Communication encryption data transmission method
The original data frame is split, recombined and verified through the quantum encryption card, and the quantum decryption card is checked, recombined and decrypted, solving the problem of data frame change when external quantum devices conduct quantum encryption communication, realizing safe and efficient "invisible" transmission.
Patent Information
- Application Number
- CN202510174768.9
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-02-18
- Publication Date
- 2025-05-23
AI Technical Summary
In the case of quantum encrypted communication through external quantum devices, how to keep the original data frame from changing and realize "invisible" transmission at both ends of the communication, especially in narrowband scenarios.
The original data frame is split, reorganized and verified through the quantum encryption card, and intermediate data frames are generated, and verification, reorganized and decrypted through the quantum decryption card to ensure the security and efficiency of data transmission.
The security of quantum encrypted communication is realized, while avoiding the reduction in transmission efficiency, ensuring "insensitive" transmission between the two ends of the communication, and effectively transmitting big data even in narrowband scenarios.
Smart Images

Figure CN120034373A_ABST
Abstract
Description
Technical Field
[0001] The present application relates to the field of data processing technology, and in particular to a communication encryption data transmission method. Background Art
[0002] With the rapid development of science and technology, the communication technology between the two ends of the communication has basically adopted encrypted communication. However, with the advent of quantum technology, traditional encrypted communication technology seems to be somewhat powerless, especially in some scenarios that attach great importance to information security. The efficient computing power of quantum always makes the setting of traditional algorithms like "decoration". Quantum encryption, with its high security based on the principles of quantum mechanics, provides unprecedented protection for data transmission and storage.
[0003] If the traditional encryption communication equipment is directly replaced with quantum encryption communication equipment on the basis of the existing communication ends, this will not only increase the transmission complexity of the communication ends, but also require the installation, debugging and maintenance of the equipment to be rearranged, which will greatly waste resources. The most direct way is to solve it through external equipment, but if the quantum encryption of data is directly performed through external equipment, this will also cause the transmitted data frame to change, and then there will be a problem of occupying the transmission bandwidth, especially for narrowband, which seriously affects the transmission efficiency; and there will also be a problem that the other end cannot normally identify the data frame (the data frame has changed).
[0004] Based on this, when conducting quantum encryption communication through external quantum devices, how to ensure that the originally transmitted data frames do not change and achieve "seamless" transmission at both ends of the communication has become an urgent problem that needs to be solved. Summary of the invention
[0005] Purpose of the invention: In order to solve the relevant technical problems raised in the background technology, the present invention provides a communication encryption data transmission method, which splits, reorganizes and verifies the original data frame through an external quantum device without affecting the transmission efficiency, so that the communication ends can achieve "invisible" transmission.
[0006] Technical solution: The present invention provides a communication encryption data transmission method, comprising the following steps:
[0007] (1) The transmitting end sends the original data frame to the quantum encryption card, and the quantum encryption card generates a first intermediate data frame based on the original data frame; wherein the original data frame includes a data header, a first payload, and a first check code;
[0008] (2) The quantum encryption card splits the first intermediate data frame and sends the split data frames obtained by splitting to the quantum decryption card;
[0009] (3) The quantum decryption card verifies and reassembles the received split data frames, decrypts them and sends them to the receiving end.
[0010] Furthermore, before step (1), the transmitting end, the receiving end, the quantum encryption card and the quantum decryption card are all pre-installed with the same CRC check calculation method.
[0011] Furthermore, the specific process of the quantum encryption card generating the first intermediate data frame based on the original data frame is:
[0012] The quantum encryption card performs quantum encryption on the first payload and the first check code in the original data frame through the quantum encryption key to obtain the first quantum ciphertext part, and generates the first quantum ciphertext information part according to the information of the quantum encryption key and the data frame size set for transmission, and then adds the first quantum ciphertext information part to the corresponding original data frame; then the quantum encryption card performs verification calculation on the first quantum ciphertext information part and the first quantum ciphertext part to generate a second check code, and adds the second check code to the original data frame to obtain the first intermediate data frame; at this time, the first intermediate data frame includes the data header of the original data frame, the first quantum ciphertext information part, the first quantum ciphertext part and the second check code.
