A Wireless QKD Access Authentication Method and Communication System

Through quantum key negotiation and encryption decryption between the target base station and the home base station, wireless QKD access authentication of the mobile terminal is realized, the security problem in cross-domain transmission of quantum keys is solved, and the stability and security of quantum encryption communication of the mobile terminal is ensured.

CN120111491BActive Publication Date: 2025-07-08中电信量子信息科技集团有限公司
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202510579468.9
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2025-05-07
Publication Date
2025-07-08
Estimated Expiration
2045-05-07

AI Technical Summary

Technical Problem

In the prior art, quantum keys lack quantum security during cross-domain transmission, making it difficult for mobile application terminals to obtain quantum key services from QKD network in real time, and cannot achieve secure cross-domain ‘last mile’ wireless access authentication.

Method used

Through the quantum key negotiation between the target base station and the home base station, the device ID, home authentication code and home HMAC value are encrypted and decrypted using the quantum key to ensure wireless QKD access authentication of the target terminal, including key charging and HMAC value comparison, to realize secure access to the terminal device.

Benefits of technology

It ensures that the mobile terminal can continuously and stably conduct quantum encrypted communication in a wireless environment, solves the problem of wireless QKD access authentication, and ensures security and reliability.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120111491B_ABST
    Figure CN120111491B_ABST
Patent Text Reader

Abstract

The present invention provides a wireless QKD access authentication method and a communication system. When the target terminal is not a home device managed by the target base station and the QKD device type deployed by the target terminal is the same as the QKD device type deployed by the target base station, the target base station sends a second type of authentication request to the home base station of the target terminal; decrypts the ciphertext fed back by the home base station using the quantum key to obtain the device ID, home authentication code, and home HMAC value, and sends the home authentication code to the target terminal corresponding to the device ID for HMAC verification; when the authentication is successful, allows the target terminal to access the target base station. It solves the problem of wireless QKD access authentication for mobile terminals and ensures that the terminal devices during the movement can continuously and stably perform quantum encryption communication.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the field of communications, and in particular, to a wireless QKD access authentication method and a communication system. Background Art

[0002] Due to the limited coverage of the QKD network in quantum technology, it is difficult for mobile application terminals to obtain quantum key services from the QKD network in real time. Currently, to securely access quantum keys from the QKD network to a widely distributed mobile application system, due to the adopted technical means, the quantum keys have been separated from the QKD network to achieve secure cross-domain "the last mile". However, traditional technical means do not have quantum security. Therefore, in practical applications, it is necessary to systematically solve the "last mile" problem of cross-domain transfer of quantum key applications from aspects such as interface security, cross-domain transfer, and application management security. Summary of the Invention

[0003] The purpose of the present invention is to provide a wireless QKD access authentication method and a communication system to improve the above problems.

[0004] To achieve the above purpose, the technical solutions adopted in the embodiments of the present invention are as follows:

[0005] In a first aspect, an embodiment of the present invention provides a wireless QKD access authentication method applied to a communication system, where the communication system includes a mobile terminal deployed with a QKD device and at least two QKD base stations, and the method includes:

[0006] A target base station receives a first type of authentication request sent by a target terminal, and determines whether the target terminal is a home device managed by the target base station according to the device ID and the home base station identifier therein, where the target base station is any one of the QKD base stations, and the target terminal is a mobile terminal that has completed QKD home authentication;

[0007] When the target terminal is not a home device managed by the target base station and the type of QKD device deployed by the target terminal is the same as the type of QKD device deployed by the target base station, the target base station sends a second type of authentication request to the home base station of the target terminal, where the second type of authentication request includes the device ID of the target terminal;

[0008] The home base station encrypts the device ID, the home authentication code, and the home HMAC value using a quantum key and sends the ciphertext to the target base station; where the home authentication code is the authentication code when the target terminal performs QKD home authentication, and the home HMAC value is the HMAC value when the target terminal performs QKD home authentication;

[0009] The target base station decrypts the ciphertext using the quantum key to obtain the device ID, the home authentication code, and the home HMAC value, and sends the home authentication code to the target terminal corresponding to the device ID;

[0010] The target terminal determines a new HMAC value using the injection key during QKD home authentication, the home authentication code, and the device ID, and sends the new HMAC value to the target base station;

[0011] When the home HMAC value and the new HMAC value match, the target base station determines that the authentication is successful and allows the target terminal to access the target base station.

