Quantum key assisted end-to-end encryption method for mobile terminal, storage medium and equipment

Through quantum key distribution network and wireless channel key distribution technology, end-to-end encryption between mobile terminals is realized, solving the problem that third parties may obtain data in the prior art, and ensuring the information security of mobile communications.

CN120018141APending Publication Date: 2025-05-16SOUTHEAST UNIV
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202510172760.9
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-02-17
Publication Date
2025-05-16

AI Technical Summary

Technical Problem

During the data transmission of existing mobile terminals, any third party except the legal communication parties may obtain data, resulting in the inability to truly guarantee user privacy and security.

Method used

The quantum key assisted end-to-end encryption method for mobile terminals is adopted, and the sharing of quantum key and wireless channel keys is realized through the quantum key distribution network and wireless channel key distribution technology, and the data is double encrypted.

Benefits of technology

End-to-end encryption between mobile terminals is realized, ensuring that third parties except for both communication parties, including service providers, network nodes and attackers, cannot obtain data content, resist quantum attacks, and ensure information security.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120018141A_ABST
    Figure CN120018141A_ABST
Patent Text Reader

Abstract

The invention discloses a quantum key assisted end-to-end encryption method for mobile terminals, a storage medium and equipment, and the method comprises the steps: in quantum key distribution, two mobile terminals accessing a quantum key distribution network use a quantum key distribution protocol, distribute symmetrical quantum keys, and achieve the sharing of the quantum keys; in the wireless channel key distribution process, two mobile terminals and a wireless base station in a mobile communication network generate wireless channel keys through wireless channel characteristics, and sharing of the wireless channel keys is achieved; and finally, the senders in the two mobile terminals perform double encryption on the data by using the quantum key generated in the quantum key distribution stage and the wireless channel key generated in the wireless channel key distribution stage, and forward the encrypted data to the receivers in the two mobile terminals through the mobile communication network. And the receiver carries out decryption by using the quantum key and the wireless channel key of the receiver to obtain the data, so that end-to-end encryption is realized. The method effectively resists quantum attacks and ensures the information security of the mobile terminal.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention belongs to the technical field of key generation, and mainly relates to a quantum key-assisted end-to-end encryption method, storage medium and device for mobile terminals. Background Art

[0002] In many messaging systems, including email and many chat platforms, messages are transmitted through intermediate nodes and stored by application servers, and are ultimately retrieved by the recipient. Even if messages are encrypted, they are only encrypted during transmission, and server-side disk encryption only prevents unauthorized external users from viewing these messages, which cannot prevent messages from being decrypted and accessed by service providers. Therefore, the privacy and security of users cannot be truly guaranteed and can be easily collected on a large scale. A feasible end-to-end encryption solution is urgently needed to ensure that third parties other than the communicating parties, including service providers, network nodes, and attackers, cannot obtain data content.

[0003] At the same time, with the rapid development of mobile communication technology, the amount of data exchanged in wireless channels will increase exponentially, including information that needs to be kept confidential, such as financial data and confidential documents, which puts higher requirements on the security of mobile communications. The growing number of mobile terminals in the Internet of Things has also expanded the attack surface. If the devices do not take appropriate encryption and security measures when collecting and transmitting sensitive data, serious security incidents may occur, which hinders the development of the Internet of Things in smart homes, unmanned driving, electronic medical care, and even military networks.

[0004] Against the backdrop of continuous breakthroughs in quantum computing technology, traditional cryptographic system architectures based on computational complexity face the risk of being cracked and leaked. Therefore, it is urgent to find security mechanisms to combat quantum attacks in order to ensure the long-term effectiveness of information security. Summary of the invention

[0005] The present invention is aimed at the problem that any third party other than the legitimate communicating parties may obtain data in the existing mobile terminal data transmission, and proposes a quantum key-assisted end-to-end encryption method, storage medium and device for mobile terminals. First, two mobile terminals connected to the quantum key distribution network use the quantum key distribution protocol to distribute symmetric quantum keys to achieve quantum key sharing; the two mobile terminals respectively use the wireless channel characteristics with the wireless base station in the mobile communication network to generate wireless channel keys to achieve wireless channel key sharing; finally, the sender in the two mobile terminals uses the quantum key generated in the quantum key distribution stage and the wireless channel key generated in the wireless channel key distribution stage to double encrypt the data, and forward it to the receiver in the two mobile terminals through the mobile communication network. The receiver uses its own quantum key and wireless channel key to decrypt and obtain the data, thereby achieving end-to-end encryption. The method of the present invention solves the problem of end-to-end encryption of mobile terminals, and uses the physical characteristics of quantum and the intrinsic security attributes of wireless channels to ensure the secure distribution of keys, and can resist quantum attacks, so that the key generation throughout the process meets information security and ensures the end-to-end security of mobile communications.