[0013] Furthermore, the first quantum ciphertext information part includes a shard identifier, the number of shards, a key file index value, key location information, and offset information.
[0014] Furthermore, the key location information refers to the storage location of the quantum encryption key; and the offset information refers to the offset value of the quantum encryption key in the key file.
[0015] Furthermore, the specific process of splitting the first intermediate data frame is:
[0016] The first quantum ciphertext part in the first intermediate data frame is split into a corresponding number of quantum ciphertext blocks according to the number of fragments in the first quantum ciphertext information part and the data frame size set for transmission, and the quantum ciphertext blocks are numbered in the order of splitting; then, the split ciphertext information part corresponding to each quantum ciphertext block is generated according to the number of the first quantum ciphertext information part and the quantum ciphertext block, and then the quantum encryption card verifies the quantum ciphertext block and the split ciphertext information part corresponding to the quantum ciphertext block to generate a split verification code corresponding to the quantum ciphertext block, and constructs a split data frame corresponding to the quantum ciphertext block based on the split verification code; the split data frame includes a data header in the original data frame, a quantum ciphertext block, a split ciphertext information part corresponding to the quantum ciphertext block, and a split verification code.
[0017] Furthermore, the sending of the split data frames to the quantum decryption card refers to sending the split data frames to the quantum decryption card in the order of numbers;
[0018] The split ciphertext information part includes the identifier of the fragment in the first quantum ciphertext information part, the key file index value, the key position information, the offset information and the split number; the split number is the number of the quantum ciphertext block.
[0019] Furthermore, the specific process of step (3) is as follows:
[0020] The quantum decryption card verifies and calculates the split ciphertext information part and the quantum ciphertext block in the received split data frame to generate a third verification code, and compares the split verification code in the split data frame with the third verification code to see if they are the same. If they are the same, the received split data frame is copied to the buffer for reassembly to generate a second intermediate data frame. If they are not the same, the quantum encryption card is notified to resend the split data frame; the second intermediate data frame includes the data header of the original data frame, the second quantum ciphertext information part, the second quantum ciphertext part and the fourth verification code;
[0021] After the second intermediate data frame is generated, the second quantum ciphertext information part and the second quantum ciphertext part of the second intermediate data frame are verified and calculated to generate a fifth verification code, and the fourth verification code and the fifth verification code in the second intermediate data frame are compared to see whether they are the same. If they are the same, the quantum decryption key is found according to the key file index value, key position information and offset information in the second quantum ciphertext information part, the second quantum ciphertext part is decrypted by the quantum decryption key to obtain the second payload, and the original data frame is generated based on the second payload and sent to the receiving end.
[0022] Furthermore, the specific process of recombining and generating the second intermediate data frame is:
[0023] Detect the fragmentation identifier and the split number of the split ciphertext information part in the current split data frame, then continue to receive the next split data frame, and judge the next split data frame. If the fragmentation identifier in the next split data frame is the same as that in the previous split data frame, and the split number in the next split data frame is larger than the split number in the previous split data frame, then continue to receive the next next split data frame; and so on, until if the fragmentation identifier in the next split data frame is different from that in the previous split data frame, or the split number in the next split data frame is smaller than the split number in the previous split data frame, then extract the quantum ciphertext blocks in the data frame according to the split number order received previously, and combine them to generate the second quantum ciphertext part, and then generate the second quantum ciphertext information part based on the split ciphertext information part in the split data frame, and then the quantum decryption card verifies and calculates the second quantum ciphertext information part and the second quantum ciphertext part to generate a fourth check code, and constructs a second intermediate data frame based on the fourth check code; the second intermediate data frame includes the data header, the second quantum ciphertext information part, the second quantum ciphertext part and the fourth check code in the original data frame.
