Method for safely using quantum key

By introducing key center and hash function mechanisms in the quantum key communication system, we ensure that the use of quantum keys is one-time, solving the risk of key reuse, and achieving absolute security of quantum encryption.

CN120017262APending Publication Date: 2025-05-16MATRICTIME DIGITAL TECH CO LTD
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202510182010.X
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-02-19
Publication Date
2025-05-16

AI Technical Summary

Technical Problem

How to ensure that the use of quantum keys is one-time, preventing the reuse of keys, and thus ensuring the absolute security of the encryption method one-crypto at a time.

Method used

By introducing a key center between the sender device and the receiver device, a hash function and an irreducible polynomial are used to generate the hash value of the key block, ensuring that the key block is deleted after each use and preventing reuse.

Benefits of technology

The secure use of quantum keys is realized, ensuring that the key is only used for one encryption operation, avoiding the risks of key leakage and reuse, and improving the security of the entire system.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120017262A_ABST
    Figure CN120017262A_ABST
Patent Text Reader

Abstract

The invention discloses a method for safely using a quantum key, and the method comprises the steps: a sender device obtains a key from a key center, and obtains a service list from the local; the sender device obtains a key block corresponding to each service in the service list, performs hash calculation on the key block to obtain a hash value, generates a key data index of each service in combination with the service number, and integrates the key data index to obtain a key data index table; the sender device uses the key block to encrypt service transmission content in the corresponding service, obtains a service ciphertext, updates the key data index table, generates a communication data packet based on the service ciphertext, and transmits the communication data packet to the receiver device; and the receiver equipment notifies the key center to authenticate the key block analyzed from the communication data packet, the key block passing the authentication is fed back to the receiver equipment as a decryption key, and the receiver equipment executes decryption operation by using the decryption key.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present application relates to the field of communication technology, and in particular to a method for securely using quantum keys. Background Art

[0002] Vernam cipher, also known as One-Time-Pad, uses a random, non-repeating set of characters as the output ciphertext. The most important thing here is that once the transformed input ciphertext is used, it will no longer be used in any other message (hence it is a one-time use). The length of the input ciphertext is equal to the length of the original message plaintext. "One-Time-Pad" is currently the most proven and absolutely secure encryption scheme.

[0003] The one-time pad encryption method relies on the randomness of the encryption key and its one-time use. For the traditional method of generating random keys, the randomness is pseudo-random, for example, the pseudo-random numbers generated by classical computers. When the algorithm of the classical computer is cracked, the randomness of the random numbers generated by the algorithm is also threatened. Especially in today's rapid development of quantum technology, the powerful computing power of quantum technology makes it easy to crack traditional algorithms. In response to quantum technology, the one-time pad encryption method based on quantum keys is gradually being used.

[0004] The randomness of quantum keys is guaranteed by the principles of quantum mechanics (for example, the uncertainty principle and quantum entanglement). The global quantum security network is a trusted network that uses quantum encryption for business, ensuring that the use of quantum keys in business can meet the one-time standard. The key can only be used once. For quantum encryption, the quantum key can only be used once. After one use, it is equivalent to key leakage. If it is reused, it faces great risks. Therefore, we must ensure that the key cannot be reused from the communication mechanism to ensure the security of the entire system. As for the one-time use of the key, there is currently no corresponding guarantee method. In view of this, how to confirm that the use of quantum keys is one-time is a technical problem that needs to be solved urgently in the process of ensuring the absolute security of the one-time encryption method. Summary of the invention

[0005] Purpose of the invention: This application provides a method for securely using quantum keys to solve the problems existing in the background technology.

[0006] Technical solution: The present invention provides a method for securely using quantum keys. The participants of the method include a sender device, a receiver device and a key center. The method includes the following steps:

[0007] Step 1: The sending device obtains the key from the key center and obtains the service list locally;

[0008] Step 2: The sending device obtains the key block corresponding to each service in the service list from the obtained key, performs hash calculation on the key block to obtain the hash value of each key block, and generates the key data index of each service in combination with the service number of the corresponding service, integrates the key data indexes of all services, and obtains the key data index table;

[0009] Step 3: The sending device uses the key block obtained in step 2 to perform encryption operations on the service transmission content in the corresponding service, obtains the service ciphertext and updates the key data index table, generates a communication data packet based on the service ciphertext, transmits the communication data packet to the receiving device, and deletes the corresponding key block from the key according to the updated data index table;

[0010] Step 4: The receiving device interacts with the key center based on the received communication data packet. After the key center authenticates the key block parsed from the communication data packet, the authenticated key block is fed back to the receiving device as the decryption key. The receiving device uses the decryption key to perform a decryption operation on the business ciphertext parsed from the communication data packet.

