Group key management system and method based on quantum key distribution and certificate authentication

By adopting a method based on quantum key distribution and credential authentication in the group key management system, the problem of low security in the transmission of user information and key information in the prior art is solved, and higher security and lower information leakage risks are achieved.

CN120128319APending Publication Date: 2025-06-10中电信量子信息科技集团有限公司
View PDF 0 Cites 2 Cited by

Patent Information

Application Number
CN202510184664.6
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-02-19
Publication Date
2025-06-10

AI Technical Summary

Technical Problem

In the management of group keys, the prior art requires the transmission of user information and key information through the network, resulting in greater risk of information leakage and lower security.

Method used

A group key management system based on quantum key distribution and credential authentication is adopted. A group key creation request and key credential creation request are sent to the key management system through the user terminal, a group key and key credential creation request are obtained, and the group messages are encrypted and decrypted through these keys.

Benefits of technology

It reduces the number of times user information is transmitted on the network, reduces the risk of information leakage, and improves the security of the system.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120128319A_ABST
    Figure CN120128319A_ABST
Patent Text Reader

Abstract

The embodiment of the invention provides a group key management system and method based on quantum key distribution and voucher authentication, and the system comprises a first user terminal which is used for transmitting a key voucher creation request to a key management system; receiving a first key certificate which is sent by the key management system and corresponds to the second user terminal; sending the encrypted group message and the first key voucher to a service system; the service system is used for sending the encrypted group message and the first key certificate to at least one second user terminal in the group; each first key certificate corresponds to one second user terminal; the second user terminal is used for sending a group key acquisition request to the belonging key management system, and the group key acquisition request comprises the first key certificate; according to the embodiment of the invention, authority authentication is performed by sending the key certificate, so that the number of times of network transmission of the user information is reduced, and the risk of leakage of the user information is reduced.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the technical field of security applications, and in particular, to a group key management system, method, device, electronic device, and computer-readable storage medium based on quantum key distribution and credential authentication. Background Art

[0002] Quantum key distribution is a quantum information technology for realizing communication security based on quantum mechanics. Its core lies in enabling both parties of communication to generate and share a random and secure key to encrypt and decrypt communication messages, thereby ensuring the security of communication. With the rapid development of quantum communication technology, quantum key distribution systems have become the research focus in the field of information security.

[0003] In the group communication technology based on quantum keys, the key management system usually first obtains the user information of the user terminal and the key information of the group key requested by the user terminal, and then compares the belonging information in the two to determine whether the user terminal and the group key it requests belong to the same group. After determination, the group key is sent to the user terminal so that the user terminal can decrypt the group message ciphertext with the group key to obtain the group message plaintext.

[0004] In the above process, it is necessary to first transmit the user information of the user terminal and the key information of the group key to the key management system, and then separately parse out the belonging information of the user terminal and the group key. Since the user information and key information need to be transmitted through the network every time the group key is obtained, the risk of information leakage is relatively large and the security is relatively low. Summary of the Invention

[0005] In view of the above problems, embodiments of the present invention are proposed to provide a group key management system, method, device, electronic device, and computer-readable storage medium based on quantum key distribution and credential authentication that overcome the above problems or at least partially solve the above problems.

[0006] On the one hand, embodiments of the present invention disclose a group key management system based on quantum key distribution and credential authentication, including: a first user terminal, a second user terminal, a key management system, a service system, and a quantum key distribution network;

[0007] The first user terminal is used to send a group key creation request to the key management system to which it belongs, receive the first key ciphertext sent by the key management system, decrypt the first key ciphertext according to the first padding key to obtain the group key; encrypt the group message according to the group key to obtain the encrypted group message; send a key credential creation request to the key management system; receive the first key credential corresponding to the second user terminal sent by the key management system; and send the encrypted group message and the first key credential to the service system.

[0008] The service system is used to send the encrypted group message and the first key credential to at least one of the second user terminals in the group; each first key credential corresponds to one second user terminal.

[0009] The second user terminal is used to send a group key acquisition request including the first key credential to the key management system to which it belongs after receiving the encrypted group message and the first key credential sent by the service system; receive the second encrypted ciphertext sent by the key management system after completing the credential authentication process; decrypt the second encrypted ciphertext according to the second padding key to obtain the group key; and decrypt the encrypted group message through the group key.

[0010] The key management system is used to, after receiving the group key creation request, call the quantum key distribution network to generate the group key according to the group key creation request, receive the group key sent by the quantum key distribution network, encrypt the group key according to the first padding key to obtain the first key ciphertext, and send the first key ciphertext to the first user terminal; after receiving the key credential creation request, generate at least one first key credential according to the key credential creation request, and send the first key credential to the first user terminal.

[0011] The key management system is further used to, after receiving the group key acquisition request, perform credential authentication processing on the second user terminal according to the first key credential in the group key acquisition request to determine whether the second user terminal has the right to obtain the group key; if it is determined that the second user terminal has the right to obtain the group key, encrypt the group key according to the second padding key to obtain the second encrypted ciphertext, and send the second encrypted ciphertext to the second user terminal.

[0012] Optionally, the first user terminal is configured to select a recipient and obtain recipient identification information, encrypt the recipient identification information using a third charging key to obtain a third key ciphertext; send the key certificate creation request to the key management system, where the key certificate creation request includes a token of the first user terminal, the third key ciphertext, and key identification information of the group key.

[0013] After receiving the key certificate creation request, the key management system is configured to decrypt the third key ciphertext using the third charging key to obtain the recipient identification information; obtain the affiliation information of the first user terminal according to the token of the first user terminal, and obtain the affiliation information of the group key according to the key identification information of the group key; compare whether the affiliation information of the first user terminal is consistent with the affiliation information of the group key; if the affiliation information of the first user terminal is consistent with the affiliation information of the group key, generate the first key certificate according to the key identification information of the group key and the recipient identification information.

[0014] Optionally, the second user terminal is configured to send the group key acquisition request to the key management system, where the group key acquisition request includes a token of the second user terminal, the first key certificate, and key identification information of the group key.

[0015] After receiving the group key acquisition request, the key management system is configured to obtain the user identification information of the second user terminal according to the token of the second user terminal, and obtain the recipient identification information according to the first key certificate; compare whether the user identification information is consistent with the recipient identification information; if the user identification information is consistent with the recipient identification information, generate a second key certificate according to the key identification information of the group key and the user identification information; compare whether the first key certificate is consistent with the second key certificate, and if the first key certificate is consistent with the second key certificate, determine that the second user terminal has the permission to obtain the group key.

[0016] Optionally, the first user terminal is configured to send an identity authentication request to the quantum key management system to obtain a token of the first user terminal sent by the quantum key management system after passing the identity authentication.

[0017] The second user terminal is configured to send an identity authentication request to the quantum key management system to obtain a token of the second user terminal sent by the quantum key management system after passing the identity authentication.

[0018] The key management system is used to receive the identity authentication request sent by the first user terminal; perform identity authentication processing on the first user terminal according to the identity authentication request, and send a token to the first user terminal after the identity authentication processing is passed;

[0019] The key management system is further used to receive the identity authentication request sent by the second user terminal; perform identity authentication processing on the user terminal according to the identity authentication request, and send a token to the second user terminal after the identity authentication processing is passed.

[0020] Optionally, the key management system is used to send first key usage information to the first user terminal, and the first key usage information includes the key block identifier, key block offset, and key length of the first charging key;

[0021] The first user terminal is used to read the first charging key according to the first key usage information.

[0022] Optionally, the key management system is used to send second key usage information to the second user terminal, and the second key usage information includes the key block identifier, key block offset, and key length of the second charging key;

[0023] The second user terminal is used to read the second charging key according to the second key usage information.

[0024] On the other hand, an embodiment of the present invention discloses a group key management method based on quantum key distribution and credential authentication, which is applied to a first user terminal. The method includes:

[0025] Sending a group key creation request to the affiliated key management system, so that the key management system calls a quantum key distribution network to generate a group key according to the group key creation request;

[0026] Receiving the first key ciphertext sent by the key management system, and decrypting the first key ciphertext according to the first charging key to obtain the group key; the first key ciphertext is obtained by the key management system encrypting the group key according to the first charging key after receiving the group key;

[0027] Encrypting the group message according to the group key to obtain the encrypted group message;

[0028] Sending a key credential creation request to the key management system, so that the key management system generates a first key credential corresponding to the second user terminal according to the key credential creation request;

[0029] Receiving the first key credential sent by the key management system;

[0030] Send the encrypted group message and the first key credential to the service system, so that the service system sends the encrypted group message and the first key credential to at least one of the second user terminals in the group.

[0031] Optionally, the method further includes:

[0032] Select a recipient and obtain recipient identification information, and encrypt the recipient identification information using a third charging key to obtain a third key ciphertext;

[0033] Send the key credential creation request to the key management system;

[0034] Wherein, the key credential creation request includes the token of the first user terminal, the third key ciphertext, and the key identification information of the group key, so that the key management system decrypts the third key ciphertext according to the third charging key to obtain the recipient identification information; obtains the affiliation information of the first user terminal according to the token of the first user terminal; obtains the affiliation information of the group key according to the key identification information of the group key, and compares whether the affiliation information of the first user terminal is consistent with the affiliation information of the group key; if the affiliation information of the first user terminal is consistent with the affiliation information of the group key, generate the first key credential according to the key identification information of the group key and the recipient identification information.

[0035] Optionally, the method further includes:

[0036] Send an identity authentication request to the quantum key management system;

[0037] After passing the identity authentication, obtain the token of the first user terminal sent by the quantum key management system.

[0038] On the other hand, an embodiment of the present invention discloses a group key management method based on quantum key distribution and credential authentication, which is applied to a second user terminal. The method includes:

[0039] Receive the group message encrypted by the group key and the first key credential sent by the service system, and each first key credential corresponds to one second user terminal;

[0040] Send a group key acquisition request to the affiliated key management system. The group key acquisition request includes the first key credential, so that the key management system performs credential authentication processing on the second user terminal according to the first key credential to determine whether the second user terminal has the right to acquire the group key;

[0041] Receive the second encrypted ciphertext sent after the key management system completes the voucher authentication process;

[0042] Decrypt the second encrypted ciphertext according to the second charging key to obtain the group key, and decrypt the encrypted group message through the group key.

[0043] Optionally, the group key acquisition request includes the token of the second user terminal, the first key voucher, and the key identification information of the group key; so that after the key management system receives the group key acquisition request, it obtains the user identification information of the second user terminal according to the token of the second user terminal, and obtains the recipient identification information according to the first key voucher; compare whether the user identification information is consistent with the recipient identification information; if the user identification information is consistent with the recipient identification information, generate a second key voucher according to the key identification information of the group key and the user identification information; compare whether the first key voucher is consistent with the second key voucher, and if the first key voucher is consistent with the second key voucher, determine that the second user terminal has the right to obtain the group key.

[0044] Optionally, the method further includes:

[0045] Send an identity authentication request to the quantum key management system;

[0046] After passing the identity authentication, obtain the token of the second user terminal sent by the quantum key management system.

[0047] On the other hand, an embodiment of the present invention discloses a group key management method based on quantum key distribution and voucher authentication, which is applied to a key management system. The method includes:

[0048] After receiving a group key creation request sent by a first user terminal, call a quantum key distribution network to generate a group key according to the group key creation request;

[0049] Receive the group key sent by the quantum key distribution network, and encrypt the group key according to the first charging key to obtain the first key ciphertext;

[0050] Send the first key ciphertext to the first user terminal, so that the first user terminal decrypts the first key ciphertext according to the first charging key to obtain the group key, encrypts the group message according to the group key, and sends the encrypted group message to the service system;

[0051] After receiving the key certificate creation request sent by the first user terminal, generate a first key certificate corresponding to the second user terminal according to the key certificate creation request;

[0052] Send the first key certificate to the first user terminal, so that the first user terminal sends the first key certificate to the service system;

[0053] After receiving the group key acquisition request sent by the second user terminal, perform certificate authentication processing on the second user terminal according to the first key certificate in the group key acquisition request to determine whether the second user terminal has the permission to acquire the group key; the group key acquisition request is sent by the second user terminal to the key management system after receiving the encrypted group message and the first key certificate sent by the service system; the group key acquisition request includes the first key certificate;

[0054] If it is determined that the second user terminal has the permission to acquire the group key, then encrypt the group key with the second injection key to obtain the second encrypted ciphertext, and send the second encrypted ciphertext to the second user terminal, so that the second user terminal decrypts the second encrypted ciphertext according to the second injection key to obtain the group key, and decrypts the encrypted group message with the group key.

