Quantum key expansion method, apparatus and device, and computer program product

By obtaining spare and original quantum keys in the quantum key distribution network and generating expanded quantum keys, the problem of insufficient expansion capacity of the quantum key distribution network in the prior art is solved, and the flexible and low-cost expansion of the quantum key is achieved.

CN120017261AActive Publication Date: 2025-05-16中国邮政储蓄银行股份有限公司

Patent Information

Application Number
CN202510176361.X
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-02-18
Publication Date
2025-05-16
Estimated Expiration
2045-02-18

AI Technical Summary

Technical Problem

When existing quantum key distribution networks (QKDNs) are distributed across domain quantum keys, the key output performance is limited, which is difficult to meet high-performance requirements, and the capacity expansion capabilities are limited and inflexible.

Method used

By acquiring multiple spare quantum keys and original quantum keys in nodes in the quantum key distribution network, an expanded quantum key is generated, thereby achieving flexible expansion of quantum keys.

Benefits of technology

Without increasing QKD device resources, the low cost and flexible expansion of quantum keys are achieved, and the performance of QKD devices in generating quantum keys is improved.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120017261A_ABST
    Figure CN120017261A_ABST
Patent Text Reader

Abstract

The invention discloses a quantum key expansion method, device and equipment and a computer program product, the quantum key expansion method is executed by a node accessing a quantum key distribution network, and the quantum key expansion method comprises the following steps: obtaining a plurality of standby quantum keys from a home terminal cryptographic device of the node, the standby quantum key is obtained through negotiation of a quantum key distribution network; obtaining an original quantum key based on quantum key distribution network negotiation; and generating a plurality of extended quantum keys according to the plurality of standby quantum keys and the original quantum key. According to the quantum key expansion method provided by the embodiment of the invention, the plurality of standby quantum keys are generated through negotiation of the quantum key distribution network, and the original quantum key is expanded through the plurality of standby quantum keys, so that flexible expansion of the quantum keys can be realized in a low-cost manner under the condition that QKD equipment resources are not increased, and the quantum key expansion efficiency is improved. And the quantum key generation performance of the QKD equipment is improved.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present application relates to the field of quantum key distribution technology, and in particular to a quantum key expansion method, device and equipment, and a computer program product. Background Art

[0002] Currently, users can achieve cross-domain quantum key security distribution by deploying QKD (Quantum Key Distribution) devices to access QKDN (Quantum Key Distribution Network). The security of the QKD protocol utilizes the randomness of quantum nature in quantum mechanics and the quantum non-cloning theorem. The former is used to generate true random keys, and the latter ensures that the keys cannot be obtained by eavesdroppers during the transmission process. Once theft occurs on the key transmission channel, it will be detected by both communicating parties, and then this part of the key will be used for confidentiality enhancement protocol processing.

[0003] QKDN distributes quantum keys based on quantum key distribution protocols, key security relay and other technologies. The quantum key generation and output performance of two remote QKD devices is mainly limited by the key security relay capability of QKDN. Taking the current commercial QKDN as an example, the quantum key output performance provided for a pair of user QKDs is about 1KB per 24 hours. If the cross-domain quantum key distribution performance requirement of a single pair of users is higher than this value, it is necessary to increase the QKD devices connected to QKDN, which may exceed the overall network load capacity, and the expansion capacity is limited and inflexible. Summary of the invention

[0004] The embodiments of the present application provide a quantum key expansion method, apparatus and device, and a computer program product to reduce the cost of quantum key expansion and improve the flexibility of quantum key expansion.

[0005] The present application embodiment adopts the following technical solutions:

[0006] In a first aspect, an embodiment of the present application provides a quantum key expansion method, the quantum key expansion method is performed by a local node connected to a quantum key distribution network, and the quantum key expansion method includes:

[0007] Obtain multiple backup quantum keys from the local cryptographic device of the node, wherein the backup quantum keys are obtained through negotiation in a quantum key distribution network;

[0008] Obtain the original quantum key through negotiation based on the quantum key distribution network;

[0009] A plurality of expanded quantum keys are generated according to the plurality of backup quantum keys and the original quantum key.

[0010] Optionally, generating a plurality of extended quantum keys according to the plurality of backup quantum keys and the original quantum key comprises:

[0011] Constructing a quantum key expansion sequence of the node according to the plurality of backup quantum keys;

[0012] A plurality of the expanded quantum keys are generated according to the quantum key expansion sequence and the original quantum key.

[0013] Optionally, the local node accessing the quantum key distribution network is divided into a master node and a slave node, and constructing a quantum key expansion sequence of the local node according to the multiple backup quantum keys includes:

[0014] When the local node is a master node, multiple backup quantum keys are obtained from the local cryptographic device of the master node;

[0015] Constructing a quantum key expansion sequence of a master node according to a plurality of the backup quantum keys;

[0016] The identities of the multiple backup quantum keys are sent to all target slave nodes.

