Mail encryption method based on quantum key distribution and related equipment
By adopting an encryption method based on quantum key distribution in the email system and using a pre-debated quantum key for encryption, the problem of low security in the prior art email encryption is solved, and higher security and reduced maintenance costs are achieved.
Patent Information
- Application Number
- CN202510172735.0
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-02-17
- Publication Date
- 2025-05-16
- Estimated Expiration
- 2045-02-17
AI Technical Summary
When existing email encryption technology faces the threat of quantum computing and quantum algorithms, it is less secure and difficult to effectively protect the confidentiality and integrity of email information.
The mail encryption method based on quantum key distribution is adopted, and the quantum keys negotiated in advance between the first key management system and the second key management system are encrypted to ensure high security of the mail during transmission.
It improves the security of email applications, reduces system maintenance costs, and effectively deals with the threats of quantum computing and quantum algorithms to traditional encryption algorithms.
Smart Images

Figure CN120017376A_ABST
Abstract
Description
Background Art
[0002] Email is a technology for sending messages electronically and is one of the important tools for communication in modern society. Email security mainly includes the identity authentication of senders and recipients, as well as the confidentiality and integrity of email information during the process of sending, forwarding and storing emails.
[0003] In the related technology, the public key algorithms currently used in emails are mostly RSA or SM2 elliptic curve cryptography algorithms. RSA is an asymmetric encryption algorithm based on the problem of large integer decomposition, which is widely used in data encryption, digital signatures and other fields; SM2 is used to replace the traditional RSA algorithm to provide a more efficient and secure encryption solution, mainly used in digital signatures, key exchange and encryption. However, the development of quantum computing and quantum algorithms will affect the security of emails.
[0004] With the continuous breakthroughs in quantum computing hardware and the emergence of quantum algorithms such as Shor's algorithm and Grover's algorithm, public key cryptography based on large number decomposition and other computational complexities has become a huge threat. Among them, Shor's algorithm can efficiently solve the problem of large integer decomposition, which means it can quickly crack RSA encryption; although Grover's algorithm does not directly threaten a specific type of encryption algorithm like Shor's algorithm, it provides a general method to speed up the search of disordered databases, including key search attacks for cracking symmetric key encryption, which can theoretically greatly reduce the time complexity required for brute force cracking, which poses a potential threat to various security measures including email encryption.
[0005] It should be noted that the information disclosed in the above background technology section is only used to enhance the understanding of the background of the present disclosure, and therefore may include information that does not constitute the prior art known to ordinary technicians in the field. Summary of the invention
[0006] The present disclosure provides an email encryption method, system, device, equipment, medium and program product based on quantum key distribution, which at least to a certain extent overcomes the problem of low security in the process of sending and receiving emails in the related art.
[0007] Other features and advantages of the present disclosure will become apparent from the following detailed description, or may be learned in part by the practice of the present disclosure.
[0008] According to one aspect of the present disclosure, a method for encrypting an email based on quantum key distribution is provided, which is applied to a first key management system, including: receiving a key acquisition request sent by a first client, wherein the key acquisition request carries security medium information of the first client and identity information of a second client acquired in advance, the first client is associated with the first key management system, and the second client is associated with the second key management system; obtaining a quantum key pre-negotiated by the first key management system and the second key management system according to the identity information of the second client; sending a key encryption request to the second key management system, so that the second key management system encrypts the quantum key according to a second injection key, and obtains a second Encrypting a quantum key and returning a key encryption response to the first key management system, wherein the second charging key is a key pre-stored in the secure medium of the second client, and the key encryption response carries the second encrypted quantum key and a second charging key identifier; encrypting the quantum key according to the first charging key to obtain a first encrypted quantum key, wherein the first charging key is a key pre-stored in the secure medium of the first client; returning a key acquisition response to the first client, so that the first client encrypts the email to be sent according to the key information carried in the key acquisition response, wherein the key information includes the first encrypted quantum key, the first charging key identifier, the second encrypted quantum key and the second charging key identifier.
[0009] In some embodiments, the key acquisition request also carries the identity authentication information of the first client; before obtaining the quantum key pre-negotiated by the first key management system and the second key management system based on the identity identification information of the second client, the method further includes: authenticating the first client based on the identity authentication information of the first client, wherein the identity authentication information includes: an identity security identifier; if the identity authentication of the first client passes, communicating with the second key management system based on the key acquisition request; if the identity authentication of the first client fails, sending an authentication failure message to the first client.
[0010] In some embodiments, before performing identity authentication on the first client based on the identity authentication information of the first client, the method also includes: receiving an identity authentication request sent by the first client, wherein the identity authentication request is used for the first client to request to establish an association relationship with the first key management system, and the identity authentication request carries the identity authentication identifier of the first client; performing identity verification on the first client based on the identity authentication identifier of the first client; if the identity verification of the first client passes, returning an identity authentication response to the first client, wherein the identity authentication response carries the identity security identifier of the first client.
[0011] According to another aspect of the present disclosure, there is also provided an email encryption method based on quantum key distribution, which is applied to a second key management system, including: receiving a key encryption request sent by a first key management system; encrypting the quantum key according to a second charging key stored in a secure medium of a second client to obtain a second encrypted quantum key, wherein the second client is associated with the second key management system, and the quantum key is a quantum key pre-negotiated by the first key management system and the second key management system; returning a key encryption response to the first key management system, wherein the key encryption response carries the second encrypted quantum key and the second charging key identifier.
[0012] In some embodiments, before receiving a key protection request sent by a first key management system, the method further includes: receiving an identity authentication request sent by a second client, wherein the identity authentication request is used for the second client to request to establish an association relationship with the second key management system, and the identity authentication request carries an identity authentication identifier of the second client; performing identity verification on the second client according to the identity authentication identifier of the second client; if the identity verification of the second client passes, returning an identity authentication response to the second client, wherein the identity authentication response carries the identity security identifier of the second client.
[0013] According to another aspect of the present disclosure, there is also provided a mail encryption system based on quantum key distribution, comprising: a first key management system and a second key management system;
[0014] The first key management system is used to receive a key acquisition request sent by a first client, wherein the key acquisition request carries the secure medium information of the first client and the pre-acquired identity information of the second client, the first client is associated with the first key management system, and the second client is associated with the second key management system; according to the identity information of the second client, the quantum key pre-negotiated by the first key management system and the second key management system is obtained; a key encryption request is sent to the second key management system; the second key management system is used to receive the key encryption request sent by the first key management system; and the quantum key is encrypted according to the second injection key stored in the secure medium of the second client. The method comprises the steps of: encrypting the first client's electronic mail with the first encrypted quantum key and obtaining a second encrypted quantum key; returning a key protection response to the first key management system, wherein the key protection response carries the second encrypted quantum key and a second charging key identifier; wherein the first key management system is further used to encrypt the quantum key according to the first charging key to obtain a first encrypted quantum key, wherein the first charging key is a key pre-stored in a secure medium of the first client; returning a key acquisition response to the first client, so that the first client encrypts the email to be sent according to the key information carried in the key acquisition response, wherein the key information includes the first encrypted quantum key, the first charging key identifier, the second encrypted quantum key and the second charging key identifier.