[0006] In order to achieve the above object, the technical solution adopted by the present invention is: a quantum key-assisted end-to-end encryption method for mobile terminals, which includes at least three stages: quantum key distribution, wireless channel key distribution and end-to-end encryption.

[0007] In the quantum key distribution phase, two mobile terminals connected to the quantum key distribution network use a quantum key distribution protocol to distribute symmetric quantum keys to achieve quantum key sharing;

[0008] In the wireless channel key distribution phase, the two mobile terminals respectively generate wireless channel keys with the wireless base station in the mobile communication network using wireless channel characteristics to achieve sharing of the wireless channel keys;

[0009] In the end-to-end encryption stage, the senders in the two mobile terminals use the quantum key generated in the quantum key distribution stage and the wireless channel key generated in the wireless channel key distribution stage to double encrypt the data, and forward it to the receivers in the two mobile terminals through the mobile communication network. The receivers use their own quantum key and wireless channel key to decrypt and obtain the data, thereby realizing end-to-end encryption.

[0010] As an improvement of the present invention, the quantum key distribution stage specifically includes the following steps:

[0011] S11: The sender applies to the quantum backbone network for a service to share the quantum key with the receiver. The quantum backbone network searches for the nearest quantum access node based on the locations of the sender and the receiver, and determines the path for communication between the two quantum access nodes.

[0012] S12: The sender and receiver use the quantum key distribution protocol to achieve symmetric distribution of quantum keys through the quantum backbone network and wireless channels.

[0013] As another improvement of the present invention, in the wireless channel key distribution stage, the two mobile terminals respectively generate wireless channel keys with the wireless base station in the mobile communication network using wireless channel characteristics, which at least includes the following steps:

[0014] S21, channel detection: the sender and the receiver send detection signals to each other to measure the common channel, and extract a random source from the wireless channel, wherein the random source includes at least received signal strength RSS, channel state information CSI or phase;

[0015] S22, quantization: converting the channel characteristic value obtained in the channel detection in step S21 into a 0, 1 bit sequence through a quantizer;

[0016] S23, information reconciliation: The two parties who generate the key correct the inconsistent bits by exchanging information on the public channel;

[0017] S24, privacy amplification: compress the key information leaked in the information reconciliation phase of step S23 through the hash function.

[0018] As another improvement of the present invention, the end-to-end encryption specifically includes the following steps:

[0019] S31: The sender uses the wireless channel key shared with base station M1 and the quantum key K shared with the recipient Q Double encrypt the confidential message X, and send the ciphertext to the base station M1. The double encrypted confidential message is specifically:

[0020]

[0021] Where Enc1(·) and Enc2(·) are the same or different symmetric encryption algorithms;

[0022] S32: After receiving the ciphertext Y, the base station M1 decrypts the ciphertext Y and sends the decrypted ciphertext Y1 to the base station M2 via the mobile communication network. The decryption process is specifically as follows:

[0023]

[0024] Where Dec2(·) represents the decryption algorithm corresponding to Enc2(·);

[0025] S33: Base station M2 uses the wireless channel key shared with the receiver The ciphertext Y1 is encrypted to obtain the ciphertext Y2, and the ciphertext Y2 is sent to the receiver through the wireless channel. The encryption process of the ciphertext Y1 is specifically as follows:

[0026]

[0027] S34: The receiver uses the wireless channel key shared with the base station M2 and the quantum key K shared with the sender Q Decrypt the ciphertext Y2 to obtain the confidential message:

[0028]

[0029] Where Dec1(·) represents the decryption algorithm corresponding to Enc1(·).

[0030] In order to achieve the above-mentioned purpose, the technical solution also adopted by the present invention is: a non-temporary machine-readable storage medium, on which executable code is stored. When the executable code is executed by a processor of an electronic device, the processor executes any of the above-mentioned quantum key-assisted end-to-end encryption methods for mobile terminals.

[0031] In order to achieve the above object, the present invention also adopts a technical solution: a computer device, comprising:

[0032] A memory, wherein executable code is stored in the memory;

[0033] A processor is used to execute the executable code so that the computer device performs any of the operations of the quantum key-assisted end-to-end encryption method for mobile terminals described above.

