Working system based on quantum key device and working method thereof
Through a working system based on the quantum key device, the one-time use of quantum keys and the security of the encryption process are ensured, and the security of classical encryption algorithms is solved in the era of quantum computing, and a high-security communication solution is realized.
Patent Information
- Application Number
- CN202510182190.1
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-02-19
- Publication Date
- 2025-05-16
AI Technical Summary
Classical encryption algorithms are insufficient in the era of quantum computing, especially the security of key distribution and management is difficult to guarantee, and there are problems such as man-in-the-middle attacks and long-term security deficiency.
The working system based on the quantum key device is adopted to communicate through the quantum key device at the sending end and the receiving end, ensuring the one-time use of quantum keys, and using technical means such as hash calculation and key block authentication to ensure the security of the encryption process.
It realizes the one-time use of quantum keys during the encryption process, improves data security during the communication process, reduces the risk of man-in-the-middle attacks, and ensures long-term security.
Smart Images

Figure CN120017263A_ABST
Abstract
Description
Technical Field
[0001] The present application relates to the field of information security technology, and in particular to a working system based on a quantum key device and a working method thereof. Background Art
[0002] The advantages of classical encryption algorithms are their maturity, reliability, efficiency and ease of implementation. They have been verified for a long time and are widely adopted. They have fast computing speed and low resource consumption, and are suitable for large-scale data encryption and resource-constrained devices. At the same time, the algorithms are open and transparent, with rich development tools, supporting multiple encryption modes and flexible key management. However, the security of classical encryption algorithms depends on computational complexity. Traditional key distribution methods (such as Diffie-Hellman) are vulnerable to quantum computing attacks, and there are algorithm vulnerabilities and key distribution problems. Key management is complex and may be subject to man-in-the-middle attacks. In particular, the Shor algorithm can crack encryption systems based on large number decomposition and discrete logarithms, and there are problems such as complex key distribution and insufficient long-term security. Even if the current data is protected by classical encryption, due to insufficient long-term security, future technological advances may decrypt the current encrypted data. Some algorithms have large computational complexity at high security levels, which may affect system performance, especially on resource-constrained devices. In the future, post-quantum cryptography and hybrid encryption schemes will become important development directions.
[0003] Quantum encryption is crucial in the communication process, especially under the threat of quantum computing, and can provide unconditional secure communication guarantee. Despite the technical and cost challenges, it has broad application prospects in government, finance, medical care, and the Internet of Things. With the advancement of technology, quantum encryption will become the core technology for future communication security.
[0004] The use of quantum key one-time-pad (OTP) is theoretically unconditionally secure and can solve the limitations of classical cryptography in the era of quantum computing, providing an unconditionally secure communication solution. However, the use of one-time-pad also has the problem of difficult to ensure the security of key distribution and management. If the quantum key is reused, the attacker may collect enough ciphertexts and known plaintexts, use quantum computing or classical algorithms to crack the key, and then obtain the encrypted information. The security of quantum key distribution depends on the one-time use of the key. Reusing the key will weaken the data security during the communication process and increase the possibility of communication data being cracked. If the key is reused, the attacker only needs to crack one key to obtain the content of multiple communications, without having to crack each communication separately, which brings serious security risks. Summary of the invention
[0005] Purpose of the invention: The present application provides a working system and a working method based on a quantum key device to ensure that the quantum key is used once during the encryption process.
[0006] Technical solution: The present invention provides a working method of a working system based on a quantum key device, which is executed by the working system based on the quantum key device. The working system based on the quantum key device includes a transmitting end and a receiving end. The working method includes the following steps:
[0007] Step 1: The sender obtains a service list, numbers multiple services in the service list, obtains service numbers, and updates each service number and corresponding service to the service list;
[0008] Step 2: The sender obtains the key block of each service, records the total key position information of the key block, performs hash calculation on the key information to obtain the hash value, and records the hash calculation parameters, associates each service with the key information, hash value, and hash calculation parameters to form a one-to-one correspondence, and updates it to the service list;
[0009] Step 3: The sending end performs encryption operations on each service in the service list and transmits it to the receiving end;
[0010] Step 4: The receiving end performs an authentication operation. After the authentication is passed, the receiving end performs a decryption operation on each encrypted service;
[0011] Step 5: The receiving end sends the result of the authentication operation to the sending end, and the sending end performs an operation on the key based on the result of the authentication operation.
[0012] As an improvement of the present invention, the step 1 comprises:
[0013] Step 1-1: The sending service area of the sending end works, and the service acquisition unit in the sending service area acquires the service list of the sending end, numbers multiple services in the service list, and obtains multiple service numbers;
[0014] Step 1-2: The service acquisition unit parses the service volume L of each service, and associates each service in the service list with its service number and service volume L to form a one-to-one correspondence, and updates the service list; wherein each service includes a service number and service content.