[0015] According to another aspect of the present disclosure, there is also provided an email encryption device based on quantum key distribution, including: a key acquisition request receiving module, used to receive a key acquisition request sent by a first client, wherein the key acquisition request carries the security medium information of the first client and the identity information of the second client obtained in advance, the first client is associated with the first key management system, and the second client is associated with the second key management system; a quantum key acquisition module, used to obtain the quantum key pre-negotiated by the first key management system and the second key management system according to the identity information of the second client; a key encryption request sending module, used to send a key encryption request to the second key management system, so that the second key management system encrypts the quantum key according to the second injection key to obtain the second Encrypting a quantum key and returning a key encryption response to the first key management system, wherein the second charging key is a key pre-stored in the secure medium of the second client, and the key encryption response carries the second encrypted quantum key and a second charging key identifier; a key encryption response receiving module, used to encrypt the quantum key according to the first charging key to obtain a first encrypted quantum key, wherein the first charging key is a key pre-stored in the secure medium of the first client; a key acquisition response returning module, used to return a key acquisition response to the first client, so that the first client encrypts the email to be sent according to the key information carried in the key acquisition response, wherein the key information includes the first encrypted quantum key, the first charging key identifier, the second encrypted quantum key and the second charging key identifier.
[0016] According to another aspect of the present disclosure, there is also provided an email encryption device based on quantum key distribution, including: a key encryption request receiving module, used to receive a key encryption request sent by a first key management system; a quantum key encryption module, used to encrypt the quantum key according to the second charging key stored in the secure medium of the second client to obtain a second encrypted quantum key, wherein the second client is associated with the second key management system, and the quantum key is a quantum key pre-negotiated by the first key management system and the second key management system; a key encryption response returning module, used to return a key encryption response to the first key management system, wherein the key encryption response carries the second encrypted quantum key and the second charging key identifier.
[0017] According to another aspect of the present disclosure, an electronic device is also provided, comprising: a processor; and a memory for storing executable instructions of the processor; wherein the processor is configured to execute any one of the above-mentioned quantum key distribution-based email encryption methods by executing the executable instructions.
[0018] According to another aspect of the present disclosure, a computer-readable storage medium is provided, on which a computer program is stored. When the computer program is executed by a processor, the email encryption method based on quantum key distribution described above is implemented.
[0019] According to another aspect of the present disclosure, a computer program product is also provided, including a computer program, which implements any of the above-mentioned quantum key distribution-based email encryption methods when executed by a processor.
[0020] In the email encryption method, system, device, equipment, medium and program product based on quantum key distribution provided in the embodiments of the present disclosure, the first key management system obtains the quantum key pre-negotiated with the second key management system according to the information carried in the key acquisition request sent by the first client, and then sends a key encryption request to the second key management system. The second key management system encrypts the quantum key using the second charging key according to the received request, and returns the encrypted second encrypted quantum key and the second charging key identifier to the first key management system, and then the first key management system encrypts the quantum key using the first charging key, and returns the encrypted quantum key and the charging key identifier to the first client, so that the first client encrypts the email to be sent according to the received key information. The embodiments of the present disclosure can improve the security of email applications and reduce system maintenance costs.
[0021] It is to be understood that the foregoing general description and the following detailed description are exemplary and explanatory only and are not restrictive of the present disclosure. BRIEF DESCRIPTION OF THE DRAWINGS
[0022] The accompanying drawings herein are incorporated into the specification and constitute a part of the specification, illustrate embodiments consistent with the present disclosure, and together with the specification are used to explain the principles of the present disclosure. Obviously, the accompanying drawings described below are only some embodiments of the present disclosure, and for ordinary technicians in this field, other accompanying drawings can be obtained based on these accompanying drawings without creative work.
[0023] Figure 1 A schematic diagram of an exemplary application system architecture to which the email encryption method based on quantum key distribution in the embodiments of the present disclosure can be applied is shown;
[0024] Figure 2 A flow chart of a method for email encryption based on quantum key distribution in an embodiment of the present disclosure is shown;
[0025] Figure 3 A flowchart of another email encryption method based on quantum key distribution in an embodiment of the present disclosure is shown;
[0026] Figure 4 A schematic diagram showing another email encryption method based on quantum key distribution in an embodiment of the present disclosure applied to the system architecture;
[0027] Figure 5 An email encryption system based on quantum key distribution in an embodiment of the present disclosure is shown;
[0028] Figure 6 A schematic diagram of a mail encryption device based on quantum key distribution in an embodiment of the present disclosure is shown;
[0029] Figure 7 A schematic diagram of another mail encryption device based on quantum key distribution in an embodiment of the present disclosure is shown;
[0030] Figure 8 A structural block diagram of an electronic device in an embodiment of the present disclosure is shown. DETAILED DESCRIPTION
[0031] Example embodiments will now be described more fully with reference to the accompanying drawings. However, example embodiments can be implemented in a variety of forms and should not be construed as limited to the examples set forth herein; rather, these embodiments are provided so that the disclosure will be more comprehensive and complete and to fully convey the concepts of the example embodiments to those skilled in the art. The described features, structures, or characteristics may be combined in any suitable manner in one or more embodiments.
[0032] In addition, the accompanying drawings are only schematic illustrations of the present disclosure and are not necessarily drawn to scale. The same reference numerals in the figures represent the same or similar parts, and their repeated description will be omitted. Some of the block diagrams shown in the accompanying drawings are functional entities and do not necessarily correspond to physically or logically independent entities. These functional entities can be implemented in software form, or implemented in one or more hardware modules or integrated circuits, or implemented in different networks and / or processor devices and / or microcontroller devices.
[0033] For ease of understanding, before introducing the embodiments of the present disclosure, several terms involved in the embodiments of the present disclosure are first explained as follows:
[0034] QKD: Quantum Key Distribution, a method in which both communicating parties generate symmetric keys by transmitting quantum states, which has information-theoretic security at the theoretical protocol level.
[0035] Security Medium: Security medium, which can be, for example, smart password keys in the form of U-shield, TF card, user identification module SIM card, etc., for various terminals to choose on demand, providing terminals with basic cryptographic capabilities such as quantum key security storage, encryption and decryption algorithms.
[0036] MAC: Message Authentication Code. A MAC is a short string attached to a message and is calculated by the sender using a shared key and a specific algorithm. The receiver can recalculate the MAC using the same key and algorithm and compare it with the received MAC to verify whether the message has been tampered with and whether the source is authentic.
[0037] Block Cipher: A block cipher is a type of symmetric cipher that divides the plaintext into multiple blocks of equal length. Such data blocks are called groups. Each group is encrypted and decrypted using the same process and the same key. SM4 and AES are both block ciphers.
[0038] The specific implementation of the embodiment of the present disclosure is described in detail below with reference to the accompanying drawings.
[0039] Figure 1 FIG. 1 shows an exemplary application system architecture diagram to which the email encryption method based on quantum key distribution in the embodiment of the present disclosure can be applied. Figure 1 As shown, the system architecture may include a terminal A equipped with a secure medium, a terminal B equipped with a secure medium, a mailbox system, a cryptographic management service platform CMSP, a key management system A (KMSA), a key management system B (KMSB), and several key managers KM and several quantum key distribution QKD devices.
[0040] In one embodiment of the present disclosure, both terminal A and terminal B can act as senders or receivers; the mailbox system is a centrally managed mailbox system, which is responsible for sending and receiving emails; the password management service platform CMSP is responsible for managing and coordinating various resources and services related to encryption and decryption operations; the key management system A is the key management system associated with terminal A, and the key management system B is the key management system associated with terminal B. There is two-way communication between KMSA and KMSB to ensure the synchronization and management of keys; the key manager KM is responsible for the generation, storage and management of keys; the quantum key distribution QKD device is used to generate and distribute highly secure keys.
[0041] In one embodiment of the present disclosure, terminal A and terminal B interact with their respective associated KMSs through their respective equipped secure media, that is, terminal A interacts with KMSA, and terminal B interacts with KMSB. KMS is a key management system, which is directly connected to KM, and can obtain the quantum key generated by the QKD network, fill the key into the secure medium, use the filled key to achieve identity authentication, and process the email encryption key application of the terminal email client. KMS is a key management system, which is directly connected to KM, and can obtain the quantum key generated by the QKD network, fill the key into the secure medium, use the filled key to achieve identity authentication, and process the email encryption key application of the terminal email client.