[0024] Beneficial effects of the present invention:
[0025] 1. Through quantum encryption, the problem of insecure communication data caused by the easy cracking of traditional encrypted data is solved;
[0026] 2. Through external quantum devices, the original data frames are split, reorganized and verified between quantum devices. Quantum encryption is used to ensure the security of data transmission without affecting the transmission efficiency, so that both ends of the communication can achieve "senseless" transmission;
[0027] 3. Using the method proposed in this application, even in a narrowband scenario, it is possible to achieve the transmission of big data, breaking the limitation of the narrowband data transmission size. BRIEF DESCRIPTION OF THE DRAWINGS
[0028] In order to more clearly illustrate the technical solutions in the embodiments of the present application, the drawings required for use in the description of the embodiments will be briefly introduced below. Obviously, the drawings described below are only some embodiments of the present application. For ordinary technicians in this field, other drawings can be obtained based on these drawings without paying creative labor.
[0029] Figure 1 It is a schematic diagram of the process of the present invention;
[0030] Figure 2 A schematic diagram of the structure of converting an original data frame into a first intermediate data frame according to the present invention;
[0031] Figure 3 A schematic diagram of the structure of splitting the first intermediate data frame of the present invention;
[0032] Figure 4 It is a structural schematic diagram of the present invention for restoring the split data frame to the original data frame. DETAILED DESCRIPTION
[0033] In order to make the purpose, technical solutions and advantages of the present application clearer, the present application will be further described in detail below in conjunction with the accompanying drawings. Obviously, the described embodiments are only part of the embodiments of the present application, rather than all the embodiments. Based on the embodiments in the present application, all other embodiments obtained by ordinary technicians in this field without making creative work are within the scope of protection of the present application.
[0034] As mentioned in the background technology, using an external device for quantum encryption communication will inevitably cause the transmitted data frame to change, which will in turn cause the problem of occupying the transmission bandwidth, especially when it comes to narrowband, which seriously affects the efficiency of transmission; and there will also be a problem that the other end cannot normally identify the data frame. Therefore, when using an external quantum device for quantum encryption communication, how to achieve the original transmission data frame without changing and realize "senseless" transmission at both ends of the communication has become an urgent problem to be solved.
[0035] To solve the above technical problems, Figure 1 As shown, the present invention proposes a communication encryption data transmission method, the participants of the method include a sending end and a receiving end at both ends of the communication, an external device quantum encryption card and a quantum decryption card, the sending end, the receiving end, the quantum encryption card and the quantum decryption card are all preset with the same CRC check calculation method; the data transmission method of the present invention includes the following steps:
[0036] (1) The transmitting end sends the original data frame to the quantum encryption card, and the quantum encryption card generates a first intermediate data frame based on the original data frame; wherein the original data frame includes a data header, a first payload, and a first check code; the specific process of the quantum encryption card generating the first intermediate data frame based on the original data frame is:
[0037] like Figure 2 As shown, the quantum encryption card performs quantum encryption on the first load and the first check code in the original data frame through the quantum encryption key to obtain the first quantum ciphertext part, and generates the first quantum ciphertext information part according to the information of the quantum encryption key and the data frame size set for transmission, and then adds the first quantum ciphertext information part to the corresponding original data frame; the first quantum ciphertext information part includes the identification of the shard, the number of shards, the key file index value, the key location information and the offset information, the key location information refers to the storage location of the quantum encryption key; the offset information refers to the offset value of the quantum encryption key in the key file. The data frame size set for transmission refers to the transmission bandwidth. In the present invention, especially for narrowband, due to the different frequency ranges, the data transmission rate of narrowband communication is relatively low, usually below 64kbps. Relatively large data frames cannot be directly transmitted in narrowband, and need to be converted into data frames that meet the narrowband transmission frame size requirements for transmission. For example, if the total size of each frame transmitted by a certain device is less than 255B, the number of fragments can be obtained according to the data frame size set for transmission. The data frame size set for transmission is less than 255B, and the frame size of the data header + the first quantum ciphertext part + the first quantum ciphertext information part is 550B, then the number of fragments can be obtained as 2, which is written into the first quantum ciphertext information part;
[0038] Then the quantum encryption card verifies the first quantum ciphertext information part and the first quantum ciphertext part to generate a second verification code, and adds the second verification code to the original data frame to obtain the first intermediate data frame; at this time, the first intermediate data frame includes the data header of the original data frame, the first quantum ciphertext information part, the first quantum ciphertext part and the second verification code. In this embodiment, the encryption ratio of quantum encryption can be 1:1, that is, the load and the quantum key are encrypted with equal length, and after quantum encryption, the key index information, i.e., the first quantum ciphertext information part, needs to be carried. It can be seen that the first intermediate data frame increases the load of the original frame structure, so the data frame needs to be disassembled and reassembled later.