[0011] As an improvement of the present invention, the specific process of step 1 is:

[0012] Step 1-1: Both the sender device and the receiver device complete registration at the key center. The key center issues a key to the registered sender device, and the sender device stores the issued key in the local key pool.

[0013] The keys stored in the key pools of the sending device and the receiving device are in the form of multiple key files;

[0014] Step 1-2: The sending device obtains a list of services to be executed locally, numbers each service in the service list, generates a service biz(n) with a service number, parses the service transmission content of each service, and reads the size of the service transmission content of each service; wherein each service number corresponds to the corresponding service one by one.

[0015] As an improvement of the present invention, the specific process of step 2 is:

[0016] Step 2-1: The sending device obtains a key block of a corresponding size from a local key pool according to the size of the service transmission content of each service, obtains key block related information, and numbers the key block to generate a key block key(n) with a key number;

[0017] The key block related information includes at least the name of the key file where the key block is located, the starting position information in the key file, and the length information of the key block; each key number corresponds to the corresponding business and business number one by one;

[0018] Step 2-2: The sending device performs hash calculation on the key block key(n) obtained in step 2-1 to obtain the hash value of each key block:

[0019] Step 2-2-1: The sending device obtains a key u1 from the local key pool as a random number to generate an irreducible polynomial p1(x). After obtaining the irreducible polynomial, the string consisting of the coefficients of each term except the highest term in the irreducible polynomial p1(x) is recorded as str1;

[0020] Step 2-2-2: The sending device obtains a key u2 from the local key pool and generates a hash function h based on the irreducible polynomial p1(x) and the key u2. p1,u2 , use the hash function to calculate the hash value h of the key block key(n) p1,u2 (key(n)); record the hash function parameters, the hash function parameters include u2 and str1;

[0021] Step 2-3: The sending device combines the service number, key block number, key number, hash value of the key block and whether to use field of each service into the key data index of the service; wherein, the number of key blocks = 1, and the whether to use field includes 0 and 1, wherein 0 indicates unused, and 1 indicates used;

[0022] Step 2-4: The sending device executes steps 2-1 to 2-3 for all services in the order of the service list, obtains the key data indexes of all services and integrates them to obtain a key data index table.

[0023] As an improvement of the present invention, the specific process of step 3 is as follows:

[0024] Step 3-1: The sending device obtains the encryption key from the local key pool through the key block related information, and generates the corresponding hash function h′ according to the hash function parameters p1,u2 , use the hash function to perform hash calculation on the encryption key to obtain a hash value h′ p1,u2 (key(n)), hash value h′ p1,u2 (key(n)) and the hash value h of the key block corresponding to the business in the key data index table p1,u2 (key(n)) is compared, if the hash value h′ p1,u2 (key(n))=h p1,u2 (key(n)), the comparison is successful and the process goes to the next step; otherwise, an error is reported and the process ends;

[0025] Step 3-2: The sending device uses the encryption key obtained in step 3-1 to perform an encryption operation on the service transmission content in the corresponding service, obtains the corresponding service ciphertext cip(n), and combines the key data index, key block related information, hash function parameters, and service ciphertext cip(n) of each service to generate a communication data packet and transmit it to the receiving device; the sending device changes the whether to use field in the key data index of the used encryption key to 1;

[0026] Step 3-3: The sending device compares the key file stored in the key pool with the key data index table, and deletes the key fragment corresponding to the key block whose use field is 1 from the key file.

[0027] As an improvement of the present invention, the step 3-2 may be:

[0028] The sending device uses the encryption key obtained in step 3-1 to perform encryption operations on the business transmission content in the corresponding business, obtains the corresponding business ciphertext cip(n), combines the business number biz(n) and the business ciphertext cip(n) to generate a ciphertext data packet, combines the key data index, key block related information and hash function parameters to generate a key data packet, and transmits the ciphertext data packet and the key data packet to the receiving device in an asynchronous manner.

[0029] As an improvement of the present invention, the specific process of step 4 is as follows:

[0030] Step 4-1: The receiving device receives a communication data packet, and sends the key data index, key block related information, and hash function parameters in the communication data packet to the key center, and the key center obtains the encryption key according to the key block related information;

[0031] Step 4-2: The key center obtains the key key′(n) from the local through the key block related information, and generates the corresponding hash function according to the hash function parameters Use the hash function to perform hash calculation on the key key'(n) to obtain a hash value Hash value Hash value of the key block corresponding to the business in the index table Compare, if the hash value If the comparison is successful, the key key′(n) is fed back to the receiving device as the decryption key; otherwise, an error is reported and the process ends;

[0032] Step 4-3: The receiving device receives the decryption key, uses the decryption key to perform a decryption operation on the business ciphertext cip(n) in the received communication data packet, obtains the business in plaintext, reads the business transmission content, and performs business operations.