[0042] In one embodiment of the present disclosure, taking terminal A as the sender as an example, when terminal A applies for an email encryption key from KMSA, it will carry its own secure media information, Token, and recipient B's information; after receiving the request, KMSA communicates with KMSB through CMSP to ensure the secure transmission and synchronization of the key; KM is responsible for specific key management tasks, including key generation, storage, and distribution; QKD provides quantum key distribution services to enhance the security of the key; CMSP acts as a central coordinator to ensure the efficient operation and security of the entire system.
[0043] Those skilled in the art will know that Figure 1 The number of each device in the system is only illustrative, and any number of devices may be provided according to actual needs. This is not limited in the embodiments of the present disclosure.
[0044] Under the above system architecture, an email encryption method based on quantum key distribution is provided in an embodiment of the present disclosure, and the method can be executed by any electronic device with computing and processing capabilities.
[0045] Figure 2 A flowchart of a method for email encryption based on quantum key distribution in an embodiment of the present disclosure is shown, which is applied to a first key management system, such as Figure 2 As shown, the method comprises the following steps:
[0046] S202, receiving a key acquisition request sent by a first client, wherein the key acquisition request carries security medium information of the first client and pre-acquired identity information of a second client, the first client is associated with a first key management system, and the second client is associated with a second key management system.
[0047] In one embodiment of the present disclosure, the first client, as the sender, will obtain in advance the identity information of the second client, as the recipient, before sending the email, which may be, for example, basic information such as the email address of the second client; the first client, the security medium equipped by the first client, and the first key system associated with the first client have a certain association relationship in advance, and the first client can carry the security medium information equipped by itself in the key acquisition request, which may be, for example, the user identification, device identification, etc.
[0048] S204, obtaining the quantum key pre-negotiated by the first key management system and the second key management system according to the identity information of the second client.
[0049] In one embodiment of the present disclosure, the first key management system and the second key management system usually first establish a physical connection that can directly carry out quantum communication, and then generate a quantum key shared by both parties through a common quantum key distribution QKD protocol, and store the quantum key in the key libraries of the first key management system and the second key management system respectively.
[0050] S206, sending a key encryption request to the second key management system, so that the second key management system encrypts the quantum key according to the second charging key to obtain a second encrypted quantum key, and returns a key encryption response to the first key management system, wherein the second charging key is a key pre-stored in the secure medium of the second client, and the key encryption response carries the second encrypted quantum key and the second charging key identifier.
[0051] In one embodiment of the present disclosure, the key encryption request sent by the first key management system to the second key management system may carry the key identifier of the quantum key and the secure medium identifier of the second client, wherein the secure medium identifier of the second client may be obtained by the first key management system through a query of the cryptographic management service platform CMSP. In addition, the first key management system may also obtain through a CMSP query that the key management system associated with the second client is the second key management system.
[0052] S208: Encrypt the quantum key according to the first charging key to obtain a first encrypted quantum key, wherein the first charging key is a key pre-stored in a secure medium of the first client.
[0053] In one embodiment of the present disclosure, the first key management system encrypts the quantum key using the first injection key stored in the secure medium of the first client to obtain a first encrypted quantum key.
[0054] S210, returning a key acquisition response to the first client, so that the first client encrypts the email to be sent according to the key information carried in the key acquisition response, wherein the key information includes the first encryption quantum key, the first charging key identifier, the second encryption quantum key, and the second charging key identifier.
[0055] In one embodiment of the present disclosure, the first client can find the first charging key from the security medium equipped with itself to decrypt the first encrypted quantum key according to the received first charging key identifier, obtain the quantum key, and use the quantum key to encrypt the content of the email to be sent, and at the same time encapsulate the received second encrypted quantum key and the second charging key identifier in the email header of the email to be sent, thereby completing the encryption process of the email to be sent.
[0056] As can be seen from the above, after receiving the key acquisition request sent by the first client, the first key management system in the disclosed embodiment obtains the quantum key pre-negotiated with the second key management system according to the identity information of the second client carried therein, and then sends a key encryption request to the second key management system so that the second key management system uses the second filling key to encrypt the quantum key, and obtains the second encrypted quantum key and the second filling key identifier returned by the second key management system, and then encrypts the quantum key according to the first filling key to obtain the first encrypted quantum key and the first filling key identifier, and carries the above-obtained encrypted quantum key and filling key identifier in the key acquisition response, and returns it to the first client so that the first client encrypts the email to be sent. The disclosed embodiment can improve the security of email applications and reduce system maintenance costs.
[0057] In one embodiment of the present disclosure, the key acquisition request also carries the identity authentication information of the first client; before the above S204, the first client is authenticated according to the identity authentication information of the first client, wherein the identity authentication information includes: an identity security identifier; if the first client identity authentication passes, communication is performed with the second key management system according to the key acquisition request; if the first client identity authentication fails, an authentication failure message is sent to the first client.
[0058] In one embodiment of the present disclosure, when the first client sends a request to the first key management system, the request also needs to carry the identity security identifier Token of the first client. The first key management system first needs to verify the Token to determine whether the identity of the first client initiating the request is legal.
[0059] In one embodiment of the present disclosure, if the Token verification passes, the proof system recognizes that the request comes from an authorized user, and the first key management system will continue to process the request, that is, the first key management system will communicate with the CMSP to query the key management system associated with the second client and the security media information possessed by the second client to ensure that the encrypted email can use the correct key management system for subsequent encryption key generation and distribution.
[0060] In one embodiment of the present disclosure, if the Token verification fails, it means that the Token carried in the request is invalid or the identity of the client cannot be verified. At this time, the first key management system will not continue to process the request, but directly return an identity authentication failure message to the first client. The identity authentication failure information can be used to notify the first client to authenticate again or check whether the identity security identifier carried in the request is correct.
[0061] In one embodiment of the present disclosure, before performing identity authentication on the first client based on the identity authentication information of the first client, the method also includes: receiving an identity authentication request sent by the first client, wherein the identity authentication request is used by the first client to request to establish an association relationship with the first key management system, and the identity authentication request carries the identity authentication identifier of the first client; performing identity verification on the first client based on the identity authentication identifier of the first client; if the identity verification of the first client passes, returning an identity authentication response to the first client, wherein the identity authentication response carries the identity security identifier of the first client.
[0062] In one embodiment of the present disclosure, the first client may initiate an identity authentication request to a key management system (i.e., the first key management system) with which it is associated. The identity authentication request may be sent when the first client communicates with the first key management system for the first time, or may be sent when the identity security identifier of the first client expires or the authentication fails.
[0063] In one embodiment of the present disclosure, the identity authentication request may carry a secure medium identifier equipped by the first client, a charging key identifier stored in the secure medium, and a key verification value. The secure medium identifier may be a unique identifier of a device such as a smart card or a USB token, which is used to identify the client and the specific secure medium it holds; the charging key identifier may be an identifier of a designated charging key to be used, which is often a symmetric key stored in the secure medium, used for encryption and decryption operations and message authentication code MAC calculation; the password verification value is obtained by the client using the charging key to symmetrically encrypt or MAC calculation the sequence number N or timestamp T and the random number R.
[0064] In one embodiment of the present disclosure, the injection key can be generated by KMS with the help of a quantum random number generator, and then a batch of injection keys are injected into a secure medium in a secure manner. The secure medium securely stores the injection keys, and KMS also securely stores the injection keys of each secure medium. Both the secure medium and KMS can associate and query a specific injection key through the injection key identifier, and use the injection key to perform encryption and decryption operations.
