Wireless QKD access authentication method and communication system

Through the wireless QKD access authentication method, quantum key decryption and HMAC value verification are used to solve the problem of quantum key access authentication of mobile terminals outside the QKD network, ensuring the security of quantum encryption communication of terminal devices.

CN120111491AActive Publication Date: 2025-06-06中电信量子信息科技集团有限公司
View PDF 8 Cites 0 Cited by

Patent Information

Application Number
CN202510579468.9
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-05-07
Publication Date
2025-06-06
Estimated Expiration
2045-05-07

AI Technical Summary

Technical Problem

It is difficult for mobile application terminals to obtain quantum key services from QKD networks in real time. Traditional technical means do not have quantum security, resulting in security risks in quantum keys during cross-domain transmission.

Method used

A wireless QKD access authentication method is provided, which receives the authentication request of the target terminal through the target base station, determines its belonging relationship, and decrypts the ciphertext using a quantum key, verifys the consistency of the HMAC value, and completes the access authentication of the terminal.

Benefits of technology

It realizes quantum key access authentication of mobile terminals in wireless environments, ensuring the security of quantum encryption communication of terminal devices during movement.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120111491A_ABST
    Figure CN120111491A_ABST
Patent Text Reader

Abstract

The invention provides a wireless QKD access authentication method and a communication system, and the method comprises the steps: under the conditions that a target terminal is not an attribution device managed by a target base station, and the type of a QKD device deployed by the target terminal is the same as the type of the QKD device deployed by the target base station, the target base station sends a second type of authentication request to the attribution base station of the target terminal; decrypting the ciphertext fed back by the home base station by using the quantum key to obtain the equipment ID, the home authentication code and the home HMAC value, and sending the home authentication code to a target terminal corresponding to the equipment ID to perform HMAC verification; and when the authentication is successful, allowing the target terminal to access the target base station. The problem of wireless QKD access authentication of the mobile terminal is solved, and it is guaranteed that terminal equipment can continuously and stably conduct quantum encryption communication in the moving process.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the field of communications, and in particular to a wireless QKD access authentication method and a communication system. Background Art

[0002] Due to the limited coverage of the QKD network in quantum technology, it is difficult for mobile application terminals to obtain quantum key services from the QKD network in real time. At present, quantum keys are securely connected to widely distributed mobile application systems from the QKD network. Due to the technical methods used, quantum keys have been separated from the QKD network to achieve the "last mile" of secure cross-domain communication. However, traditional technical means do not have quantum security. Therefore, practical applications need to systematically solve the "last mile" problem of cross-domain transfer of quantum key applications from aspects such as interface security, cross-domain transmission and application management security. Summary of the invention

[0003] The purpose of the present invention is to provide a wireless QKD access authentication method and communication system to improve the above problems.

[0004] In order to achieve the above purpose, the technical solution adopted by the embodiment of the present invention is as follows: In a first aspect, an embodiment of the present invention provides a wireless QKD access authentication method, which is applied to a communication system, wherein the communication system includes a mobile terminal with a QKD device deployed and at least two QKD base stations, and the method includes: The target base station receives the first type of authentication request sent by the target terminal, and determines whether the target terminal is a homed device managed by the target base station according to the device ID and home base station identifier, wherein the target base station is any QKD base station, and the target terminal is a mobile terminal that has completed QKD home authentication; In the case where the target terminal is not a homed device managed by the target base station, and the type of the QKD device deployed by the target terminal is the same as the type of the QKD device deployed by the target base station, the target base station sends a second type of authentication request to the home base station of the target terminal, wherein the second type of authentication request includes the device ID of the target terminal; The attribution base station encrypts the device ID, the attribution authentication code and the attribution HMAC value by using the quantum key, and sends the ciphertext to the target base station; wherein the attribution authentication code is the authentication code when the target terminal performs QKD attribution authentication, and the attribution HMAC value is the HMAC value when the target terminal performs QKD attribution authentication; The target base station decrypts the ciphertext using the quantum key to obtain the device ID, the attribution authentication code and the attribution HMAC value, and sends the attribution authentication code to the target terminal corresponding to the device ID; The target terminal determines a new HMAC value using the charging key during QKD attribution authentication, the attribution authentication code, and the device ID, and sends the new HMAC value to the target base station; When the home HMAC value is consistent with the new HMAC value, the target base station determines that the authentication is successful and allows the target terminal to access the target base station.

