] Figure 3 is a schematic diagram of another data transmission method provided in an embodiment of the present application;

[0037] Figure 4 It is a schematic diagram of a data transmission device provided in an embodiment of the present application. DETAILED DESCRIPTION

[0038] In order to make the technical solutions and advantages in the embodiments of the present application more clearly understood, the exemplary embodiments of the present application are further described in detail below in conjunction with the accompanying drawings. Obviously, the described embodiments are only part of the embodiments of the present application, rather than an exhaustive list of all the embodiments. It should be noted that the embodiments in the present application and the features in the embodiments can be combined with each other without conflict.

[0039] The present application proposes a data transmission system, comprising:

[0040] Ground terminal equipment, vehicle-mounted terminal equipment connected to the ground terminal equipment, and processors installed in the vehicle-mounted terminal equipment and the ground terminal equipment. The ground terminal equipment includes a ground data center, a quantum key management platform, and a communication encryption module.

[0041] In some embodiments of the present application, a quantum key service center is also included, which stores the identity information and keys of the vehicle-mounted terminal equipment and is communicatively connected to the ground terminal equipment; a quantum encryption equipment production terminal is communicatively connected to the quantum key service center for producing keys.

[0042] In some embodiments of the present application, the ground terminal device is an operation ground center, and the vehicle-mounted terminal device is a vehicle-mounted encryption terminal.

[0043] Figure 1 For a schematic diagram of a data transmission system provided in an embodiment of the present application, see Figure 1 :

[0044] Quantum Key Service Center, including:

[0045] Authentication function module: realize identity authentication between the quantum key service center and the vehicle-mounted encryption terminal.

[0046] Center and sub-center modules: Data interaction between the quantum key service center and the sub-center at the operation end to ensure the synchronization of information at both ends.

[0047] Data storage module: stores key data and vehicle identity information of all vehicle sections.

[0048] Server security module: boundary protection, security audit, zero trust management, disaster recovery, etc., to strengthen the security of the server system.

[0049] Quantum key distribution and management module: manages the keys of all rail vehicles, including generating quantum keys through QRNG (Quantum Random Number Generator), wirelessly charging keys through anti-quantum algorithms, emergency operations to stop using or destroy quantum keys under special circumstances, and monitoring the number, cycle and time period of wireless charging of vehicles to detect hidden dangers in advance.

[0050] Algorithm engine module: Wireless key charging provides symmetric national secret encryption algorithm, and provides symmetric encryption and hash algorithm for the identity authentication of vehicle-mounted equipment.

[0051] Communication encryption module: Use QKD (quantum key distribution) encryption or quantum IPsec (Internet Protocol Security) gateway encryption to securely send the generated quantum key to the sub-center at the operation end, and use the sub-center to charge and manage the vehicle key. At the same time, communicate with the production end of the on-board encryption device through secure communication, charge the pre-charged key and digital tag into the on-board device, and collect the UID (User Identification) and fingerprint information of the on-board device to the central service.

[0052] Operations ground centre, including:

[0053] Ground data center: For large railways (EMU, high-speed EMU and ordinary trains), the data landing of vehicles is unified through the public network 4G / 5G. For urban rail transit vehicles, data logic is carried out through the public network or LE private network. The ground data center decrypts the wireless vehicle data ciphertext through the quantum security gateway. The quantum security gateway obtains the quantum key through the quantum key service sub-center.

[0054] The quantum key management platform (sub-center) consists of quantum key distribution, quantum key emergency management, and data synchronization between the center and sub-centers. It assists the quantum key service center in using quantum-resistant algorithms to wirelessly inject quantum keys into the vehicle-mounted terminal, and also safely distributes them to the quantum gateway of the ground data center, thus achieving secure key distribution.

[0055] Security protection module: provides network security reinforcement for the operation ground center system.

[0056] Communication encryption module: Realize data communication with the quantum key service center through QKD encryption or quantum IPsec gateway encryption.

[0057] The production side of quantum encryption equipment includes:

[0058] Security charging machine: obtains quantum keys from the quantum key service center through the QKD encryption channel. The key management platform uses the charging machine to charge the preset keys into the encryption device that is about to leave the factory, and also reads the UID and fingerprint information of the encryption device back to the key management platform.

[0059] Center and production end: The center and production end interact with each other on business data through a secure communication channel.

[0060] The security and monitoring module is used to provide video monitoring and permission management functions. To improve the security of the environment, the pre-keying process of the encryption device is subject to video monitoring and permission management.

