Method and related device for mail encryption based on quantum key distribution
By using quantum key distribution technology, and in collaboration with the first and second key management systems, quantum keys are generated and encrypted, the security problem of email under the threat of quantum computing is solved, achieving higher security and reducing system maintenance costs.
Patent Information
- Application Number
- CN202510172735.0
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2025-02-17
- Publication Date
- 2025-11-18
- Estimated Expiration
- 2045-02-17
AI Technical Summary
Existing email encryption methods are less secure when faced with the threats of quantum computing and quantum algorithms, and are unable to effectively protect the confidentiality and integrity of email information.
A quantum key distribution-based approach is adopted, in which a first key management system and a second key management system work together to generate and encrypt quantum keys. The injected keys in the client's secure medium are then used to encrypt the emails, ensuring the security of the email content.
It improves the security of email applications, reduces system maintenance costs, and enhances the ability to resist quantum computing threats.
Smart Images

Figure CN120017376B_ABST
Abstract
Description
TECHNICAL FIELD
[0001] The present disclosure relates to the field of network technology and security technology, and particularly relates to a mail encryption method, system, device, equipment, medium and program product based on quantum key distribution. BACKGROUND
[0002] Electronic mail is a technology for sending messages by electronic means, and is one of the important tools for communication in modern society. The security of electronic mail mainly includes the identity authentication of the sender and the recipient, and the security and integrity of the mail information in the process of sending, forwarding and storing.
[0003] In the related art, the current electronic mail uses public key algorithms such as RSA or SM2 elliptic curve cryptography. RSA is a non-symmetric encryption algorithm based on the large integer factorization problem, and is widely used in data encryption, digital signature and other fields; SM2 is used to replace the traditional RSA algorithm to provide a more efficient and secure encryption solution, and is mainly used in digital signature, key exchange and encryption scenarios. However, the development of quantum computing and quantum algorithms will affect the security of electronic mail.
[0004] With the continuous breakthroughs in quantum computing hardware, and the emergence of quantum algorithms such as Shor algorithm and Grover algorithm, the current public key cryptography based on large number decomposition and other computational complexity has been greatly threatened. Among them, Shor algorithm can efficiently solve the large integer factorization problem, which means that it can quickly crack RSA encryption; Grover algorithm, although not as direct a threat to a specific type of encryption algorithm as Shor algorithm, provides a general method to speed up unordered database searches, including key search attacks for breaking symmetric key encryption, which can theoretically greatly reduce the time complexity required for brute force cracking, posing a potential threat to various security measures including electronic mail encryption.
[0005] It should be noted that the information disclosed in the above background section is only used to strengthen the understanding of the background of the present disclosure, and therefore can include information that does not constitute prior art known to those of ordinary skill in the art. SUMMARY
[0006] The present disclosure provides a mail encryption method, system, device, equipment, medium and program product based on quantum key distribution, which at least partially overcomes the problem of low security in the process of electronic mail sending and receiving in the related art.
[0007] Other characteristics and advantages of the present disclosure will become apparent from the following detailed description, or will be learned by practice of the present disclosure.
[0008] According to one aspect of the present disclosure, a mail encryption method based on quantum key distribution is provided, which is applied to a first key management system and includes: receiving a key acquisition request sent by a first client, wherein the key acquisition request carries security medium information of the first client and pre-acquired identity information of a second client, the first client has an association relationship with the first key management system, and the second client has an association relationship with a second key management system; obtaining a quantum key pre-agreed by the first key management system and the second key management system according to the identity information of the second client; sending a key encryption request to the second key management system, so that the second key management system encrypts the quantum key according to a second charging key pre-stored in a security medium of the second client to obtain a second encrypted quantum key, and returns a key encryption response to the first key management system, wherein the key encryption response carries the second encrypted quantum key and a second charging key identifier; encrypting the quantum key according to a first charging key pre-stored in a security medium of the first client to obtain a first encrypted quantum key; and returning a key acquisition response to the first client, so that the first client encrypts a to-be-sent mail according to key information carried in the key acquisition response, wherein the key information includes the first encrypted quantum key, the first charging key identifier, the second encrypted quantum key, and the second charging key identifier.
[0009] In some embodiments, the key acquisition request further carries identity authentication information of the first client; and before obtaining the quantum key pre-agreed by the first key management system and the second key management system according to the identity information of the second client, the method further includes: performing identity authentication on the first client according to the identity authentication information of the first client, wherein the identity authentication information includes an identity security identifier; if the identity authentication of the first client is passed, performing communication with the second key management system according to the key acquisition request; and if the identity authentication of the first client is not passed, sending an authentication failure message to the first client.
[0010] In some embodiments, before authenticating the first client according to the identity authentication information of the first client, the method further comprises: receiving an identity authentication request sent by the first client, wherein the identity authentication request is used for the first client to request to establish an association relationship with the first key management system, and the identity authentication request carries an identity authentication identifier of the first client; performing identity verification on the first client according to the identity authentication identifier of the first client; and if the identity verification of the first client is passed, returning an identity authentication response to the first client, wherein the identity authentication response carries an identity security identifier of the first client.
[0011] According to another aspect of the present disclosure, a mail encryption method based on quantum key distribution is also provided, applied to a second key management system, comprising: receiving a key encryption request sent by a first key management system; encrypting a quantum key according to a second charging key stored in a security medium of a second client to obtain a second encrypted quantum key, wherein the second client has an association relationship with the second key management system, and the quantum key is a quantum key agreed in advance by the first key management system and the second key management system; and returning a key encryption response to the first key management system, wherein the key encryption response carries the second encrypted quantum key and a second charging key identifier.
[0012] In some embodiments, before receiving a key protection request sent by the first key management system, the method further comprises: receiving an identity authentication request sent by a second client, wherein the identity authentication request is used for the second client to request to establish an association relationship with the second key management system, and the identity authentication request carries an identity authentication identifier of the second client; performing identity verification on the second client according to the identity authentication identifier of the second client; and if the identity verification of the second client is passed, returning an identity authentication response to the second client, wherein the identity authentication response carries an identity security identifier of the second client.
[0013] According to another aspect of the present disclosure, a mail encryption system based on quantum key distribution is also provided, comprising: a first key management system and a second key management system.
[0014] The first key management system is configured to receive a key acquisition request sent by a first client, wherein the key acquisition request carries security medium information of the first client and pre-acquired identity information of a second client, the first client has an association relationship with the first key management system, and the second client has an association relationship with the second key management system; obtain quantum keys pre-agreed by the first key management system and the second key management system according to the identity information of the second client; send a key encryption request to the second key management system; the second key management system is configured to receive the key encryption request sent by the first key management system; encrypt the quantum keys according to a second charging key stored in a security medium of the second client to obtain second encrypted quantum keys; and return a key protection response to the first key management system, wherein the key protection response carries the second encrypted quantum keys and a second charging key identifier; the first key management system is further configured to encrypt the quantum keys according to a first charging key to obtain first encrypted quantum keys, wherein the first charging key is a key pre-stored in a security medium of the first client; and return a key acquisition response to the first client, so that the first client encrypts a to-be-sent email according to key information carried in the key acquisition response, wherein the key information includes the first encrypted quantum keys, the first charging key identifier, the second encrypted quantum keys, and the second charging key identifier.