[0012] Optionally, when the home base station receives the second type of authentication request, the method further includes:

[0013] The target base station performs QKD negotiation with the home base station to generate a quantum key.

[0014] Optionally, when the target terminal is a home device managed by the target base station, the method further includes:

[0015] The target base station sends the home authentication code to the target terminal corresponding to the device ID.

[0016] Optionally, when a mobile terminal performs QKD home authentication, the method further includes:

[0017] The QKD device of the mobile terminal and the QKD device of the base station form a matching relationship through key dispersion;

[0018] Perform key injection on the base station and the mobile terminal that form a matching relationship;

[0019] After the key injection is completed, the base station sends an authentication code to the mobile terminal;

[0020] The mobile terminal determines a first HMAC value using the received authentication code, the injection key, and the device ID, and sends the first HMAC value to the base station;

[0021] The base station determines a second HMAC value using the authentication code, the injection key, and the device ID;

[0022] When the first HMAC value and the second HMAC value are the same, the base station determines that the mobile terminal passes the QKD home authentication.

[0023] Optionally, the method further includes: when the target base station receives a key negotiation request between mobile terminals, determining whether the peer device is within the coverage area of this station; wherein, the key negotiation request includes the initiating party number of the initiating device and the peer number of the peer device.

[0024] If it is within the coverage area of this station, the target base station sends a key negotiation indication to the peer device.

[0025] The target base station sends a relay request and first-class routing information to the QKD management unit to complete the QKD key negotiation between the initiating device and the peer device.

[0026] Wherein, the first-class routing information is the initiating device -> the target base station -> the peer device.

[0027] Optionally, the method further includes: if it is not within the coverage area of this station, the target base station sends a key negotiation indication to the peer base station; wherein, the peer base station is the QKD base station to which the peer device is currently connected.

[0028] The target base station sends a relay request and second-class routing information to the QKD management unit to complete the QKD key negotiation between the initiating device and the peer device.

[0029] Wherein, the first-class routing information is the initiating device -> the target base station -> the peer base station -> the peer device.

[0030] Optionally, when a QKD base station simultaneously accesses multiple mobile terminals, the QKD base station uses time-division multiplexing to perform wireless communication with the multiple mobile terminals.

[0031] Optionally, the method further includes: the mobile terminal obtains the signal strength and / or signal-to-noise ratio between each QKD base station, and determines its corresponding target base station according to the signal strength and / or signal-to-noise ratio.

[0032] In a second aspect, an embodiment of the present invention provides a wireless QKD access authentication method, which is applied to a target base station in a communication system, and the method includes:

[0033] Receiving a first-class authentication request sent by a target terminal, and determining whether the target terminal is a home device managed by the target base station according to the device ID and the home base station identifier therein, wherein the target terminal is a mobile terminal that has completed QKD home authentication.

[0034] When the target terminal is not a home device managed by the target base station and the QKD device type deployed by the target terminal is the same as the QKD device type deployed by the target base station, send a second type of authentication request to the home base station of the target terminal, where the second type of authentication request includes the device ID of the target terminal;

[0035] Receive the ciphertext fed back by the home base station, and decrypt the ciphertext using the quantum key to obtain the device ID, home authentication code, and home HMAC value, and send the home authentication code to the target terminal corresponding to the device ID;

[0036] Wherein, the ciphertext is encrypted by the home base station using the quantum key for the device ID, home authentication code, and home HMAC value, the home authentication code is the authentication code during QKD home authentication of the target terminal, and the home HMAC value is the HMAC value during QKD home authentication of the target terminal;

[0037] Receive the new HMAC value fed back by the target terminal. When the home HMAC value is consistent with the new HMAC value after comparison, determine that the authentication is successful and allow the target terminal to access the target base station; wherein, the new HMAC value is the HMAC value determined by the target terminal using the injection key, home authentication code, and device ID during QKD home authentication.

[0038] In a third aspect, an embodiment of the present invention provides a communication system, which includes a mobile terminal and at least two QKD base stations deployed with QKD devices;

[0039] The communication system is used for the above wireless QKD access authentication method.