[0033] As an improvement of the present invention, the step 2 may be:

[0034] Step 2-1: The sending device obtains multiple sub-key blocks from the local key pool according to the size of the service transmission content of each service, obtains relevant information of the sub-key blocks, and numbers the sub-key blocks to generate sub-key blocks key(nn) with sub-key numbers;

[0035] The sum of the sizes of the multiple sub-key blocks is ≥ the size of the business transmission content; and the size of each sub-key block is 2 n ; The subkey block related information includes at least the name of the key file where the subkey block is located, the starting position information in the key file, and the length information of the subkey block; each subkey number corresponds to the corresponding business and business number one by one;

[0036] Step 2-2: The sending device performs hash calculation on the multiple sub-key blocks obtained in step 2-1 to obtain the sub-hash value of each sub-key block:

[0037] Step 2-2-1: The sending device obtains a key v1 from the local key pool as a random number to generate an irreducible polynomial p2(x). After obtaining the irreducible polynomial, the string consisting of the coefficients of each term except the highest term in the irreducible polynomial p2(x) is recorded as str2;

[0038] Step 2-2-2: The sending device obtains a key v2 from the local key pool and generates a hash function based on the irreducible polynomial p2(x) and the key v2. Use the hash function to calculate the hash value h of the subkey block key(nn) p2,v2 (key(nn)); record sub-hash function parameters, the sub-hash function parameters include v2, str2;

[0039] Step 2-3: Concatenate the sub-hash values ​​of all sub-key blocks used for a business and calculate the hash value of the concatenated result:

[0040] Step 2-3-1: The sending device obtains a key s1 from the local key pool as a random number to generate an irreducible polynomial p3(x). After obtaining the irreducible polynomial, the string consisting of the coefficients of each term except the highest term in the irreducible polynomial p3(x) is recorded as str3;

[0041] Step 2-3-2: The sending device obtains a key s2 from the local key pool and generates a hash function h based on the irreducible polynomial p3(x) and the key s2. p3,s2 , use the hash function to calculate the hash value h of the splicing result p3,s2(key); record the total hash function parameters, the total hash function parameters include s2, str3;

[0042] Step 2-4: The sending device combines the service number, key block number, subkey number, hash value of the splicing result and whether to use the field of each service into the key data index of the service; wherein the key block number is greater than 1;

[0043] Step 2-5: The sending device executes steps 2-1 to 2-4 for all services in the order of the service list, obtains the key data indexes of all services and integrates them to obtain a key data index table.

[0044] As an improvement of the present invention, the step in step 3 in which the sending device uses the key block obtained in step 2 to perform an encryption operation on the service transmission content in the corresponding service is:

[0045] Step 3-1: Check the number of key blocks in the key data index. In response to the number of key blocks being greater than 1, first generate a hash function for the sub-key block according to the sub-hash function parameters, and calculate the sub-hash value of the sub-key block; then generate a hash function for the concatenation result according to the total hash function parameters, and calculate the hash value of the concatenation result;

[0046] Step 3-2: Compare the hash value of the concatenated result with the hash value in the key index table obtained in step 2-5. If the comparison is consistent, perform the encryption operation.

[0047] Beneficial effects:

[0048] 1. Before encrypting business data, the sender's device will perform a key authentication to ensure that the encryption key has not been tampered with by bad users during the aforementioned process, and that the key has not changed due to device problems. The encryption key comes from the ciphertext file issued by the key center, which effectively ensures the security of the use of the encryption key and ensures that the ciphertext received by the receiving device is valid ciphertext, that is, the decryption key used to decrypt the ciphertext can be addressed in the key center;

[0049] 2. The receiving device does not need to obtain all key files in advance. It only needs to obtain the key fragment related to this business from the key center according to the key-related information in the communication package, which can effectively save the key storage space in the receiving device;

[0050] 3. The key center performs authentication operations on the encryption key based on the key information sent by the receiving device (including key-related information, hash value of the key block, and hash parameters), which is equivalent to authenticating the encryption key from the source, ensuring the safe use of quantum keys;

[0051] 4. The receiving device only sends key-related information to the key center for authentication. The transmission process does not involve ciphertext, that is, it does not involve business transmission content. Therefore, the entire solution can ensure that business transmission content is only transmitted in ciphertext between the sending device and the receiving device, ensuring the transmission security of business content;