[0039] (2) The quantum encryption card splits the first intermediate data frame and sends the split data frames obtained by splitting to the quantum decryption card; Figure 3 As shown, the specific process of splitting the first intermediate data frame is:
[0040] The first quantum ciphertext part in the first intermediate data frame is split into a corresponding number of quantum ciphertext blocks according to the number of fragments in the first quantum ciphertext information part and the data frame size set for transmission, and the quantum ciphertext blocks are numbered in the order of fragmentation; in this embodiment, it is split into three quantum ciphertext blocks, and then the split ciphertext information part corresponding to each quantum ciphertext block is generated according to the first quantum ciphertext information part and the number of the quantum ciphertext block, that is, there is a split ciphertext information part corresponding to each quantum ciphertext block, and the split ciphertext information part includes the identifier of the fragment in the first quantum ciphertext information part, the key file index value, the key position information, the offset information and the split number, and the split number is the number of the quantum ciphertext block.
[0041] The quantum encryption card then verifies the quantum ciphertext block and its corresponding split ciphertext information part to generate a split verification code corresponding to the quantum ciphertext block, and constructs a split data frame corresponding to the quantum ciphertext block based on the split verification code; the split data frame includes the data header, quantum ciphertext block, split ciphertext information part corresponding to the quantum ciphertext block and split verification code in the original data frame. Sending the split data frame to the quantum decryption card means sending the split data frame to the quantum decryption card in the order of numbering, that is, sending the split data frame to the quantum decryption card in an orderly manner. Figure 3 As shown, split data frames 1, 2 and 3 each correspond to a split ciphertext information part, a quantum ciphertext block and a split check code, wherein the sum of the quantum ciphertext blocks of split data frames 1, 2 and 3 is the first quantum ciphertext part in the first intermediate data frame.
[0042] (3) The quantum decryption card verifies and reassembles the received split data frames, decrypts them and sends them to the receiving end. The specific process is as follows:
[0043] like Figure 4As shown, the quantum decryption card verifies and calculates the split ciphertext information part and the quantum ciphertext block in the received split data frame to generate a third verification code, and compares whether the split verification code in the split data frame is the same as the third verification code. If they are the same, the received split data frame is copied to the buffer for reorganization to generate a second intermediate data frame. If they are not the same, the quantum encryption card is notified to resend the split data frame; the second intermediate data frame includes the data header of the original data frame, the second quantum ciphertext information part, the second quantum ciphertext part and the fourth verification code;
[0044] The specific process of recombining and generating the second intermediate data frame is as follows: detecting the fragmentation identifier and the split number of the split ciphertext information part in the current split data frame, and then continuing to receive the next split data frame, and judging the next split data frame, if the fragmentation identifier in the next split data frame is the same as that in the previous split data frame, and the split number in the next split data frame is larger than the split number in the previous split data frame, then continue to receive the next next split data frame; and so on, until if the fragmentation identifier in the next split data frame is different from that in the previous split data frame, or the split number in the next split data frame is smaller than the split number in the previous split data frame, then extract the quantum ciphertext blocks in the data frame according to the split number order of the previously received split data frame and combine them to generate the second quantum ciphertext part. Since the split data frames are sent in the order of numbers, assuming that the fragmentation identifier in the current split data frame is 1, indicating fragmentation, and the current split number value is 3, if the fragmentation identifier in the next split data frame is also 1, and the current split number value is 4, it means that the fragmentation has not ended, and the next split data frame is continued to be received; if the fragmentation identifier in the next split data frame is also 1, and the current split number value is 2, it means that the fragmentation is ended, and the previous split data frame of the next split data frame, that is, the previously received split data frame, is extracted in the order of the split number The quantum ciphertext blocks in the data frame are combined to generate the second quantum ciphertext part.