[0061] Communication encryption module: realize data communication with the quantum key service center through QKD encryption or quantum IPsec gateway encryption.

[0062] Vehicle-mounted encryption terminal, including:

[0063] The vehicle application security module includes security boundary protection, which has the function of a firewall and can prevent and protect malicious attacks through policy formulation. The vehicle application security module includes the authentication handshake function, which is the protocol for the vehicle encryption terminal to conduct the authentication process with the key management center.

[0064] Device fingerprint: Device fingerprint refers to the combination of hardware characteristics such as ARM processor model, unique hardware ID, MAC address of network card, operating system version and security patch, network configuration, installed encryption algorithm or security module, encryption protocol at runtime, clock synchronization information, and power status to generate a unique identification of the gateway (the device fingerprint is processed by hash algorithm or other summary algorithm to obtain the unique hardware digital number of the vehicle encryption terminal).

[0065] UID number: A serial number of the vehicle encryption terminal, stored in the encryption chip, which is fixed.

[0066] Security encryption module: It consists of quantum-resistant algorithm, QRNG chip, secure storage, encryption engine, fingerprint generation and main processor. The quantum-resistant encryption algorithm is used for wireless and secure key charging to ensure that the key will not be cracked by supercomputers or quantum computers during the charging process. QRNG quantum true random numbers are used to generate true random numbers, mainly for quantum-resistant algorithms. The secure storage mainly stores the encrypted keys, which can be read and decrypted through the decryption protocol of the main processor. The fingerprint generation function mainly forms a unique fingerprint for the module hardware and firmware information, and provides it to the upper-level application security module. The cryptographic engine implements the operation of hash algorithm and symmetric encryption SM4 / DES. The main processor is used to implement quantum-resistant encryption algorithm and key derivation algorithm PBKDF2, scrypt.

[0067] In this way, according to the security risk assessment, implementation cost and application scenario boundary conditions, the embodiment of the present application is divided into four units: quantum key service center, ground operation center, vehicle-mounted encryption terminal and quantum encryption equipment production end. By integrating the QKD technology of optical fiber media, quantum random number IPsecVPN technology and anti-quantum cracking key injection technology based on Shannon's perfect theorem, the secure distribution of quantum keys in vehicle-to-ground communication application scenarios is achieved, thereby improving the security of vehicle-to-ground transmission.

[0068] In the embodiment of the present application, the quantum encryption device production end uses a rail vehicle dedicated charging device, which communicates with the quantum encryption service center through QKD encryption, and can charge keys and digital tags to the on-board encryption device online, and also read the UID and fingerprint information of the device. The link for charging keys to the device is: quantum key service center-QKD encryption channel-dedicated key charging device-on-board encryption device, and the overall link security level is relatively high.

[0069] In the embodiment of the present application, the digital link of the on-board quantum encryption device during the wireless key charging process is quantum key service center-quantum VPN gateway-ground operation and maintenance center-wireless channel-on-board encryption device. The overall wireless charging layer adopts an algorithm that resists quantum cracking to improve the security and reliability of the overall data link.

[0070] Figures 2 to 3 It is a schematic diagram of the data transmission method provided in the embodiment of the present application. Any of the following methods can be executed in the data transmission system, or in a server or terminal device that is connected to the data transmission system. In the embodiment of the present application, the vehicle-mounted terminal device and the ground terminal device of the data transmission system are used as the execution subjects to illustrate the scheme.

[0071] Based on the structure of the above data transmission system, such as Figure 2 As shown, an embodiment of the present application provides a data transmission method, including:

[0072] S21: Generate a true random number as the first key serial number and send it to the vehicle-mounted terminal device. The ground terminal device and the vehicle-mounted terminal device are configured with the same preset key, and the key corresponding to the first key serial number in the preset key is used as the first key.

[0073] S22: Generate a random digital label encrypted by the first key and send it to the vehicle-mounted terminal device.

[0074] S23: After receiving the decryption loading feedback of the random digital tag from the vehicle-mounted terminal device, a true random number is generated as the second key serial number and sent to the vehicle-mounted terminal device, and the key corresponding to the second key serial number in the preset key is used as the second key, and the second key is used to perform encrypted communication with the vehicle-mounted terminal device.