[0017] Optionally, constructing a quantum key expansion sequence of the node according to the plurality of standby quantum keys comprises:

[0018] When the node is a slave node, it receives the identifiers of multiple backup quantum keys sent by the master node;

[0019] Acquire the corresponding multiple standby quantum keys from the local cryptographic device of the slave node according to the identifiers of the multiple standby quantum keys;

[0020] A quantum key expansion sequence of a slave node is constructed according to the plurality of backup quantum keys, and the quantum key expansion sequence of the slave node is the same as the quantum key expansion sequence of the master node.

[0021] Optionally, before obtaining a plurality of backup quantum keys from a local cryptographic device of the local node, the quantum key expansion method further includes:

[0022] Acquire multiple backup quantum keys based on the quantum key distribution network;

[0023] Multiple backup quantum keys are stored in sequence in the local cryptographic device of the node.

[0024] Optionally, the quantum key expansion method further includes:

[0025] When the node is the master node, reacquire multiple new backup quantum keys based on the quantum key distribution network according to preset update conditions;

[0026] The multiple new backup quantum keys are sequentially stored in the local cryptographic device of the master node;

[0027] An expansion update instruction is initiated to the slave node, so that the slave node synchronously obtains multiple new backup quantum keys according to the expansion update instruction and stores them in sequence in the local cryptographic device of the slave node.

[0028] Optionally, after initiating an expansion update instruction to the slave node, the quantum key expansion method further includes:

[0029] Receive quantum key update results from slave nodes;

[0030] When the quantum key update result is that the update is successful, multiple new extended quantum keys are generated according to the multiple new backup quantum keys and the original quantum key.

[0031] In a second aspect, an embodiment of the present application further provides a quantum key expansion device, which is applied to a local node in a quantum key distribution network, and the quantum key expansion device includes:

[0032] A first acquisition unit is used to acquire multiple backup quantum keys from a local cryptographic device of the local node, where the backup quantum keys are obtained through negotiation in a quantum key distribution network;

[0033] A second acquisition unit, configured to acquire an original quantum key through negotiation based on a quantum key distribution network;

[0034] A generating unit is used to generate a plurality of extended quantum keys according to the plurality of backup quantum keys and the original quantum key.

[0035] In a third aspect, an embodiment of the present application further provides a device, including:

[0036] A processor; and a memory arranged to store computer executable instructions, which, when executed, cause the processor to perform any of the aforementioned quantum key expansion methods.

[0037] In a fourth aspect, an embodiment of the present application further provides a computer program product, comprising a computer program / instruction, which, when executed by a processor, implements any of the aforementioned quantum key expansion methods.

[0038] At least one of the above technical solutions adopted in the embodiments of the present application can achieve the following beneficial effects: the quantum key expansion method of the embodiment of the present application is executed by the local node connected to the quantum key distribution network, firstly obtains multiple backup quantum keys from the local cryptographic device of the node, and the backup quantum keys are obtained by negotiation of the quantum key distribution network; then obtains the original quantum key based on the negotiation of the quantum key distribution network; finally, generates multiple expanded quantum keys based on the multiple backup quantum keys and the original quantum key. The quantum key expansion method of the embodiment of the present application generates multiple backup quantum keys through negotiation of the quantum key distribution network, and expands the original quantum key using the multiple backup quantum keys, which can realize the flexible expansion of quantum keys in a low-cost manner without increasing the resources of the QKD equipment, and improves the performance of the QKD equipment in generating quantum keys. BRIEF DESCRIPTION OF THE DRAWINGS

[0039] The drawings described herein are used to provide a further understanding of the present application and constitute a part of the present application. The illustrative embodiments of the present application and their descriptions are used to explain the present application and do not constitute an improper limitation on the present application. In the drawings:

[0040] Figure 1 A schematic diagram of a process of quantum key expansion method in an embodiment of the present application;

[0041] Figure 2 This is a schematic diagram of a quantum key expansion process in an embodiment of the present application;

[0042] Figure 3 This is a schematic diagram of the structure of a quantum key expansion device in an embodiment of the present application;

[0043] Figure 4 This is a schematic diagram of the structure of a device in an embodiment of the present application. DETAILED DESCRIPTION

[0044] In order to make the purpose, technical solution and advantages of the present application clearer, the technical solution of the present application will be clearly and completely described below in combination with the specific embodiments of the present application and the corresponding drawings. Obviously, the described embodiments are only part of the embodiments of the present application, not all of the embodiments. Based on the embodiments in the present application, all other embodiments obtained by ordinary technicians in this field without making creative work are within the scope of protection of the present application.

[0045] The technical solutions provided by various embodiments of the present application are described in detail below in conjunction with the accompanying drawings.

