Quantum security near field communication system and method

By introducing quantum-safe hash function and dynamic identity authentication into the near-field communication system, combined with the terminal's control area settings, the problem of information security risks in near-field communication technology is solved, and higher information security and operation request correlation are achieved.

CN119996980APending Publication Date: 2025-05-13MATRICTIME DIGITAL TECH CO LTD
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202510131257.9
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-02-06
Publication Date
2025-05-13

AI Technical Summary

Technical Problem

Near-field communication technology has information security risks in practical applications and is easily cracked and forged, resulting in malicious attacks such as cloning attacks, man-in-the-middle attacks and packet loss attacks.

Method used

A quantum-safe near-field communication system is adopted to ensure the randomness of each operation request through a hash function, use dynamic one-time identity information for identity authentication, and set up a control area on the terminal to avoid misoperation.

Benefits of technology

It increases the relevance of operation requests, reduces the possibility of bad users forgery operation requests, ensures the legality and effectiveness of each identity authentication of the terminal, and improves information security.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN119996980A_ABST
    Figure CN119996980A_ABST
Patent Text Reader

Abstract

The invention discloses a near field communication system and method for quantum security. The system comprises a terminal set, an authentication end, an identity issuing center and a key center, the terminal set is respectively connected with the authentication end, the identity issuing center and the key center, and the authentication end is respectively connected with the identity issuing center and the key center; wherein the terminal set comprises a plurality of terminals, and the connection between the terminal set and other equipment is that each terminal in the terminal set is connected with other equipment. According to the invention, the terminal selects the input random number of the Hash function from any position in the Hash key file in the Hash key pool to ensure that the Hash function involved in each operation request satisfies randomness; meanwhile, each time of identity authentication initiated by the terminal to the authentication end is different one-time identity information obtained through Hash calculation, the identity is dynamic, and it is ensured that each time of identity authentication performed by the terminal is legal and effective.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present application relates to the field of secure communication technology, and in particular to a quantum secure near-field communication system and method. Background Art

[0002] Near Field Communication (NFC) is a short-range high-frequency radio technology that operates at a frequency of 13.56MHz within a distance of 20cm. It is an integration of contactless radio frequency identification (RFID) and interconnection technology, providing a very safe and fast communication method for various electronic products. Therefore, it has been increasingly used in payment, electronic ticketing, access control, mobile identity recognition, anti-counterfeiting and other business fields.

[0003] Near field communication technology is easy to use, but there are certain security issues in the actual application process. Since there is no password or a fixed password is set, and it is completely exposed to the wireless environment, it will face malicious attacks such as cloning attacks, man-in-the-middle attacks, and packet loss attacks. This will cause information security risks in the application of near field communication technology and is easy to be cracked and forged. For example, for access cards, attackers can easily copy the card and obtain a copy of the access card with the same permissions as the legitimate access card. The attacker can use the copy to steal. For example, for payment, criminals use the NFC function in the victim's mobile phone to place the malicious chip close to the victim's mobile phone, thereby remotely controlling the victim's mobile phone payment system, transferring money, and realizing "remote theft".

[0004] It can be seen that while near-field communication technology brings convenience to people's lives, it also brings many information security threats. In view of this, how to ensure information security in near-field communication scenarios is a technical issue that the industry is currently paying attention to. Summary of the invention

[0005] Purpose of the invention: To solve the related technical problems raised in the background technology, the present invention provides a quantum secure near-field communication system and method, which ensures that the hash function involved in each operation request satisfies randomness, and the hash key file selected next time is based on the key file integrated after the input random number was taken out last time, so that each operation behavior of the terminal is related; each time the identity authentication initiated by the terminal to the authentication end is different one-time identity information obtained by hash calculation, which is a dynamic identity, ensuring that each identity authentication performed by the terminal is legal and valid.

[0006] Technical solution: The present invention provides a quantum secure near-field communication system, which includes a terminal set, an authentication terminal, an identity issuance center, and a key center; the terminal set is connected to the authentication terminal, the identity issuance center, and the key center respectively, and the authentication terminal is connected to the identity issuance center and the key center respectively; wherein the terminal set includes a plurality of terminals, and the connection between the terminal set and other devices is that each terminal in the terminal set is connected to other devices;

[0007] Each terminal in the terminal set is used to obtain a terminal identity from an identity issuance center and communicate with an authentication terminal based on the terminal identity;

[0008] The authentication terminal is used to obtain the authentication terminal identity from the identity issuance center, and to perform identity authentication on any terminal in the terminal set, and to perform subsequent corresponding operations based on the identity authentication result;

[0009] The identity issuance center is used to generate and issue identities for each terminal and authentication terminal in the terminal set;

[0010] The key center is used to generate and issue keys to each terminal and authentication terminal in the terminal set.

[0011] The present invention also includes a quantum secure near-field communication method, comprising the following steps:

[0012] (1) The identity issuance center issues a quantum-secure identity certificate ID-2 to the authentication end, and issues a quantum-secure identity certificate ID-11 to the terminal in the terminal set;

[0013] (2) The key center issues symmetric encryption and decryption key files to the authentication end and the terminal in the terminal set respectively. The authentication end stores the encryption and decryption key files in the second encryption and decryption key pool, and the terminal stores the encryption and decryption key files in the first encryption and decryption key pool;

[0014] (3) The authentication end sends a hash key file to the terminal in the terminal set;

[0015] (4) A terminal in the terminal set initiates an operation request to the authenticator, and the authenticator authenticates the identity of the terminal based on the operation request;

[0016] (5) The response unit of the authentication end performs subsequent corresponding operations based on the identity authentication result of the terminal.

[0017] Beneficial effects of the present invention:

[0018] (1) The hash key file in the terminal is issued by the authentication end. No third party knows the hash key file. The terminal selects the input random number of the hash function from any position in the hash key file in the hash key pool to ensure that the hash function involved in each operation request satisfies the randomness. The hash key file selected next time is based on the key file obtained by integrating the input random number taken out last time. Each operation request is related to the previous operation request, so that each operation behavior of the terminal is related, which increases the possibility of bad users forging one of the operation requests.

[0019] (2) A control area is set on the terminal to control whether the terminal is in an open state. The terminal must simultaneously meet the two conditions that the switch unit is in an open state and is within the near-field communication distance of the authentication terminal before it can send an operation request, thereby avoiding the possibility of misoperation.