[0015] As an improvement of the present invention, the step 2 comprises:
[0016] Step 2-1: The service acquisition unit in the sending service area of the sending end sends the service volume size L of each service to the key block processing unit in the sending service area, and at the same time sends each service to the key usage recording unit and encryption unit in the sending service area;
[0017] Step 2-2: The key block processing unit obtains a key block of a corresponding size corresponding to the service from the local quantum key pool of the sending end according to the service volume size L, records the total key position information of the key block, and numbers the key block to obtain a key number corresponding to the service number, records the key block with the key number as an encryption key block KEYn, sends the encryption key block KEYn to the hash calculation unit and the encryption unit in the sending service area, and sends the total key position information to the key usage recording unit in the sending service area;
[0018] Step 2-3: The hash calculation unit performs hash calculation on the encryption key block KEYn obtained in step 2-2 to obtain the hash value h of each encryption key block KEYn. p1,s (KEYn);
[0019] Step 2-4: The key usage record unit creates the service, the total key location information of the encryption key KEYn, and the hash value h of the encryption key block KEYn for each service. p1,s The corresponding relationship between (KEYn) is updated in the business list.
[0020] As an improvement of the present invention, in step 2-2, the specific process of the key block processing unit obtaining a plurality of key blocks of corresponding sizes from the local quantum key pool of the transmitting end according to the service volume size L of each service is as follows:
[0021] Step 2-2-1: For the first service in the service list, the key processing unit obtains a plurality of keys of different sizes from the local quantum key pool in advance as a plurality of supplementary key blocks, and the key length of each supplementary key block is less than or equal to n; the key processing unit also records the position information of the plurality of supplementary key blocks in the key file in the local quantum key pool of the sending end, wherein the position information of the supplementary key block includes the starting position and the key length of the supplementary key block;
[0022] Step 2-2-2: the key processing unit randomly generates a positive integer N less than or equal to n, obtains a first key key1 of the first service with a length of (LN) from the key file, and records the position information of the first key key1 in the key file; then obtains any first supplementary key key2 of the first service with a length of N from multiple supplementary key blocks, and combines the first key key1 and the first supplementary key key2 into a first encryption key block KEY1 for the first service; the first encryption key block KEY1 also includes total key position information, and the total key position information includes the position information of the first key key1 and the position information of the first supplementary key key2;
[0023] Step 2-2-3: The key processing unit executes S2-2-1 to S2-2-2 on all remaining services in the order in the service list to obtain the encryption key block KEYn of each service.
[0024] As an improvement of the present invention, the step 2-3 comprises:
[0025] Step 2-3-1: The hash calculation unit obtains a key u from the local quantum key pool as a random number to generate an irreducible polynomial p1(x). After obtaining the irreducible polynomial, the string consisting of the coefficients of each term except the highest term in the irreducible polynomial p1(x) is recorded as str1;
[0026] Step 2-3-2: The hash calculation unit obtains a key s as a random number from the local quantum key pool and generates a hash function h based on the irreducible polynomial p1(x) and the random number s. p1,s , use the hash function to calculate the hash value h of the encryption key block KEYn p1,s (KEYn), and record the hash calculation parameters; wherein the hash calculation parameters include the random number s and the string str1.
[0027] As an improvement of the present invention, the step 3 comprises:
[0028] Step 3-1: The encryption unit uses the encryption key block KEYn received from step 2-2 to encrypt the service content received from step 1-2, obtains the service ciphertext, transmits the service ciphertext and service number to the sending unit, and at the same time, notifies the key usage recording unit to transmit the total key location information of the encryption key block KEYn to the sending unit. The key usage recording unit interacts with the hash calculation unit based on this notification and notifies the hash calculation unit to convert the hash value h p1,s (KEYn) and hash calculation parameters are transmitted to the sending unit;
[0029] Step 3-2: The sending unit sends the received service ciphertext, service number, total key location information and hash value h p1,s (KEYn) and hash calculation parameters are combined into the communication content mes(n) of each business, and mes(n) is sent to the receiving end.
[0030] As an improvement of the present invention, step 4 includes:
[0031] Step 4-1: The receiving service area of the receiving end works. The data parsing unit in the receiving service area parses the received mes(n) to obtain the service ciphertext, service number, total key location information and hash value h p1,s(KEYn), hash calculation parameters; according to the total key location information, obtain the decryption key block KEYn' from the key file in the local quantum key pool of the receiving end; the data parsing unit converts the hash value h p1,s (KEYn), hash calculation parameters and decryption key block KEYn' are sent to the authentication unit for authentication;
[0032] Step 4-2: The authentication unit generates a hash function h′ based on the hash calculation parameters p1,s , use the hash function to calculate the hash value of the decryption key block KEYn' to obtain the hash value h' p1,s (KEYn), compare the calculated hash value h′ p1,s (KEYn) and the parsed hash value h p1,s (KEYn), if they are equal, the authentication operation is passed. The authentication unit notifies the data parsing unit according to the authentication result to send the service ciphertext and decryption key block KEYn' to the decryption unit to perform the decryption operation, and the receiving end obtains the decrypted service.