[0052] 5. The usage of the corresponding key fragment is recorded through the identification of the "used" field in the data structure, and the key usage is traceable. By comparing the key file with the data structure, the used keys and unused keys in the key file can be distinguished. The unused keys can be used for other businesses, and the used keys are no longer reused because the identification of the "used" field is deleted, thereby improving the utilization efficiency of the keys and reducing the system workload and storage space. BRIEF DESCRIPTION OF THE DRAWINGS

[0053] In order to more clearly illustrate the technical solutions in the embodiments of the present application, the drawings required for use in the description of the embodiments will be briefly introduced below. Obviously, the drawings described below are only some embodiments of the present application. For ordinary technicians in this field, other drawings can be obtained based on these drawings without paying creative labor.

[0054] Figure 1 A connection diagram of the participants of this application method;

[0055] Figure 2 Schematic diagram of the process of this application. DETAILED DESCRIPTION

[0056] In order to make the purpose, technical solutions and advantages of the present application clearer, the present application will be further described in detail below in conjunction with the accompanying drawings. Obviously, the described embodiments are only part of the embodiments of the present application, rather than all the embodiments. Based on the embodiments in the present application, all other embodiments obtained by ordinary technicians in this field without making creative work are within the scope of protection of the present application.

[0057] The present invention provides a method for securely using quantum keys, wherein the participants of the method include a sender device, a receiver device and a key center. Figure 1 As shown, the key center provides registration, authentication, and key management tasks for the device side, and the key management includes generation, relaying, downloading, and deletion. The device side includes the sender device and the receiver device, each of which is configured with a key pool to provide key support for tasks such as quantum encryption and decryption, hash operations, etc. on the device side, which can ensure that user services provide quantum security services through the device side.

[0058] like Figure 2 As shown, the method comprises the following steps:

[0059] Step 1: The sending device obtains the key from the key center and obtains the service list locally.

[0060] Specifically:

[0061] Step 1-1: Both the sender device and the receiver device complete registration in the key center. The key center issues keys to the registered sender device, and the sender device stores the issued keys in the local key pool. It should be noted that at this time, the key center can synchronize the keys issued to the sender device to the receiver device, and the receiver device stores the received keys in the local key pool. Alternatively, the receiver device does not need to obtain all key files in advance, but only needs to obtain the key fragments related to this business from the key center according to the key-related information in the communication package, which can effectively save the key storage space in the receiver device.

[0062] Step 1-2: The sending device obtains a list of services to be executed locally, numbers each service in the service list, generates a service biz(n) with a service number, for example, service biz(1), service biz(2)...service biz(n), and parses the service transmission content of each service, and reads the size of the service transmission content of each service; wherein each service number corresponds to the corresponding service one by one.

[0063] Step 2: The sending device obtains the key block corresponding to each service in the service list from the acquired key, performs hash calculation on the key block to obtain the hash value of each key block, and generates the key data index for each service in combination with the service number of the corresponding service, integrates the key data indexes of all services, and obtains the key data index table.

[0064] Specifically:

[0065] Step 2-1: The sending device obtains a key block of a corresponding size from a local key pool according to the size of the service transmission content of each service, obtains key block related information, and numbers the key blocks to generate a key block key(n) with a key number, for example, a key block key(1) corresponding to service biz(1), a key block key(2) corresponding to service biz(2), and so on, a key block key(n) corresponding to service biz(n);

[0066] The key block related information includes at least the name of the key file where the key block is located, the starting position information in the key file, and the length information of the key block; each key number corresponds to the corresponding business and business number one by one;

[0067] In some embodiments, the sending device may directly obtain a key equal to the size of the transmission content of the service from a local key pool as the encryption key of the service.

[0068] Step 2-2: The sending device performs hash calculation on the key block key(n) obtained in step 2-1 to obtain the hash value of each key block:

[0069] Step 2-2-1: The sending device obtains a key u1 from the local key pool as a random number to generate an irreducible polynomial p1(x). After obtaining the irreducible polynomial, the string consisting of the coefficients of each term except the highest term in the irreducible polynomial p1(x) is recorded as str1;

[0070] Step 2-2-2: The sending device obtains a key u2 from the local key pool and generates a hash function based on the irreducible polynomial p1(x) and the key u2 Use this hash function to calculate the hash value of the key block key(n) Recording hash function parameters, where the hash function parameters include u2 and str1;

[0071] For example, in some embodiments, the sending device may generate a first hash function H1 for each key block, input the key block into the corresponding first hash function H1 to calculate the hash value of each key block, which is recorded as h1, h2, ...