[0020] (3) Each time the terminal initiates identity authentication to the authentication end, different one-time identity information is obtained through hash calculation. It is a dynamic identity. A bad user can only obtain a static identity by copying the card and cannot pass the identity authentication of the authentication end. This ensures that each identity authentication performed by the terminal is legal and valid. BRIEF DESCRIPTION OF THE DRAWINGS

[0021] In order to more clearly illustrate the technical solutions in the embodiments of the present application, the drawings required for use in the description of the embodiments will be briefly introduced below. Obviously, the drawings described below are only some embodiments of the present application. For ordinary technicians in this field, other drawings can be obtained based on these drawings without paying creative labor.

[0022] Figure 1 A schematic diagram of the connection of the near field communication system of the present invention;

[0023] Figure 2 This is a schematic diagram of the structure of the first terminal in Embodiment 1 of the present invention;

[0024] Figure 3 It is a schematic diagram of the structure of the authentication terminal of the present invention;

[0025] Figure 4 It is a schematic diagram of the near field communication method flow of the present invention;

[0026] Figure 5 A schematic diagram of the hash key file processing process of the present invention;

[0027] Figure 6 This is a schematic diagram of the first terminal structure in Example 2 of the present invention. DETAILED DESCRIPTION

[0028] In order to make the purpose, technical solutions and advantages of the present application clearer, the present application will be further described in detail below in conjunction with the accompanying drawings. Obviously, the described embodiments are only part of the embodiments of the present application, rather than all the embodiments. Based on the embodiments in the present application, all other embodiments obtained by ordinary technicians in this field without making creative work are within the scope of protection of the present application.

[0029] As described in the background technology, in view of the current NFC scenario, where information security is threatened by cards with near field communication functions being copied or mobile phones being stolen, there is an urgent need to propose a communication method that can ensure information security in near field communication scenarios.

[0030] Example 1

[0031] In view of this, the present application proposes a quantum secure near-field communication system, such as Figure 1 shown.

[0032] The near field communication system includes a terminal set 1, an authentication terminal 2, an identity issuance center 3 and a key center 4; wherein the terminal set 1 includes a plurality of terminals, denoted as a first terminal 11, a second terminal 12, ..., an Nth terminal 1n, each of which is held by a user. The terminal set 1 is respectively connected to the authentication terminal 2, the identity issuance center 3 and the key center 4, and the authentication terminal 2 is respectively connected to the identity issuance center 3 and the key center 4; in actual applications, the connection between the terminal set 1 and other devices is that each terminal in the terminal set 1 is respectively connected to other devices.

[0033] Each terminal in the terminal set 1 is held by a user. Each terminal is used to obtain the terminal identity from the identity issuance center 3 and communicate with the authentication terminal 2 based on the terminal identity. The terminal can be, for example, an access card, a mobile phone or other device; the authentication terminal 2 is used to obtain the authentication terminal identity from the identity issuance center 3, and configure the identity authentication of any terminal in the terminal set 1, and perform subsequent corresponding operations based on the identity authentication result. For example, the authentication terminal 2 can be an access control system, a POS machine, etc., and the corresponding operations can be opening the door, keeping the door locked, paying, payment failure, etc.; the identity issuance center 3 is used to generate and issue identities for each terminal and authentication terminal 2 in the terminal set 1; the key center 4 is used to generate and issue keys for each terminal and authentication terminal 2 in the terminal set 1.

[0034] In this system, each terminal in the terminal set 1 has the same structure. Figure 2 Taking the first terminal 11 as an example, the structure of the terminal is described.

[0035] like Figure 2As shown, the first terminal 11 in the terminal set 1 includes a first near field communication unit 111, a first encryption and decryption unit 112, a first encryption and decryption key pool 113, a hash key pool 114, a terminal identity storage unit 115, a hash calculation unit 116 and a request unit 117; the first near field communication unit 111 is respectively connected to the first encryption and decryption unit 112, the first encryption and decryption key pool 113 and the request unit 117, the first encryption and decryption unit 112 is respectively connected to the first encryption and decryption key pool 113, the hash key pool 114, the terminal identity storage unit 115 and the hash calculation unit 116, the hash key pool 114 is connected to the hash calculation unit 116, and the hash calculation unit 116 is also respectively connected to the terminal identity storage unit 115 and the request unit 117;

[0036] The first near-field communication unit 111 is a connection unit between the terminal and other devices, and is used to establish a communication connection between the terminal and other devices; the first encryption and decryption unit 112 is pre-installed with an encryption algorithm and a decryption algorithm, which is used to perform encryption or decryption operations using the encryption and decryption algorithms, such as a one-time XOR algorithm, which is used to perform encryption or decryption operations using the encryption and decryption algorithms; the first encryption and decryption key pool 113 stores a first encryption and decryption key file, which is used to provide an encryption key or a decryption key for the first encryption and decryption unit 112, and the first encryption and decryption key file comes from the key center 4; the hash key pool 114 stores a first hash key file, which is used to provide the hash calculation unit 116 with a random number or key required for the hash calculation process, and the first hash key file comes from the authentication end 2; the terminal identity storage unit 115 is used to store the terminal identity obtained by the terminal from the identity issuance center 3; the hash calculation unit 116 has a built-in hash algorithm for performing hash calculations; the request unit 117 is used to generate an operation request initiated to the authentication end 2.

[0037] In this system, the structure of the authentication terminal 2 is as follows Figure 3 shown.

[0038] The authentication end 2 includes a second near-field communication unit 21, a second encryption and decryption unit 22, a second encryption and decryption key pool 23, a key pool set 24, a key unit 25, an authentication unit 26, a response unit 27 and a registration unit 28; wherein the key pool set 24 includes multiple key pools, for example, a first key pool 241, a second key pool 242, ..., an Nth key pool 24n, the first key pool 241 corresponds to a hash key pool in one terminal, the second key pool 242 corresponds to a hash key pool in another terminal, and so on, each key pool corresponds to a hash key pool in a terminal. The second near field communication unit 21 is connected to the second encryption and decryption key pool 23 and the second encryption and decryption unit 22 respectively, the second encryption and decryption unit 22 is connected to the second encryption and decryption key pool 23, the key pool set 24, the authentication unit 26 and the registration unit 28 respectively, the authentication unit 26 is connected to the registration unit 28, the key pool set 24 and the response unit 27 respectively, the response unit 27 is connected to the key unit 25, the key unit 25 is also connected to the key pool set 24, and the key unit 25 includes a random number generator 251 and a key distribution module 252 connected in sequence;