[0033] As an improvement of the present invention, the step 5 comprises:
[0034] The authentication unit at the receiving end feeds back the authentication result to the quantum key device at the sending end, the feedback receiving unit in the quantum key device at the sending end receives the feedback, and notifies the key usage recording unit to record that the encryption key block KEYn has been used according to the feedback result, and the key usage recording unit notifies the quantum key pool to delete the key part corresponding to the encryption key block KEYn according to the used record;
[0035] Alternatively, the authentication unit at the receiving end feeds back the authentication failure result to the quantum key device at the sending end, the feedback receiving unit in the quantum key device at the sending end receives the feedback and, based on the feedback result, notifies the key usage recording unit to record that the encryption key block KEYn is not used, and the key usage recording unit notifies the key processing unit to re-obtain the key block for the service based on the unused record, and restarts the transmission process of the service.
[0036] As an improvement of the present invention, a working system based on a quantum key device is also provided, which is used to execute the working method of the working system based on the quantum key device mentioned above, including a sending end and a receiving end, wherein the sending end and the receiving end are respectively associated with a quantum key device, and the sending end and the receiving end are communicatively connected through their respective quantum key devices; the sending end is used to encrypt the service using the quantum key device and then transmit it to the receiving end, and the receiving end is used to authenticate and decrypt the received service using the quantum key device.
[0037] As an improvement of the present invention, the quantum key device includes a sending service area and a receiving service area, wherein the sending service area and the receiving service area are communicatively connected, the sending service area is used to obtain services and encrypt the obtained services, and the receiving service area is used to perform authentication operations and decryption processing on the received encrypted services; the quantum key device also includes a quantum key pool, which is independent of the sending service area and the receiving service area, or is located in the sending service area, and is used to provide key files;
[0038] The sending service area includes: a service acquisition unit, a key block processing unit, an encryption unit, a hash calculation unit, a key usage recording unit, and a sending unit;
[0039] The key processing unit is respectively connected to the service acquisition unit, the encryption unit, the hash calculation unit, the key usage recording unit, and the sending unit; the encryption unit is also connected to the service acquisition unit, the key usage recording unit, and the sending unit; the service acquisition unit is also connected to the key usage recording unit; the hash calculation unit is also connected to the key usage recording unit and the sending unit; the key usage recording unit is also connected to the sending unit; the quantum key pool is connected to the key processing unit and the key usage recording unit in the sending service area;
[0040] Among them, the service acquisition unit is used to obtain the service list; the key block processing unit is used to obtain the key block corresponding to the service from the quantum key pool, and record the total key position information of the key block; the encryption unit is used to perform encryption operations on each service in the service list; the hash calculation unit is used to perform hash calculation on the key block to obtain a hash value and record the hash calculation parameters; the key usage recording unit is used to record the total key position information and hash value corresponding to the key block; the sending unit is used to integrate the encrypted service, total key position information, hash value, and hash calculation parameters into communication content and then send it;
[0041] The receiving service area includes: feedback receiving unit, decryption unit, authentication unit, and data parsing unit;
[0042] The authentication unit is respectively connected to the data analysis unit and the decryption unit in communication, the feedback receiving unit is connected to the key usage recording unit in the sending service area in communication, and the data analysis unit is also connected to the decryption unit and the quantum key pool in communication;
[0043] Among them, the data parsing unit is used to parse the received communication content to obtain the encrypted business, total key location information, hash value, and hash calculation parameters; the authentication unit is used to perform authentication operations on the key block according to the hash value and hash calculation parameters; the decryption unit is used to perform decryption operations on the encrypted business; the feedback receiving unit notifies the key usage recording unit to interact with the quantum key pool according to the result of the authentication operation received from the other end, and deletes the used keys.
[0044] Beneficial effects:
[0045] 1. In terms of business content transmission, by selecting the first key and then combining the first key with the supplementary key to form a complete encryption key, the randomness of the key combination is improved and the security of the encryption operation is guaranteed, because the amount of the first key missing is random, and any supplementary key selected from the supplementary key set is also random; at the same time, through key block authentication, the correspondence between the encryption key and the decryption key is proved, and it is proved that the key block has not been tampered with during use and transmission, ensuring the security of the business content during transmission;
[0046] 2. In terms of key usage confirmation, after confirming that the receiving end has completed the decryption operation using the key block, the quantum key pool will delete the corresponding key content, which ensures that the same key content will not be selected in the subsequent work process, ensuring the one-time use of the key;
[0047] 3. In terms of key utilization, the encryption key block is considered to have been used up only when the decryption operation is performed at the receiving end, and the quantum key pool is notified to delete the key content corresponding to the key block. Otherwise, the key content involved in the encryption key block is not deleted and can continue to be used, which improves the key utilization and reduces unnecessary key waste. BRIEF DESCRIPTION OF THE DRAWINGS
[0048] In order to more clearly illustrate the technical solutions in the embodiments of the present application, the drawings required for use in the description of the embodiments will be briefly introduced below. Obviously, the drawings described below are only some embodiments of the present application. For ordinary technicians in this field, other drawings can be obtained based on these drawings without paying creative labor.