[0015] According to another aspect of the present disclosure, there is also provided a mail encryption device based on quantum key distribution, comprising: a key acquisition request receiving module configured to receive a key acquisition request sent by a first client, wherein the key acquisition request carries security medium information of the first client and pre-acquired identity information of a second client, the first client has an association relationship with a first key management system, and the second client has an association relationship with a second key management system; a quantum key acquisition module configured to acquire a quantum key pre-agreed by the first key management system and the second key management system according to the identity information of the second client; a key encryption request sending module configured to send a key encryption request to the second key management system, so that the second key management system encrypts the quantum key according to a second refill key pre-stored in a security medium of the second client to obtain a second encrypted quantum key, and returns a key encryption response to the first key management system, wherein the key encryption response carries the second encrypted quantum key and a second refill key identifier; a key encryption response receiving module configured to encrypt the quantum key according to a first refill key pre-stored in a security medium of the first client to obtain a first encrypted quantum key; and a key acquisition response returning module configured to return a key acquisition response to the first client, so that the first client encrypts a to-be-sent mail according to key information carried in the key acquisition response, wherein the key information comprises the first encrypted quantum key, the first refill key identifier, the second encrypted quantum key, and the second refill key identifier.
[0016] According to another aspect of the present disclosure, there is also provided a mail encryption device based on quantum key distribution, comprising: a key encryption request receiving module configured to receive a key encryption request sent by a first key management system; a quantum key encryption module configured to encrypt a quantum key according to a second refill key stored in a security medium of a second client to obtain a second encrypted quantum key, wherein the second client has an association relationship with a second key management system, and the quantum key is a quantum key pre-agreed by the first key management system and the second key management system; and a key encryption response returning module configured to return a key encryption response to the first key management system, wherein the key encryption response carries the second encrypted quantum key and a second refill key identifier.
[0017] According to another aspect of the present disclosure, there is also provided an electronic device, comprising: a processor; and a memory configured to store executable instructions of the processor; wherein the processor is configured to execute any of the above-mentioned mail encryption methods based on quantum key distribution via execution of the executable instructions.
[0018] According to another aspect of the present disclosure, there is also provided a computer readable storage medium having stored thereon a computer program which, when executed by a processor, implements the quantum key distribution based email encryption method of any of the above.
[0019] According to another aspect of the present disclosure, there is also provided a computer program product comprising a computer program which, when executed by a processor, implements the quantum key distribution based email encryption method of any of the above.
[0020] The quantum key distribution based email encryption method, system, device, equipment, medium and program product provided in the embodiments of the present disclosure, the first key management system acquires the quantum key agreed upon in advance with the second key management system according to the information carried in the key acquisition request sent by the first client, and then sends a key encryption request to the second key management system, the second key management system encrypts the quantum key using the second refill key according to the received request, and returns the second encrypted quantum key and the second refill key identification to the first key management system, and then the first key management system encrypts the quantum key using the first refill key, and returns the encrypted quantum key and the refill key identification to the first client, so that the first client encrypts the to-be-sent email according to the received key information. The embodiments of the present disclosure can improve the security of the email application, and at the same time reduce the system maintenance cost.
[0021] It should be understood that the foregoing general description and the following detailed description are only exemplary and explanatory, and cannot limit the present disclosure. BRIEF DESCRIPTION OF DRAWINGS
[0022] The drawings herein are incorporated into the specification and form a part of the specification, show embodiments consistent with the present disclosure, and together with the specification serve to explain the principles of the present disclosure. Obviously, the drawings in the following description are only some embodiments of the present disclosure, and other drawings can be obtained by those skilled in the art without creative labor on the basis of these drawings.
[0023] Figure 1 An exemplary application system architecture schematic diagram to which the quantum key distribution based email encryption method in the embodiments of the present disclosure can be applied is shown;
[0024] Figure 2 A flowchart of a quantum key distribution based email encryption method in the embodiments of the present disclosure is shown;
[0025] Figure 3 A flowchart of another quantum key distribution based email encryption method in the embodiments of the present disclosure is shown;
[0026] Figure 4 A schematic diagram of another quantum key distribution-based email encryption method applied to the system architecture is shown in an embodiment of this disclosure;
[0027] Figure 5 An embodiment of the present disclosure illustrates a quantum key distribution-based email encryption system;
[0028] Figure 6 A schematic diagram of a quantum key distribution-based email encryption device is shown in an embodiment of this disclosure;
[0029] Figure 7 A schematic diagram of another email encryption device based on quantum key distribution is shown in an embodiment of this disclosure;
[0030] Figure 8 A structural block diagram of an electronic device according to an embodiment of the present disclosure is shown. Detailed Implementation
[0031] Exemplary embodiments will now be described more fully with reference to the accompanying drawings. However, these exemplary embodiments can be implemented in many forms and should not be construed as limited to the examples set forth herein; rather, they are provided so that this disclosure will be more comprehensive and complete, and will fully convey the concept of the exemplary embodiments to those skilled in the art. The described features, structures, or characteristics may be combined in any suitable manner in one or more embodiments.
[0032] Furthermore, the accompanying drawings are merely illustrative of this disclosure and are not necessarily drawn to scale. The same reference numerals in the drawings denote the same or similar parts, and therefore repeated descriptions of them will be omitted. Some block diagrams shown in the drawings are functional entities and do not necessarily correspond to physically or logically independent entities. These functional entities may be implemented in software, in one or more hardware modules or integrated circuits, or in different network and / or processor devices and / or microcontroller devices.
[0033] To facilitate understanding, before introducing the embodiments of this disclosure, the following explanations are provided for several terms involved in the embodiments of this disclosure:
[0034] QKD: Quantum Key Distribution, a method for generating symmetric keys by transmitting quantum states between communicating parties, which theoretically possesses information-theoretic security at the protocol level.
[0035] Security Medium: Security medium can be in the form of smart cryptographic keys such as U-shields, TF cards, or SIM cards, which can be selected by various terminals as needed to provide terminals with basic cryptographic capabilities such as secure storage of quantum keys and encryption / decryption algorithms.
[0036] MAC: Message Authentication Code. A MAC is a short string appended to a message, calculated by the sender using a shared key and a specific algorithm. The receiver can recalculate the MAC using the same key and algorithm and compare it to the received MAC to verify whether the message has been tampered with and whether its origin is trustworthy.
[0037] Block cipher: A type of symmetric cipher that divides plaintext into multiple equal-length blocks. Each block is encrypted and decrypted using the same process and key. SM4 and AES are both block ciphers.
[0038] The specific implementation methods of the embodiments of this disclosure will now be described in detail with reference to the accompanying drawings.
[0039] Figure 1 A schematic diagram of an exemplary application system architecture for applying the quantum key distribution-based email encryption method described in this disclosure is shown. Figure 1 As shown, the system architecture may include a terminal A equipped with a secure medium, a terminal B equipped with a secure medium, an email system, a password management service platform (CMSP), a key management system A (KMSA), a key management system B (KMSB), as well as several key managers (KM) and several quantum key distribution (QKD) devices.
[0040] In one embodiment of this disclosure, both terminal A and terminal B can act as senders or recipients; the email system is a centrally managed email system responsible for sending and receiving emails; the cryptographic management service platform (CMSP) is responsible for managing and coordinating various resources and services related to encryption and decryption operations; the key management system (KMSA) is a key management system associated with terminal A, and the key management system (KMSB) is a key management system associated with terminal B. There is bidirectional communication between KMSA and KMSB to ensure key synchronization and management; the key manager (KM) is responsible for key generation, storage, and management; and the quantum key distribution (QKD) device is used to generate and distribute highly secure keys.
[0041] In one embodiment of this disclosure, terminal A and terminal B interact with their respective associated KMSs via their respective secure media; that is, terminal A interacts with KMSA, and terminal B interacts with KMSB. The KMS is a key management system directly connected to the KM, capable of acquiring quantum keys generated by the QKD network, filling the secure media with keys, using the filled keys for authentication, and processing email encryption key requests from the terminal's email client.