[0055] Optionally, the key certificate creation request includes the token of the first user terminal, the third key ciphertext, and the key identification information of the group key; the third key ciphertext is obtained by the first user terminal selecting a recipient and obtaining the recipient identification information, and then encrypting the recipient identification information with a third injection key;

[0056] The method further includes:

[0057] After receiving the key certificate creation request, decrypt the third key ciphertext with the third injection key to obtain the recipient identification information;

[0058] Obtain the affiliated information of the first user terminal according to the token of the first user terminal, and obtain the affiliated information of the group key according to the key identification information of the group key;

[0059] Compare whether the affiliated information of the first user terminal is consistent with the affiliated information of the group key;

[0060] If the affiliated information of the first user terminal is consistent with the affiliated information of the group key, then generate the first key certificate according to the key identification information of the group key and the recipient identification information.

[0061] Optionally, the group key acquisition request includes a token of the second user terminal, the first key credential, and key identification information of the group key;

[0062] The method further includes:

[0063] After receiving the group key acquisition request, obtaining user identification information of the second user terminal according to the token of the second user terminal, and obtaining recipient identification information according to the first key credential;

[0064] Comparing whether the user identification information is consistent with the recipient identification information;

[0065] If the user identification information is consistent with the recipient identification information, generating a second key credential according to the key identification information of the group key and the user identification information; comparing whether the first key credential is consistent with the second key credential, and if the first key credential is consistent with the second key credential, determining that the second user terminal has the right to obtain the group key.

[0066] Optionally, the method further includes:

[0067] Receiving an identity authentication request sent by the first user terminal;

[0068] Performing identity authentication processing on the first user terminal according to the identity authentication request, and sending a token to the first user terminal after the identity authentication processing passes.

[0069] Optionally, the method further includes:

[0070] Receiving an identity authentication request sent by the second user terminal;

[0071] Performing identity authentication processing on the second user terminal according to the identity authentication request, and sending a token to the second user terminal after the identity authentication processing passes.

[0072] On the other hand, an embodiment of the present invention discloses a group key management device based on quantum key distribution and credential authentication, which is applied to a first user terminal. The device includes:

[0073] A first request sending module, configured to send a group key creation request to the affiliated key management system, so that the key management system calls a quantum key distribution network to generate a group key according to the group key creation request;

[0074] The first ciphertext receiving module is used to receive the first key ciphertext sent by the key management system, and decrypt the first key ciphertext according to the first charging key to obtain the group key; the first key ciphertext is obtained by the key management system encrypting the group key according to the first charging key after receiving the group key;

[0075] The message encryption module is used to encrypt the group message according to the group key to obtain the encrypted group message;

[0076] The second request sending module is used to send a key certificate creation request to the key management system, so that the key management system generates a first key certificate corresponding to the second user terminal according to the key certificate creation request;

[0077] The certificate receiving module is used to receive the first key certificate sent by the key management system;

[0078] The message sending module is used to send the encrypted group message and the first key certificate to the service system, so that the service system sends the encrypted group message and the first key certificate to at least one of the second user terminals in the group.

[0079] Optionally, the device further includes:

[0080] The identifier acquisition module is used to select a recipient and acquire recipient identifier information, and encrypt the recipient identifier information with a third charging key to obtain a third key ciphertext;

[0081] The third request sending module is used to send the key certificate creation request to the key management system;

[0082] Wherein, the key certificate creation request includes the token of the first user terminal, the third key ciphertext and the key identifier information of the group key, so that the key management system decrypts the third key ciphertext according to the third charging key to obtain the recipient identifier information; obtains the belonging information of the first user terminal according to the token of the first user terminal; obtains the belonging information of the group key according to the key identifier information of the group key, and compares whether the belonging information of the first user terminal is consistent with the belonging information of the group key; if the belonging information of the first user terminal is consistent with the belonging information of the group key, generates the first key certificate according to the key identifier information of the group key and the recipient identifier information.

[0083] Optionally, the device further includes:

[0084] The fourth request sending module is used to send an identity authentication request to the quantum key management system;

[0085] The first token acquisition module is configured to, after passing the identity authentication, acquire the token of the first user terminal sent by the quantum key management system.

[0086] On the other hand, an embodiment of the present invention discloses a group key management device based on quantum key distribution and credential authentication, which is applied to a second user terminal. The device includes:

[0087] The message receiving module is configured to receive a group message encrypted with a group key and a first key credential sent by a service system, and each first key credential corresponds to one second user terminal;

[0088] The fifth request sending module is configured to send a group key acquisition request to the affiliated key management system, and the group key acquisition request includes a first key credential, so that the key management system performs credential authentication processing on the second user terminal according to the first key credential to determine whether the second user terminal has the right to acquire the group key;

[0089] The ciphertext receiving module is configured to receive a second encrypted ciphertext sent by the key management system after completing the credential authentication processing;

[0090] The message decryption module is configured to decrypt the second encrypted ciphertext according to a second charging key to obtain the group key, and decrypt the encrypted group message with the group key.

[0091] Optionally, the device further includes:

[0092] The sixth request sending module is configured to send an identity authentication request to the quantum key management system;

[0093] The second token acquisition module is configured to, after passing the identity authentication, acquire the token of the second user terminal sent by the quantum key management system.

[0094] On the other hand, an embodiment of the present invention discloses a group key management device based on quantum key distribution and credential authentication, which is applied to a key management system. The device includes:

[0095] The first request receiving module is configured to, after receiving a group key creation request sent by a first user terminal, call a quantum key distribution network to generate a group key according to the group key creation request;

[0096] The key receiving module is configured to receive the group key sent by the quantum key distribution network, and encrypt the group key according to the first charging key to obtain a first key ciphertext;

[0097] The first ciphertext sending module is used to send the first key ciphertext to the first user terminal, so that the first user terminal decrypts the first key ciphertext according to the first charging key to obtain the group key, encrypts the group message according to the group key, and sends the encrypted group message to the service system;

[0098] The second request receiving module is used to generate a first key certificate corresponding to the second user terminal according to the key certificate creation request after receiving the key certificate creation request sent by the first user terminal;

[0099] The certificate sending module is used to send the first key certificate to the first user terminal, so that the first user terminal sends the first key certificate to the service system;

[0100] The first certificate authentication module is used to perform certificate authentication processing on the second user terminal according to the first key certificate in the group key acquisition request after receiving the group key acquisition request sent by the second user terminal, so as to determine whether the second user terminal has the right to obtain the group key; the group key acquisition request is sent by the second user terminal to the key management system after receiving the encrypted group message and the first key certificate sent by the service system; the group key acquisition request includes the first key certificate;

[0101] The second ciphertext sending module is used to, if it is determined that the second user terminal has the right to obtain the group key, encrypt the group key according to the second charging key to obtain the second encrypted ciphertext, and send the second encrypted ciphertext to the second user terminal, so that the second user terminal decrypts the second encrypted ciphertext according to the second charging key to obtain the group key, and decrypts the encrypted group message through the group key.

[0102] Optionally, the key certificate creation request includes the token of the first user terminal, the third key ciphertext, and the key identification information of the group key; the third key ciphertext is obtained by encrypting the recipient identification information with a third charging key after the first user terminal selects a recipient and obtains the recipient identification information;

[0103] The device further includes:

[0104] The ciphertext decryption module is used to decrypt the third key ciphertext according to the third charging key to obtain the recipient identification information after receiving the key certificate creation request;

[0105] An information acquisition module, configured to obtain the information to which the first user terminal belongs according to the token of the first user terminal, and obtain the information to which the group key belongs according to the key identification information of the group key;

[0106] A first comparison module, configured to compare whether the information to which the first user terminal belongs is consistent with the information to which the group key belongs;

[0107] A credential generation module, configured to, if the information to which the first user terminal belongs is consistent with the information to which the group key belongs, generate the first key credential according to the key identification information of the group key and the recipient identification information.

[0108] Optionally, the group key acquisition request includes the token of the second user terminal, the first key credential, and the key identification information of the group key;

[0109] The apparatus further includes:

[0110] A third request receiving module, configured to, after receiving the group key acquisition request, obtain the user identification information of the second user terminal according to the token of the second user terminal, and obtain the recipient identification information according to the first key credential;

[0111] A second comparison module, configured to compare whether the user identification information is consistent with the recipient identification information;

[0112] A second credential authentication module, configured to, if the user identification information is consistent with the recipient identification information, generate a second key credential according to the key identification information of the group key and the user identification information; compare whether the first key credential is consistent with the second key credential, and if the first key credential is consistent with the second key credential, determine that the second user terminal has the permission to obtain the group key.

[0113] Optionally, the apparatus further includes:

[0114] A fourth request receiving module, configured to receive an identity authentication request sent by the first user terminal;

[0115] A first token sending module, configured to perform identity authentication processing on the first user terminal according to the identity authentication request, and send a token to the first user terminal after the identity authentication processing passes.

[0116] Optionally, the apparatus further includes:

[0117] A fifth request receiving module, configured to receive an identity authentication request sent by the second user terminal;

[0118] A second token sending module, configured to perform identity authentication processing on the second user terminal according to the identity authentication request, and send a token to the second user terminal after the identity authentication processing is passed.

[0119] On the other hand, an embodiment of the present invention discloses an electronic device, including: a processor, a memory, and a computer program stored on the memory and capable of running on the processor. When the computer program is executed by the processor, the steps of the group key management method based on quantum key distribution and credential authentication as described above are implemented.

[0120] On the other hand, an embodiment of the present invention discloses a computer-readable storage medium, on which a computer program is stored. When the computer program is executed by a processor, the steps of the group key management method based on quantum key distribution and credential authentication as described above are implemented.

[0121] The embodiments of the present invention have the following advantages:

[0122] Before sending a group message, the user terminal sends a group key creation request to the key management system to obtain a group key; the group message is encrypted by the group key and then sent to other user terminals. After receiving the group message, the other user terminals send a group key creation request to the key management system to obtain a group key and decrypt the encrypted group message. In group communication, encrypting the group message with the group key reduces the possibility of group message leakage and improves the security of the system.

[0123] At the same time, the user terminal that sends the group message also sends a key credential creation request to the key management system to obtain a key credential, and each key credential corresponds to a user terminal that receives the group message. After receiving the key credential, the user terminal sends the key credential to the key management system, and the key management system verifies the key credential to determine whether the user terminal has the permission to obtain the group key. By performing permission identification through the key credential, it is not necessary to send the user information of the user terminal, reducing the number of times of network transmission of the user information, thereby reducing the risk of user information leakage. BRIEF DESCRIPTION OF THE DRAWINGS

[0124] In order to more clearly illustrate the technical solutions of the embodiments of the present invention, the drawings required to be used in the description of the embodiments of the present invention will be briefly introduced below. Obviously, the drawings in the following description are only some embodiments of the present invention, and those of ordinary skill in the art can also obtain other drawings without creative efforts based on these drawings.

[0125] Figure 1It is a schematic structural diagram of a group key management system based on quantum key distribution and credential authentication provided by an embodiment of the present invention;

[0126] Figure 2 It is a flowchart of steps of a group key management method based on quantum key distribution and credential authentication provided by an embodiment of the present invention;

[0127] Figure 3 It is a flowchart of steps of another group key management method based on quantum key distribution and credential authentication provided by an embodiment of the present invention;

[0128] Figure 4 It is a flowchart of steps of another group key management method based on quantum key distribution and credential authentication provided by an embodiment of the present invention;

[0129] Figure 5 It is a flowchart of steps of another group key management method based on quantum key distribution and credential authentication provided by an embodiment of the present invention;

[0130] Figure 6 It is a schematic diagram of a group key management device based on quantum key distribution and credential authentication provided by an embodiment of the present invention;

[0131] Figure 7 It is a schematic diagram of another group key management device based on quantum key distribution and reverse authentication provided by an embodiment of the present invention;

[0132] Figure 8 It is a schematic diagram of another group key management device based on quantum key distribution and credential authentication provided by an embodiment of the present invention. Detailed implementation manners

[0133] To make the above objects, features, and advantages of the present invention more obvious and understandable, the present invention will be further described in detail below with reference to the accompanying drawings and specific implementation manners. Obviously, the described embodiments are part of the embodiments of the present invention, rather than all of the embodiments. All other embodiments obtained by those of ordinary skill in the art based on the embodiments of the present invention without creative efforts shall fall within the protection scope of the present invention.

[0134] In the related art, a key management system usually first obtains the user information of a user terminal and the key information of the group key requested by the user terminal, and then compares the belonging information in the two to determine whether the user terminal and the group key it requests belong to the same group. After determination, the group key is sent to the user terminal so that the user terminal can decrypt the group message ciphertext with the group key to obtain the group message plaintext. In the above process, it is necessary to first transmit the user information of the user terminal and the key information of the group key to the key management system, and then separately parse the belonging information of the user terminal and the group key. Since the user information and the key information need to be transmitted through the network every time a group key is obtained, the risk of information leakage is relatively high and the security is relatively low.