[0040] Compared with the prior art, for a wireless QKD access authentication method and a communication system provided by an embodiment of the present invention, when the target terminal is not a home device managed by the target base station and the QKD device type deployed by the target terminal is the same as the QKD device type deployed by the target base station, the target base station sends a second type of authentication request to the home base station of the target terminal; decrypt the ciphertext fed back by the home base station using the quantum key to obtain the device ID, home authentication code, and home HMAC value, and send the home authentication code to the target terminal corresponding to the device ID for HMAC verification; when the authentication is successful, allow the target terminal to access the target base station. It solves the problem of wireless QKD access authentication for mobile terminals, and ensures that terminal devices can continuously and stably perform quantum encryption communication during the movement process.

[0041] To make the above objects, features, and advantages of the present invention more obvious and understandable, the following specifically enumerates preferred embodiments and, in conjunction with the accompanying drawings, makes a detailed description as follows. Brief Description of the Drawings

[0042] To more clearly illustrate the technical solutions of the embodiments of the present invention, the drawings required for use in the embodiments will be briefly introduced below. It should be understood that the following drawings only show some embodiments of the present invention and should not be regarded as limiting the scope. For those of ordinary skill in the art, without creative efforts, other related drawings can also be obtained based on these drawings.

[0043] Figure 1 It is one of the flow diagrams of the wireless QKD access authentication method provided by the embodiments of the present invention.

[0044] Figure 2 It is another flow diagram of the wireless QKD access authentication method provided by the embodiments of the present invention.

[0045] Figure 3 It is the third flow diagram of the wireless QKD access authentication method provided by the embodiments of the present invention.

[0046] Figure 4 It is the QKD base station coverage diagram provided by the embodiments of the present invention. Detailed Description of the Embodiments

[0047] To make the objectives, technical solutions, and advantages of the embodiments of the present invention clearer, the technical solutions in the embodiments of the present invention will be clearly and completely described below in conjunction with the drawings in the embodiments of the present invention. Obviously, the described embodiments are some, but not all, of the embodiments of the present invention. Generally, the components of the embodiments of the present invention described and illustrated in the drawings here can be arranged and designed in various different configurations.

[0048] Therefore, the following detailed description of the embodiments of the present invention provided in the drawings is not intended to limit the scope of the claimed invention, but merely represents the selected embodiments of the present invention. Based on the embodiments of the present invention, all other embodiments obtained by those of ordinary skill in the art without creative efforts fall within the scope of protection of the present invention.

[0049] It should be noted that similar reference numerals and letters denote similar items in the following drawings. Therefore, once an item is defined in one drawing, it does not need to be further defined and explained in subsequent drawings. At the same time, in the description of the present invention, terms such as "first" and "second" are only used for differential description and cannot be construed as indicating or implying relative importance.

[0050] It should be noted that in this text, relational terms such as first and second are only used to distinguish one entity or operation from another entity or operation, and do not necessarily require or imply any actual relationship or order between these entities or operations. Moreover, the terms "comprising", "including" or any other variant thereof are intended to cover non-exclusive inclusion, so that a process, method, article or device comprising a series of elements not only includes those elements, but also includes other elements not expressly listed, or elements inherent to such process, method, article or device. Without further limitation, an element defined by the statement "comprising an..." does not exclude the presence of additional identical elements in the process, method, article or device comprising the element.

[0051] In the description of the present invention, it should be noted that the orientation or positional relationship indicated by the terms "upper", "lower", "inner", "outer", etc. is based on the orientation or positional relationship shown in the drawings, or the orientation or positional relationship in which the inventive product is customarily placed during use. This is only for the convenience of describing the present invention and simplifying the description, and does not indicate or imply that the device or element referred to must have a specific orientation, be constructed and operated in a specific orientation, and therefore should not be construed as a limitation of the present invention.

[0052] In the description of the present invention, it should also be noted that unless otherwise clearly specified and limited, the terms "arranged" and "connected" should be understood in a broad sense. For example, it can be a fixed connection, a detachable connection, or an integral connection; it can be a mechanical connection or an electrical connection; it can be directly connected or indirectly connected through an intermediate medium, and it can be the communication inside two elements. For those of ordinary skill in the art, the specific meanings of the above terms in the present invention can be understood according to specific circumstances.