[0034] Compared with the prior art, the present invention has the following beneficial effects:

[0035] The present invention discloses a quantum key-assisted end-to-end encryption method, storage medium and device for mobile terminals. In the existing end-to-end encryption scheme for mobile terminals, the keys generated by the legitimate communicating parties are usually based on traditional algorithms. Even if only the legitimate communicating parties hold them, they still cannot resist the quantum attack initiated by the attacker, and there is a security risk that the key is cracked and the data is illegally obtained. The method of the present invention combines quantum key distribution (QKD) and physical layer key generation (PKG) technology. The security of quantum key distribution (QKD) is guaranteed by the basic principles of quantum mechanics, does not depend on computational complexity, and can detect eavesdroppers during the key generation process. Physical layer key generation (PKG) uses channel characteristics such as channel reciprocity, rapid time variation and spatial decorrelation characteristics of wireless channels to simultaneously generate a pair of symmetric keys between legitimate users. Both QKD and PKG do not rely on computational complexity, meet the requirements of information theory security, and can resist quantum attacks. The two technologies of QKD and PKG are combined to realize end-to-end encryption of mobile terminals, further ensuring the information security of mobile terminals.

[0036] In addition, the method of the present invention uses two keys to double encrypt each message, namely the quantum key distributed through the QKD network and the wireless channel key shared with the base station in the mobile communication network. Both the QKD network and the mobile communication network only know one of the keys and cannot decrypt the message. The physical properties of quantum and the spatial decorrelation of the line channel fundamentally guarantee the secure distribution of keys. Attackers cannot obtain completely consistent keys through eavesdropping, thereby ensuring the end-to-end communication security between mobile terminals. BRIEF DESCRIPTION OF THE DRAWINGS

[0037] Figure 1 is a detailed step flow chart of Example 1 of the present invention;

[0038] Figure 2 This is the environment deployment architecture diagram of Example 1 of the present invention. DETAILED DESCRIPTION

[0039] The present invention will be further explained below in conjunction with the accompanying drawings and specific embodiments. It should be understood that the following specific embodiments are only used to illustrate the present invention and are not used to limit the scope of the present invention.

[0040] Example 1

[0041] A quantum key-assisted end-to-end encryption method for mobile terminals includes at least three stages: quantum key distribution, wireless channel key distribution, and end-to-end encryption. In the quantum key distribution stage, two mobile terminals connected to a quantum key distribution network use a quantum key distribution protocol to distribute symmetric quantum keys to achieve quantum key sharing; in the wireless channel key distribution stage, the two mobile terminals respectively generate wireless channel keys with wireless base stations in a mobile communication network using wireless channel characteristics to achieve wireless channel key sharing; in the end-to-end encryption stage, the sender in the two mobile terminals uses the quantum key generated in the quantum key distribution stage and the wireless channel key generated in the wireless channel key distribution stage to double encrypt the data, forward it to the receiver in the two mobile terminals through the mobile communication network, and the receiver uses its own quantum key and wireless channel key to decrypt and obtain the data, thereby achieving end-to-end encryption. The method of the present invention distributes quantum keys and wireless channel keys to mobile terminals through a QKD network and a mobile communication network, respectively, and uses the two keys to double encrypt each message.

[0042] In this embodiment, taking the end-to-end encryption between the message sender Alice and the receiver Bob of the mobile terminal as an example, the quantum access node on the Alice side in the QKD network is Q1, and the quantum access node on the Bob side is Q2. The wireless base station on the Alice side in the mobile communication network is M1, and the wireless base station on the Bob side is M2. The specific environment deployment architecture is as follows: Figure 2 shown.

[0043] The encryption method for achieving end-to-end confidential communication between mobile terminals includes at least three specific steps: quantum key distribution, wireless channel key distribution, and end-to-end encryption. Figure 2 As shown, the process is as follows:

[0044] Step S1, quantum key distribution: Alice and Bob use the quantum key distribution protocol and quantum key distribution scheme to achieve quantum key sharing between them.

[0045] Step S11: Alice requests the QKD network to share the quantum key with Bob. After receiving the request, the QKD network searches for the nearest QAP in the QKD network based on the locations of Alice and Bob, which are Q1 and Q2 respectively. The QKD network determines the routing path between Q1 and Q2 through the quantum relay point and determines whether they are interoperable.

[0046] Step S12: Alice and Bob use the quantum key distribution protocol and quantum key distribution scheme to achieve secure sharing of quantum keys between them through intermediate nodes such as Q1 and Q2.