[0135] In an embodiment of the present invention, the user terminal that sends a group message sends a request to the key management system to obtain a key certificate, and each key certificate corresponds to a user terminal that receives the group message. The user terminal that receives the group message receives the key certificate and sends it to the key management system, and the key management system verifies the key certificate to determine whether the user terminal has the right to obtain the group key. By performing permission identification through the key certificate, the number of times of network transmission of user information is reduced, thereby reducing the risk of user information leakage.

[0136] The present invention provides a group key management system based on quantum key distribution and credential authentication, which includes a first user terminal, a second user terminal, a key management system, a service system, and a quantum key distribution network.

[0137] In the group key management system, the user terminal can be an electronic device such as a mobile phone, a computer, or a tablet, and the user uses the user terminal to send or receive group messages. The user terminal is built-in or externally connected with a quantum security chip.

[0138] A quantum security chip is a chip integrated with quantum security technology and is used to store quantum keys. Usually, the quantum keys stored in each quantum security chip and the quantum keys stored in the key management system are symmetric keys.

[0139] In the present invention, only to distinguish the sender and the receiver of the group message, the user terminal that sends the group message is called the first user terminal, and the user terminal that receives the group message is called the second user terminal. In practical applications, each user terminal can be used to send and receive group messages.

[0140] In the group key management system, the key management system can provide functions of encrypting and distributing quantum keys and authenticating the identity of user terminals.

[0141] In a group key management system, a quantum key distribution network refers to a network composed of multiple quantum key distribution nodes connected by quantum key distribution links. In the quantum key distribution network, two communicating parties can generate and share a random and secure key for encrypting and decrypting messages. This key distribution method is a secure communication protocol based on the principles of quantum mechanics. It utilizes the quantum no-cloning theorem and the uncertainty of quantum measurement to ensure that the generated key cannot be stolen or copied during transmission. This feature makes it a theoretically unbreakable key distribution method.

[0142] The business system can receive group messages sent by group members and forward them to other group members. In practical applications, the business system can be an existing message receiving and sending platform, such as WeChat, DingTalk, and Feishu, etc., or it can be other message receiving and sending business systems independently developed according to the group key management system. The present invention places no restrictions on this.

[0143] The group key is used to encrypt group messages in group communication. The receiving party user needs to obtain the group key to decrypt the encrypted group messages in order to view the group messages. The application of the group key ensures the security of internal group communication. The user terminal encrypts the group messages to be sent using the group key, making the encrypted group messages unreadable during transmission. Only the receiver with the same group key can decrypt and read them, that is, only group members can view the content of group messages, preventing information leakage to unauthorized third parties and effectively improving the security of group messages.

[0144] Figure 1 It is a schematic structural diagram of a group key management system based on quantum key distribution and credential authentication provided by an embodiment of the present invention.

[0145] The present invention provides a group key management system based on quantum key distribution and credential authentication, as Figure 1 shown, the system includes: a first user terminal 10, a second user terminal 20, a key management system 30, a business system 40, and a quantum key distribution network 50.

[0146] The first user terminal 10 is used to send a group key creation request to the affiliated key management system 30, receive the first key ciphertext sent by the key management system 30, decrypt the first key ciphertext according to the first injection key to obtain the group key; encrypt the group messages according to the group key to obtain encrypted group messages; send a key credential creation request to the key management system 30; receive the first key credential corresponding to the second user terminal sent by the key management system 30; send the encrypted group messages and the first key credential to the business system 40;

[0147] A service system 40 for sending encrypted group messages and first key vouchers to at least one second user terminal 20 in a group; each first key voucher corresponds to a second user terminal 20;

[0148] The second user terminal 20 is configured to send a group key acquisition request including the first key voucher to the affiliated key management system 30 after receiving the encrypted group message and the first key voucher sent by the service system 40; after receiving the second encrypted ciphertext sent by the key management system 30 after completing the voucher authentication process, decrypt the second encrypted ciphertext according to the second filling key to obtain the group key; decrypt the encrypted group message with the group key;

[0149] The key management system 30 is configured to, after receiving a group key creation request, call the quantum key distribution network 50 to generate a group key according to the group key creation request, receive the group key sent by the quantum key distribution network 50, and encrypt the group key with the first filling key to obtain a first key ciphertext, and send the first key ciphertext to the first user terminal 10; after receiving a key voucher creation request, generate at least one first key voucher according to the key voucher creation request, and send the first key voucher to the first user terminal 10;

[0150] The key management system 30 is further configured to, after receiving a group key acquisition request, perform voucher authentication processing on the second user terminal 20 according to the first key voucher in the group key acquisition request to determine whether the second user terminal 20 has the permission to acquire the group key; if it is determined that the second user terminal 20 has the permission to acquire the group key, encrypt the group key with the second filling key to obtain a second encrypted ciphertext, and send the second encrypted ciphertext to the second user terminal 20.

[0151] In an embodiment of the present invention, before sending a group message, a user terminal sends a group key creation request to the key management system to obtain a group key; the group message is encrypted with the group key and then sent to other user terminals. After receiving it, the other user terminals send a group key creation request to the key management system to obtain the group key and decrypt the encrypted group message. In group communication, encrypting the group message with the group key reduces the possibility of group message leakage and improves the security of the system.

[0152] Meanwhile, the user terminal that sends the group message also sends a key certificate creation request to the key management system to obtain a key certificate, and each key certificate corresponds to a user terminal that receives the group message. After receiving the key certificate, the user terminal sends the key certificate to the key management system, and the key management system verifies the key certificate to determine whether the user terminal has the permission to obtain the group key. By authenticating the permission through the key certificate, there is no need to send the user information of the user terminal, reducing the number of times the user information is transmitted over the network, thereby reducing the risk of user information leakage.

[0153] Figure 2 FIG. is a flowchart of the steps of a group key management method based on quantum key distribution and certificate authentication provided by an embodiment of the present invention.

[0154] Combined with Figure 1 、 Figure 2 As shown, the first user terminal is used to send a group key creation request to the affiliated key management system; the key management system is used to, after receiving the group key creation request, call the quantum key distribution network to generate a group key according to the group key creation request;

[0155] In the group key management system, there are multiple key management systems, and one key management system can manage multiple user terminals. As Figure 2 shown, the first user terminal and the second user terminal belong to the same key management system. In other embodiments, the first user terminal and the second user terminal can belong to different key management systems respectively, and the present invention does not limit this.

[0156] When the first user terminal needs to send a group message, it will first send a group key acquisition request to its affiliated key management system to obtain the group key, and the group message needs to be encrypted with the group key before it can be sent.

[0157] When the key management system receives the group key creation request, it will call the quantum key distribution network to generate the group key. After the quantum key distribution network generates the group key, it sends the group key to the key management system.

[0158] In this embodiment, whenever a user terminal needs to send a group message, it will request a group key once to enhance the security within the group. That is, the group key is updated every time a group message is sent. In other embodiments, other frequencies can also be adopted to update the group key, and the present invention does not limit this.

[0159] The key management system regularly updates the group key, which can further enhance the security and reduce the risk of the group key being cracked.

[0160] In some embodiments, a key management system is configured to receive a group key sent by a quantum key distribution network, encrypt the group key with a first filling key to obtain a first key ciphertext, and send the first key ciphertext to a first user terminal; the first user terminal is configured to receive the first key ciphertext sent by the key management system and decrypt the first key ciphertext with the first filling key to obtain the group key;

[0161] The first key ciphertext is obtained by encrypting the group key with the first filling key, so that the group key exists in the form of the first key ciphertext during transmission and is not easily directly obtained by an interceptor.

[0162] In addition, the key management system and the user terminal share the first filling key, and the filling key is securely filled into the quantum security chip and the quantum key management system by a quantum key filling module with a quantum key generated by quantum key distribution (QKD), so that the same filling key is securely stored in the user terminal and its affiliated key management system.

[0163] When the first user terminal receives the first key ciphertext, it also receives relevant information of the first filling key. Therefore, the first user terminal can query the first filling key according to the relevant information of the first filling key, and then decrypt the first key ciphertext with the first filling key to obtain the group key.

[0164] In some embodiments, the first user terminal is configured to encrypt a group message with the group key to obtain an encrypted group message;

[0165] Specifically, when the first user terminal receives the first key ciphertext, it also receives a key digest value of the group key. After decrypting to obtain the group key, the first user terminal recalculates the key digest value and compares it with the received key digest value to verify the integrity and authenticity of the group key. If the two are consistent, the verification passes. After the verification passes, the key handle of the group key is thrown to the service application layer.

[0166] A key handle is an identifier of a key, used to reference the key in a security module without directly exposing the key at the application layer.

[0167] The service application layer uses the key handle of the group key, a specified cryptographic algorithm, an initialization vector, an operation mode, etc., to call the quantum security chip to perform an encryption operation on the group message, and finally obtains the encrypted group message.

[0168] In some embodiments, the first user terminal is used to send a key credential creation request to the key management system; the key management system is used to generate at least one first key credential according to the key credential creation request after receiving the key credential creation request, and send the first key credential to the first user terminal;

[0169] Specifically, the key credential creation request contains relevant information of the first key credential. After receiving the key credential creation request, the key management system parses it to obtain the relevant information of the first key credential for subsequent first key credential generation operations.

[0170] The first key credential generated by the key management system is sent to the second user terminal that receives the group message for the second user terminal to verify its identity and obtain the group key.

[0171] In some embodiments, the first user terminal is used to receive the first key credential corresponding to the second user terminal sent by the key management system; send the encrypted group message and the first key credential to the service system; the service system is used to send the encrypted group message and the first key credential to at least one second user terminal in the group; each first key credential corresponds to a second user terminal;

[0172] The key management system generates a corresponding first key credential for each second user terminal that receives the group message. After receiving these first key credentials, the first user terminal sends them together with the encrypted group message to the service system.

[0173] After receiving the first key credential and the encrypted group message, the service system parses each first key credential to obtain the user information of the second user terminal corresponding to each first key credential, and according to the user information, sends the corresponding first key credential and the encrypted group message to the corresponding second user terminal.

[0174] In some embodiments, the first user terminal also sends the key identification information of the group key used for the encrypted group message to the service system. The key identification information of the group key is generated by the first user terminal after obtaining the group key. After receiving the key identification information of the group key, the service system sends it to the second user terminal, and after receiving it, the second user terminal sends it to the key management system so that the key management system can find the group key requested by the second user terminal according to the key identification information of the group key.

[0175] In some embodiments, the second user terminal is used to send a group key acquisition request including the first key credential to the key management system to which it belongs after receiving the encrypted group message and the first key credential sent by the service system;

[0176] The key management system is used to, after receiving a group key acquisition request, perform credential authentication processing on a second user terminal according to the first key credential in the group key acquisition request to determine whether the second user terminal has the permission to acquire the group key;

[0177] The group key acquisition request includes a first key credential. After the key management system receives the group key acquisition request, it parses the request to obtain the first key credential. The key management system verifies the identity of the second user terminal through the first key credential, thereby determining whether the second user terminal has the permission to acquire the group key.

[0178] In some embodiments, the key management system is used to, if it determines that the second user terminal has the permission to acquire the group key, encrypt the group key according to the second injection key to obtain a second encrypted ciphertext, and send the second encrypted ciphertext to the second user terminal;

[0179] The second user terminal is used to receive the second encrypted ciphertext sent by the key management system after completing the credential authentication processing; decrypt the second encrypted ciphertext according to the second injection key to obtain the group key; decrypt the encrypted group message through the group key;

[0180] Specifically, similar to the first user terminal decrypting the first key ciphertext, when the key management system sends the second key ciphertext to the second user terminal, it will also send the relevant information of the second injection key to the second user terminal, so that the second user terminal can, according to the received relevant information of the second injection key, find the second injection key in the stored injection keys, thereby decrypting the second key ciphertext through the second injection key to obtain the group key.

[0181] After the second user terminal obtains the group key, it decrypts the encrypted group message according to the group key to obtain the group message plaintext, so as to be able to read the content of the group message sent by the first user terminal.

[0182] In some embodiments, the first user terminal is used to select a recipient and obtain recipient identification information, and encrypt the recipient identification information using a third injection key to obtain a third key ciphertext;

[0183] The first user terminal selects the recipient of the group information and obtains the recipient identification information to send the recipient identification information to the key management system for generating a key credential.

[0184] Specifically, the user can select the recipient according to the contact list stored in the first user terminal or the recipient list provided by the business system service provider. After the recipient selection is completed, the recipient identification information of the selected recipient is obtained through the contact information stored in the first user terminal or the recipient information provided by the business system service provider.