[0049] Figure 1 This is a schematic diagram of the structure of the working system for this application;
[0050] Figure 2 This is a schematic diagram of the structure of the quantum key device in the system of this application;
[0051] Figure 3 A flowchart of the working method of this application;
[0052] Figure 4Schematic diagram of the process flow for selecting a supplementary key block. DETAILED DESCRIPTION
[0053] In order to make the purpose, technical solutions and advantages of the present application clearer, the present application will be further described in detail below in conjunction with the accompanying drawings. Obviously, the described embodiments are only part of the embodiments of the present application, rather than all the embodiments. Based on the embodiments in the present application, all other embodiments obtained by ordinary technicians in this field without making creative work are within the scope of protection of the present application.
[0054] like Figure 1 As shown, the present invention provides a working system based on a quantum key device, the working system includes a transmitting end and a receiving end, the transmitting end and the receiving end are respectively associated with a quantum key device, and the transmitting end and the receiving end are connected to each other through their respective quantum key devices. The transmitting end is used to encrypt the service using the quantum key device and then transmit it to the receiving end, and the receiving end is used to authenticate and decrypt the received service using the quantum key device.
[0055] In an embodiment of the present invention, the quantum key device associated with the sending end and the receiving end in the working system includes a sending service area and a receiving service area, wherein the sending service area and the receiving service area are connected in communication, the sending service area is used to obtain services and encrypt the obtained services, and the receiving service area is used to authenticate and decrypt the received encrypted services; the quantum key device also includes a quantum key pool, which is independent of the sending service area and the receiving service area, or is located in the sending service area, and is used to provide key files. The device associated with the sending end and the device associated with the receiving end are both configured with symmetric key files, which are stored in the quantum key pools in the devices at both ends.
[0056] like Figure 2As shown, the sending service area includes a service acquisition unit, a key block processing unit, an encryption unit, a hash calculation unit, a key usage record unit, and a sending unit. The key processing unit is respectively connected to the service acquisition unit, the encryption unit, the hash calculation unit, the key usage record unit, and the sending unit, and the encryption unit is also connected to the service acquisition unit, the key usage record unit, and the sending unit. The service acquisition unit is also connected to the key usage record unit, the hash calculation unit is also connected to the key usage record unit and the sending unit, and the key usage record unit is also connected to the sending unit; the quantum key pool is connected to the key processing unit and the key usage record unit in the sending service area. The service acquisition unit is used to obtain the service list; the key block processing unit is used to obtain the key block corresponding to the service from the quantum key pool and record the total key position information of the key block; the encryption unit is used to perform encryption operations on each service in the service list; the hash calculation unit is used to perform hash calculation on the key block to obtain a hash value and record the hash calculation parameters; the key usage recording unit is used to record the total key position information and hash value corresponding to the key block; the sending unit is used to integrate the encrypted service, total key position information, hash value, and hash calculation parameters into communication content and then send it.
[0057] like Figure 2 As shown, the receiving service area includes a feedback receiving unit, a decryption unit, an authentication unit, and a data parsing unit. The authentication unit is connected to the data parsing unit and the decryption unit in communication, respectively. The feedback receiving unit is connected to the key usage recording unit in the sending service area in communication, and the data parsing unit is also connected to the decryption unit and the quantum key pool in communication. The data parsing unit is used to parse the received communication content to obtain the encrypted service, the total key location information, the hash value, and the hash calculation parameters; the authentication unit is used to perform an authentication operation on the key block according to the hash value and the hash calculation parameters; the decryption unit is used to perform a decryption operation on the encrypted service; the feedback receiving unit notifies the key usage recording unit to interact with the quantum key pool according to the result of the authentication operation received from the other end, and deletes the used key.
[0058] As can be seen above, the quantum key device has both a sending service area and a receiving service area, so the sender and receiver can switch identities when necessary.
[0059] In the presence of the above working system, the following describes a working method of a working system based on a quantum key device provided by the present invention, and the working method of the present invention is applied to the working system described above. Figure 3 As shown, the working method comprises the following steps:
[0060] Step 1: The sender obtains a service list, numbers multiple services in the service list, obtains service numbers, and updates each service number and corresponding service to the service list;
[0061] Specifically, step 1 includes the following:
[0062] Step 1-1: The sending service area of the sending end works, and the service acquisition unit in the sending service area acquires the service list of the sending end, and numbers multiple services in the service list to obtain multiple service numbers, such as service 1, service 2, ..., service n; it should be noted that the multiple services include the first service, for example, the first service is numbered and recorded as service 1;
[0063] Step 1-2: The business acquisition unit parses the business volume size L of each business. For example, the business acquisition unit parses the business volume size L1 of the first business; and associates each business in the business list with its business number and business volume size L to form a one-to-one correspondence, and updates it to the business list; wherein each business includes a business number and business content.