[0065] In one embodiment of the present disclosure, after the charging key is used, the secure medium and KMS can maintain the used charging key and mark it to distinguish the used charging key from the unused charging key. In the case where the recipient KMS uses a charging key first and the secure medium uses it later, the secure medium can synchronize the key usage, or actively synchronize with the KMS in the next communication process, such as the identity authentication process.
[0066] In one embodiment of the present disclosure, the first key management system finds the corresponding charging key according to the provided charging key identifier, and then uses the same algorithm (i.e., symmetric encryption or MAC calculation) and parameters (i.e., sequence number N or timestamp T and random number R) to recalculate the password check value, and compares it with the password check value provided by the client. In addition, in order to prevent replay attacks, the first key management system will also check whether the sequence number N or timestamp T is reasonable to ensure that it has not been reused to reduce the risk of replay attacks.
[0067] In one embodiment of the present disclosure, if all verifications are passed, the first key management system considers the identity authentication of the first client successful and generates a unique Token for the client. This Token usually contains some information about the user session and sets a validity period limit.
[0068] In one embodiment of the present disclosure, after receiving the Token issued by the first key management system, the first client can store it in a memory or an encrypted secure storage area to prevent unauthorized access. At the same time, the first client needs to monitor the validity period of the Token to ensure that it is updated or re-applied for a new Token in time before it expires.
[0069] In one embodiment of the present disclosure, after KMS injects a key into a secure medium, it reports the corresponding relationship between KMS and the secure medium to CMSP, and CMSP performs management and maintenance; after the mail user has the secure medium, it registers it in the mailbox system and then associates it with the mailbox user. Specifically, the following two methods can be used:
[0070] ① Pre-management: The mailbox system reports the correspondence between mailbox users and security media to CMSP, so that CMSP will maintain the correspondence between mailbox users, security media, and KMS.
[0071] ② Real-time query: When KMS queries CMSP for the KMS to which the mailbox user belongs, CMSP queries the mailbox system for the correspondence between the mailbox user and the security medium, and the mailbox system responds. At this time, it is necessary to consider whether the delay generated during data communication affects user use.
[0072] In one embodiment of the present disclosure, the identity authentication process of the secure medium can be performed simultaneously with the key application process. For example, if the validity period of the token expires, when the client applies for a key, the identity authentication and key application can be performed simultaneously, and the KMS returns the token and the email encryption key to the client. Alternatively, if the token is not used, the identity authentication needs to be performed simultaneously each time the client applies for a key.
[0073] In one embodiment of the present disclosure, considering the limited rate of quantum key distribution, KMS can obtain quantum keys from KM in advance, KMS locally stores a certain amount of quantum keys, and replenishes them in time after the keys are consumed.
[0074] Figure 3 A flowchart of another method for email encryption based on quantum key distribution in an embodiment of the present disclosure is shown, which is applied to a second key management system, such as Figure 3 As shown, the method comprises the following steps:
[0075] S302: Receive a key encryption request sent by a first key management system.
[0076] In one embodiment of the present disclosure, the key encryption request received from the first key management system may carry a key identifier of the quantum key and a secure medium identifier of the second client.
[0077] S304, encrypting the quantum key according to the second charging key stored in the secure medium of the second client to obtain a second encrypted quantum key, wherein the second client is associated with the second key management system, and the quantum key is a quantum key pre-negotiated by the first key management system and the second key management system.
[0078] In one embodiment of the present disclosure, the second key management system encrypts the quantum key using the second filling key stored in the secure medium of the second client, thereby obtaining the second encrypted quantum key.
[0079] S306: Return a key encryption response to the first key management system, wherein the key encryption response carries the second encrypted quantum key and the second injection key identifier.
[0080] As can be seen from the above, after receiving the key encryption request sent by the first key management system, the second key management system in the disclosed embodiment encrypts the quantum key according to the second charging key stored in the secure medium equipped by the second client to obtain the second encrypted quantum key, and carries the second encrypted quantum key in the key encryption response and returns it to the first key management system. The disclosed embodiment can improve the security of email applications and reduce system maintenance costs.
[0081] In one embodiment of the present disclosure, before the above S302, the method also includes: receiving an identity authentication request sent by the second client, wherein the identity authentication request is used by the second client to request to establish an association relationship with the second key management system, and the identity authentication request carries the identity authentication identifier of the second client; performing identity verification on the second client according to the identity authentication identifier of the second client; if the identity verification of the second client passes, returning an identity authentication response to the second client, wherein the identity authentication response carries the identity security identifier of the second client.
[0082] In one embodiment of the present disclosure, the second client may initiate an identity authentication request to the key management system to which it belongs (i.e., the second key management system). The identity authentication request may be sent when the second client communicates with the second key management system for the first time, or may be sent when the identity security identifier of the second client expires or the authentication fails.
[0083] In one embodiment of the present disclosure, the identity authentication request may carry a secure medium identifier equipped by the second client, a charging key identifier stored in the secure medium, and a key verification value. The secure medium identifier may be a unique identifier of a device such as a smart card or a USB token, which is used to identify the client and the specific secure medium it holds; the charging key identifier may be an identifier of a designated charging key to be used, which is often a symmetric key stored in the secure medium, used for encryption and decryption operations and message authentication code MAC calculation; the password verification value is obtained by the client using the charging key to symmetrically encrypt or MAC calculation the serial number N or timestamp T and the random number R.
[0084] In one embodiment of the present disclosure, the second key management system finds the corresponding charging key according to the provided charging key identifier, and then uses the same algorithm (i.e., symmetric encryption or MAC calculation) and parameters (i.e., sequence number N or timestamp T and random number R) to recalculate the password check value, and compares it with the password check value provided by the client. In addition, in order to prevent replay attacks, the second key management system will also check whether the sequence number N or timestamp T is reasonable to ensure that it has not been reused to reduce the risk of replay attacks.
[0085] In one embodiment of the present disclosure, if all verifications are passed, the second key management system considers the identity authentication of the second client successful and generates two unique Tokens for the client. The Tokens usually contain some information about the user session and set a validity period limit.
[0086] In one embodiment of the present disclosure, after receiving the Token issued by the second key management system, the second client can store it in a memory or an encrypted secure storage area to prevent unauthorized access. At the same time, the second client needs to monitor the validity period of the Token to ensure that it is updated or re-applied for a new Token in time before it expires.
[0087] Combined with the above Figure 1 The system architecture diagram shown in the figure is as follows: Figure 4 A schematic diagram showing another email encryption method based on quantum key distribution in an embodiment of the present disclosure applied to the system architecture is shown as follows: Figure 4 As shown, the method may include the following steps:
[0088] ① The sender's email terminal A sends a key acquisition request to the key management system KMSA associated with terminal A to obtain the email encryption key. The key acquisition request carries the secure media SMA information equipped by terminal A ( Figure 4 Not marked), Token and the identity information of the recipient terminal B.
[0089] ②KMSA verifies the Token. If the Token verification passes, KMSA queries CMSP for the key management system KMS associated with terminal B; if the Token verification fails, KMSA returns identity authentication failure information to terminal A.
[0090] ③ If the token verification is passed, CMSP returns the query result to KMSA, which may include that the KMS associated with terminal B is KMSB, and the secure medium equipped with terminal B is SMB ( Figure 4 not marked in the figure).
[0091] ④ Based on the query results, KMSA uses the quantum key EK1 pre-negotiated with KMSB as the email encryption key, and sends a key encryption request to KMSB to request the use of SMB to charge key protected EK1. The key encryption request can carry the key identifier and SMB identifier of EK1.