[0053] The following will describe in detail some embodiments of the present invention with reference to the drawings. Without conflict, the following embodiments and the features in the embodiments can be combined with each other.

[0054] An embodiment of the present invention provides a communication system, which includes a mobile terminal equipped with a QKD device and at least two QKD base stations, where the QKD base station is a base station equipped with a QKD device. The communication system can execute the following wireless QKD access authentication method.

[0055] Please refer to Figure 1 , Figure 1 which is one of the flow diagrams of the wireless QKD access authentication method provided by the embodiment of the present invention. The wireless QKD access authentication method includes: S201, S202, S203, S205, S206, S207, S208, and S209, which are specifically described as follows.

[0056] S201. The target base station receives a first - type authentication request sent by the target terminal, and determines whether the target terminal is an affiliated device managed by the target base station according to the device ID and the home base station identifier therein. If not, then execute S202; if so, then execute S207.

[0057] Among them, the target base station is any QKD base station, and the target terminal is a mobile terminal that has completed QKD affiliation authentication.

[0058] Optionally, when the target terminal accesses the target base station, it sends a first - type authentication request to the target base station, where the first - type authentication request includes the device ID of the target terminal and the home base station identifier.

[0059] Optionally, the target base station determines whether the home base station identifier in the first - type authentication request is the same as its own identifier. If it is the same, then it determines whether the device ID in the first - type authentication request is included in its corresponding affiliated management list. If it is included, then it determines that the target terminal is an affiliated device managed by the target base station. On the contrary, the target terminal is not an affiliated device managed by the target base station.

[0060] When the target terminal is not an affiliated device managed by the target base station, it means that the target terminal has moved, for example, from the communication range of its corresponding home base station to the communication range of the target base station. At this time, it is necessary to re - authenticate its access.

[0061] S202. The target base station determines whether the QKD device type deployed by the target terminal is the same as the QKD device type deployed by itself. If it is, then execute S203; if not, then end.

[0062] S203. The target base station sends a second - type authentication request to the home base station of the target terminal.

[0063] Among them, the second - type authentication request includes the device ID of the target terminal.

[0064] S205. The home base station encrypts the device ID, the affiliation authentication code, and the home HMAC value using the quantum key, and sends the ciphertext to the target base station.

[0065] Among them, the affiliation authentication code is the authentication code when the target terminal (last time) performed QKD affiliation authentication, and the home HMAC value is the HMAC value when the target terminal (last time) performed QKD affiliation authentication; the quantum key (Kt) negotiated between the target base station and the home base station.

[0066] S206. The target base station decrypts the ciphertext using the quantum key to obtain the device ID, the affiliation authentication code, and the home HMAC value, and sends the affiliation authentication code to the target terminal corresponding to the device ID.

[0067] Optionally, send the home authentication code to the target terminal corresponding to the device ID, and notify the target terminal to perform HMAC verification.

[0068] Among them, the Hash-based Message Authentication Code (HMAC) is a mechanism that uses a hash function in cryptography for message authentication and can be used for access authentication between QKD modules.

[0069] S207. The target base station sends the home authentication code to the target terminal corresponding to the device ID.

[0070] In the case where the target terminal is a home device managed by the target base station and stores the home authentication code of the target terminal, the home authentication code can be directly sent to the target terminal corresponding to the device ID.

[0071] S208. The target terminal determines a new HMAC value using the key injection, home authentication code, and device ID during QKD home authentication, and sends the new HMAC value to the target base station.

[0072] S209. When the home HMAC value is consistent with the new HMAC value, the target base station determines that the authentication is successful and allows the target terminal to access the target base station.

[0073] Optionally, compare the home HMAC value with the new HMAC value. If they are consistent (or match), it is determined that the authentication is successful, and the target terminal is allowed to access the target base station.

[0074] In the wireless QKD access authentication method provided by the embodiments of the present invention, the problem of wireless QKD access authentication for mobile terminals is solved, ensuring that terminal devices can continuously and stably perform quantum encryption communication during the movement process.

[0075] Please continue to refer to Figure 1 , after S203, when the home base station receives a second type of authentication request, the wireless QKD access authentication method further includes: S204, specifically as follows.