[0005] Optionally, when the home base station receives the second type of authentication request, the method further includes: The target base station performs QKD negotiation with the home base station to generate a quantum key.

[0006] Optionally, when the target terminal is a homed device managed by the target base station, the method further includes: The target base station sends the home authentication code to the target terminal corresponding to the device ID.

[0007] Optionally, when the mobile terminal performs QKD attribution authentication, the method further includes: The QKD device of the mobile terminal and the QKD device of the base station form a matching relationship through key distribution; Perform key charging on the base station and mobile terminal that form a matching relationship; After completing key charging, the base station sends an authentication code to the mobile terminal; The mobile terminal determines a first HMAC value using the received authentication code, the charging key, and the device ID, and sends the first HMAC value to the base station; The base station determines a second HMAC value using the authentication code, the injection key, and the device ID; When the first HMAC value is consistent with the second HMAC value, the base station determines that the mobile terminal passes the QKD attribution authentication.

[0008] Optionally, the method further includes: when the target base station receives a key negotiation request between mobile terminals, determining whether the opposite device is within the coverage of the station; wherein the key negotiation request includes an initiator number of the initiator device and an opposite number of the opposite device; If the target base station is within the coverage of the current station, the target base station sends a key negotiation instruction to the opposite device; The target base station sends a relay request and first-type routing information to the QKD management unit to complete the QKD key negotiation between the initiating device and the peer device; The first type of routing information is the initiating device->the target base station->the opposite device.

[0009] Optionally, the method further includes: if the target base station is not within the coverage of the local station, the target base station sends a key negotiation indication to the opposite base station; wherein the opposite base station is the QKD base station currently accessed by the opposite device; The target base station sends a relay request and the second type of routing information to the QKD management unit to complete the QKD key negotiation between the initiating device and the peer device; The first type of routing information is the initiating device->the target base station->the opposite base station->the opposite device.

[0010] Optionally, when the QKD base station is connected to multiple mobile terminals at the same time, the QKD base station uses time division multiplexing to communicate wirelessly with the multiple mobile terminals.

[0011] Optionally, the method further includes: the mobile terminal acquiring the signal strength and / or signal-to-noise ratio between the mobile terminal and each QKD base station, and determining its corresponding target base station according to the signal strength and / or signal-to-noise ratio.

[0012] In a second aspect, an embodiment of the present invention provides a wireless QKD access authentication method, which is applied to a target base station in a communication system, and the method includes: Receiving a first type of authentication request sent by a target terminal, and determining whether the target terminal is a homed device managed by the target base station according to the device ID and home base station identifier therein, wherein the target terminal is a mobile terminal that has completed QKD home authentication; When the target terminal is not a homed device managed by the target base station, and the type of the QKD device deployed by the target terminal is the same as the type of the QKD device deployed by the target base station, a second type of authentication request is sent to the home base station of the target terminal, wherein the second type of authentication request includes the device ID of the target terminal; Receive the ciphertext fed back by the home base station, and decrypt the ciphertext using the quantum key to obtain the device ID, the home authentication code and the home HMAC value, and send the home authentication code to the target terminal corresponding to the device ID; The ciphertext is obtained by encrypting the device ID, the attribution authentication code and the attribution HMAC value by the attribution base station using the quantum key, the attribution authentication code is the authentication code when the target terminal performs QKD attribution authentication, and the attribution HMAC value is the HMAC value when the target terminal performs QKD attribution authentication; Receive a new HMAC value fed back by the target terminal, and when the attribution HMAC value is consistent with the new HMAC value, determine that the authentication is successful, and allow the target terminal to access the target base station; wherein the new HMAC value is the HMAC value determined by the injection key when the target terminal uses QKD attribution authentication, the attribution authentication code and the device ID.

[0013] In a third aspect, an embodiment of the present invention provides a communication system, the communication system comprising a mobile terminal deployed with a QKD device and at least two QKD base stations; The communication system is used for the above-mentioned wireless QKD access authentication method.