[0185] In some embodiments, the first user terminal is used to send a key credential creation request to the key management system. The key credential creation request includes the token of the first user terminal, the third key ciphertext, and the key identification information of the group key.

[0186] After receiving the key credential creation request, the key management system decrypts the third key ciphertext according to the third charging key to obtain the recipient identification information; obtains the belonging information of the first user terminal according to the token of the first user terminal, and obtains the belonging information of the group key according to the key identification information of the group key; compares whether the belonging information of the first user terminal is consistent with the belonging information of the group key; if the belonging information of the first user terminal is consistent with the belonging information of the group key, generates a first key credential according to the key identification information of the group key and the recipient identification information.

[0187] It should be noted that the key identification information of the group key is sent by the first user terminal to the service system. After receiving it, the service system sends it to the second user terminal. After receiving it, the second user terminal uses it to generate a key credential creation request. So that after receiving the key credential creation request, the key management system can obtain the key identification information of the group key, and find the group key requested by the second user terminal according to the key identification information of the group key.

[0188] Specifically, the key management system obtains the belonging information of the first user terminal according to the token of the first user terminal, and obtains the belonging information of the group key according to the key identification information of the group key. By comparing the belonging information of the first user terminal and the belonging information of the group key, it is judged whether the belonging medium of the group key is consistent with the access medium of the token of the first user terminal, and whether their belonging application information and belonging group information are consistent. If all are consistent, the verification passes, and the key management system uses the group key to operate on the recipient identification information to obtain the first key credential of the second user terminal corresponding to the recipient identification information.

[0189] Among them, the recipient identification information is obtained by the key management system decrypting the third key ciphertext according to the third charging key after receiving the key credential creation request.

[0190] The first user terminal and the key management system store the same charging key. When the first user terminal sends the third key ciphertext to the key management system, it also sends the key usage information of the third charging key to the key management system. The key usage information includes information such as the key identification, key offset, and key length of the third charging key. So that the key management system can find the third charging key in the charging keys securely stored by it according to the received key usage information, and thus decrypt the third key ciphertext with the third charging key to obtain the recipient identification information.

[0191] In some embodiments, the second user terminal is configured to send a group key acquisition request to the key management system. The group key acquisition request includes a token of the second user terminal, a first key credential, and key identification information of the group key.

[0192] After receiving the group key acquisition request, the key management system is configured to obtain user identification information of the second user terminal based on the token of the second user terminal, and obtain recipient identification information based on the first key credential; compare whether the user identification information is consistent with the recipient identification information; if the user identification information is consistent with the recipient identification information, generate a second key credential based on the key identification information of the group key and the user identification information; compare whether the first key credential is consistent with the second key credential, and if the first key credential is consistent with the second key credential, determine that the second user terminal has the right to acquire the group key.

[0193] Specifically, the key management system parses the token of the second user terminal to obtain the user identification information of the second user terminal. The first key credential is parsed to obtain the recipient identification information in the first key credential. The user identification information of the second user terminal is compared with the recipient identification information in the first key credential. If the two are consistent, it is determined that the second user terminal and the recipient in the first key credential are the same user.

[0194] After determining that the second user terminal is the recipient in the first key credential, the group key is obtained according to the key identification information of the group key in the group key acquisition request.

[0195] Specifically, when sending the group key acquisition request to the key management system, the second user terminal also sends key information of the group key to the key management system. The key information includes information such as a key identification block, a key offset, and a key length of the group key. This enables the key management system to search for group key record information based on the received key information, thereby obtaining the group key requested by the second user terminal.

[0196] After obtaining the group key requested by the second user terminal, the user identification information is calculated using the group key requested by the second user terminal to obtain a second key credential. Compare whether the credential value of the second key credential is the same as the credential value of the first key credential sent by the second user terminal. If the credential value of the second key credential is the same as the credential value of the first key credential sent by the second user terminal, it is determined that the second user terminal has the right to acquire the group key.

[0197] It should be noted that the operation methods used to generate the first key certificate and the second key certificate are the same operation methods pre-specified by the group key system. In this embodiment, the hash-based message authentication code (HMAC) operation related to the key is adopted. In other embodiments, other operation methods may be adopted, and the present invention does not limit this.

[0198] In some embodiments, the first user terminal is used to send an identity authentication request to the quantum key management system, so as to obtain the token of the first user terminal sent by the quantum key management system after passing the identity authentication.

[0199] The key management system is used to receive the identity authentication request sent by the first user terminal; perform identity authentication processing on the first user terminal according to the identity authentication request, and send a token to the first user terminal after the identity authentication processing passes.

[0200] In order to securely access and use the key management system, the user terminal needs to perform identity authentication first to ensure that the user has the access right to obtain the key management system and the acquisition right to the corresponding resources.

[0201] The identity authentication request sent by the user terminal to the key management system contains information such as the terminal device identifier and the quantum security chip identifier. These information are packaged and encrypted to prevent being intercepted or tampered with during the transmission process. In other embodiments, the identity authentication request may also contain other identity information, and the present invention does not limit this.

[0202] After receiving the identity authentication request, the key management system will perform a series of identity authentication processing procedures to strictly verify the accuracy and validity of the identity information sent by the user terminal to ensure the correct user identity. After the user's identity information passes the identity authentication, the key management system generates a unique token and sends it to the user terminal.

[0203] The token is a security credential that represents the user's identity and access rights. The user can save the token and use it in subsequent interactions with the key management system to prove their identity and permissions for operations such as obtaining and storing keys. This identity authentication mechanism not only improves the security of the system but also provides a convenient and efficient key management service for users.

[0204] The key certificate creation request sent by the first user terminal includes the above-mentioned token of the first user terminal, enabling the key management system to identify the user information of the first user terminal to verify its identity. Thus, while ensuring the communication security of the key management system, it can quickly identify the identity of the first user terminal and complete the corresponding instruction actions in the key certificate creation request.

[0205] In some embodiments, the second user terminal is used to send an identity authentication request to the quantum key management system, so as to obtain a token of the second user terminal sent by the quantum key management system after passing the identity authentication;

[0206] The key management system is used to receive the identity authentication request sent by the second user terminal; perform identity authentication processing on the user terminal according to the identity authentication request, and send a token to the second user terminal after the identity authentication processing passes.

[0207] Similar to the identity authentication process between the above-mentioned first user terminal and the key management system, it will not be elaborated here. After obtaining the token, the second user terminal sends a group key acquisition request to the key management system. The group key acquisition request includes the token of the second user terminal, which can ensure the communication security of the key management system while quickly identifying the identity of the second user terminal to complete the corresponding instruction actions in the group key acquisition request.

[0208] In some embodiments, the key management system is used to send first key usage information to the first user terminal. The first key usage information includes the key block identifier, key block offset, and key length of the first filling key; the first user terminal is used to read the first filling key according to the first key usage information.

[0209] When the key management system sends the first key ciphertext to the first user terminal, it will also send the first key usage information to the first user terminal. The first key usage information includes information such as the key block identifier, key block offset, and key length of the first filling key. This enables the first user terminal to find the first filling key in the filling keys securely stored by it according to the received first key usage information, and thus decrypt the first key ciphertext with the first filling key to obtain the group key.

[0210] Among them, the corresponding key can be accurately found in the key record of the key management system through the key block identifier, key block offset, and key length.

[0211] The key block identifier is the unique identifier of the key, ensuring that the key corresponding to the key block identifier can be accurately distinguished and quickly found among multiple keys when needed. The key block offset refers to the value for adjusting the key during the encryption process. It is usually used to increase the complexity and security of the encryption algorithm. By introducing the offset, the same plaintext can generate different ciphertexts in different encryption processes, thus increasing the difficulty of cracking. The key length refers to the number of bits or bytes contained in the key. In cryptography, the key length directly affects the security of the encryption algorithm. A longer key can provide higher security because the difficulty of brute-force cracking increases significantly with the increase of the key length.

[0212] In some embodiments, the key management system is used to send second key usage information to the second user terminal. The second key usage information includes the key block identifier, key block offset, and key length of the second charging key. The second user terminal is used to read the second charging key according to the second key usage information.

[0213] Similar to the first user terminal decrypting the first key ciphertext, when the key management system sends the second key ciphertext to the second user terminal, it will also send the second key usage information to the second user terminal. The second key usage information includes information such as the key block identifier, key block offset, and key length of the second charging key. This enables the second user terminal to find the second charging key in the charging keys securely stored by it according to the received second key usage information, and thus decrypt the second key ciphertext through the second charging key to obtain the group key.

[0214] Figure 3 It is a flowchart of the steps of another group key management method provided by an embodiment of the present invention based on quantum key distribution and credential authentication.

[0215] As Figure 3 shown, a group key management method provided by an embodiment of the present invention, which is applied to the first user terminal, may specifically include the following steps:

[0216] Step 101: Send a group key creation request to the affiliated key management system, so that the key management system calls the quantum key distribution network to generate a group key according to the group key creation request.

[0217] In the group key management system, there are multiple key management systems, and one key management system can manage multiple user terminals. As Figure 2 shown, the first user terminal and the second user terminal belong to the same key management system. In other embodiments, the first user terminal and the second user terminal may belong to different key management systems respectively, and the present invention does not limit this.

[0218] When the first user terminal needs to send a group message, it will first send a group key acquisition request to its affiliated key management system to obtain the group key. The group message needs to be encrypted with the group key before being sent.

[0219] In some embodiments, before step 101, the method further includes:

[0220] Send an identity authentication request to the quantum key management system;

[0221] After passing the identity authentication, obtain the token of the first user terminal sent by the quantum key management system.

[0222] As an example, the identity authentication process includes:

[0223] 1) Securely charge and store the same charging key in the user terminal and its affiliated key management system;

[0224] 2) The user terminal constructs network access identity identification information based on information such as the terminal device identification and the quantum security chip identification, selects the key Km in the quantum security chip to encrypt the network access identity identification information, and sends it to the affiliated key management system;

[0225] 3) The key management system reads the key Km according to the information sent by the user terminal, decrypts and verifies the received information; after the verification passes, the quantum key management system selects a new key Kn and simultaneously generates verification data A, encrypts the verification data A with Kn, and sends the selected key Kn information and the ciphertext of the verification data A to the user terminal;

[0226] 4) The user terminal reads the key Kn according to the information sent by the key management system and decrypts it, so as to verify the verification data A returned by the key management system; after the verification passes, the terminal device generates verification data B, encrypts the verification data A and the verification data B with the key Kn to obtain verification data C, and sends the network access identity information and the verification data C to the key management system;

[0227] 5) The key management system verifies the received verification data C with the key Kn, generates a token after the verification passes, encrypts the verification data A and the verification data B with the key Kn to obtain verification data D, generates a token integrity verification value with the key Kn according to the token, and sends the token, the verification data D and the token integrity verification value to the user terminal;

[0228] 6) The user terminal verifies the received verification data D and the token integrity verification value with the key Kn, and saves the token after the verification passes.

[0229] In the above process, the key management system binds the terminal device identification of the user terminal with the chip identification of the quantum security chip by storing the network access identification information of the user terminal, so as to determine the unique user identification and complete the identity authentication.

[0230] The verification data is used for the user terminal or the key management system to confirm the identity of the sender when receiving a message, and to confirm whether the information is complete and has been tampered with during the sending process.

[0231] After receiving the identity authentication request, the key management system will perform a series of identity authentication processing procedures, strictly verify the accuracy and validity of the identity information sent by the user terminal, and ensure the correct user identity. After the user's identity information passes the identity authentication, the key management system generates a unique token and sends it to the user terminal.

[0232] The user proves their identity and permissions in subsequent interactions with the key management system by saving the token to perform operations such as obtaining and storing keys. This identity authentication mechanism not only improves the security of the system but also provides users with convenient and efficient key management services.

[0233] The key credential creation request sent by the first user terminal to the key management system includes the token of the first user terminal, thus ensuring the communication security of the key management system while being able to quickly identify the identity of the first user terminal and complete the corresponding instruction actions in the key credential creation request.

[0234] Step 102: Receive the first key ciphertext sent by the key management system and decrypt the first key ciphertext according to the first filling key to obtain the group key; the first key ciphertext is obtained by the key management system encrypting the group key according to the first filling key after receiving the group key;

[0235] Among them, the first key ciphertext is obtained by the key management system encrypting the group key according to the first filling key after receiving the group key. This makes the group key exist in the form of the first key ciphertext during transmission, and it is not easy for interceptors to directly obtain the group key.

[0236] It should be noted that the key management system and the first user terminal share the first filling key. The filling key is securely filled into the quantum security chip and the quantum key management system by the quantum key filling module distributing the quantum key generated by the quantum key, so that the same filling key is securely stored in the user terminal and its affiliated key management system.