[0092] ⑤KMSB returns the second encrypted quantum key and the key identifier of the SMB injection key CKB1 to KMSA. The second encrypted quantum key is the encrypted quantum key obtained by KMSB after encrypting EK1 using CKB1, that is, E_CKB1(EK1).
[0093] ⑥KMSA uses the SMA charging key CKA1 to encrypt EK1 to obtain the first encrypted quantum key E_CKA1(EK1), and then returns E_CKA1(EK1), the key identifier of CKA1, E_CKB1(EK1), and the key identifier of CKB1 to terminal A.
[0094] ⑦Terminal A uses CKA1 to decrypt E_CKA1(EK1) to obtain EK1, uses EK1 to encrypt the content M of the email to be sent to form the email body E_EK1(M), and encapsulates E_CKB1(EK1) and the key identifier of CKB1 in the email header to form an encrypted email.
[0095] In one embodiment of the present disclosure, after receiving the encrypted email, terminal B can decrypt the email through the following steps:
[0096] ① After receiving the encrypted email from the sender, terminal B parses the email header to obtain the key identifiers of E_CKB1 (EK1) and CKB1.
[0097] ②Terminal B uses CKB1 to decrypt E_CKB1(EK1) to obtain EK1, and uses EK1 to decrypt E_EK1(M) to obtain the plaintext of the email content.
[0098] In one embodiment of the present disclosure, if terminal B needs to forward the above encrypted email to terminal C, it can be achieved through the following steps:
[0099] ①Terminal B sends a key application request to KMSB to apply for the encapsulated email encryption key EK1. The key application request can carry SMB information, Token, identity information of the recipient terminal C, E_CKB2 (EK1) and the key identifier of CKB2.
[0100] ②KMSB verifies the Token. If the Token verification passes, KMSB uses CKB2 to decrypt E_CKB2(EK1) to obtain EK1, and queries CMSP for the key management system KMS associated with terminal C. If the Token verification fails, the identity authentication failure information is returned to terminal B.
[0101] ③CMSP returns the query result to KMSB, which may include that the KMS associated with terminal C is KMSC, and the security medium equipped with terminal C is SMC.
[0102] ④ Based on the query results, KMSB uses the quantum key EK2 pre-negotiated with KMSC as the email encryption key, and sends a key encryption request to KMSC to request the use of EK2 protected by the SMC key. The key encryption request can carry the key identifiers E_EK2 (EK1), EK2 and the SMC identifier.
[0103] ⑤KMSC uses EK2 to decrypt E_EK2(EK1) to obtain EK1, and returns the key identifier of the third encrypted quantum key and SM-C injection key CKC1 to KMSB. The third encrypted quantum key is the encrypted quantum key obtained by KMSC after encrypting EK1 using CKC1, that is, E_CKC1(EK1).
[0104] ⑥KMSB returns the key identifiers of E_CKC1 (EK1) and CKC1 to terminal B.
[0105] ⑦Terminal B removes the header of the original encrypted email, and encapsulates E_CKC1(EK1) and the key identifier of CKC1 as a new header. The body of the email is still E_EK1(M), forming an encrypted email and sending it to terminal C.
[0106] In one embodiment of the present disclosure, the above steps ④ to ⑥ may be replaced by the following steps ④' to ⑥':
[0107] ④'KMSB sends an SMC charging key acquisition request to KMSC according to the query result. The SMC charging key acquisition request may carry an SMC identifier.
[0108] ⑤'KMSC uses the quantum key EK2 pre-negotiated between KMSB as the key encryption key, encrypts the SMC injection key CKC1, obtains E_EK2(CKC1), and returns E_EK2(CKC1), the key identifier of CKC1 and the key identifier of EK2 to KMSB.
[0109] ⑥'KMSB uses EK2 to decrypt E_EK2(CKC1) to obtain CKC1, and then uses CKC1 to encrypt EK1 to obtain E_CKC1(EK1). KMSB returns E_CKC1(EK1) and the key identifier of CKC1 to terminal B.
[0110] The premise of the above method is that the sender and the recipient's client are in different domains. In one embodiment of the present disclosure, when the sender (terminal A) and the recipient (terminal B) belong to a single domain and the KMS associated with terminal A is KMSA, the following steps can be used to encrypt the email to be sent:
[0111] ① The sender's email terminal A sends a key acquisition request to KMSA to obtain the email encryption key. The key acquisition request carries the secure media SMA information, Token and the identity information of the recipient terminal B equipped with terminal A.
[0112] ②KMSA verifies the Token. If the Token verification passes, KMSA queries CMSP for the key management system KMS associated with terminal B; if the Token verification fails, KMSA returns identity authentication failure information to terminal A.
[0113] ③ If the token verification passes, CMSP returns the query result to KMSA, which may include that the KMS associated with terminal B is KMSA, and the secure medium equipped with terminal B is SMB.
[0114] ④ Based on the query results, KMSA uses EK1 generated by a quantum random number generator or other random sources as the email encryption key, and uses the SMA to charge the key CKA1 to protect EK1, obtaining E_CKA1(EK1), and uses the SMB to charge the key CKB1 to protect EK1, obtaining E_CKB1(EK1), and returns E_CKA1(EK1), the key identifier of CKA1, E_CKB1(EK1) and the key identifier of CKB1 to terminal A.
[0115] ⑤Terminal A uses CKA1 to decrypt E_CKA1(EK1) to obtain EK1, and then uses EK1 to encrypt the content M of the email to be sent to form the email body E_EK1(M), and at the same time encapsulates E_CKB1(EK1) and the key identifier of CKB1 in the email header to form an encrypted email.
[0116] In one embodiment of the present disclosure, when the forwarding sender (terminal B) and the recipient (terminal C) belong to a single domain and the KMS associated with terminal B is KMSB, email forwarding can be performed through the following steps:
[0117] ①Terminal B sends a key application request to KMSB to apply for the encapsulated email encryption key EK1. The key application request can carry SMB information, Token, identity information of the recipient terminal C, E_CKB2 (EK1) and the key identifier of CKB2.
[0118] ②KMSB verifies the Token. If the Token verification passes, KMSB uses CKB2 to decrypt E_CKB2(EK1) to obtain EK1, and queries CMSP for the key management system KMS associated with terminal C. If the Token verification fails, the identity authentication failure information is returned to terminal B.
[0119] ③CMSP returns the query result to KMSB, which may include that the KMS associated with terminal C is KMSB, and the security medium equipped with terminal C is SMC.
[0120] ④ Based on the query result, KMSB uses SMC's injection key CKC1 to encrypt EK1 to obtain E_CKC1(EK1), and then returns E_CKC1(EK1) and the key identifier of CKC1 to terminal B.
[0121] ⑤Terminal B removes the header of the original encrypted email, and encapsulates E_CKC1(EK1) and the key identifier of CKC1 as a new header. The email body is still E_EK1(M), forming an encrypted email and sending it to terminal C.
[0122] In one embodiment of the present disclosure, for mass email, that is, when a sender sends the same email to multiple recipients, it can be regarded as sending encrypted emails to different recipients with the same email encryption key but different key encapsulation parts. When processing, KMS queries the KMS associated with each recipient, and feeds back the email encryption key protected by the key of each recipient's secure medium to the sender. The sending client encrypts the email content once to form the email body, and then combines them for each recipient to form an encrypted email.
[0123] In one embodiment of the present disclosure, a symmetric cryptographic algorithm may be used as an encryption algorithm, such as SM4, AES, etc., including encryption of email content and encryption of various keys. In addition, the integrity protection of email content may be further increased, such as using block cipher working modes such as CCM with cipher block chaining-message authentication code counter mode, GCM with Galois / counter mode, etc., or using a corresponding algorithm of authenticated encryption, such as adding calculation of message authentication code MAC, etc.