[0014] Compared with the prior art, the wireless QKD access authentication method and communication system provided by the embodiment of the present invention, when the target terminal is not a homed device managed by the target base station, and the type of QKD device deployed by the target terminal is the same as the type of QKD device deployed by the target base station, the target base station sends a second type of authentication request to the home base station of the target terminal; uses the quantum key to decrypt the ciphertext fed back by the home base station to obtain the device ID, home authentication code and home HMAC value, and sends the home authentication code to the target terminal corresponding to the device ID for HMAC verification; when the authentication is successful, the target terminal is allowed to access the target base station. It solves the problem of wireless QKD access authentication of mobile terminals and ensures that terminal devices in the mobile process can continuously and stably perform quantum encryption communication.

[0015] In order to make the above-mentioned objects, features and advantages of the present invention more obvious and easy to understand, preferred embodiments are given below and described in detail with reference to the accompanying drawings. BRIEF DESCRIPTION OF THE DRAWINGS

[0016] In order to more clearly illustrate the technical solutions of the embodiments of the present invention, the drawings required for use in the embodiments are briefly introduced below. It should be understood that the following drawings only show certain embodiments of the present invention and therefore should not be regarded as limiting the scope. For ordinary technicians in this field, other related drawings can be obtained based on these drawings without creative work.

[0017] Figure 1 One of the flow charts of the wireless QKD access authentication method provided in an embodiment of the present invention.

[0018] Figure 2 The second flowchart of the wireless QKD access authentication method provided in the embodiment of the present invention.

[0019] Figure 3 The third flow chart of the wireless QKD access authentication method provided in the embodiment of the present invention.

[0020] Figure 4 A schematic diagram of QKD base station coverage provided by an embodiment of the present invention. DETAILED DESCRIPTION

[0021] In order to make the purpose, technical solutions and advantages of the embodiments of the present invention clearer, the technical solutions in the embodiments of the present invention will be clearly and completely described below in conjunction with the drawings in the embodiments of the present invention. Obviously, the described embodiments are part of the embodiments of the present invention, not all of the embodiments. Generally, the components of the embodiments of the present invention described and shown in the drawings here can be arranged and designed in various different configurations.

[0022] Therefore, the following detailed description of the embodiments of the present invention provided in the accompanying drawings is not intended to limit the scope of the invention claimed for protection, but merely represents selected embodiments of the present invention. Based on the embodiments of the present invention, all other embodiments obtained by ordinary technicians in this field without creative work are within the scope of protection of the present invention.

[0023] It should be noted that similar reference numerals and letters represent similar items in the following drawings, so once an item is defined in one drawing, it does not need to be further defined and explained in the subsequent drawings. At the same time, in the description of the present invention, the terms "first", "second", etc. are only used to distinguish the description and cannot be understood as indicating or implying relative importance.

[0024] It should be noted that, in this article, relational terms such as first and second, etc. are only used to distinguish one entity or operation from another entity or operation, and do not necessarily require or imply any such actual relationship or order between these entities or operations. Moreover, the terms "include", "comprise" or any other variants thereof are intended to cover non-exclusive inclusion, so that a process, method, article or device including a series of elements includes not only those elements, but also other elements not explicitly listed, or also includes elements inherent to such process, method, article or device. In the absence of further restrictions, the elements defined by the sentence "comprise a ..." do not exclude the existence of other identical elements in the process, method, article or device including the elements.

[0025] In the description of the present invention, it should be noted that the terms "upper", "lower", "inside", "outside", etc. indicate directions or positional relationships based on the directions or positional relationships shown in the accompanying drawings, or are directions or positional relationships in which the product of the invention is usually placed when in use. They are only for the convenience of describing the present invention and simplifying the description, and do not indicate or imply that the device or element referred to must have a specific direction, be constructed and operated in a specific direction, and therefore should not be understood as a limitation on the present invention.

[0026] In the description of the present invention, it is also necessary to explain that, unless otherwise clearly specified and limited, the terms "disposed" and "connected" should be understood in a broad sense, for example, it can be a fixed connection, a detachable connection, or an integral connection; it can be a mechanical connection or an electrical connection; it can be a direct connection, or it can be an indirect connection through an intermediate medium, or it can be the internal communication of two elements. For ordinary technicians in this field, the specific meanings of the above terms in the present invention can be understood according to specific circumstances.