[0046] The technical terms involved in this application mainly include:

[0047] 1) QKD: Quantum Key Distribution, Quantum Key Distribution, uses quantum as the carrier of information transmission, uses the microscopic state of quantum as the basis for information encoding, and generates symmetric keys at both ends of transmission. It refers to quantum key distribution technology, or quantum key distribution equipment.

[0048] 2) QKDN: Quantum Key Distribution Network, is a new technology network that uses the principles of quantum mechanics to achieve secure key distribution.

[0049] The implementation of the QKD protocol requires dedicated QKD equipment and optical fiber, or quantum satellite and free space. In a fiber-optic QKD network, the point-to-point distance of the QKD protocol generally does not exceed 100 kilometers. For long-distance communication, it is necessary to overcome the impact of transmission medium loss on the signal. In classical communication, amplifiers can be used to enhance the signal. However, in quantum networks, amplifiers cannot be used due to the quantum no-cloning theorem. Based on quantum entanglement exchange, quantum entanglement can be relayed, thereby realizing long-distance quantum communication. However, quantum relay technology is very difficult and is not yet practical. At present, the transitional solution adopted for building a long-distance quantum key distribution infrastructure is the trusted repeater solution.

[0050] The specific principle is: consider two end nodes A and B, and a trusted relay R between them. A and R generate a key KAR through quantum key distribution. Similarly, R and B generate a key KRB through quantum key distribution. The process of A and B generating a shared session key KAB through R is as follows: A encrypts KAB with a one-time-pad (OTP) through KAR and sends it to R, who decrypts it to obtain KAB. R re-encrypts KAB with the key KRB and sends it to B. B decrypts it to obtain KAB. A and B perform encrypted communication using the shared key KAB.

[0051] This method of transferring the key from A to B in a one-time pad manner can achieve information-theoretically secure key distribution, which can theoretically prevent attacks by any external eavesdropper. However, this scheme requires that any relay node must be secure and reliable, and the actual key security relay efficiency is low. The performance of relay key generation is much lower than the performance of point-to-point quantum key generation through quantum key distribution protocol.

[0052] For example, users Alice and Bob have a cryptographic application X. The two users access QKDN through a single QKD device, and the performance of synchronously outputting quantum keys on both sides is 1KB / h. If the key application is in accordance with the national secret SM4 algorithm and the quantum key is fully utilized, both ends can generate 1KB*1024 / 16B=64 keys per hour, and cryptographic application X can update the key approximately once a minute.

[0053] Assuming that Alice and Bob add a new cryptographic application Y, and Y and X update the SM4 key 64 times per hour, when the key output performance of the quantum network is 1KB / h, it is necessary to apply for twice the network resources from the QKDN operator, add one more QKD device access, and add a pair of optical fiber access to provide higher quantum key output capabilities. The overall hardware and network service costs increase exponentially, and the user-side quantum network needs to be expanded and renovated.

[0054] Since the security of the existing quantum keys distributed through QKDN is based on the principles of physics and information theory "one-time, one-pad", it is necessary to implement a low-cost and practically secure quantum key expansion solution based on the existing secure quantum key resources to support the flexible expansion of quantum key services.

[0055] Based on this, the embodiment of the present application provides a quantum key expansion method, such as Figure 1 As shown, a flow chart of a quantum key expansion method in an embodiment of the present application is provided, wherein the quantum key expansion method is executed by the node connected to the quantum key distribution network, and the quantum key expansion method comprises at least the following steps S110 to S130:

[0056] Step S110, obtaining multiple backup quantum keys from the local cryptographic device of the node, wherein the backup quantum keys are obtained by negotiation through a quantum key distribution network.

[0057] Combination Figure 2 , provides a schematic diagram of a quantum key expansion process in an embodiment of the present application. The quantum key expansion method of the embodiment of the present application can be executed by any service node that is connected to a quantum key quantum key distribution network and needs to perform network transmission based on the quantum key quantum key distribution network. When performing quantum key expansion, it is necessary to first obtain multiple pre-generated spare quantum keys from the local cryptographic device of the node. These multiple spare quantum keys can be understood as being generated based on the existing QKD equipment and QKDN network according to the existing quantum key output performance. Each node can obtain multiple quantum keys based on QKDN negotiation as the basis for subsequent expansion of quantum keys.

[0058] Step S120, obtaining the original quantum key through negotiation based on the quantum key distribution network.

[0059] The quantum key expansion object of the embodiment of the present application is the original key generated in the form of "one-time one-key" in the original quantum key distribution scheme. Therefore, it is necessary to further negotiate and obtain the original quantum key based on the quantum key distribution network as the expanded basic key.

[0060] Step S130, generating multiple extended quantum keys according to the multiple backup quantum keys and the original quantum key.

[0061] Since the generation principles of the backup quantum key and the original quantum key are the same, and both satisfy the essential randomness of quantum in quantum mechanics and the quantum non-cloning theorem, multiple backup quantum keys can be used to expand the original quantum key. The expanded quantum key also satisfies the essential randomness of quantum in quantum mechanics and the quantum non-cloning theorem. This achieves the purpose of expanding the number of quantum keys without increasing the resources of QKD equipment.