[0039] The second near-field communication unit 21 is a connection unit between the authentication terminal 2 and other devices, and is used to establish a communication connection between the authentication terminal 2 and other devices; the second encryption and decryption unit 22 is pre-set with a decryption algorithm and an encryption algorithm corresponding to the first encryption and decryption unit 112, and is used to perform encryption or decryption operations using the encryption and decryption algorithms, such as a one-time XOR algorithm, and is used to perform encryption or decryption operations using the encryption and decryption algorithms; the second encryption and decryption key pool 23 stores a second encryption and decryption key file corresponding to the first encryption and decryption key file in the first encryption and decryption key pool 113, and is used to provide an encryption key or a decryption key for the second encryption and decryption unit 22, and the second encryption and decryption key file comes from the key center 4; the key pool set 24 includes a plurality of key pools, each of which stores a second hash key file corresponding to the first hash key file stored in the hash key pool in the corresponding terminal, and the second hash key file comes from the key unit 25, and each key pool sends the second hash key file to the corresponding terminal, such as the first key pool 24 1 sends the second hash key file stored locally to its corresponding terminal, and the hash key pool in the terminal stores the received hash key file, which is recorded as the first hash key file. Therefore, the first hash key file corresponds to the second hash key file, and so on; the key unit 25 is used to generate and distribute the hash key file to each key pool in the key pool set, wherein the random number generator 251 is a quantum random number generator, which is used to generate multiple quantum keys and send the multiple quantum keys to the key distribution module 252; the key distribution module 252 is used to form multiple hash key files with the received multiple quantum keys, and distribute the multiple hash key files to each key pool in the key pool set 24; the authentication unit 26 is used to authenticate the identity legitimacy of any terminal in the terminal set 1; the response unit 27 generates corresponding instructions based on the identity authentication result of the authentication unit 26; the registration unit 28 is used to store the terminal registration record in the terminal set 1 for the authentication terminal 2 to call and query during the working process.

[0040] The authentication terminal 2 may further include a log unit, which may be connected to the response unit 27 and is used to record the authentication record of the authentication terminal 2 for reference.

[0041] Based on the above-mentioned near-field communication system, the present application also proposes a quantum-safe near-field communication method. In this embodiment, the communication between the first terminal 11 in the terminal set 1 and the authentication terminal 2 is taken as an example to illustrate the near-field communication method proposed in the present application. Figure 4 As shown, the method comprises the following steps:

[0042] (1) The identity issuance center 3 issues a quantum-secure identity certificate ID-2 to the authentication terminal 2, and issues a quantum-secure identity certificate ID-11 to the first terminal 11 in the terminal set 1;

[0043] The specific process of the identity issuance center 3 issuing a quantum-secure identity certificate ID-2 to the authentication terminal 2 is as follows: the identity issuance center 3 obtains the device number devNo-2 of the authentication terminal 2, generates the quantum-secure identity certificate ID-2 of the authentication terminal 2 based on the device number devNo-2, and distributes the identity certificate ID-2 to the authentication unit 26 in the authentication terminal 2 for storage; wherein, generating the quantum-secure identity certificate ID-2 of the authentication terminal 2 means: the identity issuance center 3 continuously obtains a set of random numbers from the local until an irreducible polynomial p1(x) is generated based on the set of random numbers, and the coefficients of the irreducible polynomial p1(x) are denoted as str1; and then obtains another set of random numbers u1 from the local as the input random numbers of the hash function, and generates the hash function h based on the irreducible polynomial p1(x) and the input random numbers u1. p1,u1 , using the hash function h p1,u1 Calculate the hash value of device number devNo-2 to get the hash value H-2=h p1,u1 (devNo-2), using the hash value H-2 as the quantum-secure identity certificate of the authentication end 2;

[0044] The specific process of issuing a quantum-secure identity certificate ID-11 to the first terminal 11 in the terminal set 1 is as follows: the identity issuance center 3 obtains the device number devNo-11 of the first terminal 11, associates the device number devNo-11 with the identity certificate ID-2 of the authentication terminal 2, and generates the quantum-secure identity certificate ID-11 of the first terminal 11 based on the associated device number devNo-11 and the identity certificate ID-2; wherein, generating the quantum-secure identity certificate ID-11 of the first terminal 11 means that the identity issuance center 3 continuously obtains a set of random numbers from the local until an irreducible polynomial p2(x) is generated based on the set of random numbers, and the coefficients of the irreducible polynomial p2(x) are denoted as str2; and then obtains another set of random numbers u2 from the local as input random numbers of the hash function, and generates the hash function h based on the irreducible polynomial p2(x) and the input random numbers u2. p2,u2 , using the hash function h p2,u2 Calculate the hash value of the associated device number devNo-11 and the identity certificate ID-2 to obtain the hash value H-11 = h p2,u2 (devNo-11, ID-2), use the hash value H-11 as the quantum secure identity certificate ID-11 of the first terminal 11, and send the identity certificate ID-11 to the terminal identity storage unit 115 in the first terminal 11 for storage; at the same time, the identity issuance center 3 stores the device number devNo-11 of the first terminal 11 in corresponding association with the identity certificate ID-11, the coefficient str2, and the input random number u2.

[0045] (2) The key center 4 issues symmetric encryption and decryption key files to the authentication terminal 2 and the first terminal 11 in the terminal set 1 respectively. The authentication terminal 2 stores the encryption and decryption key files in the second encryption and decryption key pool 23, and the first terminal 11 stores the encryption and decryption key files in the first encryption and decryption key pool 113;

[0046] It can be seen that the encryption and decryption key files in the first encryption and decryption key pool 113 of the first terminal 11 and the encryption and decryption key files in the second encryption and decryption key pool 23 of the authentication terminal 2 are symmetrical.

[0047] (3) The authentication terminal 2 sends a hash key file to the first terminal 11 in the terminal set 1;

[0048] 1) When the first terminal 11 in the terminal set 1 conducts near-field communication with the authentication end 2 for the first time, it generates a registration application req and encrypts it and sends it to the authentication end 2, that is, it initiates a registration application req to the authentication end 2; wherein, the registration application req includes the identity certificate ID-11 and device number devNo-11 of the first terminal 11; the registration application req can be generated by the first near-field communication unit 111 of the first terminal 11.

[0049] The determination of performing near field communication for the first time may be that the authentication end 2 does not find the registration identity information corresponding to the first terminal 11 in the registration unit 28 .

[0050] The first terminal 11 generates a registration application req and encrypts it and sends it to the authentication terminal 2, which means that: the first encryption and decryption unit 112 of the first terminal 11 obtains the first encryption key K1 from the first encryption and decryption key pool 113 of the first terminal 11, uses the first encryption key K1 to encrypt the registration application req to obtain the ciphertext REQ=req⊕K1, and records the location information addk1 of the first encryption key K1 in the encryption and decryption key file of the first encryption and decryption key pool 113, and sends the location information addk1 and the ciphertext REQ to the authentication terminal 2 via the first near field communication unit 111 of the first terminal 11.