[0027] Some embodiments of the present invention are described in detail below in conjunction with the accompanying drawings. In the absence of conflict, the following embodiments and features in the embodiments can be combined with each other.

[0028] An embodiment of the present invention provides a communication system, the communication system comprising a mobile terminal with a QKD device deployed and at least two QKD base stations, wherein the QKD base station is a base station with a QKD device deployed. The communication system can perform the following wireless QKD access authentication method.

[0029] Please refer to Figure 1 , Figure 1 One of the flow charts of the wireless QKD access authentication method provided in an embodiment of the present invention. The wireless QKD access authentication method includes: S201, S202, S203, S205, S206, S207, S208 and S209, which are specifically described as follows.

[0030] S201, the target base station receives a first type authentication request sent by the target terminal, and determines whether the target terminal is a localized device managed by the target base station according to the device ID and the local base station identifier. If not, execute S202; if yes, execute S207.

[0031] Among them, the target base station is any QKD base station, and the target terminal is a mobile terminal that has completed QKD attribution authentication.

[0032] Optionally, when accessing the target base station, the target terminal sends a first type of authentication request to the target base station, wherein the first type of authentication request includes a device ID of the target terminal and an identifier of a home base station.

[0033] Optionally, the target base station determines whether the home base station identifier in the first type of authentication request is consistent with its own identifier. If consistent, it determines whether its corresponding home management list includes the device ID in the first type of authentication request. If included, it determines that the target terminal is a home device managed by the target base station. Otherwise, the target terminal is not a home device managed by the target base station.

[0034] When the target terminal is not a homed device managed by the target base station, it means that the target terminal has moved, for example, from the communication range of its corresponding home base station to the communication range of the target base station, and it needs to be re-authenticated for access.

[0035] S202, the target base station determines whether the type of QKD equipment deployed by the target terminal is the same as the type of QKD equipment deployed by itself. If yes, execute S203; if no, end.

[0036] S203: The target base station sends a second type authentication request to the home base station of the target terminal.

[0037] The second type of authentication request includes the device ID of the target terminal.

[0038] S205, the home base station uses the quantum key to encrypt the device ID, the home authentication code and the home HMAC value, and sends the ciphertext to the target base station.

[0039] Among them, the attribution authentication code is the authentication code of the target terminal (most recently) when performing QKD attribution authentication, the attribution HMAC value is the HMAC value of the target terminal (most recently) when performing QKD attribution authentication; the quantum key (Kt) obtained by QKD negotiation between the target base station and the attribution base station.

[0040] S206, the target base station decrypts the ciphertext using the quantum key to obtain the device ID, the attribution authentication code and the attribution HMAC value, and sends the attribution authentication code to the target terminal corresponding to the device ID.

[0041] Optionally, before sending the attribution authentication code to the target terminal corresponding to the device ID, the target terminal is notified to perform HMAC verification.

[0042] Among them, the hash-based Message Authentication Code (HMAC) is a mechanism that uses hash functions in cryptography to perform message authentication and can be used for access authentication between QKD modules.

[0043] S207, the target base station sends the home authentication code to the target terminal corresponding to the device ID.

[0044] In the case where the target terminal is a localized device managed by the target base station, it stores the localization authentication code of the target terminal and can directly send the localization authentication code to the target terminal corresponding to the device ID.

[0045] S208, the target terminal uses the injection key, the home authentication code and the device ID during the QKD home authentication to determine a new HMAC value, and sends the new HMAC value to the target base station.

[0046] S209: When the home HMAC value is consistent with the new HMAC value, the target base station determines that the authentication is successful and allows the target terminal to access the target base station.

[0047] Optionally, the home HMAC value is compared with the new HMAC value. If they are consistent (or match), it is determined that the authentication is successful and the target terminal is allowed to access the target base station.

[0048] In the wireless QKD access authentication method provided in the embodiment of the present invention, the wireless QKD access authentication problem of the mobile terminal is solved, ensuring that the terminal equipment during the mobile process can continuously and stably perform quantum encryption communication.

[0049] Please continue to refer to Figure 1 After S203, when the home base station receives the second type of authentication request, the wireless QKD access authentication method also includes: S204, as follows.

[0050] S204: The target base station performs QKD negotiation with the home base station to generate a quantum key.