[0062] The quantum key expansion method of the embodiment of the present application generates multiple backup quantum keys through negotiation using a quantum key distribution network, and uses the multiple backup quantum keys to expand the original quantum key. This can achieve flexible expansion of quantum keys in a low-cost manner without increasing QKD device resources, thereby improving the performance of QKD devices in generating quantum keys.

[0063] In some embodiments of the present application, generating multiple extended quantum keys based on the multiple backup quantum keys and the original quantum key includes: constructing a quantum key extension sequence of the node based on the multiple backup quantum keys; and generating multiple extended quantum keys based on the quantum key extension sequence and the original quantum key.

[0064] Continue to refer Figure 2 When generating multiple extended quantum keys, multiple backup quantum keys obtained from the local cryptographic device can be used to construct a quantum key extension sequence according to certain rules or algorithms, for example, represented as {k1, k2, ..., k n It should be noted that the quantum key expansion sequence constructed here can be used directly as the quantum key itself, or the quantum key can be transformed before use to further enhance the security of the key. If the quantum key is transformed to generate a quantum key expansion sequence, each service node needs to agree on a consistent transformation method in advance and verify the consistency of the expanded sequence after the transformation.

[0065] After obtaining the above quantum key expansion sequence, it is necessary to construct the quantum key expansion sequence {k1, k2, ..., k n} is combined with the original quantum key obtained through QKDN negotiation, thereby achieving the purpose of expanding the number of original quantum keys to n times. The specific combination of the quantum key expansion sequence and the original quantum key can be, for example, a mathematical operation algorithm such as an exclusive OR (XOR) algorithm, etc., which is not specifically limited here.

[0066] Theoretically, as long as there are enough backup quantum keys, any number of extended keys can be generated. In actual application scenarios, the length n of the extended sequence can be flexibly modified according to needs.

[0067] By using the pre-generated backup quantum keys to expand the original quantum keys, the number of quantum keys can be flexibly expanded without increasing the resources of the QKD device. This is particularly important for application scenarios that require high key update frequency or a large number of keys. Compared with hardware expansion solutions such as adding QKD equipment and fiber optic access, it avoids high hardware costs and complex network transformation work, and reduces the overall cost of the quantum key distribution system. Since the backup quantum keys and the original quantum keys are generated based on the principles of quantum mechanics and have the randomness and non-cloning properties of quantum nature, the expanded quantum keys also meet these security characteristics. This ensures the security of the expanded keys during transmission and use. By expanding the number of quantum keys, the performance of QKD devices in generating quantum keys can be improved, supporting more cryptographic applications and higher key update frequencies, thereby enhancing the overall security and reliability of the network.

[0068] In some embodiments of the present application, the local node accessed in the quantum key distribution network is divided into a master node and a slave node, and constructing the quantum key expansion sequence of the local node based on the multiple backup quantum keys includes: when the local node is the master node, obtaining multiple backup quantum keys from the local cryptographic device of the master node; constructing the quantum key expansion sequence of the master node based on the multiple backup quantum keys; and sending the identifiers of the multiple backup quantum keys to all target slave nodes.

[0069] Continue to refer Figure 2 The nodes in the embodiments of the present application can be divided into master nodes and slave nodes. In actual application scenarios, if two application nodes need to synchronize quantum keys, one application node must initiate the synchronization of quantum keys first. The application node that initiates first can be defined as the master node.

[0070] When constructing the quantum key expansion sequence of this node, the master node can first obtain multiple pre-generated backup quantum keys from its own local cryptographic device, and construct the quantum key expansion sequence {k1, k2, ..., k n}, and at the same time, the ID identifications of the multiple backup quantum keys obtained need to be sent to the peer node, that is, the slave node that needs to perform network transmission, so that the slave node can perform the synchronous construction operation of the quantum key expansion sequence.

[0071] The embodiment of the present application clearly distinguishes between the master node and the slave node, and the master node is responsible for actively distributing the backup quantum key identifier, and the slave node only needs to perform the synchronization construction operation according to the instruction of the master node, thereby significantly improving the efficiency and accuracy of key synchronization.

[0072] In some embodiments of the present application, constructing a quantum key expansion sequence of the node based on multiple backup quantum keys includes: when the node is a slave node, receiving identifiers of multiple backup quantum keys sent by a master node; obtaining corresponding multiple backup quantum keys from a local cryptographic device of the slave node based on the identifiers of the multiple backup quantum keys; constructing a quantum key expansion sequence of the slave node based on the multiple backup quantum keys, the quantum key expansion sequence of the slave node being the same as the quantum key expansion sequence of the master node.