[0051] 2) When the second near-field communication unit 21 of the authentication terminal 2 detects that the distance between the authentication terminal 1 and the first terminal 11 meets the near-field communication condition, the second near-field communication unit 21 instructs the second encryption and decryption unit 22 of the authentication terminal 2 to decrypt the encrypted registration application req and send it to the registration unit 28 of the authentication terminal 2. The registration unit 28 receives the registration application req and calls the authentication unit 26 of the authentication terminal 2 to perform identity authentication based on the identity certificate ID-11 in the received registration request req. The specific process is as follows:

[0052] A: When the second near-field communication unit 21 of the authentication terminal 2 detects that the distance between the authentication terminal 2 and the first terminal 11 meets the near-field communication condition, the second near-field communication unit 21 sends the location information addk1 and the ciphertext REQ to the second encryption and decryption unit 22; after receiving the location information addk1 and the ciphertext REQ, the second encryption and decryption unit 22 obtains the first decryption key K1′ from the encryption and decryption key file in the second encryption and decryption key pool 23 of the authentication terminal 2 based on the location information addk1, decrypts the ciphertext REQ using the first decryption key K1′, obtains the registration application req′, extracts the identity certificate ID-11′ and the device number devNo-11′ of the first terminal 11 from the decrypted registration application req′, and sends the decrypted registration application req′ to the registration unit 28;

[0053] B: The registration unit 28 initiates an instruction to the authentication unit 26 to authenticate the first terminal 11 based on the registration application req′; the authentication unit 26 obtains the identity certificate ID-11′ and the device number devNo-11′ from the second encryption and decryption unit 22 based on the instruction, obtains the coefficient str2 and the input random number u2 from the identity issuance center 3 based on the device number devNo-11′, generates an irreducible polynomial p2(x) based on the coefficient str2, and generates a hash function h′ using the irreducible polynomial p2(x) and the input random number u2 p2,u2 , using the hash function h′ p2,u2 Calculate the hash value of the file consisting of the device number devNo-11′ and the local identity certificate ID-2 to obtain the hash value H=h ′ p2,u2 (devNo-11 ′ ,ID-2);

[0054] C: The authentication unit 26 compares the calculated hash value H and the decrypted identity certificate ID-11′ to see if they are consistent. If they are consistent, the identity authentication is successful. The registration unit 28 records the information of the successful registration of the first terminal 11, and stores the device number devNo-11′ and the identity certificate ID-11′ of the first terminal 11 in a corresponding manner. If they are inconsistent, the identity authentication fails, and the registration unit 28 rejects the registration request req of the first terminal 11. The first terminal 11 needs to re-initiate a new round of registration request subsequently.

[0055] 3) After the identity authentication is passed, the authentication unit 26 sends the result of the identity authentication to the response unit 27 of the authentication terminal 2. The response unit 27 sends an instruction I to generate a key file to the key unit 25 of the authentication terminal 2 based on the result. The random number generator 251 in the key unit 25 responds to the instruction I, generates multiple groups of random numbers to form the key file file, and sends the key file file to the key distribution module 252 in the key unit 25 for distribution;

[0056] 4) The key distribution module 252 selects a set of empty key pools from the key pool set 24 of the authentication terminal 2. For example, the empty key pool may be the first key pool 241. The key distribution module 252 sends the key file file to the empty key pool, i.e., the first key pool 241, and associates the empty key pool with the device number devNo-11′ of the first terminal 11. The empty key pool synchronizes the key file file in an encrypted form to the hash key pool in the first terminal 11.

[0057] The specific process of synchronizing the key file file in encrypted form to the hash key pool in the first terminal 11 by the empty key pool is as follows: the empty key pool takes the first key pool 241 as an example, and the empty key pool, i.e., the first key pool 241, sends the key file file to the second encryption and decryption unit 22, and the second encryption and decryption unit 22 obtains the second encryption key K2 from the second encryption and decryption key pool 23 of the authentication terminal 2, and uses the second encryption key K2 to encrypt the key file file, and obtains the ciphertext FILE=file⊕K2, and records the location information addk2 of the encryption and decryption key file of the second encryption key K2 in the second encryption and decryption key pool 23, and sends the location information addk2 and the ciphertext FILE to the first terminal 11 via the second near field communication unit 21;

[0058] If the authentication end 2 needs to supplement the key file for the first terminal 11 subsequently, the new key file will also be distributed to the first key pool 241 .

[0059] It is understandable that when other terminals (such as the second terminal 12) also initiate a registration request to the authentication terminal 2, the key distribution module 252 needs to select an empty key pool (such as the second key pool 242) from other key pools except the first key pool 241 as the key pool corresponding to the second terminal 12.

[0060] Here, the number of n key pools in the key pool set 24 is consistent with the number of terminals in the terminal set 1 in the present system, and a one-to-one correspondence is established. In practical applications, the n key pools can be n physical storage modules, or one large physical storage module, and the corresponding logical storage size is divided from the large physical storage module according to the size of the key file file generated each time, forming n logical storage modules.

[0061] The first encryption and decryption unit 112 of the first terminal 11 receives the location information addk2 and the ciphertext FILE via the first near field communication unit 111 of the first terminal 11, obtains the second decryption key K2′ from the encryption and decryption key file in the first encryption and decryption key pool 113 of the first terminal 11 based on the location information addk2, uses the second decryption key K2′ to decrypt the ciphertext FILE to obtain the key file file′, and the first encryption and decryption unit 112 sends the key file file′ to the hash key pool 114 for storage. The key file file′ is the hash key file.

[0062] (4) The first terminal 11 in the terminal set 1 initiates an operation request to the authentication terminal 2. The authentication terminal 2 authenticates the identity of the first terminal 11 based on the operation request. The specific steps are as follows:

[0063] S1: When the first near field communication unit 111 of the first terminal 11 detects that the distance between the first terminal 11 and the authentication terminal 2 meets the near field communication distance condition, the first terminal 11 initiates a start instruction to the request unit 117 of the first terminal 11;

[0064] S2: The request unit 117 calls the hash calculation unit 116 of the first terminal 11 based on the start instruction to generate an operation request req2; then sends the operation request req2 to the first encryption and decryption unit 112 of the first terminal 11 for encryption, and then sends it to the authentication terminal 2 through the first near field communication unit 111 of the first terminal 11;