[0051] The QKD negotiation process between the target base station and the home base station will not be described in detail here. It should be noted that the QKD negotiation between the target base station and the home base station can be, but is not limited to, generating a set of symmetric quantum keys. The generated quantum keys are used for encryption and decryption in the communication between the target base station and the home base station.

[0052] Regarding how the mobile terminal completes QKD attribution authentication, the embodiment of the present invention also provides an optional implementation method, please refer to Figure 2 When the mobile terminal performs QKD attribution authentication, the wireless QKD access authentication method also includes: S101, S102, S103, S104, S105 and S106, which are specifically described as follows.

[0053] S101, the QKD device of the mobile terminal and the QKD device of the base station form a matching relationship through key distribution.

[0054] S102, performing key charging on the base station and the mobile terminal that form a matching relationship.

[0055] Optionally, the key is injected into the base station and the mobile terminal that form a matching relationship through an injection device. The root key is injected into the base station, different mobile terminals are identified by device IDs, and the dispersed sub-keys are injected into the matching mobile terminals respectively.

[0056] For example, the root key K1s is dispersed into three pairs of sub-keys, namely K11, K12 and K13, and the three pairs of sub-keys are respectively injected into the mobile terminal.

[0057] S103, after completing key charging, the base station sends an authentication code to the mobile terminal.

[0058] S104: The mobile terminal determines a first HMAC value using the received authentication code, the charging key, and the device ID, and sends the first HMAC value to the base station.

[0059] Optionally, the mobile terminal determines a first HMAC value using the received authentication code, the charging key (subkey), and the device ID.

[0060] S105, the base station determines a second HMAC value using the authentication code, the charging key and the device ID.

[0061] Optionally, the base station determines the second HMAC value using a charging key (root key), an authentication code, and a device ID corresponding to the mobile terminal.

[0062] S106: When the first HMAC value is consistent with (or matches) the second HMAC value, the base station determines that the mobile terminal passes the QKD attribution authentication.

[0063] Optionally, the device ID of the mobile terminal is added to the home management list corresponding to the base station.

[0064] In an optional implementation, after the attribution authentication code completes authentication and the mobile terminal is within the coverage of the attribution base station, attribution authentication will be performed according to a preset period, thereby ensuring that the attribution authentication code and the attribution HMAC value (in the attribution base station and the mobile terminal) are dynamically updated to improve security.

[0065] In an optional implementation, when the mobile device leaves the coverage of the home base station and remains in the coverage of the current base station for more than a preset time, the current base station may be determined as a new home base station and home authentication may be performed again.

[0066] Based on the above, regarding how to complete key relay, the embodiment of the present invention also provides an optional implementation method, please refer to Figure 3 The wireless QKD access authentication method also includes: S301, S302, S303, S304 and S305, which are specifically described as follows.

[0067] S301, when receiving a key negotiation request between mobile terminals, the target base station determines whether the opposite terminal device is within the coverage of the station. If it is within the coverage of the station, S302 is executed; if it is not within the coverage of the station, S304 is executed.

[0068] The key negotiation request includes an initiator number of an initiating device and a peer number of a peer device, where the number may be but is not limited to a mobile phone number.

[0069] S302: The target base station sends a key negotiation instruction to the opposite device.

[0070] S303, the target base station sends a relay request and first type of routing information to the QKD management unit to complete the QKD key negotiation between the initiating device and the peer device.

[0071] Among them, the first type of routing information is initiating device->target base station->opposite device, and the QKD management unit is also called M-QKDNC.

[0072] S304: The target base station sends a key negotiation indication to the opposite base station.

[0073] Among them, the opposite base station is the QKD base station that the opposite device is currently connected to.

[0074] In an optional implementation, the location of the opposite base station may be acquired first, and a key negotiation indication may be sent to the opposite base station based on the location.

[0075] S305, the target base station sends a relay request and the second type of routing information to the QKD management unit to complete the QKD key negotiation between the initiating device and the peer device.

[0076] The first type of routing information is initiating device->target base station->opposite base station->opposite device.

[0077] After the peer device obtains the quantum key, it feeds back a relay completion notification to the corresponding base station and ends the relay process.