[0072] In other embodiments, in order to save computing power, only one second hash function H2 may be generated within a certain time interval, and the key blocks corresponding to the services within the time interval may be respectively input into the second hash function H2, and the second hash value of each key block within the time interval is calculated, which is recorded as h1, h2, ...; in the next time interval, a third hash function H3 is generated, and the key blocks corresponding to the services within the time interval are respectively input into the third hash function H3, and the third hash value of each key block within the time interval is calculated, which is recorded as h7, h8, ...; and so on, to calculate the hash value of each key block.

[0073] Step 2-3: As shown in Table 1 below, the sending device combines the service number, key block number, key number, hash value of the key block and whether the field "used" is used for each service into the key data index of the service; wherein, the number of key blocks = 1, the whether the field "used" includes 0 and 1, the 0 is the initial value, indicating that it has not been used, and the 1 indicates that it has been used;

[0074] Table 1. Key data index

[0075]

[0076] Step 2-4: As shown in Table 2 below, the sending device executes steps 2-1 to 2-3 for all services in the order of the service list, obtains the key data indexes of all services and integrates them to obtain a key data index table.

[0077] Table 2. Key data index table

[0078]

[0079] Step 3: The sending device uses the key block obtained in step 2 to perform encryption operations on the business transmission content in the corresponding business, obtains the business ciphertext and updates the key data index table, generates a communication data packet based on the business ciphertext, transmits the communication data packet to the receiving device, and deletes the corresponding key block from the key according to the updated data index table.

[0080] Since a series of operations have been performed in the previous order, in order to ensure that the encryption key has not been tampered with by bad users during the above process, and the key has not changed due to equipment problems, for example: the key stored on the disk has changed due to bit inversion of electromagnetic signals. Therefore, before performing the encryption operation, the sending device needs to verify the key. Specifically:

[0081] Step 3-1: The sending device obtains the encryption key from the local key pool through the key block related information, and generates the corresponding hash function according to the hash function parameters Use the hash function to perform a hash calculation on the encryption key to obtain a hash value Hash value Hash value of the key block corresponding to the service in the key data index table Compare, if the hash value If the comparison is successful, proceed to the next step; otherwise, an error is reported and the process ends;

[0082] Step 3-2: The sending device uses the encryption key obtained in step 3-1 to perform an encryption operation on the service transmission content in the corresponding service, obtains the corresponding service ciphertext cip(n), and combines the key data index, key block related information, hash function parameters, and service ciphertext cip(n) of each service to generate a communication data packet as shown in Table 3 below and transmit it to the receiving device; the sending device changes the whether to use field in the key data index of the used encryption key to 1;

[0083] Table 3. Communication data packets

[0084]

[0085] To ensure the security of data packet transmission, the data packet may be split into a ciphertext data packet and a key data packet. In this case, step 3-2 may also be:

[0086] The sending device uses the encryption key obtained in step 3-1 to perform encryption operations on the business transmission content in the corresponding business, obtain the corresponding business ciphertext cip(n), combine the business number biz(n) and the business ciphertext cip(n) to generate a ciphertext data packet, combine the key data index, key block related information and hash function parameters to generate a key data packet, and transmit the ciphertext data packet and the key data packet to the receiving device in an asynchronous manner. In this way, not only the probability of the ciphertext data and the key data being intercepted at the same time is reduced, but also the difficulty of cracking the ciphertext after interception is increased. . Similarly, the sending device changes the whether to use field in the key data index of the used encryption key to 1. If a bad user intercepts on the transmission path, the asynchronous transmission method reduces the possibility of the bad user directly intercepting the ciphertext data and the key data at the same time. Of course, in this scheme, the key data packet only involves key related information and does not directly transmit the key. Therefore, even if the bad user intercepts the key data packet, he cannot obtain the key content, let alone decrypt the ciphertext.

[0087] Step 3-3: The sending device compares the key file stored in the key pool with the key data index table, and deletes the key fragment corresponding to the key block whose use field is 1 from the key file, ensuring that the remaining keys in the key file are unused keys, thereby improving the utilization efficiency of the key and reducing the system workload and storage space.

[0088] Step 4: The receiving device interacts with the key center based on the received communication data packet. After the key center authenticates the key block parsed from the communication data packet, the authenticated key block is fed back to the receiving device as the decryption key. The receiving device uses the decryption key to perform a decryption operation on the business ciphertext parsed from the communication data packet.