[0042] In one embodiment of this disclosure, taking terminal A as the sender as an example, when terminal A requests an email encryption key from KMSA, it carries its own security medium information, token, and recipient B's information. After receiving the request, KMSA communicates with KMSB through CMSP to ensure the secure transmission and synchronization of the key. KM is responsible for specific key management tasks, including key generation, storage, and distribution. QKD provides quantum key distribution services to enhance key security. CMSP acts as the central coordinator to ensure the efficient operation and security of the entire system.
[0043] Those skilled in the art will know that Figure 1 The number of devices within the system shown is merely illustrative; any number of devices can be included depending on actual needs. This disclosure does not limit this.
[0044] Under the above system architecture, this disclosure provides an email encryption method based on quantum key distribution, which can be executed by any electronic device with computing power.
[0045] Figure 2 This diagram illustrates a flowchart of a quantum key distribution-based email encryption method according to an embodiment of the present disclosure, applied to a first key management system, such as... Figure 2 As shown, the method includes the following steps:
[0046] S202, receive a key acquisition request sent by the first client, wherein the key acquisition request carries the security medium information of the first client and the identity information of the second client obtained in advance, the first client is associated with the first key management system, and the second client is associated with the second key management system.
[0047] In one embodiment of this disclosure, the first client, as the sender, will know the identity information of the second client, as the recipient, before sending the email. This information may include, for example, the second client's email address or other basic information. The first client, the security medium equipped by the first client, and the first key system associated with the first client are pre-related. The first client can carry its own security medium information in the key acquisition request, such as, user identifier, device identifier, etc.
[0048] S204, based on the identity information of the second client, obtain the quantum key pre-agreed upon by the first key management system and the second key management system.
[0049] In one embodiment of this disclosure, the first key management system and the second key management system typically first establish a physical connection that enables direct quantum communication, and then generate a shared quantum key through the common quantum key distribution (QKD) protocol. The quantum key is then stored in the respective key libraries of the first key management system and the second key management system.
[0050] S206, a key encryption request is sent to the second key management system so that the second key management system encrypts the quantum key according to the second charging key to obtain the second encrypted quantum key, and returns a key encryption response to the first key management system. The second charging key is a key pre-stored in the secure medium of the second client, and the key encryption response carries the identifiers of the second encrypted quantum key and the second charging key.
[0051] In one embodiment of this disclosure, the key encryption request sent by the first key management system to the second key management system may carry the key identifier of the quantum key and the security medium identifier of the second client. The security medium identifier of the second client may be obtained by the first key management system through a query of the cryptographic management service platform (CMSP). In addition, the first key management system may also obtain the key management system associated with the second client through a query of the CMSP as the second key management system.
[0052] S208, the quantum key is encrypted according to the first charging key to obtain the first encrypted quantum key, wherein the first charging key is a key pre-stored in the secure medium of the first client.
[0053] In one embodiment of this disclosure, the first key management system uses the first charging key stored in the secure medium of the first client to encrypt the quantum key, thereby obtaining the first encrypted quantum key.
[0054] S210, a key acquisition response is returned to the first client so that the first client can encrypt the email to be sent according to the key information carried in the key acquisition response, wherein the key information includes a first encryption quantum key, a first charging key identifier, a second encryption quantum key, and a second charging key identifier.
[0055] In one embodiment of this disclosure, the first client can find the first charging key from its own security medium based on the received first charging key identifier, decrypt the first encryption quantum key to obtain the quantum key, and use the quantum key to encrypt the content of the email to be sent. At the same time, the received second encryption quantum key and the second charging key identifier are encapsulated in the email header of the email to be sent, thus completing the encryption process of the email to be sent.
[0056] As described above, in this embodiment, after receiving a key acquisition request from a first client, the first key management system obtains the quantum key pre-agreed with the second key management system based on the identity information of the second client carried in the request. Then, it sends a key encryption request to the second key management system, causing the second key management system to encrypt the quantum key using a second charging key. This results in the second encrypted quantum key and the second charging key identifier returned by the second key management system. The quantum key is then encrypted again using the first charging key, yielding a first encrypted quantum key and a first charging key identifier. These obtained encrypted quantum key and charging key identifier are included in the key acquisition response and returned to the first client so that the first client can encrypt the email to be sent. This embodiment improves the security of email applications while reducing system maintenance costs.
[0057] In one embodiment of this disclosure, the key acquisition request also carries the identity authentication information of the first client; before the above S204, the first client is authenticated based on the identity authentication information of the first client, wherein the identity authentication information includes: identity security identifier; if the first client's identity authentication is successful, then communication is established with the second key management system according to the key acquisition request; if the first client's identity authentication fails, then an authentication failure message is sent to the first client.
[0058] In one embodiment of this disclosure, when the first client sends a request to the first key management system, the request also needs to carry the first client's identity security token. The first key management system first needs to verify the token to determine whether the identity of the first client initiating the request is legitimate.
[0059] In one embodiment of this disclosure, if the token verification passes, it proves that the system has identified the request as coming from an authorized user. The first key management system will continue to process the request. That is, the first key management system will communicate with the CMSP to query the key management system associated with the second client and the security medium information of the second client, so as to ensure that the encrypted email can use the correct key management system for subsequent encryption key generation and distribution.
[0060] In one embodiment of this disclosure, if the token verification fails, it means that the token carried in the request is invalid or cannot verify the client's identity. In this case, the first key management system will not continue to process the request, but will directly return an identity authentication failure message to the first client. This identity authentication failure message can be used to notify the first client to re-authenticate or check whether the identity security identifier carried in the request is correct.
[0061] In one embodiment of this disclosure, before authenticating the first client based on the first client's authentication information, the method further includes: receiving an authentication request sent by the first client, wherein the authentication request is used by the first client to request the establishment of an association with the first key management system, and the authentication request carries the first client's authentication identifier; verifying the first client's identity based on the first client's authentication identifier; and if the first client's identity verification passes, returning an authentication response to the first client, wherein the authentication response carries the first client's security identifier.
[0062] In one embodiment of this disclosure, the first client may initiate an authentication request to the key management system (i.e., the first key management system) with which it is associated. The authentication request may be sent when the first client communicates with the first key management system for the first time, or when the first client's identity security identifier becomes invalid or authentication fails.
[0063] In one embodiment of this disclosure, the authentication request may carry a security medium identifier equipped by the first client, a recharge key identifier stored in the security medium, and a key verification value. The security medium identifier may be a unique identifier for a device such as a smart card or USB token, used to identify the client and its specific security medium. The recharge key identifier may be an identifier specifying the recharge key to be used; the recharge key is often a symmetric key stored in the security medium, used for encryption and decryption operations and message authentication code (MAC) calculation. The password verification value is obtained by the client using the recharge key to perform symmetric encryption or MAC calculation on the sequence number N or timestamp T and a random number R.
[0064] In one embodiment of this disclosure, the charging key can be generated by the KMS using a quantum random number generator, and then a batch of charging keys is charged into a secure medium in a secure manner. The secure medium securely stores the charging keys, and the KMS also securely stores the charging keys of each secure medium. Both the secure medium and the KMS can associate and query specific charging keys through the identifier of the charging key, and use the charging key to perform encryption and decryption operations.
[0065] In one embodiment of this disclosure, after the refill key is used up, the secure medium and KMS can maintain and mark the used refill keys to distinguish between used and unused refill keys. If the recipient's KMS uses a refill key first, and the secure medium uses it later, the secure medium can synchronize the key usage, or proactively synchronize it during the next communication with the KMS, for example, during the authentication process.