[0073] Continue to refer Figure 2 For the slave node to perform network transmission with the master node, it needs to construct the corresponding quantum key expansion sequence like the master node. Specifically, the slave node can receive the IDs of multiple backup quantum keys sent from the master node, and search and obtain the corresponding quantum keys in the local cryptographic device of the slave node based on the IDs of these backup quantum keys. These keys in the local cryptographic device are previously generated between the master node and the slave node through the quantum distribution process of QKDN and stored in their respective cryptographic devices.

[0074] After obtaining the corresponding backup quantum keys, the slave nodes can also use these quantum keys to construct a quantum key expansion sequence in the same way. This sequence needs to be the same as the quantum key expansion sequence of the master node to ensure that both parties can use the same key for encryption and decryption operations.

[0075] By constructing a quantum key expansion sequence by the master node and the slave node respectively, compared with the method of directly transmitting the quantum key expansion sequence from the master node to the slave node, the security of the quantum key expansion sequence can be further ensured, thereby avoiding security issues in the transmission process.

[0076] In some embodiments of the present application, before obtaining multiple backup quantum keys from the local cryptographic device of the local node, the quantum key expansion method also includes: obtaining multiple backup quantum keys based on the quantum key distribution network; and storing the multiple backup quantum keys in the local cryptographic device of the local node in sequence.

[0077] Continue to refer Figure 2 Before quantum key expansion, each node needs to negotiate and obtain multiple quantum keys based on the quantum key distribution network. These keys are used as backup keys and stored in the local cryptographic device of each node for subsequent expansion. Based on the backup keys stored in the local cryptographic device, each node can search and obtain these backup quantum keys from the cryptographic device when quantum keys need to be expanded, and use these backup quantum keys to construct the quantum key expansion sequence.

[0078] By obtaining backup quantum keys based on QKDN negotiation in advance and storing them locally, the flexibility and security of backup quantum key management are improved.

[0079] In some embodiments of the present application, the quantum key expansion method also includes: when the current node is a master node, re-acquiring multiple new backup quantum keys based on the quantum key distribution network according to preset update conditions; storing the multiple new backup quantum keys in sequence in the local cryptographic device of the master node; initiating an expansion update instruction to the slave node, so that the slave node synchronously obtains multiple new backup quantum keys according to the expansion update instruction and stores them in sequence in the local cryptographic device of the slave node.

[0080] Continue to refer Figure 2 In order to further improve the security of the extended quantum key, the embodiment of the present application can also update the backup quantum key when a preset update condition is triggered. For example, when the preset update frequency is reached or a potential security threat is detected, the master node can start the key update process. The key update process is intended to regenerate a new backup quantum key. Therefore, this process is also based on QKDN negotiation to obtain multiple new backup quantum keys and update local storage, and then generate a new extended quantum key based on the new backup quantum key.

[0081] After confirming the triggering of the preset update condition, the master node also needs to synchronously send an extended update instruction to all slave nodes in the network. This instruction is used to instruct the slave node to perform the operation of updating the backup quantum key. According to the extended update instruction, the slave node also synchronously obtains multiple new backup quantum keys based on QKDN and updates the local storage.

[0082] Through the preset update conditions and automated key update process, the backup quantum key can be updated in time to prevent potential security threats such as key leakage or quantum computer attacks, thereby enhancing the security of the entire QKDN. The master node sends an expansion update command to the slave node, ensuring that all nodes can synchronously obtain and store the new backup key, thereby maintaining the consistency of quantum key updates.

[0083] It should be noted that within the preset update cycle, if there are remaining spare quantum keys in the local storage of the node, that is, there are no spare quantum keys for generating quantum key expansion sequences, then this update can be obtained from the remaining spare quantum keys without having to re-negotiate based on QKDN.

[0084] In some embodiments of the present application, after initiating an expansion update instruction to the slave node, the quantum key expansion method further includes: receiving a quantum key update result from the slave node; when the quantum key update result is a successful update, generating multiple new expanded quantum keys based on multiple new backup quantum keys and the original quantum key.

[0085] Continue to refer Figure 2 After the master node sends an extended update command to the slave node, it waits for and receives the quantum key update result returned by the slave node. This result can be a status message indicating whether the slave node has successfully updated the backup quantum key. If the slave node reports a successful update, the master node will proceed to the next step; if a slave node reports an update failure, the master node may need to take additional measures, such as resending the update command or manually intervening to solve the problem. After confirming that the slave node has successfully updated the key, the master node can enable a new backup quantum key, that is, the new backup quantum key and the original quantum key can be used to generate a new extended quantum key.

[0086] By receiving and checking the quantum key update results of the slave nodes, the master node can ensure that the slave nodes have successfully synchronized and updated their backup quantum keys, thereby ensuring the accuracy of subsequent key expansion. By regularly updating the backup quantum keys and generating new expanded keys, potential key leaks and attacks can be prevented, thereby enhancing the security of the entire quantum key distribution network.