[0237] When the first user terminal receives the first key ciphertext, it will also receive the relevant information of the first filling key. Therefore, the first user terminal can query and obtain the first filling key according to the relevant information of the first filling key, and then decrypt the first key ciphertext according to the first filling key to obtain the group key.

[0238] Step 103: Encrypt the group message according to the group key to obtain the encrypted group message;

[0239] Specifically, when the first user terminal receives the first key ciphertext, it will also receive the key digest value of the group key. After the first user terminal decrypts to obtain the group key, it recalculates the key digest value and compares it with the received key digest value to verify the integrity and authenticity of the group key. If the two are consistent, the verification passes. After the verification passes, the key handle of the group key is thrown to the service application layer.

[0240] A key handle is an identifier of a key used to reference the key in a security module without directly exposing the key at the application layer.

[0241] The business application layer uses the key handle of the group key, the specified cryptographic algorithm, the initialization vector, the operation mode, etc., to call the quantum security chip to encrypt the group message, and finally obtains the encrypted group message.

[0242] Step 104: Send a key credential creation request to the key management system, so that the key management system generates a first key credential corresponding to the second user terminal according to the key credential creation request;

[0243] Specifically, the key credential creation request contains the relevant information of the first key credential. After receiving the key credential creation request, the key management system parses it to obtain the relevant information of the first key credential for subsequent generation operations of the first key credential.

[0244] The first key credential generated by the key management system will be sent to the second user terminal that receives the group message for the second user terminal to verify its identity and obtain the group key.

[0245] In some embodiments, the method further includes:

[0246] Select a recipient and obtain the recipient identification information, and encrypt the recipient identification information using a third charging key to obtain a third key ciphertext;

[0247] The first user terminal selects the recipient of the group information and obtains the recipient identification information to send the recipient identification information to the key management system for generating a key credential.

[0248] Specifically, the user can select the recipient according to the contact list stored in the first user terminal or the recipient list provided by the business system service provider. After the recipient selection is completed, the recipient identification information of the selected recipient is obtained through the contact information stored in the first user terminal or the recipient information provided by the business system service provider.

[0249] Send a key credential creation request to the key management system;

[0250] Among them, the key certificate creation request includes the token of the first user terminal, the third key ciphertext, and the key identification information of the group key, so that the key management system decrypts the third key ciphertext according to the third charging key to obtain the recipient identification information; obtains the affiliation information of the first user terminal according to the token of the first user terminal; obtains the affiliation information of the group key according to the key identification information of the group key, and compares whether the affiliation information of the first user terminal is consistent with the affiliation information of the group key; if the affiliation information of the first user terminal is consistent with the affiliation information of the group key, a first key certificate is generated according to the key identification information of the group key and the recipient identification information.

[0251] Specifically, the key management system obtains the affiliation information of the first user terminal according to the token of the first user terminal, and obtains the affiliation information of the group key according to the key identification information of the group key. By comparing the affiliation information of the first user terminal and the affiliation information of the group key, it is judged whether the affiliation medium of the group key is consistent with the access medium of the first user terminal token, and whether their affiliation application information and affiliation group information are consistent. If all are consistent, the verification passes, and the key management system uses the group key to operate on the recipient identification information to obtain the first key certificate of the second user terminal corresponding to the recipient identification information.

[0252] Among them, the recipient identification information is obtained by the key management system decrypting the third key ciphertext according to the third charging key after receiving the key certificate creation request.

[0253] Step 105: Receive the first key certificate sent by the key management system;

[0254] The key management system generates a corresponding first key certificate for each second user terminal that receives group messages. After the first user terminal receives these first key certificates, it sends them to the service system together with the encrypted group messages.

[0255] Step 106: Send the encrypted group message and the first key certificate to the service system, so that the service system sends the encrypted group message and the first key certificate to at least one second user terminal in the group.

[0256] After receiving the first key certificate and the encrypted group message, the service system parses each first key certificate to obtain the user information of the second user terminal corresponding to each first key certificate, and according to this user information, sends the corresponding first key certificate and the encrypted group message to the corresponding second user terminal.

[0257] Figure 4 It is the step flowchart of another group key management method based on quantum key distribution and certificate authentication provided by the embodiments of the present invention.

[0258] As Figure 4 shown, a group key management method based on quantum key distribution and credential authentication provided by an embodiment of the present invention is applied to a second user terminal. The method may specifically include the following steps:

[0259] Step 201, receiving a group message encrypted by a group key and a first key credential sent by a service system, where each first key credential corresponds to a second user terminal;

[0260] The second user terminal receives a group message encrypted by a group key and a first key credential sent by the service system, and will also receive key identification information of the group key sent by the service system to send to the key management system to complete credential authentication and obtain the group key.

[0261] Step 202, sending a group key acquisition request to the affiliated key management system, where the group key acquisition request includes the first key credential, so that the key management system performs credential authentication processing on the second user terminal according to the first key credential to determine whether the second user terminal has the permission to obtain the group key;

[0262] After receiving the group key acquisition request, the key management system performs credential authentication processing on the second user terminal according to the first key credential in the group key acquisition request to determine whether the second user terminal has the permission to obtain the group key;

[0263] The group key acquisition request includes the first key credential. After receiving the group key acquisition request, the key management system parses it to obtain the first key credential. The key management system verifies the identity of the second user terminal through the first key credential, so as to determine whether the second user terminal has the permission to obtain the group key.

[0264] In some embodiments, the group key acquisition request includes a token of the second user terminal, the first key credential, and key identification information of the group key;

[0265] After receiving the group key acquisition request, the key management system obtains the user identification information of the second user terminal according to the token of the second user terminal, and obtains the recipient identification information according to the first key credential; compares whether the user identification information is consistent with the recipient identification information; if the user identification information is consistent with the recipient identification information, generates a second key credential according to the key identification information of the group key and the user identification information; compares whether the first key credential is consistent with the second key credential, and if the first key credential is consistent with the second key credential, determines that the second user terminal has the permission to obtain the group key.

[0266] In some embodiments, before step 202, the method further includes:

[0267] Send an identity authentication request to the quantum key management system;

[0268] After passing the identity authentication, obtain the token of the second user terminal sent by the quantum key management system.

[0269] Similar to the identity authentication process of the first user terminal, it will not be elaborated here.

[0270] After obtaining the token, the second user terminal sends a group key acquisition request to the key management system. The group key acquisition request includes the token of the second user terminal, which can ensure the communication security of the key management system while quickly identifying the identity of the second user terminal to complete the corresponding instruction actions in the group key acquisition request.

[0271] Step 203, receive the second encrypted ciphertext sent by the key management system after completing the voucher authentication process;

[0272] If the key management system determines that the second user terminal has the permission to obtain the group key, it will encrypt the group key with the second injection key to obtain the second encrypted ciphertext, and then send the second encrypted ciphertext to the second user terminal.

[0273] Step 204, decrypt the second encrypted ciphertext according to the second injection key to obtain the group key, and decrypt the encrypted group message with the group key.

[0274] Specifically, similar to the first user terminal decrypting the first key ciphertext, when the key management system sends the second key ciphertext to the second user terminal, it will send the relevant information of the second injection key to the second user terminal, so that the second user terminal can find the second injection key in the stored injection keys according to the received relevant information of the second injection key, and thus decrypt the second key ciphertext with the second injection key to obtain the group key.

[0275] After obtaining the group key, the second user terminal decrypts the encrypted group message according to the group key to obtain the plaintext of the group message, so that it can read the content of the group message sent by the first user terminal.

[0276] Figure 5 It is the step flowchart of another group key management method provided by the embodiment of the present invention based on quantum key distribution and voucher authentication.

[0277] As Figure 5 shown, a group key management method provided by the embodiment of the present invention based on quantum key distribution and voucher authentication is applied to the key management system. The method may specifically include the following steps:

[0278] Step 301, after receiving the group key creation request sent by the first user terminal, call the quantum key distribution network to generate the group key according to the group key creation request;

[0279] When the key management system receives the group key creation request, it will call the quantum key distribution network to generate the group key. In the quantum key distribution network, the group key is generated through the transmission and measurement of quantum states. This process has unconditional security, and any attempt to eavesdrop will disrupt the quantum state and thus be detected. Therefore, the group key generated by the quantum key distribution network has high security.

[0280] In addition, the group key generated by the quantum key distribution network will be sent to the key management system for further processing and management by the key management system.

[0281] In some embodiments, before step 301, the method further includes:

[0282] Receiving an identity authentication request sent by the first user terminal;

[0283] Performing identity authentication processing on the first user terminal according to the identity authentication request, and after the identity authentication processing is passed, sending a token to the first user terminal.

[0284] In order to securely access and use the key management system, the user terminal needs to perform identity authentication first to ensure that the user has the access permission to obtain the key management system and the acquisition permission for the corresponding resources.

[0285] After the key management system receives the identity authentication request from the first user terminal, the identity authentication request usually contains the user's identity identification information. Then, the key management system will strictly verify this information to confirm the authenticity and legality of the user identity of the first user terminal. After the user's identity is confirmed, the key management system will generate a unique token. This token serves as the credential for the user to access the service subsequently, contains key information such as the user's identity information, access permission, and validity period, and is encrypted to ensure its security.

[0286] Subsequently, the key management system sends the token back to the first user terminal through a secure communication channel. After receiving the token, the first user terminal will save it in the local secure storage and present the token when accessing the service subsequently to prove its identity and permission.

[0287] In this way, the key management system can not only ensure the authenticity of the user identity, but also quickly confirm the user's access permission through the token mechanism. This provides a secure and convenient access experience for the user, while avoiding unauthorized access and potential security threats.

[0288] A token is a security credential that represents a user's identity and access rights. By introducing tokens, the security of the system can be improved, and at the same time, a more convenient and efficient key management service can be provided for users.

[0289] Step 302: Receive the group key sent by the quantum key distribution network, and encrypt the group key according to the first filling key to obtain the first key ciphertext.

[0290] Specifically, the same filling key is securely stored in the first user terminal and its affiliated key management system.

[0291] When the key management system sends the first key ciphertext to the first user terminal, it will also send the key usage information of the first filling key to the first user terminal. The key usage information includes information such as the key identification block, key offset, and key length of the first filling key. This enables the first user terminal to find the first filling key in the filling key it securely stores according to the received key usage information, and thus decrypt the first key ciphertext through the first filling key to obtain the group key.

[0292] Encrypting the group key with the first filling key makes the group key exist in the form of the first key ciphertext during transmission, and it is not easy for interceptors to directly obtain the group key, which improves the security of the system.

[0293] Step 303: Send the first key ciphertext to the first user terminal so that the first user terminal decrypts the first key ciphertext according to the first filling key to obtain the group key, encrypts the group message according to the group key, and sends the encrypted group message to the service system.

[0294] The key management system sends the first key ciphertext to the first user terminal so that the first user terminal can perform subsequent processing on the group message after obtaining the group key.

[0295] In this embodiment, whenever a user terminal needs to send a group message, it requests a group key once to enhance the security within the group. That is, different group keys are used for each sending of a group message. In other embodiments, other frequencies can also be adopted to update the group key, and the present invention does not limit this.

[0296] Step 304: After receiving the key credential creation request sent by the first user terminal, generate the first key credential corresponding to the second user terminal according to the key credential creation request.

[0297] Specifically, the key credential creation request contains the relevant information of the first key credential. After receiving the key credential creation request, the key management system parses it to obtain the relevant information of the first key credential for completing the subsequent generation operation of the first key credential.

[0298] The key management system generates a corresponding first key certificate for each second user terminal that receives group messages. After receiving these first key certificates, the first user terminal sends them together with the encrypted group messages to the service system.

[0299] In some embodiments, the key certificate creation request includes the token of the first user terminal, the third key ciphertext, and the key identification information of the group key; the third key ciphertext is obtained by the first user terminal selecting the recipient and obtaining the recipient identification information, and then encrypting the recipient identification information using the third infusion key;

[0300] After receiving the key certificate creation request, the key management system decrypts the third key ciphertext according to the third infusion key to obtain the recipient identification information; obtains the affiliation information of the first user terminal according to the token of the first user terminal, and obtains the affiliation information of the group key according to the key identification information of the group key; compares whether the affiliation information of the first user terminal is consistent with the affiliation information of the group key; if the affiliation information of the first user terminal is consistent with the affiliation information of the group key, then generates a first key certificate according to the key identification information of the group key and the recipient identification information;

[0301] It should be noted that the key identification information of the group key is sent by the first user terminal to the service system, and after receiving it, the service system sends it to the second user terminal. After receiving it, the second user terminal uses it to generate a key certificate creation request. So that after the key management system receives the key certificate creation request, it can obtain the key identification information of the group key, and find the group key requested by the second user terminal according to the key identification information of the group key.