[0066] In one embodiment of this disclosure, the first key management system locates the corresponding charging key based on the provided charging key identifier, then recalculates the password verification value using the same algorithm (i.e., symmetric encryption or MAC calculation) and parameters (i.e., sequence number N or timestamp T and random number R), and compares it with the password verification value provided by the client. Furthermore, to prevent replay attacks, the first key management system also checks whether the sequence number N or timestamp T is valid to ensure it has not been reused, thereby reducing the risk of replay attacks.
[0067] In one embodiment of this disclosure, if all verifications pass, the first key management system considers the first client to be successfully authenticated and generates a unique token for the client. This token typically contains some information about the user session and has an expiration period.
[0068] In one embodiment of this disclosure, after receiving the token issued by the first key management system, the first client can store it in memory or an encrypted secure storage area to prevent unauthorized access. Simultaneously, the first client needs to monitor the token's validity period to ensure that it is updated or a new token is applied for in a timely manner before expiration.
[0069] In one embodiment of this disclosure, after the KMS (Knowledge Management System) injects the key into the security medium, it reports the correspondence between the KMS and the security medium to the CMSP (Central Management Service Platform), which then manages and maintains it. Once an email user possesses the security medium, it registers it in the email system and then associates it with the email user's information. Specifically, this can be achieved using the following two methods:
[0070] ① Front-end management: The email system reports the correspondence between email users and security media to the CMSP, thereby the CMSP will maintain the correspondence between email users, security media, and KMS.
[0071] ② Real-time query: When KMS queries CMSP to determine the KMS to which a mailbox user belongs, CMSP queries the mailbox system to determine the mapping between the mailbox user and the security medium, and the mailbox system provides feedback. At this point, it is necessary to consider whether the latency generated during data communication will affect user experience.
[0072] In one embodiment of this disclosure, the authentication process of the secure medium can be performed simultaneously with the key request process. For example, if the token expires, when the client requests a key, authentication and key request can be performed concurrently, and the KMS returns the token and the email encryption key to the client together. Alternatively, without using a token, authentication must be performed every time the client requests a key.
[0073] In one embodiment of this disclosure, considering the limited rate of quantum key distribution, the KMS can obtain the quantum key from the KM in advance, and the KMS can store a certain amount of quantum key locally and replenish it in a timely manner after the key is consumed.
[0074] Figure 3 This illustration shows a flowchart of another email encryption method based on quantum key distribution, applied to a second key management system, as shown in the embodiment of this disclosure. Figure 3 As shown, the method includes the following steps:
[0075] S302, Receive key encryption request sent by the first key management system.
[0076] In one embodiment of this disclosure, the key encryption request received from the first key management system may carry the key identifier of the quantum key and the security medium identifier of the second client.
[0077] S304, the quantum key is encrypted using the second charging key stored in the secure medium of the second client to obtain the second encrypted quantum key. The second client is associated with the second key management system, and the quantum key is a quantum key pre-agreed upon by the first key management system and the second key management system.
[0078] In one embodiment of this disclosure, the second key management system uses the second charging key stored in the secure medium of the second client to encrypt the quantum key, thereby obtaining the second encrypted quantum key.
[0079] S306, return a key encryption response to the first key management system, wherein the key encryption response carries a second encryption quantum key and a second charging key identifier.
[0080] As described above, in this embodiment of the present disclosure, after receiving the key encryption request sent by the first key management system, the second key management system encrypts the quantum key according to the second charging key stored in the security medium equipped by the second client, obtaining a second encrypted quantum key, and carries the second encrypted quantum key in the key encryption response, returning it to the first key management system. This embodiment of the present disclosure can improve the security of email applications while reducing system maintenance costs.
[0081] In one embodiment of this disclosure, prior to S302 above, the method further includes: receiving an authentication request sent by a second client, wherein the authentication request is used by the second client to request the establishment of an association with the second key management system, and the authentication request carries an authentication identifier of the second client; verifying the identity of the second client based on the authentication identifier of the second client; and if the identity verification of the second client passes, returning an authentication response to the second client, wherein the authentication response carries an identity security identifier of the second client.
[0082] In one embodiment of this disclosure, the second client may initiate an authentication request to the key management system to which it belongs (i.e., the second key management system). The authentication request may be sent when the second client communicates with the second key management system for the first time, or it may be sent when the second client's identity security identifier becomes invalid or authentication fails.
[0083] In one embodiment of this disclosure, the authentication request may carry a security medium identifier equipped by the second client, a recharge key identifier stored in the security medium, and a key verification value. The security medium identifier may be a unique identifier for a device such as a smart card or USB token, used to identify the client and its specific security medium. The recharge key identifier may be an identifier specifying the recharge key to be used; the recharge key is often a symmetric key stored in the security medium, used for encryption and decryption operations and message authentication code (MAC) calculation. The password verification value is obtained by the client using the recharge key to perform symmetric encryption or MAC calculation on the sequence number N or timestamp T and a random number R.
[0084] In one embodiment of this disclosure, the second key management system locates the corresponding recharge key based on the provided recharge key identifier, then recalculates the password verification value using the same algorithm (i.e., symmetric encryption or MAC calculation) and parameters (i.e., sequence number N or timestamp T and random number R), and compares it with the password verification value provided by the client. Furthermore, to prevent replay attacks, the second key management system also checks whether the sequence number N or timestamp T is valid to ensure it has not been reused, thereby reducing the risk of replay attacks.
[0085] In one embodiment of this disclosure, if all verifications pass, the second key management system considers the second client to be successfully authenticated and generates two unique tokens for the client. These tokens typically contain some information about the user session and have an expiration period.
[0086] In one embodiment of this disclosure, after receiving the token issued by the second key management system, the second client can store it in memory or an encrypted secure storage area to prevent unauthorized access. Simultaneously, the second client needs to monitor the token's validity period to ensure that it is updated or a new token is applied for in a timely manner before expiration.
[0087] In combination with the above Figure 1 The system architecture diagram shown is as follows. Figure 4 A schematic diagram illustrating another quantum key distribution-based email encryption method applied to the system architecture in an embodiment of this disclosure is shown, such as... Figure 4 As shown, the method may include the following steps:
[0088] ① The sender's email terminal A sends a key retrieval request to the Key Management System (KMSA) associated with terminal A to obtain the email encryption key. This key retrieval request carries the SMA information of the security medium equipped by terminal A. Figure 4 (Not marked in the text), Token, and the identity information of the recipient terminal B.
[0089] ②KMSA verifies the Token. If the Token verification passes, KMSA queries CMSP for the Key Management System (KMS) associated with terminal B. If the Token verification fails, KMSA returns an authentication failure message to terminal A.
[0090] ③ If the token verification passes, the CMSP returns the query result to the KMSA. This query result may include the KMS associated with terminal B as KMSB, and the security medium equipped by terminal B as SMB. Figure 4 (Not marked in the text).
[0091] ④ Based on the query results, KMSA uses the quantum key EK1, which was agreed upon in advance with KMSB, as the email encryption key, and sends a key encryption request to KMSB to request that the key-protected EK1 be filled with SMB. The key encryption request may carry the key identifier of EK1 and the SMB identifier.
[0092] ⑤ KMSB returns the second encryption quantum key and the key identifier of SMB charging key CKB1 to KMSA. The second encryption quantum key is the encryption quantum key obtained by KMSB after encrypting EK1 using CKB1, namely E_CKB1(EK1).