[0064] Step 2: The sender obtains the key block of each service, records the total key position information of the key block, performs hash calculation on the key information to obtain the hash value, and records the hash calculation parameters, associates each service with the key information, hash value, and hash calculation parameters to form a one-to-one correspondence, and updates it to the service list;
[0065] Specifically, step 2 includes the following:
[0066] Step 2-1: The service acquisition unit in the sending service area of the sending end sends the service volume size L of each service to the key block processing unit in the sending service area, and at the same time sends each service to the key usage recording unit and the encryption unit in the sending service area; taking the first service as an example: the service volume size data L1 of service 1 is sent to the key block processing unit, and at the same time, the service 1 is sent to the key usage recording unit and the encryption unit, wherein the service 1 includes the service number 1 and the service content therein.
[0067] Step 2-2: The key block processing unit obtains the key block of the corresponding service of the corresponding size from the quantum key pool of the local transmitting end according to the service volume size L, records the total key position information of the key block, and numbers the key block to obtain the key number corresponding to the service number, and records the key block with the key number as the encryption key block KEYn, sends the encryption key block KEYn to the hash calculation unit and the encryption unit in the sending service area, and sends the total key position information to the key usage recording unit in the sending service area. Still taking the first service as an example: the key block processing unit obtains the key block of the corresponding size corresponding to service 1 from the quantum key pool of the local transmitting end according to the service volume size L1 of service 1, and numbers the key block and marks it as the first encryption key block KEY1 corresponding to service 1. The first encryption key block KEY1 is sent to the hash calculation unit and the encryption unit, and the total key position information of the first encryption key block KEY1 is sent to the key usage recording unit. It should be noted that the quantum key pool can be a module built into the quantum security terminal device, or it can also be deployed in a quantum key device.
[0068] In step 2-2, the specific process of the key block processing unit obtaining a plurality of key blocks of corresponding sizes from the local quantum key pool of the transmitting end according to the business volume size L of each business is as follows:
[0069] Step 2-2-1: For the first service in the service list, i.e., service 1, the key processing unit obtains a plurality of keys of different sizes from the local quantum key pool in advance as a plurality of supplementary key blocks, and the key length of each supplementary key block is relatively small, and is less than or equal to n, for example, the n can be an integer of 10. The key processing unit also records the position information of the plurality of supplementary key blocks in the key file in the local quantum key pool of the sending end, wherein the position information of the supplementary key block includes, for example, the starting position and key length of the supplementary key block;
[0070] Step 2-2-2: The key processing unit randomly generates a positive integer N less than or equal to n, obtains the first key key1 of the first service (i.e., service 1) with a length of (LN) from the key file, and records the location information of the first key key1 in the key file; Figure 4As shown, any first supplementary key key2 of service 1 with a length of N is obtained from multiple supplementary key blocks, and the first key key1 and the first supplementary key key2 are combined into the first encryption key block KEY1 of service 1. The first encryption key block KEY1 also includes total key position information, and the total key position information includes the position information of the first key key1 and the position information of the first supplementary key key2. In terms of service content transmission, by selecting the first key and then combining the first key with the supplementary key to form a complete encryption key, the randomness of the key combination is improved and the security of the encryption operation is guaranteed, because the amount of the first key missing is random, and any one of the supplementary keys selected from the supplementary key set is also random.
[0071] Step 2-2-3: The key processing unit executes S2-2-1 to S2-2-2 on all remaining services in the order in the service list to obtain the encryption key block KEYn of each service.
[0072] Step 2-3: The hash calculation unit generates a hash function for each encryption key block of different services, and inputs the key block into the hash function H1 to calculate the hash value of each key block. Specifically, the hash calculation unit performs a hash calculation on the encryption key block KEYn obtained in step 2-2 to obtain the hash value h of each encryption key block KEYn. p1,s (KEYn);
[0073] The steps 2-3 include:
[0074] Step 2-3-1: The hash calculation unit obtains a key u from the local quantum key pool as a random number to generate an irreducible polynomial p1(x). After obtaining the irreducible polynomial, the string consisting of the coefficients of each term except the highest term in the irreducible polynomial p1(x) is recorded as str1;
[0075] Step 2-3-2: The hash calculation unit obtains a key s as a random number from the local quantum key pool and generates a hash function h based on the irreducible polynomial p1(x) and the random number s. p1,s , use the hash function to calculate the hash value h of the encryption key block KEYn p1,s (KEYn), and record the hash calculation parameters; wherein the hash calculation parameters include the input random number s and the character string str1 of the coefficients of the irreducible polynomial.