[0045] Then, based on the split ciphertext information part in the split data frame, a second quantum ciphertext information part is generated, and the second quantum ciphertext information part also includes the identifier of the shard, the number of shards, the key file index value, the key location information and the offset information; then the quantum decryption card verifies and calculates the second quantum ciphertext information part and the second quantum ciphertext part to generate a fourth check code, and constructs a second intermediate data frame based on the fourth check code; the second intermediate data frame includes the data header in the original data frame, the second quantum ciphertext information part, the second quantum ciphertext part and the fourth check code.
[0046] After the second intermediate data frame is generated, the second quantum ciphertext information part and the second quantum ciphertext part of the second intermediate data frame are verified and calculated to generate the fifth verification code, and the fourth verification code and the fifth verification code in the second intermediate data frame are compared to see if they are the same. If they are the same, the quantum decryption key is found according to the key file index value, key location information and offset information in the second quantum ciphertext information part, and the second quantum ciphertext part is decrypted by the quantum decryption key to obtain the second load, which is the first load and the first verification code. The original data frame is generated based on the second load and sent to the receiving end. At this time, the original data frame still includes the data header, the first load and the first verification code. The receiving end can normally recognize the data frame, and realizes "senseless" transmission for quantum encryption in the communication process.
[0047] Based on the above transmission process, the present invention first solves the problem of insecure communication data caused by the easy cracking of traditional encrypted data through quantum encryption; then, through external quantum devices, the original data frames are split, reorganized and verified between quantum devices. It uses quantum encryption to ensure the security of data transmission without affecting the transmission efficiency, so that "seamless" transmission can be achieved at both ends of the communication.
Claims
1. A communication encryption data transmission method, characterized in that: The following steps are involved: (1) The transmitting end sends the original data frame to the quantum encryption card, and the quantum encryption card generates a first intermediate data frame based on the original data frame; wherein the original data frame includes a data header, a first payload, and a first check code; (2) The quantum encryption card splits the first intermediate data frame and sends the split data frames obtained by splitting to the quantum decryption card; (3) The quantum decryption card verifies and reassembles the received split data frames, decrypts them and sends them to the receiving end.
2. A communication encryption data transmission method according to claim 1, characterized in that: Before step (1), the sending end, the receiving end, the quantum encryption card and the quantum decryption card are all preset with the same CRC check calculation method.
3. A communication encryption data transmission method according to claim 1, characterized in that: The specific process of the quantum encryption card generating the first intermediate data frame based on the original data frame is: The quantum encryption card performs quantum encryption on the first payload and the first check code in the original data frame through the quantum encryption key to obtain the first quantum ciphertext part, and generates the first quantum ciphertext information part according to the information of the quantum encryption key and the data frame size set for transmission, and then adds the first quantum ciphertext information part to the corresponding original data frame; then the quantum encryption card performs verification calculation on the first quantum ciphertext information part and the first quantum ciphertext part to generate a second check code, and adds the second check code to the original data frame to obtain the first intermediate data frame; at this time, the first intermediate data frame includes the data header of the original data frame, the first quantum ciphertext information part, the first quantum ciphertext part and the second check code.