[0093] ⑥ KMSA uses the SMA-filled key CKA1 to encrypt EK1, obtaining the first encryption quantum key E_CKA1(EK1), and then returns E_CKA1(EK1), the key identifier of CKA1, E_CKB1(EK1), and the key identifier of CKB1 to terminal A.
[0094] ⑦ Terminal A uses CKA1 to decrypt E_CKA1(EK1) to obtain EK1, uses EK1 to encrypt the content M of the email to be sent to form the email body E_EK1(M), and encapsulates the key identifiers E_CKB1(EK1) and CKB1 in the email header to form an encrypted email.
[0095] In one embodiment of this disclosure, after receiving an encrypted email, terminal B can decrypt the email through the following steps:
[0096] ① After receiving the encrypted email from the sender, terminal B parses the email header to obtain the key identifiers E_CKB1 (EK1) and CKB1.
[0097] ② Terminal B uses CKB1 to decrypt E_CKB1(EK1) to obtain EK1, and uses EK1 to decrypt E_EK1(M) to obtain the plaintext of the email content.
[0098] In one embodiment of this disclosure, if terminal B needs to forward the encrypted email to terminal C, it can be achieved through the following steps:
[0099] ① Terminal B sends a key request to KMSB to request the email encryption key EK1. The key request may carry SMB information, Token, the identity information of the recipient terminal C, and the key identifiers E_CKB2 (EK1) and CKB2.
[0100] ②KMSB verifies the Token. If the Token verification passes, KMSB uses CKB2 to decrypt E_CKB2(EK1) to obtain EK1, and queries the CMSP for the key management system KMS associated with terminal C. If the Token verification fails, it returns an authentication failure message to terminal B.
[0101] ③CMSP returns the query results to KMSB. The query results may include the KMS associated with terminal C being KMSC, and the security medium equipped with terminal C being SMC.
[0102] ④ Based on the query results, KMSB uses the quantum key EK2, which was agreed upon in advance with KMSC, as the email encryption key, and sends a key encryption request to KMSC to request that EK2 be filled with SMC for key protection. The key encryption request may carry E_EK2 (EK1), the key identifier of EK2, and the SMC identifier.
[0103] ⑤ KMSC uses EK2 to decrypt E_EK2(EK1) to obtain EK1, and returns the key identifier of the third encryption quantum key and the SM-C charging key CKC1 to KMSB. The third encryption quantum key is the encryption quantum key obtained by KMSC using CKC1 to encrypt EK1, namely E_CKC1(EK1).
[0104] ⑥KMSB returns the key identifiers of E_CKC1 (EK1) and CKC1 to terminal B.
[0105] ⑦ Terminal B removes the header of the original encrypted email and encapsulates E_CKC1(EK1) and the key identifier of CKC1 as a new email header. The email body remains E_EK1(M), forming an encrypted email, which is then sent to terminal C.
[0106] In one embodiment of this disclosure, steps ④ to ⑥ above can be replaced by steps ④' to ⑥' below:
[0107] ④'Based on the query results, KMSB sends an SMC recharge key retrieval request to KMSC. This SMC recharge key retrieval request may carry an SMC identifier.
[0108] ⑤'KMSC uses the quantum key EK2, which is pre-agreed between KMSBs, as the key encryption key to encrypt the SMC charging key CKC1, to obtain E_EK2(CKC1), and returns E_EK2(CKC1), the key identifier of CKC1 and the key identifier of EK2 to KMSB.
[0109] ⑥'KMSB uses EK2 to decrypt E_EK2(CKC1) to obtain CKC1, and then uses CKC1 to encrypt EK1 to obtain E_CKC1(EK1). KMSB returns the key identifiers of E_CKC1(EK1) and CKC1 to terminal B.
[0110] The above method assumes that the sender and recipient clients are in different domains. In one embodiment of this disclosure, when the sender (terminal A) and recipient (terminal B) belong to a single domain and the KMS associated with terminal A is KMSA, the email to be sent can be encrypted through the following steps:
[0111] ① The sender's email terminal A sends a key retrieval request to KMSA to obtain the email encryption key. The key retrieval request carries the SMA information of the security medium equipped by terminal A, the token, and the identity information of the recipient terminal B.
[0112] ②KMSA verifies the Token. If the Token verification passes, KMSA queries CMSP for the Key Management System (KMS) associated with terminal B. If the Token verification fails, KMSA returns an authentication failure message to terminal A.
[0113] ③ If the token verification is successful, the CMSP returns the query result to the KMSA. The query result may include the KMS associated with terminal B as KMSA, and the security medium equipped by terminal B as SMB.
[0114] ④ Based on the query results, KMSA uses EK1 generated by a quantum random number generator or other random source as the email encryption key, and uses SMA to fill the key CKA1 to protect EK1, resulting in E_CKA1(EK1). It then uses SMB to fill the key CKB1 to protect EK1, resulting in E_CKB1(EK1). Finally, it returns E_CKA1(EK1), the key identifier of CKA1, and the key identifiers of E_CKB1(EK1) and CKB1 to terminal A.
[0115] ⑤ Terminal A uses CKA1 to decrypt E_CKA1(EK1) to obtain EK1, and then uses EK1 to encrypt the content M of the email to be sent to form the email body E_EK1(M). At the same time, the key identifiers E_CKB1(EK1) and CKB1 are encapsulated in the email header to form an encrypted email.
[0116] In one embodiment of this disclosure, when the forwarding sender (terminal B) and the recipient (terminal C) belong to a single domain and the KMS associated with terminal B is KMSB, email forwarding can be performed through the following steps:
[0117] ① Terminal B sends a key request to KMSB to request the email encryption key EK1. The key request may carry SMB information, Token, the identity information of the recipient terminal C, and the key identifiers E_CKB2 (EK1) and CKB2.
[0118] ②KMSB verifies the Token. If the Token verification passes, KMSB uses CKB2 to decrypt E_CKB2(EK1) to obtain EK1, and queries the CMSP for the key management system KMS associated with terminal C. If the Token verification fails, it returns an authentication failure message to terminal B.
[0119] ③CMSP returns the query results to KMSB. The query results may include KMSB as the KMS associated with terminal C, and SMC as the security medium equipped with terminal C.
[0120] ④ Based on the query results, KMSB uses the SMC's charging key CKC1 to encrypt EK1, obtaining E_CKC1(EK1), and then returns E_CKC1(EK1) and the key identifier of CKC1 to terminal B.
[0121] ⑤ Terminal B removes the header of the original encrypted email and encapsulates E_CKC1(EK1) and the key identifier of CKC1 as the new email header. The email body remains E_EK1(M), forming an encrypted email, which is then sent to terminal C.
[0122] In one embodiment of this disclosure, for mass email sending, where a sender sends the same email to multiple recipients, it can be considered as sending encrypted emails to different recipients with the same encryption key but different key encapsulation parts. During processing, the KMS queries the KMS associated with each recipient and returns the email encryption key protected by the key filling key on each recipient's security medium to the sender. The sending client encrypts the email content once to form the email body, and then combines these encryption keys separately for each recipient to form an encrypted email.
[0123] In one embodiment of this disclosure, a symmetric cryptographic algorithm can be used as the encryption algorithm, such as Commercial Cryptography 4 (SM4) or Advanced Encryption Standard (AES), including encryption of email content and encryption of various keys. Furthermore, the integrity protection of the email content can be further enhanced, for example by employing block ciphers such as Cipher Block Chaining-Message Authentication Code (CCM) or Galois / Counter Mode (GCM), or by using corresponding authentication encryption algorithms, such as adding the calculation of the Message Authentication Code (MAC).