[0076] S204. The target base station and the home base station perform QKD negotiation to generate a quantum key.

[0077] Regarding the QKD negotiation process between the target base station and the home base station, it will not be elaborated here. It should be noted that the QKD negotiation between the target base station and the home base station can, but is not limited to, generate a set of symmetric quantum keys. The generated quantum key is used for encryption and decryption in the communication between the target base station and the home base station.

[0078] Regarding how a mobile terminal completes QKD attribution authentication, an optional implementation manner is further provided in an embodiment of the present invention. Please refer to Figure 2 When a mobile terminal performs QKD attribution authentication, the wireless QKD access authentication method further includes: S101, S102, S103, S104, S105, and S106, which are specifically described as follows.

[0079] S101, the QKD device of the mobile terminal and the QKD device of the base station form a matching relationship through key dispersion.

[0080] S102, perform key injection on the base station and the mobile terminal that form a matching relationship.

[0081] Optionally, perform key injection on the base station and the mobile terminal that form a matching relationship through an injection device. The root key is injected at the base station. Different mobile terminals are identified by device IDs, and the dispersed sub-keys are respectively injected into the matching mobile terminals.

[0082] For example, if the root key is K1s and 3 pairs of sub-keys are respectively K11, K12, and K13, the 3 pairs of sub-keys are respectively injected into the mobile terminal.

[0083] S103, after completing key injection, the base station sends an authentication code to the mobile terminal.

[0084] S104, the mobile terminal uses the received authentication code, the injected key, and the device ID to determine the first HMAC value and sends the first HMAC value to the base station.

[0085] Optionally, the mobile terminal uses the received authentication code, the injected key (sub-key), and the device ID to determine the first HMAC value.

[0086] S105, the base station uses the authentication code, the injected key, and the device ID to determine the second HMAC value.

[0087] Optionally, the base station uses the injected key (root key) corresponding to the mobile terminal, the authentication code, and the device ID to determine the second HMAC value.

[0088] S106, when the first HMAC value is consistent (or matches) with the second HMAC value, the base station determines that the mobile terminal passes the QKD attribution authentication.

[0089] Optionally, add the device ID of the mobile terminal to the corresponding attribution management list of the base station.

[0090] In an alternative embodiment, after the home authentication code is authenticated and the mobile terminal is within the coverage area of the home base station, home authentication is performed at a preset period to ensure that the home authentication code and the home HMAC value (within the home base station and the mobile terminal) are dynamically updated to improve security.

[0091] In an alternative embodiment, when the mobile device leaves the coverage area of the home base station and the duration of staying within the coverage area of the current base station exceeds a preset time length, the current base station can be determined as the new home base station and home authentication is performed again.

[0092] Based on the above, the embodiments of the present invention also provide an alternative embodiment on how to complete key relay. Please refer to Figure 3 , the wireless QKD access authentication method further includes: S301, S302, S303, S304, and S305, which are specifically described as follows.

[0093] S301, when the target base station receives a key negotiation request between mobile terminals, it determines whether the peer device is within the coverage area of this station. If it is within the coverage area of this station, S302 is executed; if it is not within the coverage area of this station, S304 is executed.

[0094] Among them, the key negotiation request includes the initiator number of the initiating device and the peer number of the peer device. The number here can be, but is not limited to, a mobile phone number.

[0095] S302, the target base station sends a key negotiation indication to the peer device.

[0096] S303, the target base station sends a relay request and a first type of routing information to the QKD management unit to complete the QKD key negotiation between the initiating device and the peer device.

[0097] Among them, the first type of routing information is initiating device -> target base station -> peer device, and the QKD management unit is also called M-QKDNC.

[0098] S304, the target base station sends a key negotiation indication to the peer base station.

[0099] Among them, the peer base station is the QKD base station to which the peer device is currently connected.

[0100] In an alternative embodiment, the location of the peer base station can be obtained first, and a key negotiation indication is sent to the peer base station based on this location.

[0101] S305, the target base station sends a relay request and a second type of routing information to the QKD management unit to complete the QKD key negotiation between the initiating device and the peer device.