[0076] Step 2-4: The key usage record unit establishes the service (i.e., service n), the total key location information of the encryption key KEYn, and the hash value h of the encryption key block KEYn for each service. p1,sThe corresponding relationship between (KEYn) is updated to the service list. Therefore, the new index formed by the updated service list can display the information corresponding to each service more quickly.
[0077] Step 3: The sending end performs encryption operations on each service in the service list and transmits it to the receiving end;
[0078] Specifically, step 3 includes the following:
[0079] Step 3-1: The encryption unit uses the encryption key block KEYn received from step 2-2 to encrypt the service content of the corresponding service n received from step 1-2, obtains the service ciphertext of the service, transmits the service ciphertext and the service number to the sending unit, and at the same time, notifies the key usage recording unit to transmit the total key location information of the encryption key block KEYn to the sending unit. The key usage recording unit interacts with the hash calculation unit according to this notification and notifies the hash calculation unit to convert the hash value h p1,s (KEYn) and hash calculation parameters are transmitted to the sending unit;
[0080] Step 3-2: According to the order of each service in the service list, the sending unit sends the received service ciphertext, service number, total key location information and hash value h p1,s (KEYn) and hash calculation parameters are combined into the communication content mes(n) of each service, and mes(n) is sent to the receiving end. For example, the communication content mes(1) of the first service includes: mes(1) = (service 1, service ciphertext of service 1, total key location information of service 1, h p1,s (KEY1), random number s, str1).
[0081] Step 4: The receiving end performs an authentication operation. After the authentication is passed, the receiving end performs a decryption operation on each encrypted service;
[0082] Specifically, step 4 includes the following:
[0083] Step 4-1: The receiving service area of the receiving end works, and the data parsing unit in the receiving service area parses the received mes(n) to obtain the service ciphertext, service number, total key location information and hash value h p1,s (KEYn), hash calculation parameters; according to the total key location information, obtain the decryption key block KEYn' from the key file in the local quantum key pool of the receiving end; the data parsing unit converts the hash value h p1,s (KEYn), hash calculation parameters and decryption key block KEYn' are sent to the authentication unit for authentication;
[0084] Step 4-2: The authentication unit generates a hash function h′ based on the hash calculation parameters p1,s, use the hash function to calculate the hash value of the decryption key block KEYn' to obtain the hash value h' p1,s (KEYn). It should be noted that the process of generating the hash function and calculating the hash value in this step is the same as step 2-3, and will not be repeated here. Compare the calculated hash value h′ p1,s (KEYn) and the parsed hash value h p1,s (KEYn), if they are equal, the key block authentication is passed, proving that the decryption key block KEYn' corresponds to the encryption key block KEYn, and has not been tampered with during use and transmission. The authentication operation is passed, and the authentication unit notifies the data parsing unit based on the authentication result to send the business ciphertext and decryption key block KEYn' to the decryption unit to perform the decryption operation, and the receiving end obtains the decrypted business. If they are not equal, the key block authentication fails, which means that the two do not correspond, and there is a problem with the encryption key block during use and transmission. The transmission process of this business n is terminated and the transmission process is restarted. In this step, the key block authentication is used to prove the correspondence between the encryption key and the decryption key, and to prove that the key block has not been tampered with during use and transmission, thereby ensuring the security of the business content during transmission.
[0085] Step 5: The receiving end sends the result of the authentication operation to the sending end, and the sending end performs an operation on the key based on the result of the authentication operation.
[0086] Specifically, step 5 includes the following:
[0087] In response to the above authentication success, the authentication unit at the receiving end feeds back the authentication result to the quantum key device at the sending end, and the feedback receiving unit in the quantum key device at the sending end receives the feedback, and notifies the key usage recording unit to record that the encryption key block KEYn has been used according to the feedback result. The key usage recording unit notifies the quantum key pool to delete the key part corresponding to the encryption key block KEYn according to the used record, and more specifically, deletes the key part corresponding to the encryption key block KEYn in the key file, completing the whole process of key use; in order to ensure that the quantum key is used once in the encryption process, the used key part is deleted according to the index (that is, the key block number corresponding to the business number), which can ensure that the unused keys in the key file are available for use and the used keys cannot be obtained, which ensures that the same key content will not be selected to perform encryption operations in subsequent work processes, thereby ensuring the one-time use of the key.
[0088] Alternatively, in response to the above authentication failure, the authentication unit at the receiving end feeds back the authentication failure result to the quantum key device at the sending end, and the feedback receiving unit in the quantum key device at the sending end receives the feedback, and notifies the key usage recording unit to record that the encryption key block KEYn is not used according to the feedback result, and the key usage recording unit notifies the key processing unit to re-acquire the encryption key block for the service according to the unused record, and restarts the transmission process of the service. The key content involved in the encryption key block is not deleted in the key file and can continue to be used, thereby improving the utilization rate of the key and reducing unnecessary key waste.