[0124] Figure 5 An embodiment of the present disclosure illustrates a quantum key distribution-based email encryption system, such as... Figure 5 As shown, the system includes: a first key management system 501 and a second key management system 502.
[0125] The first key management system 501 is used to receive a key acquisition request sent by a first client. The key acquisition request carries the first client's security medium information and the pre-acquired identity information of a second client. The first client is associated with the first key management system 501, and the second client is associated with the second key management system 502. Based on the identity information of the second client, the first key management system 501 obtains the quantum key pre-agreed by the second key management system 501 and the second key management system 502. The first key management system 501 then sends a key encryption request to the second key management system 502.
[0126] The second key management system 502 is used to receive a key encryption request sent by the first key management system 501; encrypt the quantum key according to the second charging key stored in the security medium of the second client to obtain the second encrypted quantum key; and return a key protection response to the first key management system 501, wherein the key protection response carries the identifier of the second encrypted quantum key and the second charging key.
[0127] The first key management system 501 is further configured to encrypt the quantum key according to the first charging key to obtain the first encrypted quantum key, wherein the first charging key is a key pre-stored in the secure medium of the first client; and to return a key acquisition response to the first client so that the first client can encrypt the email to be sent according to the key information carried in the key acquisition response, wherein the key information includes the first encrypted quantum key, the first charging key identifier, the second encrypted quantum key, and the second charging key identifier.
[0128] As described above, in this embodiment, the first key management system obtains the quantum key pre-agreed with the second key management system based on the information carried in the key acquisition request sent by the first client. Then, it sends a key encryption request to the second key management system. The second key management system, based on the received request, encrypts the quantum key using a second charging key and returns the encrypted second quantum key and the second charging key identifier to the first key management system. The first key management system then uses the first charging key to encrypt the quantum key and returns the encrypted quantum key and the charging key identifier to the first client, enabling the first client to encrypt the email to be sent based on the received key information. This embodiment improves the security of email applications while reducing system maintenance costs.
[0129] Based on the same inventive concept, this disclosure also provides an email encryption device based on quantum key distribution, as described in the following embodiments. Since the principle by which this device embodiment solves the problem is similar to that of the above-described method embodiment, the implementation of this device embodiment can refer to the implementation of the above-described method embodiment, and repeated details will not be elaborated further.
[0130] Figure 6 This illustration shows a schematic diagram of a quantum key distribution-based email encryption device according to an embodiment of the present disclosure, such as... Figure 6 As shown, the device includes: a key acquisition request receiving module 601, a quantum key acquisition module 602, a key encryption request sending module 603, a key encryption response receiving module 604, and a key acquisition response return module 605.
[0131] The system includes a key acquisition request receiving module 601, used to receive a key acquisition request sent by a first client. The key acquisition request carries the first client's security medium information and pre-acquired identity information of a second client. The first client is associated with a first key management system, and the second client is associated with a second key management system. A quantum key acquisition module 602 is used to obtain the quantum key pre-agreed between the first and second key management systems based on the second client's identity information. A key encryption request sending module 603 is used to send a key encryption request to the second key management system, so that the second key management system encrypts the quantum key according to a second charging key to obtain a second encrypted quantum key, and then sends it to the first client. A key management system returns a key encryption response, wherein the second refill key is a key pre-stored in the secure medium of the second client, and the key encryption response carries a second encryption quantum key and a second refill key identifier; a key encryption response receiving module 604 is used to encrypt the quantum key according to the first refill key to obtain a first encryption quantum key, wherein the first refill key is a key pre-stored in the secure medium of the first client; a key acquisition response returning module 605 is used to return a key acquisition response to the first client so that the first client can encrypt the email to be sent according to the key information carried in the key acquisition response, wherein the key information includes a first encryption quantum key, a first refill key identifier, a second encryption quantum key, and a second refill key identifier.
[0132] As described above, in this embodiment, after receiving a key acquisition request from a first client, the first key management system obtains the quantum key pre-agreed with the second key management system based on the identity information of the second client carried in the request. Then, it sends a key encryption request to the second key management system, causing the second key management system to encrypt the quantum key using a second charging key. This results in the second encrypted quantum key and the second charging key identifier returned by the second key management system. The quantum key is then encrypted again using the first charging key, yielding a first encrypted quantum key and a first charging key identifier. These obtained encrypted quantum key and charging key identifier are included in the key acquisition response and returned to the first client so that the first client can encrypt the email to be sent. This embodiment improves the security of email applications while reducing system maintenance costs.
[0133] In one embodiment of this disclosure, the key acquisition request also carries the identity authentication information of the first client; the device further includes: a first identity authentication module 606, used to authenticate the first client based on the first client's identity authentication information, wherein the identity authentication information includes: an identity security identifier; if the first client's identity authentication is successful, then communication is established with the second key management system according to the key acquisition request; if the first client's identity authentication fails, then an authentication failure message is sent to the first client.
[0134] In one embodiment of this disclosure, the first identity authentication module 606 is further configured to receive an identity authentication request sent by a first client, wherein the identity authentication request is used by the first client to request the establishment of an association relationship with the first key management system, and the identity authentication request carries the identity authentication identifier of the first client; to perform identity verification on the first client based on the identity authentication identifier of the first client; and to return an identity authentication response to the first client if the identity verification of the first client passes, wherein the identity authentication response carries the identity security identifier of the first client.
[0135] Figure 7 This illustration shows a schematic diagram of another email encryption device based on quantum key distribution, as shown in the embodiments of this disclosure. Figure 7 As shown, the device includes: a key encryption request receiving module 701, a quantum key encryption module 702, and a key encryption response return module 703.
[0136] The system includes a key encryption request receiving module 701, which receives a key encryption request sent by the first key management system; a quantum key encryption module 702, which encrypts the quantum key according to the second charging key stored in the secure medium of the second client to obtain a second encrypted quantum key, wherein the second client and the second key management system are associated, and the quantum key is a quantum key pre-agreed upon by the first key management system and the second key management system; and a key encryption response return module 703, which returns a key encryption response to the first key management system, wherein the key encryption response carries the identifiers of the second encrypted quantum key and the second charging key.
[0137] As described above, in this embodiment of the present disclosure, after receiving the key encryption request sent by the first key management system, the second key management system encrypts the quantum key according to the second charging key stored in the security medium equipped by the second client, obtaining a second encrypted quantum key, and carries the second encrypted quantum key in the key encryption response, returning it to the first key management system. This embodiment of the present disclosure can improve the security of email applications while reducing system maintenance costs.
[0138] In one embodiment of this disclosure, the device further includes: a second identity authentication module 704, configured to receive an identity authentication request sent by a second client, wherein the identity authentication request is used by the second client to request the establishment of an association with the second key management system, and the identity authentication request carries an identity authentication identifier of the second client; to perform identity verification on the second client based on the identity authentication identifier of the second client; and to return an identity authentication response to the second client if the identity verification of the second client passes, wherein the identity authentication response carries an identity security identifier of the second client.
[0139] Those skilled in the art will understand that various aspects of this disclosure can be implemented as a system, method, or program product. Therefore, various aspects of this disclosure can be specifically implemented in the following forms: a completely hardware implementation, a completely software implementation (including firmware, microcode, etc.), or a combination of hardware and software aspects, collectively referred to herein as a "circuit," "module," or "system."
[0140] The following reference Figure 8 To describe an electronic device 800 according to such an embodiment of the present disclosure. Figure 8 The electronic device 800 shown is merely an example and should not impose any limitation on the functionality and scope of use of the embodiments disclosed herein.