[0089] Specifically:

[0090] Step 4-1: The receiving device receives a communication data packet, and sends the key data index, key block related information, and hash function parameters in the communication data packet to the key center, and the key center obtains the encryption key according to the key block related information;

[0091] Step 4-2: The key center obtains the key key′(n) from the local through the key block related information, and generates the corresponding hash function according to the hash function parameters Use this hash function to perform hash calculation on the key key′(n) to get the hash value Hash value Hash value of the key block corresponding to the business in the index table Compare, if the hash value If the comparison is successful, the encryption key key′(n) is fed back to the receiving device as the decryption key; otherwise, an error is reported and the process ends;

[0092] Step 4-3: The receiving device receives the decryption key, uses the decryption key to perform a decryption operation on the business ciphertext cip(n) in the received communication data packet, obtains the business in plaintext, reads the business transmission content, and performs business operations.

[0093] In another embodiment of the present invention, in the method for securely using quantum keys of the present invention, step 2 may also be:

[0094] Step 2-1: The sending device obtains multiple sub-key blocks from the local key pool according to the size of the service transmission content of each service, obtains relevant information of the sub-key blocks, and numbers the sub-key blocks to generate sub-key blocks key(nn) with sub-key numbers;

[0095] The sum of the sizes of the multiple sub-key blocks is ≥ the size of the business transmission content; and the size of each sub-key block is 2 n ; The subkey block related information includes at least the name of the key file where the subkey block is located, the starting position information in the key file, and the length information of the subkey block; each subkey number corresponds to the corresponding business and business number one by one;

[0096] Step 2-2: The sending device performs hash calculation on the multiple sub-key blocks obtained in step 2-1 to obtain the sub-hash value of each sub-key block:

[0097] Step 2-2-1: The sending device obtains a key v1 from the local key pool as a random number to generate an irreducible polynomial p2(x). After obtaining the irreducible polynomial, the string consisting of the coefficients of each term except the highest term in the irreducible polynomial p2(x) is recorded as str2;

[0098] Step 2-2-2: The sending device obtains a key v2 from the local key pool and generates a hash function h based on the irreducible polynomial p2(x) and the key v2. p2,v2 , use this hash function to calculate the hash value h of the subkey block key(nn) p2,v2 (key(nn)); record sub-hash function parameters, the sub-hash function parameters include v2, str2;

[0099] Step 2-3: Concatenate the sub-hash values ​​of all sub-key blocks used for a business and calculate the hash value of the concatenated result:

[0100] Step 2-3-1: The sending device obtains a key s1 from the local key pool as a random number to generate an irreducible polynomial p3(x). After obtaining the irreducible polynomial, the string consisting of the coefficients of each term except the highest term in the irreducible polynomial p3(x) is recorded as str3;

[0101] Step 2-3-2: The sending device obtains a key s2 from the local key pool and generates a hash function h based on the irreducible polynomial p3(x) and the key s2. p3,s2 , use this hash function to calculate the hash value of the concatenated result Recording total hash function parameters, where the total hash function parameters include s2 and str3;

[0102] Step 2-4: The sending device combines the service number, key block number, subkey number, hash value of the splicing result and whether to use the field of each service into the key data index of the service; wherein the key block number is greater than 1;

[0103] It should be noted that the parameter number of key blocks is for the case where there are sub-key blocks. This parameter indicates the number of sub-key blocks. If it is 1, it means there are no sub-key blocks. If it is an integer greater than 1, it means there are sub-key blocks for verification by the receiving device during hash value authentication.

[0104] Step 2-5: The sending device executes steps 2-1 to 2-4 for all services in the order of the service list, obtains the key data indexes of all services and integrates them to obtain a key data index table.

[0105] In this embodiment, the step in step 3 in which the sending device uses the key block obtained in step 2 to perform an encryption operation on the service transmission content in the corresponding service is:

[0106] Step 3-1: Check the number of key blocks in the key data index. If the number of key blocks is greater than 1, it means that the key block used for encryption includes a corresponding number of sub-key blocks. The hash function parameters at this time include the total hash function parameters and the sub-hash function parameters. First, generate a hash function for the sub-key block according to the sub-hash function parameters, calculate the sub-hash value of the sub-key block, and concatenate all the sub-hash values ​​to obtain the concatenation result. Then, generate a hash function for the concatenation result according to the total hash function parameters, and calculate the hash value of the concatenation result. It should be noted that the calculation process of the hash value in this step is the same as that in step 2-2, and will not be repeated here. For example, first generate a hash function for the sub-key block according to the sub-hash function parameters, calculate the sub-hash value h21′ of the first sub-key block key(21) and the sub-hash value h22′ of the second sub-key block key(22), and then generate a hash function for the key block key(2) according to the total hash function parameters, and calculate the hash value h2′ of (h21′, h22′).