[0047] Step S2, wireless channel key distribution: Alice and M1, as well as Bob and M2, use wireless channel key generation technology to achieve wireless channel key sharing, specifically including:

[0048] Step S21: Alice and M1 send detection signals to each other to measure the common channel, and each extracts the received signal strength RSS, channel state information CS1, phase, etc. from the received signal as a random source of the key;

[0049] Step S22: Alice and M1 use the same quantization method to convert the obtained channel characteristic values ​​into 0 and 1 bit sequences;

[0050] Step S23: Alice and M1 use an error correction protocol or an error correction code to correct the inconsistent bits after quantization of both parties;

[0051] Step S24: Alice and M1 compress the key through the hash function to obtain the final generated wireless channel key Similarly, Bob and M2 generate the wireless channel key according to the above steps

[0052] Step S3, end-to-end encryption: Alice uses the quantum key and the wireless channel key to double encrypt the message to achieve end-to-end encryption, which specifically includes:

[0053] Step S31: Alice uses the wireless channel key shared with base station M1 and the quantum key K shared with Bob Q Double encrypt confidential message X: Where Enc1(·) and Enc2(·) are the same or different symmetric encryption algorithms, and the ciphertext Y is sent to M1;

[0054] Step S32: After receiving the ciphertext Y, M1 decrypts Y into: Where Dec2(·) represents the decryption algorithm corresponding to Enc2(·), and the decrypted Y1 is sent to the base station M2 through the mobile communication network;

[0055] Step S33: M2 uses the wireless channel key shared with Bob Encrypt Y1 as: And send the ciphertext Y2 to Bob through the wireless channel;

[0056] Step S34: Bob uses the wireless channel key shared with base station M2 and the quantum key K shared with Alice Q Decrypt the ciphertext Y2 to obtain the confidential message:

[0057] In summary, the present invention solves the problem of end-to-end encryption of mobile terminals, and utilizes the physical properties of quantum and the intrinsic security properties of wireless channels to ensure the secure distribution of keys, which can resist quantum attacks, so that the entire key generation process meets information-theoretic security and ensures the end-to-end security of mobile communications.

[0058] Example 2

[0059] This embodiment provides a non-transitory machine-readable memory having executable codes stored thereon. When the executable codes are executed by a processor of an electronic device, the processor is caused to execute the method in the above embodiment.

[0060] A non-temporary machine-readable memory (or computer-readable memory, or machine-readable memory) having executable code (or computer program, or computer instruction code) stored thereon, which, when executed by a processor of an electronic device (or computing device, server, etc.), enables the processor to perform the various steps of the above-mentioned method according to the present invention.

[0061] Example 3

[0062] This embodiment discloses a computer device, including a processor and a memory, wherein the memory stores codes for executing the method in the above embodiment.

[0063] The processor may be a multi-core processor or may include multiple processors. In some embodiments, the processor may include a general-purpose main processor and one or more special coprocessors, such as a graphics processing unit (GPU), a digital signal processor (DSP), etc. In some embodiments, the processor may be implemented using a customized circuit, such as an application-specific integrated circuit (ASIC) or a field programmable gate array (FPGA).

[0064] The memory may include various types of storage units, such as system memory, read-only memory (ROM), and permanent storage. Among them, ROM can store static data or instructions required by the processor or other modules of the computer. The permanent storage device may be a readable and writable storage device. The permanent storage device may be a non-volatile storage device that does not lose the stored instructions and data even after the computer is powered off. In some embodiments, the permanent storage device uses a large-capacity storage device (such as a magnetic or optical disk, flash memory) as a permanent storage device. In some other embodiments, the permanent storage device may be a removable storage device (such as a floppy disk, optical drive). The system memory may be a readable and writable storage device or a volatile readable and writable storage device, such as a dynamic random access memory. The system memory may store some or all instructions and data required by the processor at run time. In addition, the memory may include any combination of computer-readable storage media, including various types of semiconductor memory chips (DRAM, SRAM, SDRAM, flash memory, programmable read-only memory), and disks and / or optical disks may also be used. In some embodiments, the memory may include a readable and / or writable removable storage device, such as a laser disc (CD), a read-only digital versatile disc (e.g., DVD-ROM, double-layer DVD-ROM), a read-only Blu-ray disc, an ultra-density optical disc, a flash memory card (e.g., SD card, minSD card, Micro-SD card, etc.), a magnetic floppy disk, etc. The computer-readable storage medium does not include carrier waves and transient electronic signals transmitted wirelessly or wired.