[0124] Figure 5 An email encryption system based on quantum key distribution in an embodiment of the present disclosure is shown. Figure 5 As shown, the system includes: a first key management system 501 and a second key management system 502 .
[0125] The first key management system 501 is used to receive a key acquisition request sent by a first client, wherein the key acquisition request carries the security medium information of the first client and the identity information of the second client obtained in advance, the first client is associated with the first key management system 501, and the second client is associated with the second key management system 502; according to the identity information of the second client, the quantum key pre-negotiated by the first key management system 501 and the second key management system 502 is obtained; and a key encryption request is sent to the second key management system 502;
[0126] The second key management system 502 is used to receive the key encryption request sent by the first key management system 501; encrypt the quantum key according to the second charging key stored in the secure medium of the second client to obtain a second encrypted quantum key; return a key protection response to the first key management system 501, wherein the key protection response carries the second encrypted quantum key and the second charging key identifier;
[0127] Among them, the first key management system 501 is also used to encrypt the quantum key according to the first charging key to obtain a first encrypted quantum key, wherein the first charging key is a key pre-stored in the secure medium of the first client; return a key acquisition response to the first client, so that the first client encrypts the email to be sent according to the key information carried in the key acquisition response, wherein the key information includes the first encrypted quantum key, the first charging key identifier, the second encrypted quantum key and the second charging key identifier.
[0128] As can be seen from the above, the first key management system in the disclosed embodiment obtains the quantum key pre-negotiated with the second key management system according to the information carried in the key acquisition request sent by the first client, and then sends a key encryption request to the second key management system. The second key management system encrypts the quantum key using the second filling key according to the received request, and returns the encrypted second encrypted quantum key and the second filling key identifier to the first key management system. Then, the first key management system encrypts the quantum key using the first filling key, and returns the encrypted quantum key and the filling key identifier to the first client, so that the first client encrypts the email to be sent according to the received key information. The disclosed embodiment can improve the security of email applications and reduce system maintenance costs.
[0129] Based on the same inventive concept, the embodiments of the present disclosure also provide a mail encryption device based on quantum key distribution, as described in the following embodiments. Since the principle of solving the problem in the device embodiment is similar to that in the above method embodiment, the implementation of the device embodiment can refer to the implementation of the above method embodiment, and the repeated parts will not be repeated.
[0130] Figure 6 A schematic diagram of a mail encryption device based on quantum key distribution in an embodiment of the present disclosure is shown. Figure 6 As shown, the device includes: a key acquisition request receiving module 601, a quantum key acquisition module 602, a key encryption request sending module 603, a key encryption response receiving module 604 and a key acquisition response returning module 605.
[0131] The key acquisition request receiving module 601 is used to receive a key acquisition request sent by a first client, wherein the key acquisition request carries the security medium information of the first client and the identity information of the second client obtained in advance, and the first client is associated with the first key management system, and the second client is associated with the second key management system; the quantum key acquisition module 602 is used to obtain the quantum key pre-negotiated by the first key management system and the second key management system according to the identity information of the second client; the key encryption request sending module 603 is used to send a key encryption request to the second key management system, so that the second key management system encrypts the quantum key according to the second filling key, obtains the second encrypted quantum key, and sends the key encryption request to the first key management system. A key management system returns a key encryption response, wherein the second charging key is a key pre-stored in the secure medium of the second client, and the key encryption response carries the second encrypted quantum key and the second charging key identifier; a key encryption response receiving module 604 is used to encrypt the quantum key according to the first charging key to obtain the first encrypted quantum key, wherein the first charging key is a key pre-stored in the secure medium of the first client; a key acquisition response returning module 605 is used to return a key acquisition response to the first client, so that the first client encrypts the email to be sent according to the key information carried in the key acquisition response, wherein the key information includes the first encrypted quantum key, the first charging key identifier, the second encrypted quantum key and the second charging key identifier.
[0132] As can be seen from the above, after receiving the key acquisition request sent by the first client, the first key management system in the disclosed embodiment obtains the quantum key pre-negotiated with the second key management system according to the identity information of the second client carried therein, and then sends a key encryption request to the second key management system so that the second key management system uses the second filling key to encrypt the quantum key, and obtains the second encrypted quantum key and the second filling key identifier returned by the second key management system, and then encrypts the quantum key according to the first filling key to obtain the first encrypted quantum key and the first filling key identifier, and carries the above-obtained encrypted quantum key and filling key identifier in the key acquisition response, and returns it to the first client so that the first client encrypts the email to be sent. The disclosed embodiment can improve the security of email applications and reduce system maintenance costs.
[0133] In one embodiment of the present disclosure, the key acquisition request also carries the identity authentication information of the first client; the device also includes: a first identity authentication module 606, which is used to authenticate the first client based on the identity authentication information of the first client, wherein the identity authentication information includes: an identity security identifier; if the first client identity authentication passes, communicating with the second key management system based on the key acquisition request; if the first client identity authentication fails, sending an authentication failure message to the first client.
[0134] In one embodiment of the present disclosure, the above-mentioned first identity authentication module 606 is also used to receive an identity authentication request sent by the first client, wherein the identity authentication request is used by the first client to request to establish an association relationship with the first key management system, and the identity authentication request carries the identity authentication identifier of the first client; according to the identity authentication identifier of the first client, the identity of the first client is verified; if the identity verification of the first client passes, an identity authentication response is returned to the first client, wherein the identity authentication response carries the identity security identifier of the first client.
[0135] Figure 7 A schematic diagram of another mail encryption device based on quantum key distribution in an embodiment of the present disclosure is shown. Figure 7 As shown, the device includes: a key encryption request receiving module 701, a quantum key encryption module 702 and a key encryption response returning module 703.
[0136] Among them, the key encryption request receiving module 701 is used to receive the key encryption request sent by the first key management system; the quantum key encryption module 702 is used to encrypt the quantum key according to the second injection key stored in the security medium of the second client to obtain the second encrypted quantum key, wherein the second client is associated with the second key management system, and the quantum key is the quantum key pre-negotiated by the first key management system and the second key management system; the key encryption response returning module 703 is used to return the key encryption response to the first key management system, wherein the key encryption response carries the second encrypted quantum key and the second injection key identifier.
[0137] As can be seen from the above, after receiving the key encryption request sent by the first key management system, the second key management system in the disclosed embodiment encrypts the quantum key according to the second charging key stored in the secure medium equipped by the second client to obtain the second encrypted quantum key, and carries the second encrypted quantum key in the key encryption response and returns it to the first key management system. The disclosed embodiment can improve the security of email applications and reduce system maintenance costs.
[0138] In one embodiment of the present disclosure, the device also includes: a second identity authentication module 704, which is used to receive an identity authentication request sent by a second client, wherein the identity authentication request is used by the second client to request to establish an association relationship with a second key management system, and the identity authentication request carries an identity authentication identifier of the second client; based on the identity authentication identifier of the second client, an identity verification is performed on the second client; if the identity verification of the second client passes, an identity authentication response is returned to the second client, wherein the identity authentication response carries the identity security identifier of the second client.
[0139] Those skilled in the art will appreciate that various aspects of the present disclosure may be implemented as systems, methods or program products. Therefore, various aspects of the present disclosure may be specifically implemented in the following forms, namely: complete hardware implementation, complete software implementation (including firmware, microcode, etc.), or a combination of hardware and software, which may be collectively referred to herein as "circuits", "modules" or "systems".
[0140] Refer to the following Figure 8 The electronic device 800 according to this embodiment of the present disclosure is described. Figure 8 The electronic device 800 shown is merely an example and should not bring any limitation to the functions and scope of use of the embodiments of the present disclosure.
