Group key management system and method based on quantum key distribution and reverse authentication

By using quantum key distribution and reverse authentication technology in the group key management system, group keys are generated and managed and authentication is performed in the business system, the problem of increased logical complexity in existing systems when handling a large number of transactions is solved, and the security of the system is improved.

CN120128320APending Publication Date: 2025-06-10中电信量子信息科技集团有限公司
View PDF 0 Cites 1 Cited by

Patent Information

Application Number
CN202510184666.5
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-02-19
Publication Date
2025-06-10

AI Technical Summary

Technical Problem

The existing group key management system has increased its logical complexity when handling a large number of transactions, which is prone to errors and exceptions, and is more prone to attack, resulting in reduced system security.

Method used

A group key management system based on quantum key distribution and reverse authentication is adopted to generate group keys through the quantum key distribution network and authenticate in the business system to reduce the transaction complexity of the key management system.

Benefits of technology

By reducing the transaction complexity of the key management system, the probability of errors and exceptions occurring during the operation of the system is reduced, and the security of the system is improved.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120128320A_ABST
    Figure CN120128320A_ABST
Patent Text Reader

Abstract

The embodiment of the invention provides a group key management system and method based on quantum key distribution and reverse authentication, and the system comprises a second user terminal which is used for transmitting a group key obtaining request to a second key management system to which the second user terminal belongs after receiving an encrypted group message transmitted by a service system; the second key management system is used for sending an authentication request to the service system after receiving a group key acquisition request sent by a second user terminal; the service system is used for determining whether the second user terminal has the authority of acquiring the group key after receiving an authentication request sent by a second key management system to which the second user terminal belongs; and sending the authentication result to the second key management system. According to the embodiment of the invention, the transaction for authenticating the user terminal is transferred to the service system, so that the transaction complexity of the key management system is reduced, and the probability of errors in the running process of the key management system is reduced.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the technical field of security applications, and particularly to a group key management system, method, device, electronic device, and computer-readable storage medium based on quantum key distribution and reverse authentication. Background Art

[0002] Quantum key distribution is a quantum information technology for realizing communication security based on quantum mechanics. Its core lies in enabling both parties of communication to generate and share a random and secure key to encrypt and decrypt communication messages, thereby ensuring the security of communication. With the rapid development of quantum communication technology, quantum key distribution systems have become the research focus in the field of information security.

[0003] In related technologies, a group key management system usually manages the keys in a group and authenticates user terminals by a key management system. After the key management system determines that a user terminal has the permission to view group information through authentication, it sends the group key to the user terminal, so that the user terminal decrypts the encrypted group message with the group key and can view the group message.

[0004] Due to too many transactions to be processed, the logical complexity of the key management system increases. The system is prone to errors and exceptions during operation, and it is also easier to discover vulnerabilities and be attacked, resulting in a reduction in the security of the system. Summary of the Invention

[0005] In view of the above problems, embodiments of the present invention are proposed to provide a group key management system, method, device, electronic device, and computer-readable storage medium based on quantum key distribution and reverse authentication that overcome the above problems or at least partially solve the above problems.

[0006] On the one hand, embodiments of the present invention disclose a group key management system based on quantum key distribution and reverse authentication, including: a first user terminal, a second user terminal, a first key management system, a second key management system, a service system, and a quantum key distribution network;

[0007] The first user terminal is configured to send a group key creation request to the first key management system to which it belongs, receive a first key ciphertext sent by the first key management system, and decrypt the first key ciphertext according to a first charging key to obtain a group key; encrypt a group message according to the group key, and send the encrypted group message to the service system;

[0008] The first key management system is used to call the quantum key distribution network according to the group key creation request to generate the group key, receive the group key sent by the quantum key distribution network, encrypt the group key with the first filling key to obtain the first key ciphertext, and send the first key ciphertext to the first user terminal;

[0009] The service system is used to send the encrypted group message to at least one of the second user terminals in the group, and determine whether the second user terminal has the permission to obtain the group key after receiving the authentication request sent by the second key management system to which the second user terminal belongs; send the authentication result to the second key management system;

[0010] The second user terminal is used to send a group key acquisition request to the second key management system to which it belongs after receiving the encrypted group message sent by the service system; receive the second encrypted ciphertext sent by the second key management system after obtaining the authentication result; decrypt the second encrypted ciphertext with the second filling key to obtain the group key; decrypt the encrypted group message with the group key;

[0011] The second key management system is used to receive the group key sent by the quantum key distribution network; send the authentication request to the service system after receiving the group key acquisition request sent by the second user terminal, and encrypt the group key with the second filling key to obtain the second encrypted ciphertext and send the second encrypted ciphertext to the second user terminal after receiving the authentication result.