[0065] Specifically, the request unit 117 generates a serial number NO for this request and sends it to the hash calculation unit 116. In response to receiving the serial number NO, the hash calculation unit 116 generates an irreducible polynomial p3(x) locally, and the coefficient of the irreducible polynomial p3(x) is recorded as str3. Then, the key u3 is selected from the first hash key file in the hash key pool 114 of the first terminal 11 as the input random number, and the starting position add and length l of the key u3 are recorded. The starting position add is arbitrarily determined. It is only necessary to select a section of the key u3 from the starting position add as the input random number, and record the starting position add and length l. The process used here is as follows: Figure 5 The hash calculation unit 116 then generates a hash function h based on the irreducible polynomial p3(x) and the input random number u3. p3,u3 , and obtain the identity certificate ID-11 and the device number devNo-11 of the first terminal 11 from the terminal identity storage unit 115 of the first terminal 11; the hash calculation unit 116 uses the hash function h p3,u3 Calculate the hash value of serial number NO, identity certificate ID-11, and device number devNo-11 to get the hash value H3=h p3,u3(NO, ID-11, devNo-11), the serial number NO, the device number devNo-11, the starting position add and length l of the key u3, the hash value H3, and the coefficient str3 together constitute the operation request req2 = (NO, devNo-11, add, l, H3, str3); at the same time, the first hash key file where the key u3 is located in the hash key pool 114 of the first terminal 11 deletes the key u3, and integrates the remaining keys of the first hash key file to form a new first hash key file for subsequent key acquisition, such as Figure 5 As shown, after removing the key u3 from the first hash key file, the hash key pool 114 integrates the file part1 before the key u3 and the file part2 after the key u3 into a new first hash key file. When the key is retrieved again in the future, the key is retrieved by using the above-mentioned arbitrary method of determining the starting position, so as to achieve a completely random key effect.

[0066] It can be seen that the hash key file in the terminal is issued by the authentication terminal 2, and no third party knows the hash key file. The terminal ensures that the hash function involved in each operation request satisfies the randomness by selecting the input random number of the hash function from any position in the hash key file in the hash key pool. The hash key file selected next time is based on the key file integrated after the input random number was taken out last time. Each operation request is related to the previous operation request, so that each operation behavior of the terminal is related, which increases the possibility of bad users forging one of the operation requests.

[0067] Then, the hash calculation unit 116 sends the operation request req2 to the first encryption and decryption unit 112, the first encryption and decryption unit 112 obtains the third encryption key K3 from the first encryption and decryption key pool 113 of the first terminal 11 and records the location information addk3 of the third encryption key K3, encrypts the operation request req2 using the third encryption key K3 to obtain the ciphertext REQ2=req2⊕K3, and sends the ciphertext REQ2 and the location information addk3 to the authentication terminal 2 via the first near field communication unit 111;

[0068] S3: The second near field communication unit 21 of the authentication end 2 receives and forwards the received operation request to the second encryption and decryption unit 22 of the authentication end 2. The second encryption and decryption unit 22 decrypts the operation request to obtain the decrypted operation request req2′, and then sends the operation request req2′ to the authentication unit 26 of the authentication end 2. The authentication unit 26 authenticates the identity of the first terminal 11 based on the operation request req2′.

[0069] Specifically, the second near field communication unit 21 of the authentication end 2 receives the ciphertext REQ2 and the location information addk3 and then forwards them to the second encryption and decryption unit 22. The second encryption and decryption unit 22 obtains the third decryption key K3′ from the second encryption and decryption key pool 23 of the authentication end 2 based on the location information addk3, and then performs a decryption operation on the ciphertext REQ2, and sends the decrypted operation request req2′=(NO ′ ,devNo-11 ″ ,add ′ ,l ′ ,H3 ′ ,str3′) is sent to the authentication unit 26;

[0070] The authentication unit 26 generates an irreducible polynomial p3′(x) based on the coefficient str3′, and searches for the key pool associated with the device number devNo-11″ in the key pool set 24 of the authentication end 2 based on the device number devNo-11″ of the first terminal 11 obtained after decryption, that is, the first key pool 241, and then adds the first key pool 241 to the key pool 241 according to the starting position add′ and l ′ The input random number u3′ is obtained from the second hash key file of the key pool, and the authentication unit 26 generates a hash function h′ based on the irreducible polynomial p3′(x) and the random number u3′. p3,u3 ;

[0071] The authentication unit 26 obtains the identity certificate ID-11′ stored by the first terminal 11 during registration from the registration unit 28 of the authentication terminal 2 based on the device number devNo-11″ of the first terminal 11 obtained after decryption, and then uses the generated hash function h′ p3,u3 Calculate NO ′ , ID-11′, devNo-11″ hash value to get hash value H3 ″ =h ′ p3,u3 (NO′,ID-11′,devNo-11″);

[0072] The authentication unit 26 compares the calculated hash value H3 ″ and the hash value H3 obtained from the decrypted operation request req2′ ′ Are they consistent? If they are consistent, the identity authentication of the first terminal 11 is passed, and the authentication unit 26 sends the identity authentication pass result to the response unit 27 of the authentication terminal 2, and the response unit 27 generates a work instruction based on the result; if they are inconsistent, the identity authentication of the first terminal 11 is failed, and the authentication unit 26 sends the identity authentication fail result to the response unit 27 of the authentication terminal 2, and the response unit 27 generates an error instruction based on the result.

[0073] (5) The response unit 27 of the authentication terminal 2 performs subsequent corresponding operations based on the instructions generated by the identity authentication result of the first terminal 11. If the response unit 27 generates a work instruction, operations such as opening the door can be performed. If the response unit 27 generates an error instruction, the door can continue to be locked.

[0074] It can be seen that each time the identity authentication initiated by the terminal of the present invention to the authentication terminal 2 is performed, different one-time identity information is obtained through hash calculation, which is a dynamic identity. A bad user can only obtain a static identity by copying the card and cannot pass the identity authentication of the authentication terminal, ensuring that each identity authentication performed by the terminal is legal and valid.

[0075] Example 2

[0076] like Figure 6 As shown, this embodiment is basically the same as the embodiment 1, except that: in this embodiment, the structure of the first terminal 11 in the embodiment 1 can be configured as a communication area, and the first terminal 11 in the embodiment 2 further includes a control area, that is, the first terminal 11 further includes a switch unit 121, a biometric information recognition unit 122 and a biometric information storage unit 123 connected in sequence, wherein the switch unit 121 is also connected to the request unit 117;

[0077] The switch unit 121 is used to execute an open or closed state according to the biometric information recognition result; the biometric information recognition unit 122 is an input unit and comparison unit of the biometric information (for example, fingerprint) of the user to which the first terminal 11 belongs, and is used to enter the biometric information of the user to which the terminal belongs when it is used for the first time, and transmit the biometric information to the biometric information storage unit 123 for storage; and is used to compare whether the biometric information subsequently entered by the user is consistent with the locally stored biometric information obtained from the biometric information storage unit 123, and feed back the compared biometric information recognition result to the switch unit 121; the biometric information storage unit 123 is used to store the biometric information of the user to which the first terminal 11 belongs.