[0075] In the embodiment of the present application, during the production process of the on-board quantum encryption device, a preset key is injected into the device through a special injection device and method based on QKD secure communication, and the device UID and device fingerprint information are obtained and uploaded to the quantum key service platform. After the on-board quantum encryption device is installed in the vehicle, it is necessary to enter the device UID number on the manual platform of the operating ground center or quantum key service for registration and activation when it is used for the first time. When the device is powered on, it will go through the wireless channel of the operating ground center to perform a handshake process and identity authentication with the quantum key service center.

[0076] In the embodiment of the present application, after the vehicle-mounted encryption device and the operating ground center complete the handshake and identity authentication, the ground center generates a random number through a quantum random number generator. Specifically, the random number will not exceed the number of vehicle-mounted pre-set keys. A key with a random number as a serial number is selected from the pre-set keys as the encryption key K1 for the business data, that is, the first key. The random number is sent wirelessly to the vehicle-mounted encryption device, and the vehicle-mounted encryption device also uses the key with the serial number in the pre-set keys as the business encryption key K1. Since the key pools of the service center and the vehicle-mounted end are the same, the keys with the same serial number at both ends are the same.

[0077] In an embodiment of the present application, the ground center generates a random digital tag through QRNG, encrypts it with the key K1, and sends it to the on-board encryption device. Optionally, the encryption algorithm can choose the symmetric encryption in the encryption engine. After the on-board encryption device decrypts the digital tag, it is placed in SRAM (Static Random-Access Memory) as a digital tag for anti-disassembly. When the device board is removed, the SRAM stops supplying power and the digital tag disappears, which is equivalent to the label being torn off. After the label is torn off, the encryption device becomes inactive and the activation process needs to be re-performed.

[0078] In an embodiment of the present application, the decryption loading feedback of step S23 includes the hash algorithm calculation value of the vehicle-mounted terminal device identity information and the random digital tag, and the vehicle-mounted terminal device identity information is verified. If the verification passes, a second key is generated and used to perform encrypted communication with the vehicle-mounted terminal device.

[0079] In this way, during the authentication process, when manual activation by the ground platform is required, the vehicle-mounted end first sends the UID and the server sends the key serial number. Both parties use the key with the same serial number as the business key. The vehicle-mounted end performs a hash algorithm on the device fingerprint and the digital tag, encrypts the hash algorithm value with the business key, and sends it to the service center. The service center uses the same business key to decrypt and obtain the vehicle-mounted encrypted device fingerprint, and compares it with the device fingerprint in the database. If they are consistent, the identity authentication is passed, which greatly improves the security and efficiency of key transmission.

[0080] The on-board encryption device responds that the digital tag has been loaded. The ground center uses the same method as above to replace the business encryption key K2, the second key, and uses symmetric encryption for encrypted communication of business data.

[0081] In an embodiment of the present application, when a key charging request is received from a vehicle-mounted terminal device, a key is wirelessly charged to the vehicle-mounted terminal device.

[0082] In this way, when the preset keys of the vehicle-mounted encryption device are insufficient, the keys are injected through a secure wireless communication method that is resistant to quantum algorithms to ensure that the vehicle-mounted encryption device has sufficient keys to use.

[0083] In an embodiment of the present application, when an abnormal situation occurs, a communication emergency mode can be activated in the operating ground center or the quantum key service, and the encryption mode is converted to a plaintext mode.

[0084] In the embodiment of the present application, the quantum key service center is responsible for the key management of all vehicles, and will also assign management authority for the keys of its vehicles to the operating ground center. The key databases of all vehicles are stored in the quantum key service center.

[0085] In an embodiment of the present application, the operation ground center and the quantum key service center conduct encrypted communication through QKD or quantum VPN gateway, and the ground operation center has the functions of emergency management, monitoring and charging of the keys of its vehicles.

[0086] In the embodiment of the present application, the ground operation center securely distributes the quantum key obtained by the quantum key service center to the quantum security gateway and the vehicle encryption device to realize the encryption and decryption functions of the data communication between the vehicle and the ground. The vehicle data needs to be encrypted by the on-board encryption device, and then the ciphertext is sent to the quantum security gateway for data decryption, and the gateway then sends the decrypted data to the ground center.

[0087] Based on the structure of the above data transmission system, such as Figure 3 As shown, an embodiment of the present application provides a data transmission method, including:

[0088] S31: receiving a first key serial number sent by the ground terminal device, the vehicle-mounted terminal device and the ground terminal device are configured with the same preset key, and taking the key corresponding to the first key serial number in the preset key as the first key.