[0012] Optionally, the authentication request includes the user information and group information of the second user terminal;

[0013] The service system is used to parse the received authentication request to obtain the user information and group information of the second user terminal; determine whether the user of the second user terminal has the permission to obtain the group key corresponding to the group information according to the user information and group information of the second user terminal; if the user of the second user terminal has the permission to obtain the group key corresponding to the group information, the service system sends an authentication success message to the second key management system; if the user of the second user terminal does not have the permission to obtain the group key corresponding to the group information, the service system sends an authentication failure message to the second key management system.

[0014] Optionally, the first user terminal is configured to send an authentication request to the first key management system to obtain a token of the first user terminal sent by the first key management system after passing the authentication; and send the group key creation request to the first key management system, where the group key creation request includes the token of the first user terminal.

[0015] The first key management system is configured to receive the authentication request sent by the first user terminal; perform an authentication process on the first user terminal according to the authentication request, and send a token to the first user terminal after the authentication process passes; parse the received group key creation request to obtain the token of the first user terminal; and identify the user information of the first user terminal according to the token of the first user terminal.

[0016] Optionally, the second user terminal is configured to send an authentication request to the second key management system to obtain a token of the second user terminal sent by the second key management system after passing the authentication; and send the group key acquisition request to the second key management system, where the group key acquisition request includes the token of the second user terminal.

[0017] The second key management system is configured to receive the authentication request sent by the second user terminal; perform an authentication process on the second user terminal according to the authentication request, and send a token to the second user terminal after the authentication process passes; parse the received group key acquisition request to obtain the token of the second user terminal; and identify the user information of the second user terminal according to the token of the second user terminal.

[0018] Optionally, the quantum key distribution network includes a first quantum key distribution network and a second quantum key distribution network.

[0019] The first quantum key distribution network is configured to generate the group key, send the group key to the first key management system, and send the group key to the second key management system to which at least one second user terminal in the group belongs through a second quantum distribution network node.

[0020] On the other hand, an embodiment of the present invention discloses a group key management method based on quantum key distribution and reverse authentication, which is applied to a first user terminal. The method includes:

[0021] Send a group key creation request to the first key management system to which it belongs, so that the first key management system calls a quantum key distribution network to generate a group key according to the group key creation request.

[0022] Receive the first key ciphertext sent by the first key management system, and decrypt the first key ciphertext according to the first charging key to obtain the group key; the first key ciphertext is obtained by the first key management system encrypting the group key according to the first charging key after receiving the group key;

[0023] Encrypt the group message according to the group key, and send the encrypted group message to the service system, so that the service system sends the encrypted group message to at least one second user terminal in the group.

[0024] Optionally, the method further includes:

[0025] Send an identity authentication request to the first key management system;

[0026] Receive the token of the first user terminal sent by the first key management system;

[0027] The sending a group key creation request to the first key management system to which it belongs includes:

[0028] Send the group key creation request to the first key management system, and the group key creation request includes the token of the first user terminal.

[0029] On the other hand, an embodiment of the present invention discloses a group key management method based on quantum key distribution and reverse authentication, which is applied to a first key management system, and the method includes:

[0030] Call the quantum key distribution network to create a group key according to the group key creation request sent by the first user terminal;

[0031] Receive the group key sent by the quantum key distribution network, and encrypt the group key according to the first charging key to obtain a first key ciphertext;

[0032] Send the first key ciphertext to the first user terminal, so that the first user terminal decrypts the first key ciphertext according to the first charging key to obtain the group key, encrypts the group message according to the group key, and sends the encrypted group message to the service system.

[0033] Optionally, the method further includes:

[0034] Receive the identity authentication request sent by the first user terminal;

[0035] Perform identity authentication processing on the first user terminal according to the identity authentication request, and send a token to the first user terminal after the identity authentication processing passes;

[0036] Parse the received group key creation request to obtain the token of the first user terminal;

[0037] Invoking a quantum key distribution network to create a group key according to the group key creation request sent by the first user terminal includes:

[0038] Identify the user information of the first user terminal according to the token of the first user terminal.