[0078] In an optional implementation, the QKD base station simultaneously accesses multiple mobile terminals. How to distribute communication resources? The embodiment of the present invention also provides an optional implementation, please refer to the following. When the QKD base station simultaneously accesses multiple mobile terminals, the QKD base station uses time division multiplexing to communicate wirelessly with the multiple mobile terminals.

[0079] Optionally, the QKD base station divides the communication cycle into multiple time slices, and allocates a time slice to each mobile terminal based on a pre-configured scheduling mechanism, and the QKD base station and the mobile terminal perform key negotiation within the allocated time slice. It should be noted that the length of the allocated time slice is greater than the preset length to avoid restricting the key negotiation rate.

[0080] On the basis of the above, regarding how the mobile terminal determines the target base station that needs to be accessed currently, the embodiment of the present invention further provides an optional implementation, please refer to the following. The wireless QKD access authentication method also includes: S401 and S402, which are specifically described as follows.

[0081] S401, the mobile terminal obtains the signal strength and / or signal-to-noise ratio between the mobile terminal and each QKD base station.

[0082] S402: The mobile terminal determines its corresponding target base station according to signal strength and / or signal-to-noise ratio.

[0083] Optionally, the QKD base station with the largest signal strength is determined as the target base station, or the QKD base station with the largest signal-to-noise ratio is determined as the target base station, or the QKD base station with the largest weighted calculation value of signal strength and signal-to-noise ratio is determined as the target base station.

[0084] In an optional implementation, when selecting a target base station, the mobile terminal may also refer to historical location information of the mobile terminal within a previously preset time period.

[0085] Optionally, when the mobile terminal is in the overlapping coverage area of ​​multiple QKD base stations, and the signal strength and / or signal-to-noise ratio between the mobile terminal and at least two QKD base stations meets a preset condition (greater than a corresponding threshold), the movement direction of the mobile terminal is determined based on the historical location information, and the QKD base station with a smaller deviation angle from the movement direction is determined as the target base station.

[0086] Please refer to Figure 4 , Figure 4 A schematic diagram of QKD base station coverage provided by an embodiment of the present invention. 1 Indicates QKD base station 1, BS 2 Indicates QKD base station 2, MD 1 Indicates mobile terminal 1, MD 3 Indicates mobile terminal 3, MD 4 Indicates mobile terminal 4, MD 2,1 Indicates the mobile terminal 2 at the last time point, MD 2,2 Represents mobile terminal 2 at the current time point.

[0087] As can be seen from the figure, MD 1 In BS 1 Coverage, MD 1 The corresponding target base station is BS 1 , MD 4 In BS 2 Coverage, MD 4 The corresponding target base station is BS 2 MD 3 In BS 1 and BS 2 The coverage overlap area is in a stationary state, then the corresponding target base station can be BS 1 or BS 2 .

[0088] MD2 (Mobile terminal 2) belongs to BS 1 , after moving (Move), arrive at BS 2 Coverage, MD 2 Need to re-do BS 2 Perform access authentication.

[0089] In the embodiment of the present invention, the framework of key negotiation between the mobile terminal and the QKD base station follows the 4301 standard framework. The overall quantum network architecture is still divided into a quantum layer, a key management layer, a control layer, etc. Both the mobile terminal and the base station have built-in QKD modules and KM modules.

[0090] The QKDNC of the mobile QKD network is referred to as M-QKDNC. It can be deployed in a base station or deployed separately in a fixed computer room. The mobile QKD terminal matched by the base station and several base stations form a mobile QKD key distribution network, and use traditional Kq, Kx, Ck, Qx interfaces and other interfaces to realize data forwarding at different layers.

[0091] An embodiment of the present invention also provides a wireless QKD access authentication method, which is applied to a target base station in a communication system, including: S501, S502, S503 and S504, which are specifically described as follows.