[0087] The present application also provides a quantum key expansion device 300, such as Figure 3 As shown, a schematic diagram of the structure of a quantum key expansion device in an embodiment of the present application is provided. The quantum key expansion device is applied to a local node in a quantum key distribution network. The quantum key expansion device 300 includes: a first acquisition unit 310, a second acquisition unit 320 and a generation unit 330, wherein:

[0088] A first acquisition unit 310 is configured to acquire a plurality of backup quantum keys from a local cryptographic device of the local node, wherein the backup quantum keys are obtained through negotiation in a quantum key distribution network;

[0089] A second acquisition unit 320 is used to negotiate and acquire an original quantum key based on a quantum key distribution network;

[0090] The generating unit 330 is configured to generate a plurality of extended quantum keys according to the plurality of backup quantum keys and the original quantum key.

[0091] In some embodiments of the present application, the generating unit 330 is specifically used to: construct a quantum key expansion sequence of the node according to the multiple backup quantum keys; and generate multiple expanded quantum keys according to the quantum key expansion sequence and the original quantum key.

[0092] In some embodiments of the present application, the local node accessing the quantum key distribution network is divided into a master node and a slave node, and the generation unit 330 is specifically used to: when the local node is a master node, obtain multiple backup quantum keys from the local cryptographic device of the master node; construct a quantum key expansion sequence of the master node according to the multiple backup quantum keys; and send the identifiers of the multiple backup quantum keys to all target slave nodes.

[0093] In some embodiments of the present application, the generating unit 330 is specifically used to: when the current node is a slave node, receive the identifiers of multiple backup quantum keys sent by the master node; obtain the corresponding multiple backup quantum keys from the local cryptographic device of the slave node according to the identifiers of the multiple backup quantum keys; construct a quantum key expansion sequence of the slave node according to the multiple backup quantum keys, and the quantum key expansion sequence of the slave node is the same as the quantum key expansion sequence of the master node.

[0094] In some embodiments of the present application, the quantum key expansion device 300 also includes: a third acquisition unit, used to obtain multiple backup quantum keys based on the quantum key distribution network before obtaining multiple backup quantum keys from the local cryptographic device of the local node; a first storage unit, used to store the multiple backup quantum keys in the local cryptographic device of the local node in sequence.

[0095] In some embodiments of the present application, the quantum key expansion device 300 also includes: an update unit, which is used to re-acquire multiple new backup quantum keys based on the quantum key distribution network according to preset update conditions when the local node is a master node; a second storage unit, which is used to store the multiple new backup quantum keys in sequence in the local cryptographic device of the master node; and an initiating unit, which is used to initiate an expansion update instruction to the slave node, so that the slave node synchronously obtains multiple new backup quantum keys according to the expansion update instruction and stores them in sequence in the local cryptographic device of the slave node.

[0096] In some embodiments of the present application, the quantum key expansion device 300 further includes: a receiving unit, configured to receive a quantum key update result of the slave node after initiating an expansion update instruction to the slave node; the generating unit, further configured to generate a plurality of new expanded quantum keys based on a plurality of new backup quantum keys and the original quantum key when the quantum key update result is a successful update.

[0097] It can be understood that the above-mentioned quantum key expansion device can implement each step of the quantum key expansion method provided in the aforementioned embodiment, and the relevant explanations about the quantum key expansion method are applicable to the quantum key expansion device and will not be repeated here.

[0098] Figure 4 Schematic diagram of the structure of a device in the embodiment of the present application. Figure 4 As shown, the device includes one or more processors (or processing units), may further include one or more memories coupled to the processors, and may further include a communication module coupled to the processors.

[0099] The communication module can be used to communicate with other devices or apparatuses, such as the transmission or reception of data and / or signals. The communication module can have at least one communication module for communication. The communication module can include any interface necessary for communicating with other devices. Exemplarily, the communication module can be a transceiver, a circuit, a bus, a module, or other types of communication modules.

[0100] The processor may include, but is not limited to, at least one of the following: a general-purpose computer, a special-purpose computer, a microcontroller, a digital signal controller (DSP), or one or more of a controller-based multi-core controller architecture. The device may have multiple processors, such as application-specific integrated circuit chips, which are time-dependent and synchronized with a clock of a main processor.

[0101] The memory may include one or more non-volatile memories and one or more volatile memories. Examples of non-volatile memories include, but are not limited to, at least one of the following: read-only memory (ROM), erasable programmable read-only memory (EPROM), flash memory, hard disk, compact disc (CD), digital video disc (DVD), or other magnetic storage and / or optical storage. Examples of volatile memories include, but are not limited to, at least one of the following: random access memory (RAM), or other volatile memories that do not persist during the duration of a power outage.

[0102] The computer program includes computer executable instructions executed by an associated processor. The program can be stored in ROM. The processor can perform any suitable actions and processes by loading the program into RAM.