[0107] Step 3-2: Compare the hash value h2′ of the concatenated result with the hash value in the key index table obtained in step 2-5. If the comparison is consistent, it proves that the key has not been changed and the encryption operation can be performed.

[0108] In this embodiment, in step 4, the key center extracts the corresponding key according to the key block related information. Similarly, it can be clearly determined whether the extracted key is a total key block or a sub-key block according to the number of key blocks. The key center uses the authentication method used in the encryption operation in step 3 to authenticate the extracted total key block and / or sub-key block. In response to the calculated hash value being consistent with the received "hash value of the key block", it indicates that the extracted key is used correctly, and the extracted key is fed back to the receiving device as a decryption key for it to perform a decryption operation.

Claims

1. A method for securely using quantum keys, characterized in that: The participants of the method include a sender device, a receiver device and a key center; the method includes the following steps: Step 1: The sending device obtains the key from the key center and obtains the service list locally; Step 2: The sending device obtains the key block corresponding to each service in the service list from the obtained key, performs hash calculation on the key block to obtain the hash value of each key block, and generates the key data index of each service in combination with the service number of the corresponding service, integrates the key data indexes of all services, and obtains the key data index table; Step 3: The sending device uses the key block obtained in step 2 to perform encryption operations on the service transmission content in the corresponding service, obtains the service ciphertext and updates the key data index table, generates a communication data packet based on the service ciphertext, transmits the communication data packet to the receiving device, and deletes the corresponding key block from the key according to the updated data index table; Step 4: The receiving device interacts with the key center based on the received communication data packet. After the key center authenticates the key block parsed from the communication data packet, the authenticated key block is fed back to the receiving device as the decryption key. The receiving device uses the decryption key to perform a decryption operation on the business ciphertext parsed from the communication data packet.

2. The method for securely using quantum keys according to claim 1, characterized in that: The specific process of step 1 is as follows: Step 1-1: Both the sender device and the receiver device complete registration at the key center. The key center issues a key to the registered sender device, and the sender device stores the issued key in the local key pool. The keys stored in the key pools of the sending device and the receiving device are in the form of multiple key files; Step 1-2: The sending device obtains a list of services to be executed locally, numbers each service in the service list, generates a service biz(n) with a service number, parses the service transmission content of each service, and reads the size of the service transmission content of each service; wherein each service number corresponds to the corresponding service one by one.

3. The method for securely using quantum keys according to claim 2, characterized in that: The specific process of step 2 is: Step 2-1: The sending device obtains a key block of a corresponding size from a local key pool according to the size of the service transmission content of each service, obtains key block related information, and numbers the key block to generate a key block key(n) with a key number; The key block related information includes at least the name of the key file where the key block is located, the starting position information in the key file, and the length information of the key block; each key number corresponds to the corresponding business and business number one by one; Step 2-2: The sending device performs hash calculation on the key block key(n) obtained in step 2-1 to obtain the hash value of each key block: Step 2-2-1: The sending device obtains a key u1 from the local key pool as a random number to generate an irreducible polynomial p1(x). After obtaining the irreducible polynomial, the string consisting of the coefficients of each term except the highest term in the irreducible polynomial p1(x) is recorded as str1; Step 2-2-2: The sending device obtains a key u2 from the local key pool and generates a hash function based on the irreducible polynomial p1(x) and the key u2 Use the hash function to calculate the hash value of the key block key(n) Recording hash function parameters, where the hash function parameters include u2 and str1; Step 2-3: The sending device combines the service number, key block number, key number, hash value of the key block and whether to use field of each service into the key data index of the service; wherein, the number of key blocks = 1, and the whether to use field includes 0 and 1, wherein 0 indicates unused, and 1 indicates used; Step 2-4: The sending device executes steps 2-1 to 2-3 for all services in the order of the service list, obtains the key data indexes of all services and integrates them to obtain a key data index table.

4. The method for securely using quantum keys according to claim 3, characterized in that: The specific process of step 3 is as follows: Step 3-1: The sending device obtains the encryption key from the local key pool through the key block related information, and generates the corresponding hash function according to the hash function parameters Use the hash function to perform hash calculation on the encryption key to obtain a hash value Hash value Hash value of the key block corresponding to the service in the key data index table Compare, if the hash value If the comparison is successful, proceed to the next step; Otherwise, report an error and end the process; Step 3-2: The sending device uses the encryption key obtained in step 3-1 to perform an encryption operation on the service transmission content in the corresponding service, obtains the corresponding service ciphertext cip(n), and combines the key data index, key block related information, hash function parameters, and service ciphertext cip(n) of each service to generate a communication data packet and transmit it to the receiving device; the sending device changes the whether to use field in the key data index of the used encryption key to 1; Step 3-3: The sending device compares the key file stored in the key pool with the key data index table, and deletes the key fragment corresponding to the key block whose use field is 1 from the key file.