[0092] S501, receiving a first type of authentication request sent by a target terminal, and determining whether the target terminal is a homed device managed by the target base station according to the device ID and home base station identifier therein, wherein the target terminal is a mobile terminal that has completed QKD home authentication; S502, when the target terminal is not a homed device managed by the target base station, and the type of QKD device deployed by the target terminal is the same as the type of QKD device deployed by the target base station, sending a second type of authentication request to the home base station of the target terminal, wherein the second type of authentication request includes a device ID of the target terminal; S503, receiving the ciphertext fed back by the home base station, and decrypting the ciphertext using the quantum key to obtain the device ID, the home authentication code and the home HMAC value, and sending the home authentication code to the target terminal corresponding to the device ID; The ciphertext is obtained by encrypting the device ID, the belonging authentication code and the belonging HMAC value by the belonging base station using the quantum key. The belonging authentication code is the authentication code when the target terminal performs QKD belonging authentication, and the belonging HMAC value is the HMAC value when the target terminal performs QKD belonging authentication. S504, receiving the new HMAC value fed back by the target terminal, and when the attribution HMAC value is consistent (or matches) with the new HMAC value, determining that the authentication is successful, and allowing the target terminal to access the target base station; wherein the new HMAC value is the HMAC value determined by the injection key, attribution authentication code and device ID when the target terminal uses QKD attribution authentication.

[0093] It should be noted that the target base station can execute the steps completed by the target base station in the above-mentioned wireless QKD access authentication method applied to the communication system.

[0094] In summary, the embodiment of the present invention provides a wireless QKD access authentication method and communication system. When the target terminal is not a homed device managed by the target base station, and the type of QKD device deployed by the target terminal is the same as the type of QKD device deployed by the target base station, the target base station sends a second type of authentication request to the home base station of the target terminal; the ciphertext fed back by the home base station is decrypted using the quantum key to obtain the device ID, home authentication code and home HMAC value, and the home authentication code is sent to the target terminal corresponding to the device ID for HMAC verification; when the authentication is successful, the target terminal is allowed to access the target base station. This solves the problem of wireless QKD access authentication for mobile terminals, ensuring that terminal devices during movement can continuously and stably perform quantum encryption communications.

[0095] The above description is only a preferred embodiment of the present invention and is not intended to limit the present invention. For those skilled in the art, the present invention may have various modifications and variations. Any modification, equivalent replacement, improvement, etc. made within the spirit and principle of the present invention shall be included in the protection scope of the present invention.

[0096] It will be apparent to those skilled in the art that the invention is not limited to the details of the exemplary embodiments described above and that the invention can be implemented in other specific forms without departing from the spirit or essential features of the invention. Therefore, the embodiments should be considered exemplary and non-limiting in all respects, and the scope of the invention is defined by the appended claims rather than the foregoing description, and it is intended that all variations falling within the meaning and scope of the equivalent elements of the claims be included in the invention. Any reference numeral in a claim should not be considered as limiting the claim to which it relates.

Claims

1. A wireless QKD access authentication method, characterized in that: Applied to a communication system, the communication system includes a mobile terminal equipped with a QKD device and at least two QKD base stations, the method includes: The target base station receives the first type of authentication request sent by the target terminal, and determines whether the target terminal is a homed device managed by the target base station according to the device ID and home base station identifier, wherein the target base station is any QKD base station, and the target terminal is a mobile terminal that has completed QKD home authentication; In the case where the target terminal is not a homed device managed by the target base station, and the type of the QKD device deployed by the target terminal is the same as the type of the QKD device deployed by the target base station, the target base station sends a second type of authentication request to the home base station of the target terminal, wherein the second type of authentication request includes the device ID of the target terminal; The attribution base station encrypts the device ID, the attribution authentication code and the attribution HMAC value by using the quantum key, and sends the ciphertext to the target base station; wherein the attribution authentication code is the authentication code when the target terminal performs QKD attribution authentication, and the attribution HMAC value is the HMAC value when the target terminal performs QKD attribution authentication; The target base station decrypts the ciphertext using the quantum key to obtain the device ID, the attribution authentication code and the attribution HMAC value, and sends the attribution authentication code to the target terminal corresponding to the device ID; The target terminal determines a new HMAC value using the charging key during QKD attribution authentication, the attribution authentication code, and the device ID, and sends the new HMAC value to the target base station; When the home HMAC value is consistent with the new HMAC value, the target base station determines that the authentication is successful and allows the target terminal to access the target base station.

2. The wireless QKD access authentication method according to claim 1, characterized in that: When the home base station receives the second type of authentication request, the method further includes: The target base station performs QKD negotiation with the home base station to generate a quantum key.

3. The wireless QKD access authentication method according to claim 1, characterized in that: The target terminal is a homed device managed by the target base station, and the method further includes: The target base station sends the home authentication code to the target terminal corresponding to the device ID.