[0078] The near field communication method in which the first terminal 11 participates in the second embodiment further includes:

[0079] When the first terminal 11 is used for the first time, the biometric information recognition unit 122 records the biometric information (eg, fingerprint) of the user of the first terminal 11 and transmits the biometric information to the biometric information storage unit 123 for storage. This step can be performed before step (4) in Embodiment 1.

[0080] In view of the fact that the first terminal 11 has a newly added control area, step S1 in embodiment 1 includes:

[0081] When the first near field communication unit 111 of the first terminal 11 detects that the distance between the first terminal 11 and the authentication terminal 2 meets the near field communication distance condition, it sends a start instruction to the request unit 117 of the first terminal 11;

[0082] The biometric information recognition unit 122 of the first terminal 11 compares the biometric information input by the user at this time with the locally stored biometric information obtained from the biometric information storage unit 123 to see if they are consistent. If the comparison is consistent, the switch unit 121 is fed back that the biometric information comparison is successful, and the switch unit 121 configures the state to the open state based on the feedback of the successful comparison; if the comparison is inconsistent, the switch unit 121 is fed back that the biometric information comparison fails, and the switch unit 121 is configured to the closed state based on the feedback of the failed comparison;

[0083] When the request unit 117 receives the start instruction and detects that the switch unit 121 is in an open state, it executes the next step; otherwise, it does not execute the near field communication with the authentication end.

[0084] The present invention sets a control area on the terminal to control whether the terminal is in an open state. The terminal needs to simultaneously meet the two conditions that the switch unit is in an open state and is within the near field communication distance of the authentication terminal before sending an operation request, thereby avoiding the possibility of misoperation.

Claims

1. A quantum-secure near-field communication system, characterized in that: The system includes a terminal set, an authentication terminal, an identity issuance center and a key center; the terminal set is connected to the authentication terminal, the identity issuance center and the key center respectively, and the authentication terminal is connected to the identity issuance center and the key center respectively; wherein the terminal set includes a plurality of terminals, and the connection between the terminal set and other devices is that each terminal in the terminal set is connected to other devices; Each terminal in the terminal set is used to obtain a terminal identity from an identity issuance center and communicate with an authentication terminal based on the terminal identity; The authentication terminal is used to obtain the authentication terminal identity from the identity issuance center, and to perform identity authentication on any terminal in the terminal set, and to perform subsequent corresponding operations based on the identity authentication result; The identity issuance center is used to generate and issue identities for each terminal and authentication terminal in the terminal set; The key center is used to generate and issue keys to each terminal and authentication terminal in the terminal set.

2. A quantum secure near-field communication system according to claim 1, characterized in that: Each terminal in the terminal set has the same structure, and the terminal includes a first near field communication unit, a first encryption and decryption unit, a first encryption and decryption key pool, a hash key pool, a terminal identity storage unit, a hash calculation unit and a request unit; the first near field communication unit is respectively connected to the first encryption and decryption unit, the first encryption and decryption key pool and the request unit, the first encryption and decryption unit is respectively connected to the first encryption and decryption key pool, the hash key pool, the terminal identity storage unit and the hash calculation unit, the hash key pool is connected to the hash calculation unit, and the hash calculation unit is also respectively connected to the terminal identity storage unit and the request unit; The first near field communication unit is used for the terminal to establish a communication connection with other devices; The first encryption and decryption unit is pre-installed with an encryption algorithm and a decryption algorithm, which is used to perform encryption or decryption operations using the encryption and decryption algorithms; The first encryption and decryption key pool stores a first encryption and decryption key file, which is used to provide an encryption key or a decryption key for the first encryption and decryption unit, and the first encryption and decryption key file comes from a key center; The hash key pool stores a first hash key file, which is used to provide the hash calculation unit with a random number or key required for the hash calculation process, and the first hash key file comes from the authentication end; The terminal identity storage unit is used to store the terminal identity obtained from the identity issuance center; The hash calculation unit has a built-in hash algorithm for performing hash calculation; The request unit is used to generate an operation request initiated to the authentication end.

3. A quantum secure near-field communication system according to claim 2, characterized in that: The terminal further comprises a switch unit, a biometric information recognition unit and a biometric information storage unit connected in sequence, and the switch unit is also connected to the request unit; The switch unit is used to execute an open or closed state according to the biometric information recognition result; The biometric information recognition unit is used to enter the biometric information of the user to whom the terminal belongs when it is used for the first time, and transmit the biometric information to the biometric information storage unit for storage; and for comparing the biometric information subsequently input by the user with the locally stored biometric information obtained from the biometric information storage unit to see if they are consistent, and feeding back the biometric information recognition result obtained by the comparison to the switch unit; The biometric information storage unit is used to store the biometric information of the user to which the terminal belongs.

4. A quantum secure near-field communication system according to claim 2, characterized in that: The authentication end includes a second near-field communication unit, a second encryption and decryption unit, a second encryption and decryption key pool, a key pool set, a key unit, an authentication unit, a response unit and a registration unit; the second near-field communication unit is respectively connected to the second encryption and decryption key pool and the second encryption and decryption unit, the second encryption and decryption unit is respectively connected to the second encryption and decryption key pool, the key pool set, the authentication unit and the registration unit, the authentication unit is respectively connected to the registration unit, the key pool set and the response unit, the response unit is connected to the key unit, and the key unit is also connected to the key pool set; The second near field communication unit is used for the authentication end to establish a communication connection with other devices; The second encryption and decryption unit is pre-installed with a decryption algorithm and an encryption algorithm corresponding to those in the first encryption and decryption unit, and is used to perform encryption or decryption operations using the encryption and decryption algorithms; The second encryption / decryption key pool stores a second encryption / decryption key file corresponding to the first encryption / decryption key file in the first encryption / decryption key pool, and is used to provide an encryption key or a decryption key for the second encryption / decryption unit, and the second encryption / decryption key file comes from the key center; The key pool set includes multiple key pools, each key pool stores a second hash key file corresponding to the first hash key file stored in the hash key pool in the corresponding terminal, and the second hash key file comes from the key unit; The key unit is used to generate and distribute hash key files to each key pool in the key pool set; The authentication unit is used to authenticate the legitimacy of the identity of any terminal in the terminal set; The response unit generates a corresponding instruction based on the identity authentication result of the authentication unit; The registration unit is used to store terminal registration records in the terminal set for the authentication terminal to call and query.

5. A quantum secure near field communication system according to claim 4, characterized in that: The key unit includes a random number generator and a key distribution module connected in sequence; The random number generator is used to generate multiple quantum keys and send the multiple quantum keys to the key distribution module; The key distribution module is used to form multiple hash key files from the received multiple quantum keys, and distribute the multiple hash key files to each key pool in the key pool set.