[0302] In some embodiments, the method further includes:

[0303] After receiving the key certificate creation request, decrypt the third key ciphertext according to the third infusion key to obtain the recipient identification information;

[0304] Obtain the affiliation information of the first user terminal according to the token of the first user terminal, and obtain the affiliation information of the group key according to the key identification information of the group key;

[0305] Compare whether the affiliation information of the first user terminal is consistent with the affiliation information of the group key;

[0306] If the affiliation information of the first user terminal is consistent with the affiliation information of the group key, then generate a first key certificate according to the key identification information of the group key and the recipient identification information.

[0307] The first user terminal and the key management system store the same refilling key. When the first user terminal sends the third key ciphertext to the key management system, it also sends the key usage information of the third refilling key to the key management system. The key usage information includes information such as the key identifier, key offset, and key length of the third refilling key. This enables the key management system to find the third refilling key in the refilling keys it securely stores based on the received key usage information, and thus decrypt the third key ciphertext with the third refilling key to obtain the recipient identification information.

[0308] Specifically, the key management system obtains the belonging information of the first user terminal based on the token of the first user terminal, and obtains the belonging information of the group key based on the key identifier information of the group key. By comparing the belonging information of the first user terminal and the belonging information of the group key, it is determined whether the belonging medium of the group key is the same as the access medium of the first user terminal token, and whether their belonging application information and belonging group information are the same. If all are the same, the verification passes, and the key management system uses the group key to perform an operation on the recipient identification information to obtain the first key credential of the second user terminal corresponding to the recipient identification information.

[0309] Step 305: Send the first key credential to the first user terminal so that the first user terminal sends the first key credential to the service system;

[0310] The first key credential generated by the key management system is sent to the second user terminal that receives the group message for the second user terminal to verify its identity and obtain the group key.

[0311] Step 306: After receiving the group key acquisition request sent by the second user terminal, perform credential authentication processing on the second user terminal according to the first key credential in the group key acquisition request to determine whether the second user terminal has the permission to obtain the group key;

[0312] The group key acquisition request is sent by the second user terminal to the key management system after receiving the encrypted group message and the first key credential sent by the service system; the group key acquisition request includes the first key credential;

[0313] The group key acquisition request includes the first key credential. After receiving the group key acquisition request, the key management system parses it to obtain the first key credential. The key management system verifies the identity of the second user terminal through the first key credential, thereby determining whether the second user terminal has the permission to obtain the group key.

[0314] In some embodiments, the group key acquisition request includes the token of the second user terminal, the first key credential, and the key identifier information of the group key;

[0315] After the key management system receives a group key acquisition request, it obtains the user identification information of the second user terminal based on the token of the second user terminal, and obtains the recipient identification information based on the first key certificate; compares whether the user identification information is consistent with the recipient identification information; if the user identification information is consistent with the recipient identification information, it generates a second key certificate based on the key identification information and user identification information of the group key; compares whether the first key certificate is consistent with the second key certificate, and if the first key certificate is consistent with the second key certificate, it determines that the second user terminal has the permission to acquire the group key.

[0316] In some embodiments, the method further includes:

[0317] After receiving the group key acquisition request, it obtains the user identification information of the second user terminal based on the token of the second user terminal, and obtains the recipient identification information based on the first key certificate;

[0318] Compares whether the user identification information is consistent with the recipient identification information;

[0319] If the user identification information is consistent with the recipient identification information, it generates a second key certificate based on the key identification information and user identification information of the group key; compares whether the first key certificate is consistent with the second key certificate, and if the first key certificate is consistent with the second key certificate, it determines that the second user terminal has the permission to acquire the group key.

[0320] Specifically, the key management system parses the token of the second user terminal to obtain the user identification information of the second user terminal. Parses the first key certificate to obtain the recipient identification information in the first key certificate. Compares the user identification information of the second user terminal with the recipient identification information in the first key certificate. If the two are consistent, it determines that the second user terminal and the recipient in the first key certificate are the same user.

[0321] After determining that the second user terminal is the recipient in the first key certificate, according to the key identification information of the group key in the group key acquisition request, the group key.

[0322] Specifically, when the second user terminal sends a group key acquisition request to the key management system, it also sends the key information of the group key to the key management system. The key information includes information such as the key identification block, key offset, and key length of the group key. So that the key management system can search for the group key record information according to the received key information, and thus obtain the group key requested by the second user terminal to query.

[0323] After obtaining the group key requested by the second user terminal, use the group key requested by the second user terminal to perform an operation on the user identification information to obtain a second key certificate. Compare whether the certificate value of the second key certificate is the same as the certificate value of the first key certificate sent by the second user terminal. If the certificate value of the second key certificate is the same as the certificate value of the first key certificate sent by the second user terminal, it is determined that the second user terminal has the permission to obtain the group key.

[0324] It should be noted that the operation methods used to generate the first key certificate and the second key certificate are the same operation methods pre-specified by the group key system. In this embodiment, the hash-based message authentication code (HMAC) operation related to the key is adopted. In other embodiments, other operation methods may be adopted, and the present invention does not limit this.

[0325] In some embodiments, before step 306, the method further includes:

[0326] Receive an identity authentication request sent by the second user terminal;

[0327] Perform identity authentication processing on the second user terminal according to the identity authentication request. After the identity authentication processing is passed, send a token to the second user terminal.

[0328] Similar to the identity authentication process between the first user terminal and the key management system described above, it will not be elaborated here. After obtaining the token, the second user terminal sends a group key acquisition request to the key management system. The group key acquisition request includes the token of the second user terminal, so as to ensure the communication security of the key management system and be able to quickly identify the identity of the second user terminal to complete the corresponding instruction actions in the group key acquisition request.

[0329] Step 307, if it is determined that the second user terminal has the permission to obtain the group key, then encrypt the group key according to the second charging key to obtain a second encrypted ciphertext, and send the second encrypted ciphertext to the second user terminal, so that the second user terminal decrypts the second encrypted ciphertext according to the second charging key to obtain the group key, and decrypts the encrypted group message through the group key.

[0330] Specifically, when the key management system sends the second key ciphertext to the second user terminal, it will also send the relevant information of the second charging key to the second user terminal, so that the second user terminal can find the second charging key in the charging keys stored by it according to the received relevant information of the second charging key, and thus decrypt the second key ciphertext through the second charging key to obtain the group key.

[0331] In an embodiment of the present invention, before a user terminal sends a group message, it sends a group key creation request to a key management system to obtain a group key; the group message is encrypted with the group key and then sent to other user terminals. After receiving the encrypted group message, the other user terminals send a group key creation request to the key management system to obtain the group key and decrypt the encrypted group message. In group communication, encrypting group messages with a group key reduces the possibility of group message leakage and improves the security of the system.

[0332] At the same time, the user terminal that sends the group message also sends a key credential creation request to the key management system to obtain a key credential, and each key credential corresponds to a user terminal that receives the group message. After receiving the key credential, the user terminal sends the key credential to the key management system, and the key management system verifies the key credential to determine whether the user terminal has the permission to obtain the group key. By performing permission authentication through key credentials, it is not necessary to send the user information of the user terminal, reducing the number of times of network transmission of user information, thereby reducing the risk of user information leakage.

[0333] It should be noted that for method embodiments, for the sake of simple description, they are all expressed as a series of action combinations. However, those skilled in the art should know that the embodiments of the present invention are not limited by the described action sequence, because according to the embodiments of the present invention, certain steps can be performed in other sequences or simultaneously. Secondly, those skilled in the art should also know that the embodiments described in the specification are all preferred embodiments, and the actions involved are not necessarily essential to the embodiments of the present invention.

[0334] Figure 6 It is a schematic diagram of a group key management device based on quantum key distribution and credential authentication provided by an embodiment of the present invention.

[0335] As Figure 6 shown, an embodiment of the present invention provides a group key management device based on quantum key distribution and credential authentication, which is applied to a first user terminal. The device includes:

[0336] A first request sending module 401, configured to send a group key creation request to the affiliated key management system, so that the key management system calls a quantum key distribution network to generate a group key according to the group key creation request;

[0337] A first ciphertext receiving module 402, configured to receive a first key ciphertext sent by the key management system and decrypt the first key ciphertext according to a first padding key to obtain a group key; the first key ciphertext is obtained by the key management system encrypting the group key according to the first padding key after receiving the group key;

[0338] The message encryption module 403 is configured to encrypt the group message according to the group key to obtain an encrypted group message;

[0339] The second request sending module 404 is configured to send a key certificate creation request to the key management system, so that the key management system generates a first key certificate corresponding to the second user terminal according to the key certificate creation request;

[0340] The certificate receiving module 405 is configured to receive the first key certificate sent by the key management system;

[0341] The message sending module 406 is configured to send the encrypted group message and the first key certificate to the service system, so that the service system sends the encrypted group message and the first key certificate to at least one second user terminal in the group.

[0342] In some embodiments, the apparatus further includes:

[0343] The identification acquisition module is configured to select a recipient and acquire recipient identification information, and encrypt the recipient identification information using a third charging key to obtain a third key ciphertext;

[0344] The third request sending module is configured to send a key certificate creation request to the key management system;

[0345] Wherein, the key certificate creation request includes the token of the first user terminal, the third key ciphertext, and the key identification information of the group key, so that the key management system decrypts the third key ciphertext according to the third charging key to obtain the recipient identification information; obtains the affiliation information of the first user terminal according to the token of the first user terminal; obtains the affiliation information of the group key according to the key identification information of the group key, and compares whether the affiliation information of the first user terminal is consistent with the affiliation information of the group key; if the affiliation information of the first user terminal is consistent with the affiliation information of the group key, then generate a first key certificate according to the key identification information of the group key and the recipient identification information.

[0346] In some embodiments, the apparatus further includes:

[0347] The fourth request sending module is configured to send an identity authentication request to the quantum key management system;

[0348] The first token acquisition module is configured to obtain the token of the first user terminal sent by the quantum key management system after passing the identity authentication.

[0349] Figure 7 It is a schematic diagram of another group key management apparatus based on quantum key distribution and certificate authentication provided by an embodiment of the present invention.

[0350] Such as Figure 7As shown in the figure, an embodiment of the present invention provides a group key management device based on quantum key distribution and credential authentication, which is applied to a second user terminal. The device includes:

[0351] A message receiving module 501, configured to receive a group message encrypted by a group key and a first key credential sent by a service system, where each first key credential corresponds to a second user terminal;

[0352] A fifth request sending module 502, configured to send a group key acquisition request to the affiliated key management system, where the group key acquisition request includes a first key credential, so that the key management system performs credential authentication processing on the second user terminal according to the first key credential to determine whether the second user terminal has the right to acquire the group key;

[0353] A ciphertext receiving module 503, configured to receive a second encrypted ciphertext sent by the key management system after completing the credential authentication processing;

[0354] A message decryption module 504, configured to decrypt the second encrypted ciphertext according to a second filling key to obtain a group key, and decrypt the encrypted group message through the group key.

[0355] In some embodiments, the device further includes:

[0356] A sixth request sending module, configured to send an identity authentication request to a quantum key management system;

[0357] A second token acquisition module, configured to obtain a token of the second user terminal sent by the quantum key management system after passing the identity authentication.

[0358] Figure 8 It is a schematic diagram of another group key management device based on quantum key distribution and credential authentication provided by an embodiment of the present invention.

[0359] As Figure 8 shown, an embodiment of the present invention provides a group key management device based on quantum key distribution and credential authentication, which is applied to a key management system. The device includes:

[0360] A first request receiving module 601, configured to, after receiving a group key creation request sent by a first user terminal, call a quantum key distribution network to generate a group key according to the group key creation request;

[0361] A key receiving module 602, configured to receive the group key sent by the quantum key distribution network, and encrypt the group key according to a first filling key to obtain a first key ciphertext;

[0362] The first ciphertext sending module 603 is configured to send the first key ciphertext to the first user terminal, so that the first user terminal decrypts the first key ciphertext according to the first charging key to obtain the group key, encrypts the group message according to the group key, and sends the encrypted group message to the service system;

[0363] The second request receiving module 604 is configured to, after receiving the key certificate creation request sent by the first user terminal, generate a first key certificate corresponding to the second user terminal according to the key certificate creation request;

[0364] The certificate sending module 605 is configured to send the first key certificate to the first user terminal, so that the first user terminal sends the first key certificate to the service system;

[0365] The first certificate authentication module 606 is configured to, after receiving the group key acquisition request sent by the second user terminal, perform certificate authentication processing on the second user terminal according to the first key certificate in the group key acquisition request to determine whether the second user terminal has the permission to acquire the group key; the group key acquisition request is sent by the second user terminal to the key management system after receiving the encrypted group message and the first key certificate sent by the service system; the group key acquisition request includes the first key certificate;

[0366] The second ciphertext sending module 607 is configured to, if it is determined that the second user terminal has the permission to acquire the group key, encrypt the group key according to the second charging key to obtain a second encrypted ciphertext, and send the second encrypted ciphertext to the second user terminal, so that the second user terminal decrypts the second encrypted ciphertext according to the second charging key to obtain the group key, and decrypts the encrypted group message through the group key.