4. The wireless QKD access authentication method according to claim 1, characterized in that: When the mobile terminal performs QKD attribution authentication, the method further includes: The QKD device of the mobile terminal and the QKD device of the base station form a matching relationship through key distribution; Perform key charging on the base station and mobile terminal that form a matching relationship; After completing key charging, the base station sends an authentication code to the mobile terminal; The mobile terminal determines a first HMAC value using the received authentication code, the charging key, and the device ID, and sends the first HMAC value to the base station; The base station determines a second HMAC value using the authentication code, the injection key, and the device ID; When the first HMAC value is consistent with the second HMAC value, the base station determines that the mobile terminal passes the QKD attribution authentication.

5. The wireless QKD access authentication method according to claim 1, characterized in that: The method further comprises: The target base station determines whether the opposite device is within the coverage of the station when receiving the key negotiation request between the mobile terminals; wherein the key negotiation request includes the initiator number of the initiator device and the opposite number of the opposite device; If the target base station is within the coverage of the current station, the target base station sends a key negotiation instruction to the opposite device; The target base station sends a relay request and first-type routing information to the QKD management unit to complete the QKD key negotiation between the initiating device and the peer device; The first type of routing information is the initiating device->the target base station->the opposite device.

6. The wireless QKD access authentication method according to claim 5, characterized in that: The method further comprises: If the target base station is not in the coverage of the current station, the target base station sends a key negotiation instruction to the opposite base station; wherein the opposite base station is the QKD base station to which the opposite device is currently connected; The target base station sends a relay request and the second type of routing information to the QKD management unit to complete the QKD key negotiation between the initiating device and the peer device; The first type of routing information is the initiating device->the target base station->the opposite base station->the opposite device.

7. The wireless QKD access authentication method according to claim 1, characterized in that: When the QKD base station is connected to multiple mobile terminals at the same time, the QKD base station uses time division multiplexing to communicate wirelessly with the multiple mobile terminals.

8. The wireless QKD access authentication method according to claim 1, characterized in that: The method further comprises: The mobile terminal obtains the signal strength and / or signal-to-noise ratio between each QKD base station, and determines its corresponding target base station according to the signal strength and / or signal-to-noise ratio.

9. A wireless QKD access authentication method, characterized in that: Applied to a target base station in a communication system, the method comprises: Receiving a first type of authentication request sent by a target terminal, and determining whether the target terminal is a homed device managed by the target base station according to the device ID and home base station identifier therein, wherein the target terminal is a mobile terminal that has completed QKD home authentication; When the target terminal is not a homed device managed by the target base station, and the type of the QKD device deployed by the target terminal is the same as the type of the QKD device deployed by the target base station, a second type of authentication request is sent to the home base station of the target terminal, wherein the second type of authentication request includes the device ID of the target terminal; Receive the ciphertext fed back by the home base station, and decrypt the ciphertext using the quantum key to obtain the device ID, the home authentication code and the home HMAC value, and send the home authentication code to the target terminal corresponding to the device ID; The ciphertext is obtained by encrypting the device ID, the attribution authentication code and the attribution HMAC value by the attribution base station using the quantum key, the attribution authentication code is the authentication code when the target terminal performs QKD attribution authentication, and the attribution HMAC value is the HMAC value when the target terminal performs QKD attribution authentication; Receive a new HMAC value fed back by the target terminal, and when the attribution HMAC value is consistent with the new HMAC value, determine that the authentication is successful, and allow the target terminal to access the target base station; wherein the new HMAC value is the HMAC value determined by the injection key when the target terminal uses QKD attribution authentication, the attribution authentication code and the device ID.

10. A communication system, characterized in that: The communication system includes a mobile terminal deployed with a QKD device and at least two QKD base stations; The communication system is used to execute the wireless QKD access authentication method described in any one of claims 1-8.

Citation Information

Patent Citations

  • Authentication method and authentication system

    CN101304365A

  • Switching preparation method, related base station, and UE

    CN108471631A

  • Method and device for requesting connection recovery

    CN109803456A

  • Authentication method for quantum security terminal to access quantum security network

    CN116074839A

  • Method for acquring authentication cryptographic key context from object base station

    CN1819698A