4. A communication encryption data transmission method according to claim 3, characterized in that: The first quantum ciphertext information part includes a shard identifier, the number of shards, a key file index value, key location information, and offset information.
5. A communication encryption data transmission method according to claim 4, characterized in that: The key location information refers to the storage location of the quantum encryption key; the offset information refers to the offset value of the quantum encryption key in the key file.
6. A communication encryption data transmission method according to claim 4, characterized in that: The specific process of splitting the first intermediate data frame is: The first quantum ciphertext part in the first intermediate data frame is split into a corresponding number of quantum ciphertext blocks according to the number of fragments in the first quantum ciphertext information part and the data frame size set for transmission, and the quantum ciphertext blocks are numbered in the order of splitting; then, the split ciphertext information part corresponding to each quantum ciphertext block is generated according to the number of the first quantum ciphertext information part and the quantum ciphertext block, and then the quantum encryption card verifies the quantum ciphertext block and the split ciphertext information part corresponding to the quantum ciphertext block to generate a split verification code corresponding to the quantum ciphertext block, and constructs a split data frame corresponding to the quantum ciphertext block based on the split verification code; the split data frame includes a data header in the original data frame, a quantum ciphertext block, a split ciphertext information part corresponding to the quantum ciphertext block, and a split verification code.
7. A communication encryption data transmission method according to claim 6, characterized in that: The sending of the split data frames to the quantum decryption card refers to sending the split data frames to the quantum decryption card in the order of numbers; The split ciphertext information part includes the identifier of the fragment in the first quantum ciphertext information part, the key file index value, the key position information, the offset information and the split number; the split number is the number of the quantum ciphertext block.
8. A communication encryption data transmission method according to claim 7, characterized in that: The specific process of step (3) is as follows: The quantum decryption card verifies and calculates the split ciphertext information part and the quantum ciphertext block in the received split data frame to generate a third verification code, and compares the split verification code in the split data frame with the third verification code to see if they are the same. If they are the same, the received split data frame is copied to the buffer for reassembly to generate a second intermediate data frame. If they are not the same, the quantum encryption card is notified to resend the split data frame; the second intermediate data frame includes the data header of the original data frame, the second quantum ciphertext information part, the second quantum ciphertext part and the fourth verification code; After the second intermediate data frame is generated, the second quantum ciphertext information part and the second quantum ciphertext part of the second intermediate data frame are verified and calculated to generate a fifth verification code, and the fourth verification code and the fifth verification code in the second intermediate data frame are compared to see whether they are the same. If they are the same, the quantum decryption key is found according to the key file index value, key position information and offset information in the second quantum ciphertext information part, the second quantum ciphertext part is decrypted by the quantum decryption key to obtain the second payload, and the original data frame is generated based on the second payload and sent to the receiving end.
9. A communication encryption data transmission method according to claim 8, characterized in that: The specific process of recombining and generating the second intermediate data frame is as follows: Detect the fragmentation identifier and the split number of the split ciphertext information part in the current split data frame, then continue to receive the next split data frame, and judge the next split data frame. If the fragmentation identifier in the next split data frame is the same as that in the previous split data frame, and the split number in the next split data frame is greater than the split number in the previous split data frame, continue to receive the next next split data frame; And so on, until if the fragmentation identifier in the next split data frame is different from that in the previous split data frame, or the split number in the next split data frame is smaller than the split number in the previous split data frame, the previously received split data frame is extracted from the quantum ciphertext blocks in the data frame in the order of the split numbers and combined to generate the second quantum ciphertext part, and then the second quantum ciphertext information part is generated based on the split ciphertext information part in the split data frame, and then the quantum decryption card verifies the second quantum ciphertext information part and the second quantum ciphertext part to generate a fourth check code, and constructs a second intermediate data frame based on the fourth check code; the second intermediate data frame includes the data header in the original data frame, the second quantum ciphertext information part, the second quantum ciphertext part and the fourth check code.