[0141] like Figure 8As shown, the electronic device 800 is manifested in the form of a general-purpose computing device. The components of the electronic device 800 may include, but are not limited to: at least one processing unit 810, at least one storage unit 820, and a bus 830 connecting different system components (including storage unit 820 and processing unit 810).
[0142] The storage unit stores program code that can be executed by the processing unit 810, causing the processing unit 810 to perform the steps described in the "Exemplary Methods" section above according to various exemplary embodiments of this disclosure.
[0143] In one embodiment of this disclosure, when the electronic device 800 is a first key management system, the processing unit 810 may perform the following steps: receiving a key acquisition request sent by a first client, wherein the key acquisition request carries the security medium information of the first client and the identity information of a pre-acquired second client, the first client being associated with the first key management system and the second client being associated with the second key management system; obtaining a quantum key pre-agreed between the first key management system and the second key management system based on the identity information of the second client; and sending a key encryption request to the second key management system so that the second key management system encrypts the quantum key according to the second charging key. The system obtains a second encryption quantum key and returns a key encryption response to the first key management system. The second charging key is a key pre-stored in the secure medium of the second client, and the key encryption response carries the second encryption quantum key and the second charging key identifier. The quantum key is encrypted according to the first charging key to obtain a first encryption quantum key, which is also a key pre-stored in the secure medium of the first client. A key retrieval response is returned to the first client so that the first client can encrypt the email to be sent according to the key information carried in the key retrieval response. The key information includes the first encryption quantum key, the first charging key identifier, the second encryption quantum key, and the second charging key identifier.
[0144] In one embodiment of this disclosure, when the electronic device 800 is a second key management system, the processing unit 810 may perform the following steps: receiving a key encryption request sent by the first key management system; encrypting the quantum key according to the second charging key stored in the security medium of the second client to obtain a second encrypted quantum key, wherein the second client and the second key management system are associated, and the quantum key is a quantum key pre-agreed upon by the first key management system and the second key management system; and returning a key encryption response to the first key management system, wherein the key encryption response carries the second encrypted quantum key and the second charging key identifier.
[0145] Storage unit 820 may include a readable medium in the form of a volatile storage unit, such as random access memory (RAM) 8201 and / or cache memory 8202, and may further include a read-only memory (ROM) 8203.
[0146] The storage unit 820 may also include a program / utility 8204 having a set (at least one) of program modules 8205, including but not limited to: an operating system, one or more application programs, other program modules, and program data, each or some combination of these examples may include an implementation of a network environment.
[0147] Bus 830 can represent one or more of several types of bus structures, including a memory cell bus or memory cell controller, a peripheral bus, a graphics acceleration port, a processing unit, or a local bus using any of the various bus structures.
[0148] Electronic device 800 can also communicate with one or more external devices 840 (e.g., keyboard, pointing device, Bluetooth device, etc.), and with one or more devices that enable a user to interact with electronic device 800, and / or with any device that enables electronic device 800 to communicate with one or more other computing devices (e.g., router, modem, etc.). This communication can be performed via input / output (I / O) interface 850. Furthermore, electronic device 800 can also communicate with one or more networks (e.g., local area network (LAN), wide area network (WAN), and / or public networks, such as the Internet) via network adapter 860. As shown, network adapter 860 communicates with other modules of electronic device 800 via bus 830. It should be understood that, although not shown in the figures, other hardware and / or software modules can be used in conjunction with electronic device 800, including but not limited to: microcode, device drivers, redundant processing units, external disk drive arrays, RAID systems, tape drives, and data backup storage systems.
[0149] From the above description of the embodiments, those skilled in the art will readily understand that the exemplary embodiments described herein can be implemented by software or by combining software with necessary hardware. Therefore, the technical solutions according to the embodiments of this disclosure can be embodied in the form of a software product, which can be stored in a non-volatile storage medium (such as a CD-ROM, USB flash drive, external hard drive, etc.) or on a network, including several instructions to cause a computing device (such as a personal computer, server, terminal device, or network device, etc.) to execute the methods according to the embodiments of this disclosure.
[0150] Based on the same inventive concept, this disclosure also provides a computer-readable storage medium storing a computer program that, when executed by a processor, implements any of the above-described quantum key distribution-based email encryption methods. Since the principle by which this computer-readable storage medium solves the problem is similar to that of the above-described method embodiments, the implementation of this computer-readable storage medium embodiment can refer to the implementation of the above-described method embodiments, and repeated details will not be elaborated further.
[0151] More specific examples of computer-readable storage media in this disclosure may include, but are not limited to: electrical connections having one or more wires, portable computer disks, hard disks, random access memory (RAM), read-only memory (ROM), erasable programmable read-only memory (EPROM or flash memory), optical fiber, portable compact disk read-only memory (CD-ROM), optical storage devices, magnetic storage devices, or any suitable combination of the foregoing.
[0152] In this disclosure, a computer-readable storage medium may include a data signal propagated in baseband or as part of a carrier wave, carrying readable program code. Such propagated data signals may take various forms, including but not limited to electromagnetic signals, optical signals, or any suitable combination thereof. A readable signal medium may also be any readable medium other than a readable storage medium, capable of transmitting, propagating, or transmitting a program for use by or in connection with an instruction execution system, apparatus, or device.
[0153] Optionally, the program code contained on the computer-readable storage medium may be transmitted using any suitable medium, including but not limited to wireless, wired, optical fiber, RF, etc., or any suitable combination thereof.
[0154] In practical implementation, program code for performing the operations of this disclosure can be written in any combination of one or more programming languages, including object-oriented programming languages such as Java and C++, and conventional procedural programming languages such as C or similar languages. The program code can execute entirely on the user's computing device, partially on the user's device, as a standalone software package, partially on the user's computing device and partially on a remote computing device, or entirely on a remote computing device or server. In cases involving remote computing devices, the remote computing device can be connected to the user's computing device via any type of network, including a local area network (LAN) or a wide area network (WAN), or it can be connected to an external computing device (e.g., via the Internet using an Internet service provider).
[0155] Based on the same inventive concept, this disclosure also provides a computer program product, including a computer program or instructions, which, when executed by a processor, implements any one of the quantum key distribution-based email encryption methods described in the above method embodiments. Since the principle by which this computer program product embodiment solves the problem is similar to that of the above method embodiments, the implementation of this computer program product embodiment can refer to the implementation of the above method embodiments, and repeated details will not be elaborated further.
[0156] It should be noted that although several modules or units for the device used to perform actions have been mentioned in the detailed description above, this division is not mandatory. In fact, according to embodiments of this disclosure, the features and functions of two or more modules or units described above can be embodied in one module or unit. Conversely, the features and functions of one module or unit described above can be further divided and embodied by multiple modules or units.
[0157] Furthermore, although the steps of the method in this disclosure are described in a specific order in the accompanying drawings, this does not require or imply that the steps must be performed in that specific order, or that all the steps shown must be performed to achieve the desired result. Additional or alternative steps may be omitted, multiple steps may be combined into one step, and / or a step may be broken down into multiple steps.
[0158] From the above description of the embodiments, those skilled in the art will readily understand that the exemplary embodiments described herein can be implemented by software or by combining software with necessary hardware. Therefore, the technical solutions according to the embodiments of this disclosure can be embodied in the form of a software product, which can be stored in a non-volatile storage medium (such as a CD-ROM, USB flash drive, external hard drive, etc.) or on a network, including several instructions to cause a computing device (such as a personal computer, server, mobile terminal, or network device, etc.) to execute the methods according to the embodiments of this disclosure.