5. The method for securely using quantum keys according to claim 4, characterized in that: The step 3-2 may be: The sending device uses the encryption key obtained in step 3-1 to perform encryption operations on the business transmission content in the corresponding business, obtains the corresponding business ciphertext cip(n), combines the business number biz(n) and the business ciphertext cip(n) to generate a ciphertext data packet, combines the key data index, key block related information and hash function parameters to generate a key data packet, and transmits the ciphertext data packet and the key data packet to the receiving device in an asynchronous manner.

6. The method for securely using quantum keys according to claim 4, characterized in that: The specific process of step 4 is as follows: Step 4-1: The receiving device receives a communication data packet, and sends the key data index, key block related information, and hash function parameters in the communication data packet to the key center, and the key center obtains the encryption key according to the key block related information; Step 4-2: The key center obtains the key key′(n) from the local through the key block related information, and generates the corresponding hash function according to the hash function parameters Use the hash function to perform hash calculation on the key key'(n) to obtain a hash value Hash value Hash value of the key block corresponding to the business in the index table Compare, if the hash value If the comparison is successful, the key key′(n) is fed back to the receiving device as the decryption key; otherwise, an error is reported and the process ends; Step 4-3: The receiving device receives the decryption key, uses the decryption key to perform a decryption operation on the business ciphertext cip(n) in the received communication data packet, obtains the business in plaintext, reads the business transmission content, and performs business operations.

7. The method for securely using quantum keys according to claim 1, characterized in that: The step 2 may be: Step 2-1: The sending device obtains multiple sub-key blocks from the local key pool according to the size of the service transmission content of each service, obtains relevant information of the sub-key blocks, and numbers the sub-key blocks to generate sub-key blocks key(nn) with sub-key numbers; The sum of the sizes of the multiple sub-key blocks is ≥ the size of the business transmission content; and the size of each sub-key block is 2 n ; The subkey block related information includes at least the name of the key file where the subkey block is located, the starting position information in the key file, and the length information of the subkey block; each subkey number corresponds to the corresponding business and business number one by one; Step 2-2: The sending device performs hash calculation on the multiple sub-key blocks obtained in step 2-1 to obtain the sub-hash value of each sub-key block: Step 2-2-1: The sending device obtains a key v1 from the local key pool as a random number to generate an irreducible polynomial p2(x). After obtaining the irreducible polynomial, the string consisting of the coefficients of each term except the highest term in the irreducible polynomial p2(x) is recorded as str2; Step 2-2-2: The sending device obtains a key v2 from the local key pool and generates a hash function based on the irreducible polynomial p2(x) and the key v2. Use the hash function to calculate the hash value of the subkey block key(nn) Record sub-hash function parameters, where the sub-hash function parameters include v2 and str2; Step 2-3: Concatenate the sub-hash values ​​of all sub-key blocks used for a business and calculate the hash value of the concatenated result: Step 2-3-1: The sending device obtains a key s1 from the local key pool as a random number to generate an irreducible polynomial p3(x). After obtaining the irreducible polynomial, the string consisting of the coefficients of each term except the highest term in the irreducible polynomial p3(x) is recorded as str3; Step 2-3-2: The sending device obtains a key s2 from the local key pool and generates a hash function based on the irreducible polynomial p3(x) and the key s2. Use the hash function to calculate the hash value of the concatenation result Recording total hash function parameters, where the total hash function parameters include s2 and str3; Step 2-4: The sending device combines the service number, key block number, subkey number, hash value of the splicing result and whether to use the field of each service into the key data index of the service; wherein the key block number is greater than 1; Step 2-5: The sending device executes steps 2-1 to 2-4 for all services in the order of the service list, obtains the key data indexes of all services and integrates them to obtain a key data index table.

8. The method for securely using quantum keys according to claim 7, characterized in that: In step 3, the sending device uses the key block obtained in step 2 to perform encryption operation on the service transmission content in the corresponding service: Step 3-1: Check the number of key blocks in the key data index. In response to the number of key blocks being greater than 1, first generate a hash function for the sub-key block according to the sub-hash function parameters, and calculate the sub-hash value of the sub-key block; then generate a hash function for the concatenation result according to the total hash function parameters, and calculate the hash value of the concatenation result; Step 3-2: Compare the hash value of the concatenated result with the hash value in the key index table obtained in step 2-5. If the comparison is consistent, perform the encryption operation.