6. A quantum-secure near-field communication method, characterized in that: The following steps are involved: (1) The identity issuance center issues a quantum-secure identity certificate ID-2 to the authentication end, and issues a quantum-secure identity certificate ID-11 to the terminal in the terminal set; (2) The key center issues symmetric encryption and decryption key files to the authentication end and the terminal in the terminal set respectively. The authentication end stores the encryption and decryption key files in the second encryption and decryption key pool, and the terminal stores the encryption and decryption key files in the first encryption and decryption key pool; (3) The authentication end sends a hash key file to the terminal in the terminal set; (4) A terminal in the terminal set initiates an operation request to the authenticator, and the authenticator authenticates the identity of the terminal based on the operation request; (5) The response unit of the authentication end executes subsequent corresponding operations based on the instructions generated by the terminal's identity authentication result.

7. A quantum secure near-field communication method according to claim 6, characterized in that: The specific process of the identity issuance center issuing a quantum secure identity certificate ID-2 to the authentication end is as follows: The identity issuance center obtains the device number devNo-2 of the authentication end, generates a quantum secure identity certificate ID-2 of the authentication end based on the device number devNo-2, and distributes the identity certificate ID-2 to the authentication unit in the authentication end for storage; Among them, generating the quantum secure identity certificate ID-2 of the authentication end means: the identity issuing center continuously obtains random numbers from the local until an irreducible polynomial p1(x) is generated based on the group of random numbers, and the coefficient of the irreducible polynomial p1(x) is recorded as str1; then another group of random numbers u1 are obtained from the local as the input random numbers of the hash function, and the hash function h is generated based on the irreducible polynomial p1(x) and the input random numbers u1. p1,u1 , using the hash function h p1,u1 Calculate the hash value of device number devNo-2 to get the hash value H-2=h p1,u1 (devNo-2), using the hash value H-2 as the quantum-safe identity certificate of the authentication end; The specific process of issuing a quantum secure identity certificate ID-11 to a terminal in the terminal set is as follows: The identity issuance center obtains the device number devNo-11 of the terminal, associates the device number devNo-11 with the identity certificate ID-2 of the authentication end, and generates a quantum secure identity certificate ID-11 of the terminal based on the associated device number devNo-11 and identity certificate ID-2; Among them, generating the quantum secure identity certificate ID-11 of the terminal means: the identity issuing center continuously obtains random numbers from the local until an irreducible polynomial p2(x) is generated based on the group of random numbers, and the coefficient of the irreducible polynomial p2(x) is recorded as str2; then another group of random numbers u2 are obtained from the local as the input random numbers of the hash function, and the hash function h is generated based on the irreducible polynomial p2(x) and the input random number u2. p2,u2 , using the hash function h p2,u2 Calculate the hash value of the associated device number devNo-11 and the identity certificate ID-2 to obtain the hash value H-11 = h p2,u2 (devNo-11, ID-2), use the hash value H-11 as the quantum secure identity certificate ID-11 of the terminal, and send the identity certificate ID-11 to the terminal identity storage unit in the terminal for storage; at the same time, the identity issuance center stores the terminal's device number devNo-11 in correspondence with the identity certificate ID-11, coefficient str2, and input random number u2.

8. A quantum secure near-field communication method according to claim 7, characterized in that: The specific process steps of the authentication end sending the hash key file to the terminal in the terminal set are: 1) When a terminal in the terminal set performs near field communication with the authentication end for the first time, it generates a registration application req and encrypts it and sends it to the authentication end; wherein the registration application req includes the identity certificate ID-11 and the device number devNo-11 of the terminal; 2) When the second near-field communication unit of the authentication end detects that the distance between the authentication end and the terminal meets the near-field communication condition, the second near-field communication unit instructs the second encryption and decryption unit of the authentication end to decrypt the encrypted registration application req and send it to the registration unit of the authentication end. The registration unit receives the registration application req and calls the authentication unit of the authentication end to perform identity authentication based on the identity certificate ID-11 in the received registration request req; 3) After the identity authentication is passed, the authentication unit sends the result of the identity authentication to the response unit of the authentication end. The response unit initiates an instruction I to generate a key file to the key unit of the authentication end based on the result. The random number generator in the key unit responds to the instruction I, generates multiple groups of random numbers to form a key file file, and sends the key file file to the key distribution module in the key unit for distribution; 4) The key distribution module selects a set of empty key pools from the key pool set of the authentication end, sends the key file file to the empty key pool, and associates the empty key pool with the device number devNo-11′ of the terminal. The empty key pool synchronizes the key file file in an encrypted form to the hash key pool in the terminal.

9. A quantum secure near-field communication method according to claim 8, characterized in that: The encryption and sending to the authentication end means: the first encryption and decryption unit of the terminal obtains the first encryption key K1 from the first encryption and decryption key pool of the terminal, uses the first encryption key K1 to encrypt the registration application req to obtain the ciphertext REQ=req⊕K1, and records the location information addk1 of the first encryption key K1 in the encryption and decryption key file of the first encryption and decryption key pool, and sends the location information addk1 and the ciphertext REQ to the authentication end via the first near field communication unit of the terminal.

10. A quantum secure near-field communication method according to claim 9, characterized in that: The specific process of step 2) is as follows: A: When the second near-field communication unit of the authentication end detects that the distance between the authentication end and the terminal meets the near-field communication condition, the second near-field communication unit sends the location information addk1 and the ciphertext REQ to the second encryption and decryption unit; after receiving the location information addk1 and the ciphertext REQ, the second encryption and decryption unit obtains the first decryption key K1′ from the encryption and decryption key file in the second encryption and decryption key pool of the authentication end based on the location information addk1, decrypts the ciphertext REQ using the first decryption key K1′, obtains the registration application req′, extracts the terminal's identity certificate ID-11′ and the device number devNo-11′ from the decrypted registration application req′, and sends the decrypted registration application req′ to the registration unit; B: The registration unit initiates an instruction to the authentication unit to authenticate the terminal based on the registration application req′; the authentication unit obtains the identity certificate ID-11′ and the device number devNo-11′ from the second encryption and decryption unit based on the instruction, obtains the coefficient str2 and the input random number u2 from the identity issuance center based on the device number devNo-11′, generates an irreducible polynomial p2(x) based on the coefficient str2, and generates a hash function h′ using the irreducible polynomial p2(x) and the input random number u2 p2,u2 , using the hash function h′ p2,u2 Calculate the hash value of the file consisting of the device number devNo-11′ and the local identity certificate ID-2 to obtain the hash value H=h ′ p2,u2 (devNo-11 ′ ,ID-2); C: The authentication unit compares the calculated hash value H and the decrypted identity certificate ID-11′ to see if they are consistent. If they are consistent, the identity authentication is successful, and the registration unit records the successful registration information of the terminal, and stores the terminal's device number devNo-11′ and the identity certificate ID-11′ in correspondence; if they are inconsistent, the identity authentication fails, and the registration unit rejects the terminal's registration request req, and the terminal needs to re-initiate a new round of registration request.