[0065] The memory stores executable codes thereon, and when the executable codes are executed by the processor, the processor is enabled to execute the above method.

[0066] It should be noted that the above content only illustrates the technical idea of ​​the present invention and cannot be used to limit the protection scope of the present invention. For ordinary technicians in this technical field, several improvements and modifications can be made without departing from the principle of the present invention. These improvements and modifications all fall within the protection scope of the claims of the present invention.

Claims

1. A quantum key-assisted end-to-end encryption method for mobile terminals, characterized in that: It includes at least three stages: quantum key distribution, wireless channel key distribution and end-to-end encryption. In the quantum key distribution phase, two mobile terminals connected to the quantum key distribution network use a quantum key distribution protocol to distribute symmetric quantum keys to achieve quantum key sharing; In the wireless channel key distribution phase, the two mobile terminals respectively generate wireless channel keys with the wireless base station in the mobile communication network using wireless channel characteristics to achieve sharing of the wireless channel keys; In the end-to-end encryption stage, the senders in the two mobile terminals use the quantum key generated in the quantum key distribution stage and the wireless channel key generated in the wireless channel key distribution stage to double encrypt the data, and forward it to the receivers in the two mobile terminals through the mobile communication network. The receivers use their own quantum key and wireless channel key to decrypt and obtain the data, thereby realizing end-to-end encryption.

2. The quantum key-assisted end-to-end encryption method for mobile terminals according to claim 1, characterized in that: The quantum key distribution stage specifically includes the following steps: S11: The sender applies to the quantum backbone network for a service to share the quantum key with the receiver. The quantum backbone network searches for the nearest quantum access node based on the locations of the sender and the receiver, and determines the path for communication between the two quantum access nodes. S12: The sender and receiver use the quantum key distribution protocol to achieve symmetric distribution of quantum keys through the quantum backbone network and wireless channels.

3. The quantum key-assisted end-to-end encryption method for mobile terminals as claimed in claim 2, characterized in that: In the wireless channel key distribution phase, the two mobile terminals respectively generate wireless channel keys with the wireless base stations in the mobile communication network using wireless channel characteristics, which at least includes the following steps: S21, channel detection: the sender and the receiver send detection signals to each other to measure the common channel, and extract a random source from the wireless channel, wherein the random source includes at least received signal strength RSS, channel state information CSI or phase; S22, quantization: converting the channel characteristic value obtained in the channel detection in step S21 into a 0, 1 bit sequence through a quantizer; S23, information reconciliation: The two parties who generate the key correct the inconsistent bits by exchanging information on the public channel; S24, privacy amplification: compress the key information leaked in the information reconciliation phase of step S23 through the hash function.

4. The quantum key-assisted end-to-end encryption method for mobile terminals as claimed in claim 3, characterized in that: The end-to-end encryption specifically includes the following steps: S31: The sender uses the wireless channel key shared with base station M1 and the quantum key K shared with the recipient Q Double encrypt the confidential message X, and send the ciphertext to the base station M1. The double encrypted confidential message is specifically: Where Enc1(·) and Enc2(·) are the same or different symmetric encryption algorithms; S32: After receiving the ciphertext Y, the base station M1 decrypts the ciphertext Y and sends the decrypted ciphertext Y1 to the base station M2 via the mobile communication network. The decryption process is specifically as follows: Where Dec2(·) represents the decryption algorithm corresponding to Enc2(·); S33: Base station M2 uses the wireless channel key shared with the receiver The ciphertext Y1 is encrypted to obtain the ciphertext Y2, and the ciphertext Y2 is sent to the receiver through the wireless channel. The encryption process of the ciphertext Y1 is specifically as follows: S34: The receiver uses the wireless channel key shared with the base station M2 and the quantum key K shared with the sender Q Decrypt the ciphertext Y2 to obtain the confidential message: Where Dec1(·) represents the decryption algorithm corresponding to Enc1(·).

5. A non-transitory machine-readable storage medium, characterized in that: An executable code is stored thereon, and when the executable code is executed by a processor of an electronic device, the processor is caused to execute a quantum key-assisted end-to-end encryption method for mobile terminals as described in any one of claims 1 to 4 above.

6. A computer device, characterized in that: include: A memory, wherein executable code is stored in the memory; A processor, configured to execute the executable code so that the computer device performs the operation of the quantum key-assisted end-to-end encryption method for mobile terminals as described in any one of claims 1 to 4.