[0089] S32: Receive a random digital label encrypted by a first key from a ground terminal device, decrypt and load the random digital label, store it in a static random access memory, and send a decryption and loading feedback to the ground terminal device.

[0090] S33: Receive the second key serial number sent by the ground terminal device, use the key corresponding to the second key serial number in the preset key as the second key, and use the second key to perform encrypted communication with the ground terminal device.

[0091] S34: The ground terminal device regenerates the first key using a random salt to obtain a second key, and updates the preset key using the second key.

[0092] In an embodiment of the present application, a hash algorithm is performed on the identity information of the vehicle-mounted terminal device and the random digital tag, and the value of the hash algorithm is encrypted with a first key and sent to the ground terminal device.

[0093] In this way, during the authentication process, when manual activation by the ground platform is required, the vehicle-mounted end first sends the UID and the server sends the key serial number. Both parties use the key with the same serial number as the business key. The vehicle-mounted end performs a hash algorithm on the device fingerprint and the digital tag, encrypts the hash algorithm value with the business key, and sends it to the service center. The service center uses the same business key to decrypt and obtain the vehicle-mounted encrypted device fingerprint, and compares it with the device fingerprint in the database. If they are consistent, the identity authentication is passed, which greatly improves the security and efficiency of key transmission.

[0094] In an embodiment of the present application, when the number of preset keys is lower than a set number, a key injection request is sent to a ground terminal device; and a key sent by the ground terminal device according to the key injection request is received.

[0095] In this way, when the preset keys of the vehicle-mounted encryption device are insufficient, the keys are injected through a secure wireless communication method that is resistant to quantum algorithms to ensure that the vehicle-mounted encryption device has sufficient keys to use.

[0096] Further, such as Figure 4As shown, an embodiment of the present application provides a data transmission device 800, including a processor (processor) 801 and a memory (memory) 802. Optionally, the device may also include a communication interface (Communication Interface) 803 and a bus 804. Among them, the processor 801, the communication interface 803, and the memory 802 can communicate with each other through the bus 804. The communication interface 803 can be used for information transmission. The processor 801 can call the logic instructions in the memory 802 to execute the data transmission method of the above embodiment.

[0097] In addition, the logic instructions in the memory 802 described above may be implemented in the form of software functional units and when sold or used as independent products, may be stored in a computer-readable storage medium.

[0098] The memory 802 is a computer-readable storage medium that can be used to store software programs and computer executable programs, such as program instructions / modules corresponding to the method in the embodiment of the present application. The processor executes the function application and data processing by running the program instructions / modules stored in the memory 802, that is, implementing the data transmission method in the above embodiment.

[0099] The memory 802 may include a program storage area and a data storage area, wherein the program storage area may store an operating system and an application required for at least one function; the data storage area may store data created according to the use of the terminal device, etc. In addition, the memory 802 may include a high-speed random access memory and may also include a non-volatile memory.

[0100] The embodiment of the present application provides a data transmission system, including: a data transmission system body, and the above-mentioned data transmission device 800. The data transmission device is installed in the data transmission system body. The installation relationship described here is not limited to placement inside the data transmission system, but also includes installation connections with other components of the data transmission system, including but not limited to physical connections, electrical connections or signal transmission connections. It can be understood by those skilled in the art that the data transmission device can be adapted to a feasible data transmission system body, thereby realizing other feasible embodiments.

[0101] An embodiment of the present application provides a computer-readable storage medium storing computer-executable instructions, wherein the computer-executable instructions are configured to execute the above-mentioned data transmission method.

[0102] The technical solution of the embodiment of the present application can be embodied in the form of a software product, which is stored in a storage medium and includes one or more instructions for a computer device (which can be a personal computer, a server, or a network device, etc.) to perform all or part of the steps of the method described in the embodiment of the present application. The aforementioned storage medium can be a non-transient storage medium, including: a USB flash drive, a mobile hard disk, a read-only memory (ROM), a random access memory (RAM), a disk or an optical disk, and other media that can store program codes.

[0103] Although the preferred embodiments of the present application have been described, those skilled in the art may make other changes and modifications to these embodiments once they have learned the basic creative concept. Therefore, the appended claims are intended to be interpreted as including the preferred embodiments and all changes and modifications falling within the scope of the present application.

[0104] Obviously, those skilled in the art can make various changes and modifications to the present application without departing from the spirit and scope of the present application. Thus, if these modifications and variations of the present application fall within the scope of the claims of the present application and their equivalents, the present application is also intended to include these modifications and variations.