11. A quantum secure near-field communication method according to claim 8, characterized in that: The specific process of synchronizing the key file file in encrypted form to the hash key pool in the terminal is as follows: The empty key pool sends the key file file to the second encryption and decryption unit, and the second encryption and decryption unit obtains the second encryption key K2 from the second encryption and decryption key pool of the authentication end, encrypts the key file file with the second encryption key K2, obtains the ciphertext FILE=file⊕K2, and records the location information addk2 of the encryption and decryption key file of the second encryption key K2 in the second encryption and decryption key pool, and sends the location information addk2 and the ciphertext FILE to the terminal via the second near field communication unit; The first encryption and decryption unit of the terminal receives the location information addk2 and the ciphertext FILE via the first near-field communication unit of the terminal, obtains the second decryption key K2′ from the encryption and decryption key file in the first encryption and decryption key pool of the terminal based on the location information addk2, uses the second decryption key K2′ to decrypt the ciphertext FILE to obtain the key file file′, and the first encryption and decryption unit sends the key file file′ to the hash key pool for storage.

12. A quantum secure near field communication method according to claim 6, characterized in that: The specific steps of step (4) are as follows: S1: When the first near field communication unit of the terminal detects that the distance between the terminal and the authentication end meets the near field communication distance condition, it sends a start instruction to the request unit of the terminal; S2: The request unit calls the hash calculation unit of the terminal based on the start instruction to generate an operation request req2; then sends the operation request req2 to the first encryption and decryption unit of the terminal for encryption, and then sends it to the authentication end through the first near field communication unit of the terminal; S3: The second near-field communication unit of the authentication end receives and forwards the request to the second encryption and decryption unit of the authentication end. The second encryption and decryption unit decrypts the request to obtain the decrypted operation request req2′, and then sends the operation request req2′ to the authentication unit of the authentication end. The authentication unit authenticates the identity of the terminal based on the operation request req2′.

13. A quantum secure near field communication method according to claim 12, characterized in that: The step S2 refers to: The request unit generates a serial number NO for this request and sends it to the hash calculation unit. In response to receiving the serial number NO, the hash calculation unit generates an irreducible polynomial p3(x) locally, and records the coefficient of the irreducible polynomial p3(x) as str3. Then, the key u3 is selected from the first hash key file in the hash key pool of the terminal as the input random number, and the starting position add and length l of the key u3 are recorded. The hash calculation unit then generates a hash function h based on the irreducible polynomial p3(x) and the input random number u3. p3,u3 , and obtain the terminal's identity certificate ID-11 and device number devNo-11 from the terminal's terminal identity storage unit; the hash calculation unit uses the hash function h p3,u3 Calculate the hash value of serial number NO, identity certificate ID-11, and device number devNo-11 to get the hash value H3=h p3,u3 (NO, ID-11, devNo-11), the serial number NO, the device number devNo-11, the starting position add and length l of the key u3, the hash value H3, and the coefficient str3 together constitute the operation request req2 = (NO, devNo-11, add, l, H3, str3); at the same time, the first hash key file where the key u3 is located in the hash key pool of the terminal deletes the key u3, and integrates the remaining keys of the first hash key file to form a new first hash key file for subsequent key acquisition; Then, the hash calculation unit sends the operation request req2 to the first encryption and decryption unit, the first encryption and decryption unit obtains the third encryption key K3 from the first encryption and decryption key pool of the terminal and records the location information addk3 of the third encryption key K3, encrypts the operation request req2 using the third encryption key K3 to obtain the ciphertext REQ2=req2⊕K3, and sends the ciphertext REQ2 and the location information addk3 to the authentication end via the first near field communication unit; The step S3 refers to: The second near field communication unit of the authentication end receives the ciphertext REQ2 and the location information addk3 and then forwards them to the second encryption and decryption unit. The second encryption and decryption unit obtains the third decryption key K3′ from the second encryption and decryption key pool of the authentication end based on the location information addk3, and then performs a decryption operation on the ciphertext REQ2, and sends the decrypted operation request req2′=(NO ′ ,devNo-11 ″ ,add ′ ,l ′ ,H3 ′ ,str3′) is sent to the authentication unit; The authentication unit generates an irreducible polynomial p3′(x) based on the coefficient str3′, and finds the key pool associated with the device number devNo-11″ in the key pool set of the authentication end based on the device number devNo-11″ of the terminal obtained after decryption, and then adds the key pool associated with the device number devNo-11″ according to the starting position add′ and l ′ The input random number u3′ is obtained from the second hash key file of the key pool, and the authentication unit generates a hash function h′ based on the irreducible polynomial p3′(x) and the random number u3′. p3,u3 ; The authentication unit obtains the identity certificate ID-11′ stored by the terminal during registration from the registration unit of the authentication end based on the device number devNo-11″ of the terminal obtained after decryption, and then uses the generated hash function h′ p3,u3 Calculate NO ′ , ID-11′, devNo-11″ hash value to get hash value H3 ″ =h ′ p3,u3 (NO′,ID-11′,devNo-11″); The authentication unit compares the calculated hash value H3 ″ and the hash value H3 obtained from the decrypted operation request req2′ ′ Whether they are consistent, if they are consistent, the identity authentication of the terminal is passed, and the authentication unit sends the identity authentication result to the response unit of the authentication end, and the response unit generates a work instruction based on the result; If they are inconsistent, the terminal's identity authentication fails, and the authentication unit sends an identity authentication failure result to the response unit, and the response unit generates an error reporting instruction based on the result.

14. A quantum secure near field communication method according to claim 12, characterized in that: The step S1 further comprises: The biometric information recognition unit of the terminal compares the biometric information input by the user at this time with the locally stored biometric information obtained from the biometric information storage unit to see if they are consistent. If the comparison is consistent, the switch unit is fed back that the biometric information comparison is successful, and the switch unit configures the state to the open state based on the feedback of the successful comparison; if the comparison is inconsistent, the switch unit is fed back that the biometric information comparison fails, and the switch unit is configured to the closed state based on the feedback of the failed comparison; When the request unit receives the start instruction and detects that the switch unit is in an open state, it executes the next step; otherwise, it does not perform the near field communication with the authentication end.