Claims
1. A working method of a working system based on a quantum key device, performed by a working system based on a quantum key device, wherein the working system based on the quantum key device comprises a transmitting end and a receiving end, and is characterized in that: The working method comprises the following steps: Step 1: The sender obtains a service list, numbers multiple services in the service list, obtains service numbers, and updates each service number and corresponding service to the service list; Step 2: The sender obtains the key block of each service, records the total key position information of the key block, performs hash calculation on the key information to obtain the hash value, and records the hash calculation parameters, associates each service with the key information, hash value, and hash calculation parameters to form a one-to-one correspondence, and updates it to the service list; Step 3: The sending end performs encryption operations on each service in the service list and transmits it to the receiving end; Step 4: The receiving end performs an authentication operation. After the authentication is passed, the receiving end performs a decryption operation on each encrypted service; Step 5: The receiving end sends the result of the authentication operation to the sending end, and the sending end performs an operation on the key based on the result of the authentication operation.
2. The working method of the working system based on the quantum key device according to claim 1, characterized in that: The step 1 comprises: Step 1-1: The sending service area of the sending end works, and the service acquisition unit in the sending service area acquires the service list of the sending end, numbers multiple services in the service list, and obtains multiple service numbers; Step 1-2: The service acquisition unit parses the service volume L of each service, and associates each service in the service list with its service number and service volume L to form a one-to-one correspondence, and updates the service list; wherein each service includes a service number and service content.
3. The working method of the working system based on the quantum key device according to claim 2, characterized in that: The step 2 comprises: Step 2-1: The service acquisition unit in the sending service area of the sending end sends the service volume size L of each service to the key block processing unit in the sending service area, and at the same time sends each service to the key usage recording unit and encryption unit in the sending service area; Step 2-2: The key block processing unit obtains a key block of a corresponding size corresponding to the service from the local quantum key pool of the sending end according to the service volume size L, records the total key position information of the key block, and numbers the key block to obtain a key number corresponding to the service number, records the key block with the key number as an encryption key block KEYn, sends the encryption key block KEYn to the hash calculation unit and the encryption unit in the sending service area, and sends the total key position information to the key usage recording unit in the sending service area; Step 2-3: The hash calculation unit performs hash calculation on the encryption key block KEYn obtained in step 2-2 to obtain the hash value of each encryption key block KEYn. Step 2-4: The key usage record unit creates the service, the total key location information of the encryption key KEYn, and the hash value of the encryption key block KEYn for each service. The corresponding relationship between them is updated in the business list.
4. The working method of the working system based on the quantum key device according to claim 3, characterized in that: In step 2-2, the specific process of the key block processing unit obtaining a plurality of key blocks of corresponding sizes from the local quantum key pool of the transmitting end according to the business volume size L of each business is as follows: Step 2-2-1: For the first service in the service list, the key processing unit obtains a plurality of keys of different sizes from the local quantum key pool in advance as a plurality of supplementary key blocks, and the key length of each supplementary key block is less than or equal to n; the key processing unit also records the position information of the plurality of supplementary key blocks in the key file in the local quantum key pool of the sending end, wherein the position information of the supplementary key block includes the starting position and the key length of the supplementary key block; Step 2-2-2: the key processing unit randomly generates a positive integer N less than or equal to n, obtains a first key key1 of the first service with a length of (LN) from the key file, and records the position information of the first key key1 in the key file; then obtains any first supplementary key key2 of the first service with a length of N from multiple supplementary key blocks, and combines the first key key1 and the first supplementary key key2 into a first encryption key block KEY1 for the first service; the first encryption key block KEY1 also includes total key position information, and the total key position information includes the position information of the first key key1 and the position information of the first supplementary key key2; Step 2-2-3: The key processing unit executes S2-2-1 to S2-2-2 on all remaining services in the order in the service list to obtain the encryption key block KEYn of each service.
5. The working method of the working system based on the quantum key device according to claim 3 or 4, characterized in that: The steps 2-3 include: Step 2-3-1: The hash calculation unit obtains a key u from the local quantum key pool as a random number to generate an irreducible polynomial p1(x). After obtaining the irreducible polynomial, the string consisting of the coefficients of each term except the highest term in the irreducible polynomial p1(x) is recorded as str1; Step 2-3-2: The hash calculation unit obtains a key s as a random number from the local quantum key pool and generates a hash function based on the irreducible polynomial p1(x) and the random number s. Use the hash function to calculate the hash value of the encryption key block KEYn And record the hash calculation parameters; wherein the hash calculation parameters include the random number s and the character string str1.
6. The working method of the working system based on the quantum key device according to claim 3, characterized in that: The step 3 comprises: Step 3-1: The encryption unit uses the encryption key block KEYn received from step 2-2 to encrypt the service content received from step 1-2, obtains the service ciphertext, transmits the service ciphertext and service number to the sending unit, and at the same time, notifies the key usage recording unit to transmit the total key location information of the encryption key block KEYn to the sending unit. The key usage recording unit interacts with the hash calculation unit based on this notification and notifies the hash calculation unit to convert the hash value and hash calculation parameters are transmitted to a sending unit; Step 3-2: The sending unit receives the service ciphertext, service number, total key location information and hash value. The hash calculation parameters are combined together to form the communication content mes(n) of each business, and mes(n) is sent to the receiving end.