Claims

1. A data transmission method, characterized in that: Applied to ground terminal equipment; the method includes: Generate a true random number as a first key serial number and send it to the vehicle-mounted terminal device, the ground terminal device and the vehicle-mounted terminal device are configured with the same pre-set key, and use the key corresponding to the first key serial number in the pre-set key as the first key; Generate a random digital label encrypted by the first key and send it to the vehicle-mounted terminal device; After receiving the decryption loading feedback of the random digital tag from the vehicle-mounted terminal device, a true random number is generated as the second key serial number and sent to the vehicle-mounted terminal device, and the key corresponding to the second key serial number in the preset key is used as the second key, and the second key is used to perform encrypted communication with the vehicle-mounted terminal device.

2. The data transmission method according to claim 1, characterized in that: After receiving the decryption loading feedback of the random digital tag by the vehicle terminal device, generating a true random number as the second key serial number and sending it to the vehicle terminal device, using the key corresponding to the second key serial number in the preset key as the second key, and using the second key to perform encrypted communication with the vehicle terminal device also includes: The decryption loading feedback includes the vehicle-mounted terminal device identity information and the hash algorithm calculation value of the random digital tag, and the vehicle-mounted terminal device identity information is verified. If the verification passes, the second key is generated and used to perform encrypted communication with the vehicle-mounted terminal device.

3. The data transmission method according to claim 1, characterized in that: Also includes: When receiving a key charging request from the vehicle-mounted terminal device, wirelessly charging the key to the vehicle-mounted terminal device.

4. A data transmission method, characterized in that: Applied to vehicle-mounted terminal equipment; the method includes: Receiving a first key serial number sent by a ground terminal device, the vehicle-mounted terminal device and the ground terminal device are configured with the same pre-set key, and using a key corresponding to the first key serial number in the pre-set key as the first key; Receiving a random digital label encrypted by the first key from a ground terminal device, decrypting and loading the random digital label, storing it in a static random access memory, and sending a decryption and loading feedback to the ground terminal device; Receive the second key serial number sent by the ground terminal device, use the key corresponding to the second key serial number in the preset key as the second key, and use the second key to perform encrypted communication with the ground terminal device.

5. The data transmission method according to claim 4, characterized in that: The step of receiving the random digital label encrypted by the first key sent by the vehicle-mounted terminal device, decrypting the random digital label and loading it, and sending decryption and loading feedback to the ground terminal device also includes: A hash algorithm is performed on the identity information of the vehicle-mounted terminal device and the random digital tag, and the value of the hash algorithm is encrypted by the first key and sent to the ground terminal device.

6. The data transmission method according to claim 4, characterized in that: Also includes: When the number of the preset keys is less than a set number, sending a key filling request to the ground terminal device; Receive the key sent by the ground terminal device according to the key injection request.

7. A data transmission device, comprising a processor and a memory storing program instructions, characterized in that: The processor is configured to execute the data transmission method according to any one of claims 1 to 6 when running the program instructions.

8. A data transmission system, characterized in that: include: Ground terminal equipment, including ground data center, quantum key management platform, and communication encryption module; a vehicle-mounted terminal device, which is in communication connection with the ground terminal device; and The data transmission device as described in claim 7 is installed in the ground terminal equipment and the vehicle-mounted terminal equipment.

9. The data transmission system according to claim 8, characterized in that: Also includes: A quantum key service center stores the identity information of a vehicle-mounted terminal device, is communicatively connected with the ground terminal device, and is used to verify the identity information of the vehicle-mounted terminal device received by the ground terminal device according to a request sent by the ground terminal device; and stores a key, which is used to inject a key into the vehicle-mounted terminal device through the ground terminal device according to a request sent by the ground terminal device.

10. The data transmission system according to claim 9, characterized in that: Also includes: The quantum encryption device production terminal is connected to the quantum key service center for producing keys and sending keys to the quantum key service center according to a request received from the quantum key service center.

Citation Information

Patent Citations

  • Handshaking method for network safety, apparatus for initiating and responding handshake

    CN101409882A

  • WLAN (Wireless Local Area Network) access control system and method based on multi-password identity authentication

    CN109561431A

  • Asymmetric cryptographic terminal based on quantum random number, communication system and method

    CN110611572A

  • Data transmission method and related device

    CN111541716A

  • Data transmission encryption method and device, electronic equipment and storage medium

    CN114338005A

Cited By

  • Rail transit quantum communication system data transmission method, device, system and medium

    CN120785532A