[0102] Among them, the first type of routing information is Initiating device -> Target base station -> Peer base station -> Peer device.

[0103] After the peer device obtains the quantum key, it feeds back a relay completion notification to the corresponding base station and ends the relay process.

[0104] In an alternative embodiment, when a QKD base station simultaneously accesses multiple mobile terminals and how to distribute communication resources, the embodiments of the present invention also provide an alternative embodiment. Please refer to the following text. When a QKD base station simultaneously accesses multiple mobile terminals, the QKD base station performs wireless communication with the multiple mobile terminals using time-division multiplexing.

[0105] Optionally, the QKD base station divides the communication cycle into multiple time slots, and based on a pre-configured scheduling mechanism, allocates a time slot to each mobile terminal. The QKD base station and the mobile terminal perform key negotiation within the allocated time slot. It should be noted that the length of the allocated time slot is greater than a preset length to avoid restricting the key negotiation rate.

[0106] Based on the above, regarding how a mobile terminal determines the target base station to be accessed currently, the embodiments of the present invention also provide an alternative embodiment. Please refer to the following text. The wireless QKD access authentication method further includes: S401 and S402, which are specifically described as follows.

[0107] S401, the mobile terminal obtains the signal strength and / or signal-to-noise ratio between itself and each QKD base station.

[0108] S402, the mobile terminal determines its corresponding target base station according to the signal strength and / or signal-to-noise ratio.

[0109] Optionally, the QKD base station with the maximum signal strength is determined as the target base station, or the QKD base station with the maximum signal-to-noise ratio is determined as the target base station, or the QKD base station with the maximum weighted operation value of the signal strength and the signal-to-noise ratio is determined as the target base station.

[0110] In an alternative embodiment, when selecting the target base station, the mobile terminal also refers to the historical location information of the mobile terminal within a previously preset time length.

[0111] Optionally, when the mobile terminal is in the coverage overlapping area of multiple QKD base stations and the signal strength and / or signal-to-noise ratio between the mobile terminal and at least two QKD base stations meet a preset condition (greater than the corresponding threshold), at this time, the movement direction of the mobile terminal is determined according to the historical location information, and the QKD base station with a smaller deviation angle from the movement direction is determined as the target base station.

[0112] Please refer to Figure 4 , Figure 4Schematic diagram of QKD base station coverage provided by an embodiment of the present invention. In the figure, BS1 represents QKD base station 1, BS2 represents QKD base station 2, MD1 represents mobile terminal 1, MD3 represents mobile terminal 3, MD4 represents mobile terminal 4, MD 2,1 represents mobile terminal 2 at the previous time point, MD 2,2 represents mobile terminal 2 at the current time point.

[0113] As can be seen from the figure, MD1 is within the coverage area of BS1, and the target base station corresponding to MD1 is BS1. MD4 is within the coverage area of BS2, and the target base station corresponding to MD4 is BS2. MD3 is in the overlapping coverage area of BS1 and BS2 and is in a stationary state, so its corresponding target base station can be BS1 or BS2.

[0114] MD2 (mobile terminal 2) has BS1 as its home base station. After moving (Move), it reaches the coverage area of BS2, and MD2 needs to re - authenticate for access at BS2.

[0115] In an embodiment of the present invention, the framework for key negotiation between a mobile terminal and a QKD base station follows the 4301 standard framework. The overall quantum network architecture is still divided into a quantum layer, a key management layer, a control layer, etc. Both the mobile terminal and the base station are embedded with QKD modules and KM modules.

[0116] The QKDNC of the mobile QKD network is abbreviated as M - QKDNC, which can be deployed at the base station or separately deployed in a fixed computer room. The mobile QKD terminals matched by the base station, and several base stations form a mobile QKD key distribution network, and traditional interfaces such as Kq, Kx, Ck, Qx interfaces are used to implement data forwarding at different layers.

[0117] An embodiment of the present invention also provides a wireless QKD access authentication method, which is applied to a target base station in a communication system and includes: S501, S502, S503, and S504, which are specifically described as follows.