[0103] The possible implementation of the present application can be implemented by means of a program, so that the communication device can perform any process discussed in the above embodiments. The possible implementation of the present application can also be implemented by hardware or by a combination of software and hardware.

[0104] In some embodiments, the program may be tangibly contained in a computer-readable storage medium, which may be included in the device (such as in a memory) or other storage device accessible by the device. The program may be loaded from the computer-readable storage medium to the RAM for execution. The computer-readable storage medium may include any type of tangible non-volatile memory, such as ROM, EPROM, flash memory, hard disk, CD, DVD, etc.

[0105] The present application embodiment also provides a computer-readable storage medium, on which computer instructions or program codes are stored, and when the processor runs the instructions or the program codes, the processor executes the methods and functions involved in any of the above embodiments. Computer-readable media can be any tangible medium containing or storing programs for or related to instruction execution systems, devices or equipment. Computer-readable media can be computer-readable signal media or computer-readable storage media. Computer-readable media can include, but are not limited to, electronic, magnetic, optical, electromagnetic, infrared or semiconductor systems, devices or devices, or any suitable combination thereof. The computer-readable storage medium can be any available medium that can be accessed by a computer or a data storage device such as a server or data center that includes one or more available media integrations. More detailed examples of computer-readable storage media include electrical connections with one or more wires, magnetic media (e.g., disks, floppy disks, hard disks, tapes, magnetic storage devices), optical media (e.g., optical storage devices, DVDs), semiconductor media (e.g., solid-state hard drives), random access memory (RAM), read-only memory (ROM), erasable programmable read-only memory (EPROM or flash memory), or any suitable combination thereof, etc.

[0106] In the above embodiments, it can be implemented in whole or in part by software, hardware, firmware or any combination thereof. When implemented using software, it can be implemented in whole or in part in the form of a computer program product. The embodiment of the present application also provides at least one computer program product tangibly stored on a non-temporary computer-readable storage medium. The computer program product includes one or more computer executable instructions, such as instructions included in a program module, which are executed in a device on a real or virtual processor of the target to perform the process, method and function involved in any of the above embodiments. When the computer program instruction is loaded and executed on a computer, a process or function according to an embodiment of the present application is generated in whole or in part. The computer can be a general-purpose computer, a special-purpose computer, a computer network, or other programmable device. The computer instruction can be stored in a computer-readable storage medium, or transmitted from one computer-readable storage medium to another computer-readable storage medium, for example, the computer instruction can be transmitted from a website site, computer, server or data center by wired (e.g., coaxial cable, optical fiber, digital subscriber line) or wireless (e.g., infrared, wireless, microwave, etc.) mode to another website site, computer, server or data center.

[0107] The present application embodiment also proposes a computer program product, including a computer program or instruction, when the computer program or instruction is run on a computer, the computer is made to perform the process, method and function in the above-mentioned embodiment. Usually, a program module includes routines, programs, libraries, objects, classes, components, data structures, etc. that perform specific tasks or realize specific abstract data types. In various embodiments, the functions of program modules can be combined or divided between program modules as needed. Machine executable instructions for program modules can be executed in local or distributed devices. In distributed devices, program modules can be located in local and remote storage media.

[0108] In general, various embodiments of the present application may be implemented in hardware or dedicated circuits, software, logic, or any combination thereof. Some aspects may be implemented in hardware, while other aspects may be implemented in firmware or software, which may be performed by a controller, microprocessor, or other computing device. Although various aspects of the embodiments of the present disclosure are shown and described as block diagrams, flow charts, or using some other graphical representations, it should be understood that the boxes, devices, systems, techniques, or methods described herein may be implemented as, for example, non-limiting examples, hardware, software, firmware, dedicated circuits or logic, general hardware or controllers or other computing devices, or some combination thereof.

[0109] It should be noted that although the embodiments of the present application are described above in conjunction with the accompanying drawings, the above embodiments are not independent of each other, and they can also be combined to obtain other embodiments. The division of the modes, situations, categories and embodiments in the embodiments of the present application is only for the convenience of description and should not constitute a special limitation. The features in the various modes, categories, situations and embodiments can be combined with each other in a logical manner. The various implementation methods of the present application can be combined arbitrarily to achieve different technical effects. The embodiments of the present application no longer list various combinations.

[0110] In addition, although the operation of the method of the present disclosure is described in a particular order in the accompanying drawings, this does not require or imply that these operations must be performed in this particular order, or that all the operations shown must be performed to achieve the desired result. On the contrary, the steps depicted in the flow chart can change the order of execution. Additionally or alternatively, some steps can be omitted, multiple steps can be combined into one step for execution, and / or one step can be decomposed into multiple steps for execution. It should also be noted that the features and functions of two or more devices according to the present disclosure can be embodied in one device. Conversely, the features and functions of a device described above can be further divided into being embodied by multiple devices.