[0367] In some embodiments, the key certificate creation request includes the token of the first user terminal, the third key ciphertext, and the key identification information of the group key; the third key ciphertext is obtained by the first user terminal selecting a recipient and obtaining the recipient identification information, and then encrypting the recipient identification information using the third charging key;

[0368] In some embodiments, the apparatus further includes:

[0369] The ciphertext decryption module is configured to, after receiving the key certificate creation request, decrypt the third key ciphertext according to the third charging key to obtain the recipient identification information;

[0370] The information acquisition module is configured to obtain the affiliation information of the first user terminal according to the token of the first user terminal, and obtain the affiliation information of the group key according to the key identification information of the group key;

[0371] The first comparison module is configured to compare whether the affiliation information of the first user terminal is consistent with the affiliation information of the group key;

[0372] A voucher generation module, configured to generate a first key voucher according to the key identification information of the group key and the recipient identification information if the affiliation information of the first user terminal is consistent with the affiliation information of the group key.

[0373] In some embodiments, the group key acquisition request includes a token of the second user terminal, a first key voucher, and the key identification information of the group key;

[0374] In some embodiments, the apparatus further includes:

[0375] A third request receiving module, configured to, after receiving the group key acquisition request, obtain the user identification information of the second user terminal according to the token of the second user terminal, and obtain the recipient identification information according to the first key voucher;

[0376] A second comparison module, configured to compare whether the user identification information is consistent with the recipient identification information;

[0377] A second voucher authentication module, configured to, if the user identification information is consistent with the recipient identification information, generate a second key voucher according to the key identification information of the group key and the user identification information; compare whether the first key voucher is consistent with the second key voucher, and if the first key voucher is consistent with the second key voucher, determine that the second user terminal has the permission to obtain the group key.

[0378] In some embodiments, the apparatus further includes:

[0379] A fourth request receiving module, configured to receive an identity authentication request sent by the first user terminal;

[0380] A first token sending module, configured to perform identity authentication processing on the first user terminal according to the identity authentication request, and send a token to the first user terminal after the identity authentication processing is passed.

[0381] In some embodiments, the apparatus further includes:

[0382] A fifth request receiving module, configured to receive an identity authentication request sent by the second user terminal;

[0383] A second token sending module, configured to perform identity authentication processing on the second user terminal according to the identity authentication request, and send a token to the second user terminal after the identity authentication processing is passed.

[0384] For the apparatus embodiments, since they are basically similar to the method embodiments, details are not described herein again. For related parts, please refer to the description of the method embodiments.

[0385] An embodiment of the present invention further provides an electronic device, including:

[0386] A processor, a memory, and a computer program stored on the memory and capable of running on the processor. When the computer program is executed by the processor, it implements each process of the above-mentioned embodiment of the group key management method based on quantum key distribution and credential authentication, and can achieve the same technical effects. To avoid repetition, it will not be elaborated here.

[0387] An embodiment of the present invention also provides a computer-readable storage medium. A computer program is stored on the computer-readable storage medium. When the computer program is executed by the processor, it implements each process of the above-mentioned embodiment of the group key management method based on quantum key distribution and credential authentication, and can achieve the same technical effects. To avoid repetition, it will not be elaborated here.

[0388] Each embodiment in this specification is described in a progressive manner. The key point of each embodiment is to illustrate the differences from other embodiments. For the same or similar parts among the embodiments, reference can be made to each other.

[0389] Those skilled in the art should understand that the embodiments of the present invention can be provided as methods, devices, or computer program products. Therefore, the embodiments of the present invention can take the form of completely hardware embodiments, completely software embodiments, or embodiments combining software and hardware aspects. Moreover, the embodiments of the present invention can take the form of computer program products implemented on one or more computer-usable storage media (including but not limited to disk memories, CD-ROMs, optical memories, etc.) containing computer-usable program codes.

[0390] The embodiments of the present invention are described with reference to the flowcharts and / or block diagrams of methods, terminal devices (systems), and computer program products according to the embodiments of the present invention. It should be understood that each process and / or block in the flowchart and / or block diagram can be implemented by computer program instructions, and the combination of processes and / or blocks in the flowchart and / or block diagram can also be implemented by computer program instructions. These computer program instructions can be provided to the processor of a general-purpose computer, a special-purpose computer, an embedded processor, or other programmable data processing terminal devices to generate a machine, so that the instructions executed by the processor of the computer or other programmable data processing terminal devices generate a device for implementing the functions specified in Figure 1 one process or multiple processes and / or blocks Figure 1 one block or multiple blocks.

[0391] These computer program instructions can also be stored in a computer-readable memory that can direct a computer or other programmable data processing terminal device to work in a specific manner, so that the instructions stored in the computer-readable memory generate a manufactured product including an instruction device, and the instruction device implements the functions in Figure 1 one process or multiple processes and / or blocks Figure 1The functions specified in one or more boxes.

[0392] These computer program instructions can also be loaded onto a computer or other programmable data processing terminal device, so that a series of operation steps are executed on the computer or other programmable terminal device to generate a computer-implemented process. Thus, the instructions executed on the computer or other programmable terminal device provide for implementing the steps of the functions specified in one Figure 1 One process or multiple processes and / or boxes Figure 1 The steps of the functions specified in one or more boxes.

[0393] Although the preferred embodiments of the embodiments of the present invention have been described, those skilled in the art can make additional changes and modifications to these embodiments once they know the basic creative concept. Therefore, the appended claims are intended to be construed to include the preferred embodiments and all changes and modifications falling within the scope of the embodiments of the present invention.

[0394] Finally, it should also be noted that in this text, relational terms such as first and second are only used to distinguish one entity or operation from another entity or operation, and do not necessarily require or imply any such actual relationship or order between these entities or operations. Moreover, the term "comprising", "including" or any other variant thereof is intended to cover non-exclusive inclusion, so that a process, method, article or terminal device comprising a series of elements includes not only those elements but also other elements not expressly listed, or elements inherent to such process, method, article or terminal device. Without further limitation, an element defined by the statement "comprising an..." does not exclude the presence of additional identical elements in the process, method, article or terminal device comprising the element.

[0395] The above has introduced in detail the group key management system, method, device, electronic device and computer-readable storage medium provided by the present invention. Specific examples are used in this text to elaborate on the principle and implementation manner of the present invention. The description of the above embodiments is only used to help understand the method and its core idea of the present invention; at the same time, for those of ordinary skill in the art, according to the idea of the present invention, there will be changes in the specific implementation manner and application scope. In summary, the content of this specification should not be construed as a limitation to the present invention.

Claims

1. A group key management system based on quantum key distribution and credential authentication, characterized in that: include: A first user terminal, a second user terminal, a key management system, a business system, and a quantum key distribution network; The first user terminal is configured to send a group key creation request to the key management system to which it belongs, receive a first key ciphertext sent by the key management system, decrypt the first key ciphertext according to a first charging key to obtain a group key; encrypt a group message according to the group key to obtain the encrypted group message; Sending a key credential creation request to the key management system; receiving a first key certificate corresponding to the second user terminal sent by the key management system; and sending the encrypted group message and the first key certificate to the service system; The business system is used to send the encrypted group message and the first key certificate to at least one of the second user terminals in the group; each of the first key certificates corresponds to one of the second user terminals; The second user terminal is configured to, after receiving the encrypted group message and the first key certificate sent by the business system, send a group key acquisition request to the key management system to which it belongs, wherein the group key acquisition request includes the first key certificate; receive a second encrypted ciphertext sent by the key management system after completing the credential authentication process; decrypt the second encrypted ciphertext according to the second charging key to obtain the group key; and decrypt the encrypted group message by using the group key; The key management system is configured to, after receiving the group key creation request, call the quantum key distribution network to generate the group key according to the group key creation request, receive the group key sent by the quantum key distribution network, encrypt the group key according to the first injection key to obtain the first key ciphertext, and send the first key ciphertext to the first user terminal; after receiving the key credential creation request, generate at least one first key credential according to the key credential creation request, and send the first key credential to the first user terminal; The key management system is further used to, after receiving the group key acquisition request, perform credential authentication processing on the second user terminal according to the first key credential in the group key acquisition request to determine whether the second user terminal has the authority to obtain the group key; if it is determined that the second user terminal has the authority to obtain the group key, encrypt the group key according to the second injection key to obtain the second encrypted ciphertext, and send the second encrypted ciphertext to the second user terminal.

2. The system according to claim 1, characterized in that The first user terminal is configured to select a recipient and obtain recipient identification information, encrypt the recipient identification information using a third charging key to obtain a third key ciphertext; send the key credential creation request to the key management system, the key credential creation request including a token of the first user terminal, the third key ciphertext and the key identification information of the group key; The key management system is configured to, after receiving the key credential creation request, decrypt the third key ciphertext according to the third charging key to obtain the recipient identification information; obtain the ownership information of the first user terminal according to the token of the first user terminal, and obtain the ownership information of the group key according to the key identification information of the group key; comparing whether the belonging information of the first user terminal is consistent with the belonging information of the group key; If the belonging information of the first user terminal is consistent with the belonging information of the group key, the first key certificate is generated according to the key identification information of the group key and the recipient identification information.

3. The system according to claim 1, characterized in that The second user terminal is used to send the group key acquisition request to the key management system, where the group key acquisition request includes a token of the second user terminal, the first key credential and key identification information of the group key; The key management system is used to, after receiving the group key acquisition request, obtain user identification information of the second user terminal according to the token of the second user terminal, and obtain recipient identification information according to the first key certificate; compare whether the user identification information is consistent with the recipient identification information; if the user identification information is consistent with the recipient identification information, generate a second key certificate according to the key identification information of the group key and the user identification information; compare whether the first key certificate is consistent with the second key certificate, and if the first key certificate is consistent with the second key certificate, determine that the second user terminal has the authority to obtain the group key.

4. The system according to claim 1, characterized in that The first user terminal is used to send an identity authentication request to the quantum key management system, so as to obtain a token of the first user terminal sent by the quantum key management system after passing the identity authentication; The second user terminal is used to send an identity authentication request to the quantum key management system, so as to obtain a token of the second user terminal sent by the quantum key management system after passing the identity authentication; The key management system is configured to receive an identity authentication request sent by the first user terminal; perform identity authentication processing on the first user terminal according to the identity authentication request, and send a token to the first user terminal after the identity authentication processing passes; The key management system is also used to receive an identity authentication request sent by the second user terminal; perform identity authentication processing on the user terminal according to the identity authentication request, and send a token to the second user terminal after the identity authentication processing is passed.

5. The system according to claim 1, characterized in that The key management system is used to send first key usage information to the first user terminal, where the first key usage information includes a key block identifier, a key block offset, and a key length of the first injection key; The first user terminal is used to read the first charging key according to the first key usage information.

6. The system according to claim 1, characterized in that The key management system is used to send second key usage information to the second user terminal, where the second key usage information includes a key block identifier, a key block offset, and a key length of the second injection key; The second user terminal is used to read the second charging key according to the second key usage information.

7. A group key management method based on quantum key distribution and credential authentication, characterized in that: Applied to a first user terminal, the method includes: Sending a group key creation request to the key management system to which it belongs, so that the key management system calls the quantum key distribution network to generate a group key according to the group key creation request; receiving a first key ciphertext sent by the key management system, and decrypting the first key ciphertext according to a first charging key to obtain a group key; the first key ciphertext is obtained by encrypting the group key according to the first charging key after the key management system receives the group key; Encrypting the group message according to the group key to obtain the encrypted group message; Sending a key certificate creation request to the key management system, so that the key management system generates a first key certificate corresponding to the second user terminal according to the key certificate creation request; Receiving the first key certificate sent by the key management system; The encrypted group message and the first key certificate are sent to the service system, so that the service system sends the encrypted group message and the first key certificate to at least one of the second user terminals in the group.