[0118] S501, receive a first - type authentication request sent by a target terminal, and determine whether the target terminal is a home - based device managed by the target base station according to the device ID and home base station identifier therein, where the target terminal is a mobile terminal that has completed QKD home authentication;

[0119] S502, when the target terminal is not a home - based device managed by the target base station and the QKD device type deployed by the target terminal is the same as the QKD device type deployed by the target base station, send a second - type authentication request to the home base station of the target terminal, where the second - type authentication request includes the device ID of the target terminal;

[0120] S503. Receive the ciphertext fed back by the home base station, and decrypt the ciphertext using the quantum key to obtain the device ID, home authentication code, and home HMAC value. Send the home authentication code to the target terminal corresponding to the device ID.

[0121] Among them, the ciphertext is obtained by the home base station encrypting the device ID, home authentication code, and home HMAC value using the quantum key. The home authentication code is the authentication code during the QKD home authentication of the target terminal, and the home HMAC value is the HMAC value during the QKD home authentication of the target terminal.

[0122] S504. Receive the new HMAC value fed back by the target terminal. When the home HMAC value is consistent (or matched) with the new HMAC value, determine that the authentication is successful and allow the target terminal to access the target base station. Among them, the new HMAC value is the HMAC value determined by the target terminal using the injection key, home authentication code, and device ID during the QKD home authentication.

[0123] It should be noted that the target base station can execute the steps completed by the target base station in the above wireless QKD access authentication method applied to the communication system.

[0124] In summary, for a wireless QKD access authentication method and communication system provided by an embodiment of the present invention, when the target terminal is not a home device managed by the target base station and the QKD device types deployed by the target terminal and the target base station are the same, the target base station sends a second type of authentication request to the home base station of the target terminal; decrypt the ciphertext fed back by the home base station using the quantum key to obtain the device ID, home authentication code, and home HMAC value, and send the home authentication code to the target terminal corresponding to the device ID for HMAC verification; when the authentication is successful, allow the target terminal to access the target base station. This solves the problem of wireless QKD access authentication for mobile terminals and ensures that the terminal devices can perform quantum encryption communication continuously and stably during the movement process.

[0125] The above are only the preferred embodiments of the present invention and are not used to limit the present invention. For those skilled in the art, the present invention can have various changes and modifications. Any modification, equivalent replacement, improvement, etc. made within the spirit and principle of the present invention shall be included within the protection scope of the present invention.

[0126] It is obvious to those skilled in the art that the present invention is not limited to the details of the above-mentioned exemplary embodiments, and the present invention can be implemented in other specific forms without departing from the spirit or basic characteristics of the present invention. Therefore, from any point of view, the embodiments should be regarded as exemplary and non-restrictive. The scope of the present invention is defined by the appended claims rather than the above description. Therefore, all changes falling within the meaning and scope of the equivalent elements of the claims are intended to be embraced within the present invention. Any reference signs in the claims should not be construed as limiting the claims involved.

Claims

1. A wireless QKD access authentication method, characterized in that, Applied to a communication system, the communication system includes a mobile terminal equipped with a QKD device and at least two QKD base stations, and the method includes: The target base station receives a first type of authentication request sent by the target terminal, and determines whether the target terminal is a home device managed by the target base station according to the device ID and the home base station identifier therein. Wherein, the target base station is any one of the QKD base stations, and the target terminal is a mobile terminal that has completed QKD home authentication; When the target terminal is not a home device managed by the target base station and the type of QKD device deployed by the target terminal is the same as the type of QKD device deployed by the target base station, the target base station sends a second type of authentication request to the home base station of the target terminal, where the second type of authentication request includes the device ID of the target terminal; The home base station encrypts the device ID, the home authentication code, and the home HMAC value using a quantum key and sends the ciphertext to the target base station; wherein, the home authentication code is the authentication code when the target terminal performs QKD home authentication, and the home HMAC value is the HMAC value when the target terminal performs QKD home authentication; The target base station decrypts the ciphertext using a quantum key to obtain the device ID, the home authentication code, and the home HMAC value, and sends the home authentication code to the target terminal corresponding to the device ID; The target terminal determines a new HMAC value using the injection key, the home authentication code, and the device ID during QKD home authentication, and sends the new HMAC value to the target base station; When the home HMAC value is consistent with the new HMAC value, the target base station determines that the authentication is successful and allows the target terminal to access the target base station.