[0141] like Figure 8As shown, the electronic device 800 is in the form of a general computing device. The components of the electronic device 800 may include but are not limited to: at least one processing unit 810, at least one storage unit 820, and a bus 830 connecting different system components (including the storage unit 820 and the processing unit 810).
[0142] The storage unit stores program codes, which can be executed by the processing unit 810, so that the processing unit 810 executes the steps described in the above “exemplary method” section of this specification according to various exemplary embodiments of the present disclosure.
[0143] In one embodiment of the present disclosure, when the electronic device 800 is a first key management system, the processing unit 810 may perform the following steps: receiving a key acquisition request sent by a first client, wherein the key acquisition request carries the security medium information of the first client and the identity information of the second client acquired in advance, the first client is associated with the first key management system, and the second client is associated with the second key management system; obtaining a quantum key pre-negotiated by the first key management system and the second key management system according to the identity information of the second client; sending a key encryption request to the second key management system, so that the second key management system encrypts the quantum key according to the second injection key The method comprises: encrypting the quantum key according to the first charging key to obtain the first encrypted quantum key, obtaining the second encrypted quantum key, and returning a key encryption response to the first key management system, wherein the second charging key is a key pre-stored in the secure medium of the second client, and the key encryption response carries the second encrypted quantum key and the second charging key identifier; encrypting the quantum key according to the first charging key to obtain the first encrypted quantum key, wherein the first charging key is a key pre-stored in the secure medium of the first client; returning a key acquisition response to the first client, so that the first client encrypts the email to be sent according to the key information carried in the key acquisition response, wherein the key information includes the first encrypted quantum key, the first charging key identifier, the second encrypted quantum key, and the second charging key identifier.
[0144] In one embodiment of the present disclosure, when the electronic device 800 is a second key management system, the processing unit 810 may perform the following steps: receiving a key encryption request sent by the first key management system; encrypting the quantum key according to the second charging key stored in the secure medium of the second client to obtain a second encrypted quantum key, wherein the second client is associated with the second key management system, and the quantum key is a quantum key pre-negotiated by the first key management system and the second key management system; returning a key encryption response to the first key management system, wherein the key encryption response carries the second encrypted quantum key and the second charging key identifier.
[0145] The storage unit 820 may include a readable medium in the form of a volatile storage unit, such as a random access memory unit (RAM) 8201 and / or a cache memory unit 8202 , and may further include a read-only memory unit (ROM) 8203 .
[0146] The storage unit 820 may also include a program / utility 8204 having a set (at least one) of program modules 8205, such program modules 8205 including but not limited to: an operating system, one or more application programs, other program modules, and program data, each of which or some combination may include an implementation of a network environment.
[0147] Bus 830 may represent one or more of several types of bus structures, including a memory unit bus or memory unit controller, a peripheral bus, an accelerated graphics port, a processing unit, or a local bus using any of a variety of bus architectures.
[0148] The electronic device 800 may also communicate with one or more external devices 840 (e.g., keyboards, pointing devices, Bluetooth devices, etc.), may also communicate with one or more devices that enable a user to interact with the electronic device 800, and / or communicate with any device that enables the electronic device 800 to communicate with one or more other computing devices (e.g., routers, modems, etc.). Such communication may be performed via an input / output (I / O) interface 850. Furthermore, the electronic device 800 may also communicate with one or more networks (e.g., local area networks (LANs), wide area networks (WANs), and / or public networks, such as the Internet) via a network adapter 860. As shown, the network adapter 860 communicates with other modules of the electronic device 800 via a bus 830. It should be understood that, although not shown in the figure, other hardware and / or software modules may be used in conjunction with the electronic device 800, including but not limited to: microcode, device drivers, redundant processing units, external disk drive arrays, RAID systems, tape drives, and data backup storage systems, etc.
[0149] Through the description of the above implementation, it is easy for those skilled in the art to understand that the example implementation described here can be implemented by software, or by software combined with necessary hardware. Therefore, the technical solution according to the implementation of the present disclosure can be embodied in the form of a software product, which can be stored in a non-volatile storage medium (which can be a CD-ROM, a USB flash drive, a mobile hard disk, etc.) or on a network, including several instructions to enable a computing device (which can be a personal computer, a server, a terminal device, or a network device, etc.) to execute the method according to the implementation of the present disclosure.
[0150] Based on the same inventive concept, the embodiment of the present disclosure also provides a computer-readable storage medium on which a computer program is stored. When the computer program is executed by a processor, any of the above-mentioned email encryption methods based on quantum key distribution is implemented. Since the principle of solving the problem in the embodiment of the computer-readable storage medium is similar to that in the above-mentioned method embodiment, the implementation of the embodiment of the computer-readable storage medium can refer to the implementation of the above-mentioned method embodiment, and the repeated parts will not be repeated.
[0151] More specific examples of computer-readable storage media in the present disclosure may include, but are not limited to, an electrical connection having one or more conductors, a portable computer disk, a hard disk, a random access memory (RAM), a read-only memory (ROM), an erasable programmable read-only memory (EPROM or flash memory), optical fiber, a portable compact disk read-only memory (CD-ROM), an optical storage device, a magnetic storage device, or any suitable combination of the foregoing.
[0152] In the present disclosure, a computer readable storage medium may include a data signal propagated in baseband or as part of a carrier wave, wherein a readable program code is carried. Such propagated data signals may take a variety of forms, including but not limited to electromagnetic signals, optical signals, or any suitable combination of the above. A readable signal medium may also be any readable medium other than a readable storage medium, which may send, propagate, or transmit a program for use by or in conjunction with an instruction execution system, apparatus, or device.
[0153] Alternatively, the program code contained on the computer-readable storage medium may be transmitted using any appropriate medium, including but not limited to wireless, wired, optical cable, RF, etc., or any suitable combination of the foregoing.
[0154] In a specific implementation, the program code for performing the operations of the present disclosure may be written in any combination of one or more programming languages, including object-oriented programming languages such as Java, C++, etc., and conventional procedural programming languages such as "C" or similar programming languages. The program code may be executed entirely on the user computing device, partially on the user device, as a separate software package, partially on the user computing device and partially on a remote computing device, or entirely on a remote computing device or server. In the case of a remote computing device, the remote computing device may be connected to the user computing device through any type of network, including a local area network (LAN) or a wide area network (WAN), or may be connected to an external computing device (e.g., using an Internet service provider to connect through the Internet).
[0155] Based on the same inventive concept, a computer program product is also provided in the embodiments of the present disclosure, including a computer program product, including: a computer program or an instruction, which, when executed by a processor, implements any one of the above method embodiments for email encryption based on quantum key distribution. Since the principle of solving the problem in the computer program product embodiment is similar to that in the above method embodiment, the implementation of the computer program product embodiment can refer to the implementation of the above method embodiment, and the repeated parts will not be repeated.
[0156] It should be noted that, although several modules or units of the device for action execution are mentioned in the above detailed description, this division is not mandatory. In fact, according to the embodiments of the present disclosure, the features and functions of two or more modules or units described above can be embodied in one module or unit. On the contrary, the features and functions of one module or unit described above can be further divided into multiple modules or units to be embodied.
[0157] In addition, although the steps of the method in the present disclosure are described in a specific order in the drawings, this does not require or imply that the steps must be performed in this specific order, or that all the steps shown must be performed to achieve the desired results. Additionally or alternatively, some steps may be omitted, multiple steps may be combined into one step, and / or one step may be decomposed into multiple steps, etc.