8. The method according to claim 7, characterized in that The method further comprises: Selecting a recipient and obtaining identification information of the recipient, and encrypting the identification information of the recipient using a third charging key to obtain a third key ciphertext; Sending the key credential creation request to the key management system; The key credential creation request includes the token of the first user terminal, the third key ciphertext and the key identification information of the group key, so that the key management system decrypts the third key ciphertext according to the third injection key to obtain the recipient identification information; obtains the belonging information of the first user terminal according to the token of the first user terminal; obtains the belonging information of the group key according to the key identification information of the group key, and compares whether the belonging information of the first user terminal is consistent with the belonging information of the group key; if the belonging information of the first user terminal is consistent with the belonging information of the group key, generates the first key credential according to the key identification information of the group key and the recipient identification information.

9. The method according to claim 8, characterized in that The method further comprises: Sending an identity authentication request to the quantum key management system; After passing identity authentication, obtain a token of the first user terminal sent by the quantum key management system.

10. A group key management method based on quantum key distribution and credential authentication, characterized in that: Applied to a second user terminal, the method includes: receiving a group message encrypted by a group key and a first key certificate sent by a business system, each of the first key certificates corresponding to one of the second user terminals; Sending a group key acquisition request to the key management system to which it belongs, the group key acquisition request including a first key credential, so that the key management system performs credential authentication processing on the second user terminal according to the first key credential to determine whether the second user terminal has the authority to obtain the group key; Receiving a second encrypted ciphertext sent by the key management system after completing the credential authentication process; The second encrypted ciphertext is decrypted according to the second injection key to obtain the group key, and the encrypted group message is decrypted by the group key.

11. The method according to claim 10, characterized in that The group key acquisition request includes the token of the second user terminal, the first key certificate and the key identification information of the group key; so that after the key management system receives the group key acquisition request, it obtains the user identification information of the second user terminal according to the token of the second user terminal, and obtains the recipient identification information according to the first key certificate; compares whether the user identification information is consistent with the recipient identification information; if the user identification information is consistent with the recipient identification information, generates a second key certificate according to the key identification information of the group key and the user identification information; compares whether the first key certificate is consistent with the second key certificate, and if the first key certificate is consistent with the second key certificate, determines that the second user terminal has the authority to obtain the group key.

12. The method according to claim 11, characterized in that The method further comprises: Sending an identity authentication request to the quantum key management system; After passing identity authentication, obtain the token of the second user terminal sent by the quantum key management system.

13. A group key management method based on quantum key distribution and credential authentication, characterized in that: Applied to a key management system, the method comprises: After receiving the group key creation request sent by the first user terminal, calling the quantum key distribution network to generate a group key according to the group key creation request; receiving the group key sent by the quantum key distribution network, and encrypting the group key according to the first injection key to obtain the first key ciphertext; sending the first key ciphertext to the first user terminal, so that the first user terminal decrypts the first key ciphertext according to the first charging key to obtain the group key, encrypts the group message according to the group key, and sends the encrypted group message to the service system; After receiving the key credential creation request sent by the first user terminal, generating a first key credential corresponding to the second user terminal according to the key credential creation request; Sending the first key certificate to a first user terminal, so that the first user terminal sends the first key certificate to a business system; After receiving the group key acquisition request sent by the second user terminal, performing credential authentication processing on the second user terminal according to the first key credential in the group key acquisition request to determine whether the second user terminal has the authority to obtain the group key; the group key acquisition request is sent by the second user terminal to the key management system after receiving the encrypted group message and the first key credential sent by the service system; the group key acquisition request includes the first key credential; If it is determined that the second user terminal has the authority to obtain the group key, the group key is encrypting according to the second injection key to obtain the second encrypted ciphertext, and the second encrypted ciphertext is sent to the second user terminal, so that the second user terminal decrypts the second encrypted ciphertext according to the second injection key to obtain the group key, and decrypts the encrypted group message by using the group key.

14. The method according to claim 13, characterized in that The key credential creation request includes the token of the first user terminal, the third key ciphertext and the key identification information of the group key; the third key ciphertext is obtained by the first user terminal selecting a recipient and obtaining the recipient identification information, and then encrypting the recipient identification information using the third injection key; The method further comprises: After receiving the key credential creation request, decrypting the third key ciphertext according to the third charging key to obtain the recipient identification information; Obtaining ownership information of the first user terminal according to the token of the first user terminal, and obtaining ownership information of the group key according to the key identification information of the group key; comparing whether the belonging information of the first user terminal is consistent with the belonging information of the group key; If the belonging information of the first user terminal is consistent with the belonging information of the group key, the first key certificate is generated according to the key identification information of the group key and the recipient identification information.

15. The method according to claim 13, characterized in that The group key acquisition request includes the token of the second user terminal, the first key credential and the key identification information of the group key; The method further comprises: After receiving the group key acquisition request, obtaining user identification information of the second user terminal according to the token of the second user terminal, and obtaining recipient identification information according to the first key credential; Comparing the user identification information with the recipient identification information to see if they are consistent; If the user identification information is consistent with the recipient identification information, a second key certificate is generated according to the key identification information of the group key and the user identification information; and the first key certificate is compared with the second key certificate to see whether they are consistent. If the first key certificate is consistent with the second key certificate, it is determined that the second user terminal has the authority to obtain the group key.

16. The method according to claim 14, characterized in that The method further comprises: Receiving an identity authentication request sent by the first user terminal; Perform identity authentication processing on the first user terminal according to the identity authentication request, and send a token to the first user terminal after the identity authentication processing passes.

17. The method according to claim 15, characterized in that The method further comprises: receiving an identity authentication request sent by the second user terminal; Perform identity authentication processing on the second user terminal according to the identity authentication request, and send a token to the second user terminal after the identity authentication processing passes.

18. A group key management device based on quantum key distribution and credential authentication, characterized in that: Applied to a first user terminal, the device includes: A first request sending module is used to send a group key creation request to the key management system to which it belongs, so that the key management system calls the quantum key distribution network to generate a group key according to the group key creation request; a first ciphertext receiving module, configured to receive a first key ciphertext sent by the key management system, and decrypt the first key ciphertext according to a first charging key to obtain a group key; the first key ciphertext is obtained by encrypting the group key according to the first charging key after the key management system receives the group key; A message encryption module, used for encrypting the group message according to the group key to obtain the encrypted group message; A second request sending module, configured to send a key credential creation request to the key management system, so that the key management system generates a first key credential corresponding to the second user terminal according to the key credential creation request; A certificate receiving module, used for receiving the first key certificate sent by the key management system; The message sending module is used to send the encrypted group message and the first key certificate to the service system, so that the service system sends the encrypted group message and the first key certificate to at least one of the second user terminals in the group.

19. The device according to claim 18, characterized in that The device also includes: An identification acquisition module, used to select a recipient and obtain the recipient identification information, and encrypt the recipient identification information using a third charging key to obtain a third key ciphertext; A third request sending module, used to send the key credential creation request to the key management system; The key credential creation request includes the token of the first user terminal, the third key ciphertext and the key identification information of the group key, so that the key management system decrypts the third key ciphertext according to the third injection key to obtain the recipient identification information; obtains the belonging information of the first user terminal according to the token of the first user terminal; obtains the belonging information of the group key according to the key identification information of the group key, and compares whether the belonging information of the first user terminal is consistent with the belonging information of the group key; if the belonging information of the first user terminal is consistent with the belonging information of the group key, generates the first key credential according to the key identification information of the group key and the recipient identification information.

20. The device according to claim 18, characterized in that The device also includes: A fourth request sending module, used to send an identity authentication request to the quantum key management system; The first token acquisition module is used to obtain the token of the first user terminal sent by the quantum key management system after passing the identity authentication.

21. A group key management device based on quantum key distribution and credential authentication, characterized in that: Applied to a second user terminal, the device includes: A message receiving module, used for receiving a group message encrypted by a group key and a first key certificate sent by a business system, each of the first key certificates corresponding to one of the second user terminals; a fifth request sending module, configured to send a group key acquisition request to the key management system to which it belongs, wherein the group key acquisition request includes a first key credential, so that the key management system performs credential authentication processing on the second user terminal according to the first key credential to determine whether the second user terminal has the authority to obtain the group key; A ciphertext receiving module, used to receive a second encrypted ciphertext sent by the key management system after completing the credential authentication process; The message decryption module is used to decrypt the second encrypted ciphertext according to a second injection key to obtain the group key, and decrypt the encrypted group message by using the group key.

22. The device according to claim 21, characterized in that The device also includes: A sixth request sending module, used to send an identity authentication request to the quantum key management system; The second token acquisition module is used to obtain the token of the second user terminal sent by the quantum key management system after passing the identity authentication.

23. A group key management device based on quantum key distribution and credential authentication, characterized in that: Applied to a key management system, the device comprises: A first request receiving module is configured to, after receiving a group key creation request sent by a first user terminal, call a quantum key distribution network to generate a group key according to the group key creation request; A key receiving module, configured to receive the group key sent by the quantum key distribution network, and encrypt the group key according to the first injection key to obtain the first key ciphertext; a first ciphertext sending module, configured to send the first key ciphertext to the first user terminal, so that the first user terminal decrypts the first key ciphertext according to the first charging key to obtain the group key, encrypts the group message according to the group key, and sends the encrypted group message to the service system; A second request receiving module, configured to generate a first key credential corresponding to the second user terminal according to the key credential creation request after receiving the key credential creation request sent by the first user terminal; A certificate sending module, used for sending the first key certificate to a first user terminal, so that the first user terminal sends the first key certificate to a business system; a first credential authentication module, configured to, after receiving a group key acquisition request sent by the second user terminal, perform credential authentication processing on the second user terminal according to the first key credential in the group key acquisition request, so as to determine whether the second user terminal has the authority to obtain the group key; the group key acquisition request is sent by the second user terminal to the key management system after receiving the encrypted group message and the first key credential sent by the service system; the group key acquisition request includes the first key credential; A second ciphertext sending module is used for, if it is determined that the second user terminal has the authority to obtain the group key, encrypting the group key according to the second injection key to obtain the second encrypted ciphertext, and sending the second encrypted ciphertext to the second user terminal, so that the second user terminal decrypts the second encrypted ciphertext according to the second injection key to obtain the group key, and decrypts the encrypted group message by using the group key.

24. The device according to claim 23, characterized in that The key credential creation request includes the token of the first user terminal, the third key ciphertext and the key identification information of the group key; the third key ciphertext is obtained by the first user terminal selecting a recipient and obtaining the recipient identification information, and then encrypting the recipient identification information using the third injection key; The device also includes: a ciphertext decryption module, configured to, after receiving the key credential creation request, decrypt the third key ciphertext according to the third charging key to obtain the recipient identification information; an information acquisition module, configured to obtain the ownership information of the first user terminal according to the token of the first user terminal, and obtain the ownership information of the group key according to the key identification information of the group key; A first comparison module, used to compare whether the belonging information of the first user terminal is consistent with the belonging information of the group key; The credential generation module is configured to generate the first key credential according to the key identification information of the group key and the receiver identification information if the belonging information of the first user terminal is consistent with the belonging information of the group key.

25. The device according to claim 23, characterized in that The group key acquisition request includes the token of the second user terminal, the first key credential and the key identification information of the group key; The device also includes: a third request receiving module, configured to, after receiving the group key acquisition request, obtain user identification information of the second user terminal according to the token of the second user terminal, and obtain recipient identification information according to the first key credential; A second comparison module, used to compare whether the user identification information is consistent with the recipient identification information; The second credential authentication module is used to generate a second key credential based on the key identification information of the group key and the user identification information if the user identification information is consistent with the recipient identification information; compare whether the first key credential is consistent with the second key credential, and if the first key credential is consistent with the second key credential, determine that the second user terminal has the authority to obtain the group key.

26. The device according to claim 24, characterized in that The device also includes: A fourth request receiving module, configured to receive an identity authentication request sent by the first user terminal; The first token sending module is used to perform identity authentication processing on the first user terminal according to the identity authentication request, and send a token to the first user terminal after the identity authentication processing is passed.

27. The device according to claim 25, characterized in that The device also includes: a fifth request receiving module, configured to receive an identity authentication request sent by the second user terminal; The second token sending module is used to perform identity authentication processing on the second user terminal according to the identity authentication request, and send a token to the second user terminal after the identity authentication processing is passed.

28. An electronic device, characterized in that: include: A processor, a memory, and a computer program stored in the memory and capable of running on the processor, wherein when the computer program is executed by the processor, the steps of the group key management method based on quantum key distribution and credential authentication as described in any one of claims 7-9 or 10-12 or 13-17 are implemented.

29. A computer-readable storage medium, characterized in that: The computer-readable storage medium stores a computer program, and when the computer program is executed by the processor, the steps of the group key management method based on quantum key distribution and credential authentication are implemented as described in any one of claims 7-9 or 10-12 or 13-17.

Citation Information

Cited By

  • Workflow authority control method and system based on quantum encryption mechanism

    CN121150950A

  • Workflow permission control method and system based on quantum encryption mechanism

    CN121150950B