[0111] It should also be noted that the terms "include", "comprises" or any other variations thereof are intended to cover non-exclusive inclusion, so that a process, method, commodity or device including a series of elements includes not only those elements, but also other elements not explicitly listed, or also includes elements inherent to such process, method, commodity or device. In the absence of more restrictions, the elements defined by the sentence "comprises a ..." do not exclude the existence of other identical elements in the process, method, commodity or device including the elements.

[0112] The above is only an embodiment of the present application and is not intended to limit the present application. For those skilled in the art, the present application may have various changes and variations. Any modification, equivalent replacement, improvement, etc. made within the spirit and principle of the present application should be included in the scope of the claims of the present application.

Claims

1. A quantum key expansion method, characterized in that: The quantum key expansion method is performed by a local node connected to a quantum key distribution network, and the quantum key expansion method includes: Obtain multiple backup quantum keys from the local cryptographic device of the node, wherein the backup quantum keys are obtained through negotiation in a quantum key distribution network; Obtain the original quantum key through negotiation based on the quantum key distribution network; A plurality of expanded quantum keys are generated according to the plurality of backup quantum keys and the original quantum key.

2. The quantum key expansion method according to claim 1, characterized in that: Generating a plurality of extended quantum keys according to the plurality of backup quantum keys and the original quantum key comprises: Constructing a quantum key expansion sequence of the node according to the plurality of backup quantum keys; A plurality of the expanded quantum keys are generated according to the quantum key expansion sequence and the original quantum key.

3. The quantum key expansion method according to claim 2, characterized in that: The node accessing the quantum key distribution network is divided into a master node and a slave node, and the quantum key expansion sequence of the node is constructed according to the plurality of backup quantum keys, including: When the local node is a master node, multiple backup quantum keys are obtained from the local cryptographic device of the master node; Constructing a quantum key expansion sequence of a master node according to a plurality of the backup quantum keys; The identities of the multiple backup quantum keys are sent to all target slave nodes.

4. The quantum key expansion method according to claim 3, characterized in that: The step of constructing a quantum key expansion sequence of the node according to the plurality of standby quantum keys comprises: When the node is a slave node, it receives the identifiers of multiple backup quantum keys sent by the master node; Acquire the corresponding multiple standby quantum keys from the local cryptographic device of the slave node according to the identifiers of the multiple standby quantum keys; A quantum key expansion sequence of a slave node is constructed according to the plurality of backup quantum keys, and the quantum key expansion sequence of the slave node is the same as the quantum key expansion sequence of the master node.

5. The quantum key expansion method according to any one of claims 1 to 4, characterized in that: Before obtaining a plurality of spare quantum keys from the local cryptographic device of the local node, the quantum key expansion method further includes: Acquire multiple backup quantum keys based on the quantum key distribution network; Multiple backup quantum keys are stored in sequence in the local cryptographic device of the node.

6. The quantum key expansion method according to claim 5, characterized in that: The quantum key expansion method also includes: When the node is the master node, reacquire multiple new backup quantum keys based on the quantum key distribution network according to preset update conditions; The multiple new backup quantum keys are sequentially stored in the local cryptographic device of the master node; An expansion update instruction is initiated to the slave node, so that the slave node synchronously obtains multiple new backup quantum keys according to the expansion update instruction and stores them in sequence in the local cryptographic device of the slave node.

7. The quantum key expansion method according to claim 6, characterized in that: After initiating an expansion update instruction to the slave node, the quantum key expansion method further includes: Receive quantum key update results from slave nodes; When the quantum key update result is that the update is successful, multiple new extended quantum keys are generated according to the multiple new backup quantum keys and the original quantum key.

8. A quantum key expansion device, characterized in that: The quantum key expansion device is applied to a local node in a quantum key distribution network, and the quantum key expansion device includes: A first acquisition unit is used to acquire multiple backup quantum keys from a local cryptographic device of the local node, where the backup quantum keys are obtained through negotiation in a quantum key distribution network; A second acquisition unit, configured to acquire an original quantum key through negotiation based on a quantum key distribution network; A generating unit is used to generate a plurality of extended quantum keys according to the plurality of backup quantum keys and the original quantum key.

9. A device comprising: processor; and a memory arranged to store computer executable instructions, which, when executed, cause the processor to perform the quantum key expansion method according to any one of claims 1 to 7.

10. A computer program product comprising a computer program / instructions, characterized in that When the computer program / instructions are executed by a processor, the quantum key expansion method according to any one of claims 1 to 7 is implemented.

Citation Information

Patent Citations

  • Quantum key expansion method and system based on SM9 key exchange, medium and terminal

    CN114021173A

  • Quantum cryptography network key relay dynamic routing method, device and system

    CN117176345A

  • Key expansion method

    CN117201012A

  • Acquisition terminal, load management center and quantum safety load management system

    CN117749371A

  • Secret key updating method and device for external connection service

    CN118449689A

Cited By

  • Quantum communication method, device and system

    CN121396463A