[0158] Through the description of the above implementation, it is easy for those skilled in the art to understand that the example implementation described here can be implemented by software, or by software combined with necessary hardware. Therefore, the technical solution according to the implementation of the present disclosure can be embodied in the form of a software product, which can be stored in a non-volatile storage medium (which can be a CD-ROM, a USB flash drive, a mobile hard disk, etc.) or on a network, including several instructions to enable a computing device (which can be a personal computer, a server, a mobile terminal, or a network device, etc.) to execute the method according to the implementation of the present disclosure.
[0159] Those skilled in the art will readily appreciate other embodiments of the present disclosure after considering the specification and practicing the invention disclosed herein. The present disclosure is intended to cover any variations, uses or adaptations of the present disclosure, which follow the general principles of the present disclosure and include common knowledge or customary techniques in the art that are not disclosed in the present disclosure. The description and examples are intended to be exemplary only, and the true scope and spirit of the present disclosure are indicated by the appended claims.
Claims
1. A method for email encryption based on quantum key distribution, characterized in that: Applied to the first key management system, including: Receiving a key acquisition request sent by a first client, wherein the key acquisition request carries security medium information of the first client and pre-acquired identity information of a second client, the first client is associated with the first key management system, and the second client is associated with a second key management system; Obtaining, according to the identity information of the second client, a quantum key pre-negotiated by the first key management system and the second key management system; Sending a key encryption request to the second key management system, so that the second key management system encrypts the quantum key according to the second charging key to obtain a second encrypted quantum key, and returns a key encryption response to the first key management system, wherein the second charging key is a key pre-stored in the secure medium of the second client, and the key encryption response carries the second encrypted quantum key and the second charging key identifier; Encrypting the quantum key according to a first charging key to obtain a first encrypted quantum key, wherein the first charging key is a key pre-stored in a secure medium of the first client; Return a key acquisition response to the first client, so that the first client encrypts the email to be sent according to the key information carried in the key acquisition response, wherein the key information includes the first encryption quantum key, the first charging key identifier, the second encryption quantum key, and the second charging key identifier.
2. The email encryption method based on quantum key distribution according to claim 1 is characterized in that: The key acquisition request also carries the identity authentication information of the first client; Before obtaining the quantum key pre-negotiated by the first key management system and the second key management system according to the identity information of the second client, the method further includes: Performing identity authentication on the first client according to the identity authentication information of the first client, wherein the identity authentication information includes: an identity security identifier; If the first client identity authentication is passed, communicating with the second key management system according to the key acquisition request; If the identity authentication of the first client fails, an authentication failure message is sent to the first client.
3. The email encryption method based on quantum key distribution according to claim 2 is characterized in that: Before performing identity authentication on the first client according to the identity authentication information of the first client, the method further includes: Receiving an identity authentication request sent by a first client, wherein the identity authentication request is used by the first client to request to establish an association relationship with a first key management system, and the identity authentication request carries an identity authentication identifier of the first client; Performing identity verification on the first client according to the identity authentication identifier of the first client; If the identity verification of the first client passes, an identity authentication response is returned to the first client, wherein the identity authentication response carries the identity security identifier of the first client.
4. A method for email encryption based on quantum key distribution, characterized in that: Applicable to the second key management system, including: Receiving a key encryption request sent by a first key management system; Encrypting the quantum key according to the second charging key stored in the secure medium of the second client to obtain a second encrypted quantum key, wherein the second client is associated with the second key management system, and the quantum key is a quantum key pre-negotiated by the first key management system and the second key management system; Return a key encryption response to the first key management system, wherein the key encryption response carries the second encrypted quantum key and the second injection key identifier.
5. The email encryption method based on quantum key distribution according to claim 4 is characterized in that: Before receiving the key protection request sent by the first key management system, the method further includes: Receiving an identity authentication request sent by a second client, wherein the identity authentication request is used by the second client to request to establish an association relationship with a second key management system, and the identity authentication request carries an identity authentication identifier of the second client; Performing identity verification on the second client according to the identity authentication identifier of the second client; If the identity verification of the second client passes, an identity authentication response is returned to the second client, wherein the identity authentication response carries the identity security identifier of the second client.
6. An email encryption system based on quantum key distribution, characterized in that: include: a first key management system and a second key management system; The first key management system is used to receive a key acquisition request sent by a first client, wherein the key acquisition request carries the security medium information of the first client and the identity information of the second client obtained in advance, the first client is associated with the first key management system, and the second client is associated with the second key management system; according to the identity information of the second client, obtain the quantum key pre-negotiated by the first key management system and the second key management system; and send a key encryption request to the second key management system; The second key management system is used to receive a key encryption request sent by the first key management system; encrypt the quantum key according to the second charging key stored in the secure medium of the second client to obtain a second encrypted quantum key; and return a key protection response to the first key management system, wherein the key protection response carries the second encrypted quantum key and the second charging key identifier; The first key management system is further used to encrypt the quantum key according to the first charging key to obtain a first encrypted quantum key, wherein the first charging key is a key pre-stored in the secure medium of the first client; return a key acquisition response to the first client, so that the first client encrypts the email to be sent according to the key information carried in the key acquisition response, wherein the key information includes the first encrypted quantum key, the first charging key identifier, the second encrypted quantum key and the second charging key identifier.
7. An email encryption device based on quantum key distribution, characterized in that: include: A key acquisition request receiving module, configured to receive a key acquisition request sent by a first client, wherein the key acquisition request carries the security medium information of the first client and the pre-acquired identity information of a second client, the first client is associated with a first key management system, and the second client is associated with a second key management system; A quantum key acquisition module, configured to obtain, according to the identity information of the second client, a quantum key pre-negotiated by the first key management system and the second key management system; a key encryption request sending module, configured to send a key encryption request to the second key management system, so that the second key management system encrypts the quantum key according to the second charging key to obtain a second encrypted quantum key, and returns a key encryption response to the first key management system, wherein the second charging key is a key pre-stored in the secure medium of the second client, and the key encryption response carries the second encrypted quantum key and the second charging key identifier; a key encryption response receiving module, configured to encrypt the quantum key according to a first injection key to obtain a first encrypted quantum key, wherein the first injection key is a key pre-stored in a secure medium of the first client; A key acquisition response returning module is used to return a key acquisition response to the first client, so that the first client encrypts the email to be sent according to the key information carried in the key acquisition response, wherein the key information includes the first encryption quantum key, the first charging key identifier, the second encryption quantum key and the second charging key identifier.
8. An email encryption device based on quantum key distribution, characterized in that: include: A key encryption request receiving module, used to receive a key encryption request sent by the first key management system; a quantum key encryption module, configured to encrypt the quantum key according to a second charging key stored in a secure medium of a second client to obtain a second encrypted quantum key, wherein the second client is associated with a second key management system, and the quantum key is a quantum key pre-negotiated by the first key management system and the second key management system; A key encryption response returning module is used to return a key encryption response to the first key management system, wherein the key encryption response carries the second encrypted quantum key and the second injection key identifier.
9. An electronic device, characterized in that: include: processor; as well as A memory, configured to store executable instructions of the processor; The processor is configured to execute the email encryption method based on quantum key distribution as described in any one of claims 1 to 5 by executing the executable instructions.
10. A computer-readable storage medium having a computer program stored thereon, characterized in that: When the computer program is executed by a processor, the email encryption method based on quantum key distribution described in any one of claims 1 to 5 is implemented.
11. A computer program product comprising: A computer program or instruction, characterized in that when the computer program or instruction is executed by a processor, it implements the email encryption method based on quantum key distribution as described in any one of claims 1 to 5.
Citation Information
Patent Citations
System for sharing quantum key and secure communication method based on system
CN113132090A
Cross-domain identity authentication method and system based on quantum key distribution network
CN116527259A
Using Keyboard App to Encrypt E-mail and Other Digital Data
US20210352055A1
Cited By
Mail transmission method based on quantum local area network
CN120582913A