2. The wireless QKD access authentication method according to claim 1, wherein When the home base station receives the second type of authentication request, the method further includes: The target base station and the home base station perform QKD negotiation to generate a quantum key.

3. The wireless QKD access authentication method according to claim 1, wherein When the target terminal is a home device managed by the target base station, the method further includes: The target base station sends the home authentication code to the target terminal corresponding to the device ID.

4. The wireless QKD access authentication method according to claim 1, wherein When the mobile terminal performs QKD home authentication, the method further includes: The QKD device of the mobile terminal and the QKD device of the base station form a matching relationship through key dispersion; Performing key injection on the base station and the mobile terminal that form a matching relationship; After the key injection is completed, the base station sends an authentication code to the mobile terminal; The mobile terminal determines a first HMAC value using the received authentication code, the injection key, and the device ID, and sends the first HMAC value to the base station; The base station determines a second HMAC value using the authentication code, the injection key, and the device ID; When the first HMAC value is consistent with the second HMAC value, the base station determines that the mobile terminal passes the QKD home authentication.

5. The wireless QKD access authentication method according to claim 1, wherein The method further includes: When the target base station receives a key negotiation request between mobile terminals, it determines whether the peer device is within the coverage area of this station; wherein, the key negotiation request includes the initiator number of the initiating device and the peer number of the peer device; If it is within the coverage area of this station, the target base station sends a key negotiation indication to the peer device; The target base station sends a relay request and a first type of routing information to the QKD management unit to complete the QKD key negotiation between the initiating device and the peer device; Wherein, the first type of routing information is the initiating device -> the target base station -> the peer device.

6. The wireless QKD access authentication method according to claim 5, wherein The method further includes: If it is not within the coverage area of this station, the target base station sends a key negotiation indication to the peer base station; wherein, the peer base station is the QKD base station to which the peer device is currently connected; The target base station sends a relay request and a second type of routing information to the QKD management unit to complete the QKD key negotiation between the initiating device and the peer device; Wherein, the first type of routing information is the initiating device -> the target base station -> the peer base station -> the peer device.

7. The wireless QKD access authentication method according to claim 1, wherein When a QKD base station simultaneously accesses multiple mobile terminals, the QKD base station uses time-division multiplexing to perform wireless communication with the multiple mobile terminals.

8. The wireless QKD access authentication method according to claim 1, wherein The method further includes: The mobile terminal acquires the signal strength and / or signal-to-noise ratio between itself and each QKD base station, and determines its corresponding target base station according to the signal strength and / or signal-to-noise ratio.

9. A wireless QKD access authentication method, characterized in that Applied to the target base station in a communication system, the method includes: Receiving a first type of authentication request sent by a target terminal, and determining whether the target terminal is a home device managed by the target base station according to the device ID and the home base station identifier therein, wherein the target terminal is a mobile terminal that has completed QKD home authentication; In the case that the target terminal is not a home device managed by the target base station and the QKD device type deployed by the target terminal is the same as the QKD device type deployed by the target base station, sending a second type of authentication request to the home base station of the target terminal, wherein the second type of authentication request includes the device ID of the target terminal; Receiving the ciphertext fed back by the home base station, and decrypting the ciphertext using the quantum key to obtain the device ID, the home authentication code, and the home HMAC value, and sending the home authentication code to the target terminal corresponding to the device ID; Wherein, the ciphertext is encrypted by the home base station using the quantum key for the device ID, the home authentication code, and the home HMAC value, the home authentication code is the authentication code when the target terminal performs QKD home authentication, and the home HMAC value is the HMAC value when the target terminal performs QKD home authentication; Receive the new HMAC value fed back by the target terminal. When the home HMAC value is consistent with the new HMAC value after comparison, determine that the authentication is successful and allow the target terminal to access the target base station; wherein, the new HMAC value is the HMAC value determined by the target terminal using the injection key, the home authentication code, and the device ID during QKD home authentication.

10. A communication system, characterized in that, The communication system includes a mobile terminal equipped with a QKD device and at least two QKD base stations; The communication system is used to execute the wireless QKD access authentication method described in any one of claims 1-8.

Citation Information

Patent Citations

  • Authentication method and authentication system

    CN101304365A

  • Switching preparation method, related base station, and UE

    CN108471631A