7. The working method of the working system based on the quantum key device according to claim 6, characterized in that: The step 4 comprises: Step 4-1: The receiving service area of the receiving end works. The data parsing unit in the receiving service area parses the received mes(n) to obtain the service ciphertext, service number, total key location information and hash value. Hash calculation parameters; according to the total key location information, obtain the decryption key block KEYn' from the key file in the local quantum key pool of the receiving end; the data parsing unit converts the hash value The hash calculation parameters and the decryption key block KEYn' are sent to the authentication unit for authentication; Step 4-2: The authentication unit generates a hash function based on the hash calculation parameters The hash value of the decryption key block KEYn' is calculated using the hash function to obtain a hash value Compare the calculated hash value and the parsed hash value If they are equal, the authentication operation is passed. The authentication unit notifies the data parsing unit to send the service ciphertext and the decryption key block KEYn' to the decryption unit to perform the decryption operation according to the authentication result, and the receiving end obtains the decrypted service.
8. The working method of the working system based on the quantum key device according to claim 7, characterized in that: The step 5 comprises: The authentication unit at the receiving end feeds back the authentication result to the quantum key device at the sending end, the feedback receiving unit in the quantum key device at the sending end receives the feedback, and notifies the key usage recording unit to record that the encryption key block KEYn has been used according to the feedback result, and the key usage recording unit notifies the quantum key pool to delete the key part corresponding to the encryption key block KEYn according to the used record; Alternatively, the authentication unit at the receiving end feeds back the authentication failure result to the quantum key device at the sending end, the feedback receiving unit in the quantum key device at the sending end receives the feedback and, based on the feedback result, notifies the key usage recording unit to record that the encryption key block KEYn is not used, and the key usage recording unit notifies the key processing unit to re-obtain the key block for the service based on the unused record, and restarts the transmission process of the service.
9. A working system based on a quantum key device, used to execute the working method of a working system based on a quantum key device according to any one of claims 1 to 8, characterized in that: The invention comprises a transmitting end and a receiving end, wherein the transmitting end and the receiving end are respectively associated with a quantum key device, and the transmitting end and the receiving end are communicatively connected via their respective quantum key devices; the transmitting end is used to encrypt a service using the quantum key device and then transmit the service to the receiving end, and the receiving end is used to authenticate and decrypt the received service using the quantum key device.
10. The working system based on the quantum key device according to claim 9, characterized in that: The quantum key device includes a sending service area and a receiving service area, wherein the sending service area and the receiving service area are communicatively connected, the sending service area is used to obtain services and encrypt the obtained services, and the receiving service area is used to authenticate and decrypt the received encrypted services; the quantum key device also includes a quantum key pool, which is independent of the sending service area and the receiving service area, or is located in the sending service area, and is used to provide key files; The sending service area includes: a service acquisition unit, a key block processing unit, an encryption unit, a hash calculation unit, a key usage recording unit, and a sending unit; The key processing unit is respectively connected to the service acquisition unit, the encryption unit, the hash calculation unit, the key usage recording unit, and the sending unit; the encryption unit is also connected to the service acquisition unit, the key usage recording unit, and the sending unit; the service acquisition unit is also connected to the key usage recording unit; the hash calculation unit is also connected to the key usage recording unit and the sending unit; the key usage recording unit is also connected to the sending unit; the quantum key pool is connected to the key processing unit and the key usage recording unit in the sending service area; Among them, the service acquisition unit is used to obtain the service list; the key block processing unit is used to obtain the key block corresponding to the service from the quantum key pool, and record the total key position information of the key block; the encryption unit is used to perform encryption operations on each service in the service list; the hash calculation unit is used to perform hash calculation on the key block to obtain a hash value and record the hash calculation parameters; the key usage recording unit is used to record the total key position information and hash value corresponding to the key block; the sending unit is used to integrate the encrypted service, total key position information, hash value, and hash calculation parameters into communication content and then send it; The receiving service area includes: feedback receiving unit, decryption unit, authentication unit, and data parsing unit; The authentication unit is respectively connected to the data analysis unit and the decryption unit in communication, the feedback receiving unit is connected to the key usage recording unit in the sending service area in communication, and the data analysis unit is also connected to the decryption unit and the quantum key pool in communication; Among them, the data parsing unit is used to parse the received communication content to obtain the encrypted business, total key location information, hash value, and hash calculation parameters; the authentication unit is used to perform authentication operations on the key block according to the hash value and hash calculation parameters; the decryption unit is used to perform decryption operations on the encrypted business; the feedback receiving unit notifies the key usage recording unit to interact with the quantum key pool according to the result of the authentication operation received from the other end, and deletes the used keys.