[0159] Other embodiments of this disclosure will readily occur to those skilled in the art upon consideration of the specification and practice of the invention disclosed herein. This disclosure is intended to cover any variations, uses, or adaptations of this disclosure that follow the general principles of this disclosure and include common knowledge or customary techniques in the art not disclosed herein. The specification and examples are to be considered exemplary only, and the true scope and spirit of this disclosure are indicated by the appended claims.
Claims
1. A method for encrypting emails based on quantum key distribution, characterized in that, Applications to the first key management system include: The system receives a key acquisition request sent by a first client, wherein the key acquisition request carries the security medium information of the first client and the identity information of a second client that has been acquired in advance. The first client is associated with the first key management system, and the second client is associated with the second key management system. Based on the identity information of the second client, the quantum key agreed upon in advance by the first key management system and the second key management system is obtained; A key encryption request is sent to the second key management system so that the second key management system encrypts the quantum key according to the second charging key to obtain a second encrypted quantum key, and returns a key encryption response to the first key management system. The second charging key is a key pre-stored in the secure medium of the second client, and the key encryption response carries the identifiers of the second encrypted quantum key and the second charging key. The quantum key is encrypted using the first charging key to obtain the first encrypted quantum key, wherein the first charging key is a key pre-stored in the secure medium of the first client; A key acquisition response is returned to the first client, so that the first client can encrypt the email to be sent based on the key information carried in the key acquisition response, wherein the key information includes the first encryption quantum key, the first refill key identifier, the second encryption quantum key, and the second refill key identifier.
2. The email encryption method based on quantum key distribution according to claim 1, characterized in that, The key acquisition request also carries the identity authentication information of the first client; Before obtaining the quantum key pre-agreed upon by the first key management system and the second key management system based on the identity information of the second client, the method further includes: The first client is authenticated based on its identity authentication information, wherein the identity authentication information includes: an identity security identifier; If the first client's identity authentication is successful, then it will communicate with the second key management system according to the key acquisition request; If the first client fails authentication, an authentication failure message is sent to the first client.
3. The email encryption method based on quantum key distribution according to claim 2, characterized in that, Before authenticating the first client based on its authentication information, the method further includes: Receive an authentication request sent by a first client, wherein the authentication request is used by the first client to request the establishment of an association with the first key management system, and the authentication request carries the authentication identifier of the first client; The identity of the first client is verified based on the first client's authentication identifier; If the identity verification of the first client passes, an identity authentication response is returned to the first client, wherein the identity authentication response carries the identity security identifier of the first client.
4. A method for encrypting emails based on quantum key distribution, characterized in that, Applications to the second key management system include: Receive key encryption requests sent by the first key management system; The quantum key is encrypted using the second charging key stored in the secure medium of the second client to obtain the second encrypted quantum key. The second client is associated with the second key management system, and the quantum key is a quantum key pre-agreed upon by the first key management system and the second key management system. The system returns a key encryption response to the first key management system, wherein the key encryption response carries the second encryption quantum key and the second refill key identifier, so that the first key management system returns a key acquisition response to the first client. The key acquisition response carries key information, which is used by the first client to encrypt the email to be sent. The key information includes the first encryption quantum key, the first refill key identifier, the second encryption quantum key, and the second refill key identifier.
5. The email encryption method based on quantum key distribution according to claim 4, characterized in that, Before receiving a key protection request sent by the first key management system, the method further includes: Receive an authentication request sent by a second client, wherein the authentication request is used by the second client to request the establishment of an association with the second key management system, and the authentication request carries the authentication identifier of the second client; The identity of the second client is verified based on the identity authentication identifier of the second client; If the identity verification of the second client passes, an identity authentication response is returned to the second client, wherein the identity authentication response carries the identity security identifier of the second client.
6. A mail encryption system based on quantum key distribution, characterized in that, include: First key management system and second key management system; The first key management system is configured to receive a key acquisition request sent by a first client, wherein the key acquisition request carries the first client's security medium information and the pre-acquired identity information of a second client, the first client being associated with the first key management system and the second client being associated with the second key management system; based on the second client's identity information, the first key management system and the second key management system obtain the quantum key pre-agreed upon by them; and send a key encryption request to the second key management system. The second key management system is used to receive a key encryption request sent by the first key management system; encrypt the quantum key according to the second charging key stored in the security medium of the second client to obtain a second encrypted quantum key; and return a key protection response to the first key management system, wherein the key protection response carries the second encrypted quantum key and the second charging key identifier. The first key management system is further configured to encrypt the quantum key according to the first charging key to obtain a first encrypted quantum key, wherein the first charging key is a key pre-stored in the secure medium of the first client; and to return a key acquisition response to the first client so that the first client can encrypt the email to be sent according to the key information carried in the key acquisition response, wherein the key information includes the first encrypted quantum key, the first charging key identifier, the second encrypted quantum key, and the second charging key identifier.
7. A mail encryption device based on quantum key distribution, characterized in that, include: The key acquisition request receiving module is used to receive a key acquisition request sent by a first client, wherein the key acquisition request carries the security medium information of the first client and the identity identification information of a second client obtained in advance, the first client is associated with a first key management system, and the second client is associated with a second key management system; The quantum key acquisition module is used to obtain the quantum key pre-agreed between the first key management system and the second key management system based on the identity information of the second client. A key encryption request sending module is used to send a key encryption request to the second key management system, so that the second key management system encrypts the quantum key according to the second charging key to obtain a second encrypted quantum key, and returns a key encryption response to the first key management system, wherein the second charging key is a key pre-stored in the secure medium of the second client, and the key encryption response carries the identifiers of the second encrypted quantum key and the second charging key; A key encryption response receiving module is used to encrypt the quantum key according to a first charging key to obtain a first encrypted quantum key, wherein the first charging key is a key pre-stored in the secure medium of the first client; The key acquisition response return module is used to return a key acquisition response to the first client, so that the first client can encrypt the email to be sent according to the key information carried in the key acquisition response, wherein the key information includes the first encryption quantum key, the first refill key identifier, the second encryption quantum key and the second refill key identifier.
8. A mail encryption device based on quantum key distribution, characterized in that, include: The key encryption request receiving module is used to receive key encryption requests sent by the first key management system; A quantum key encryption module is used to encrypt a quantum key based on a second charging key stored in a secure medium of a second client to obtain a second encrypted quantum key. The second client is associated with a second key management system, and the quantum key is a quantum key pre-agreed upon by the first key management system and the second key management system. A key encryption response return module is used to return a key encryption response to the first key management system. The key encryption response carries the second encryption quantum key and the second refill key identifier, so that the first key management system returns a key acquisition response to the first client. The key acquisition response carries key information, which is used by the first client to encrypt the email to be sent. The key information includes the first encryption quantum key, the first refill key identifier, the second encryption quantum key, and the second refill key identifier.
9. An electronic device, characterized in that, include: processor; as well as Memory for storing the executable instructions of the processor; The processor is configured to execute the email encryption method based on quantum key distribution according to any one of claims 1 to 5 by executing the executable instructions.
10. A computer-readable storage medium having a computer program stored thereon, characterized in that, When the computer program is executed by the processor, it implements the email encryption method based on quantum key distribution as described in any one of claims 1 to 5.
11. A computer program product, comprising: A computer program or instruction, characterized in that, when executed by a processor, the computer program or instruction implements the email encryption method based on quantum key distribution as described in any one of claims 1 to 5.
Citation Information
Patent Citations
System for sharing quantum key and secure communication method based on system
CN113132090A
Cross-domain identity authentication method and system based on quantum key distribution network
CN116527259A