[0039] On the other hand, an embodiment of the present invention discloses a group key management method based on quantum key distribution and reverse authentication, which is applied to a second user terminal. The method includes:

[0040] Receive a group message encrypted by a group key sent by a service system;

[0041] Send a group key acquisition request to the second key management system to which it belongs, so that after receiving the group key acquisition request, the second key management system sends an authentication request to the service system;

[0042] Receive a second encrypted ciphertext sent by the second key management system after obtaining an authentication result; the authentication result is sent by the service system to the second key management system after receiving the authentication request and determining whether the second user terminal has the right to obtain the group key; the second encrypted ciphertext is obtained by the second key management system encrypting the group key according to a second filling key after receiving the authentication result;

[0043] Decrypt the second encrypted ciphertext according to the second filling key to obtain the group key;

[0044] Decrypt the encrypted group message with the group key.

[0045] Optionally, the method further includes:

[0046] Send an identity authentication request to the second key management system;

[0047] Receive the token of the second user terminal sent by the second key management system;

[0048] The sending the group key acquisition request to the second key management system to which it belongs includes:

[0049] Send the group key acquisition request to the second key management system, and the group key acquisition request includes the token of the second user terminal.

[0050] On the other hand, an embodiment of the present invention discloses a group key management method based on quantum key distribution and reverse authentication, which is applied to a second key management system. The method includes:

[0051] Receiving a group key sent by a quantum key distribution network, where the group key is generated by a first key management system to which a first user terminal belongs after receiving a group key creation request sent by the first user terminal and then invoking the quantum key distribution network;

[0052] Receiving a group key acquisition request sent by a second user terminal, and sending an authentication request to a service system. The group key acquisition request is sent by the second user terminal to the second key management system after receiving a group message encrypted by the group key sent by the service system;

[0053] Receiving an authentication result, encrypting the group key with a second padding key to obtain a second encrypted ciphertext, and sending the second encrypted ciphertext to the second user terminal, so that the second user terminal decrypts the second encrypted ciphertext with the second padding key to obtain the group key, and decrypts the encrypted group message with the group key.

[0054] Optionally, the method further includes:

[0055] Receiving an identity authentication request sent by the second user terminal;

[0056] Performing identity authentication processing on the second user terminal according to the identity authentication request, and sending a token to the second user terminal after the identity authentication processing passes;

[0057] The receiving the group key acquisition request sent by the second user terminal includes:

[0058] Parsing the received group key acquisition request to obtain the token of the second user terminal; and identifying the user information of the second user terminal according to the token of the second user terminal.

[0059] On the other hand, an embodiment of the present invention discloses a group key management method based on quantum key distribution and reverse authentication, which is applied to a service system. The method includes:

[0060] Receiving a group message encrypted with a group key sent by a first user terminal;

[0061] Sending the encrypted group message to at least one second user terminal in the group;

[0062] Receive the authentication request sent by the second key management system, and determine whether the second user terminal has the permission to obtain the group key; the authentication request is sent by the second key management system to the service system after receiving the group key acquisition request sent by the second user terminal; the group key acquisition request is sent by the second user terminal to the affiliated second key management system after receiving the encrypted group message;

[0063] Send the authentication result to the second key management system, so that after obtaining the authentication result, the second key management system encrypts the group key according to the second filling key to obtain a second encrypted ciphertext, and sends the second encrypted ciphertext to the second user terminal.

[0064] Optionally, the authentication request includes the user information and group information of the second user terminal;

[0065] The receiving the authentication request sent by the second key management system and determining whether the second user terminal has the permission to obtain the group key includes:

[0066] According to the user information and group information of the second user terminal, determine whether the user of the second user terminal has the permission to obtain the group key corresponding to the group information.

[0067] On the other hand, an embodiment of the present invention discloses a group key management device based on quantum key distribution and reverse authentication, which is applied to a first user terminal. The device includes:

[0068] A first request sending module, configured to send a group key creation request to the affiliated first key management system, so that the first key management system calls a quantum key distribution network to generate a group key according to the group key creation request;

[0069] A first key acquisition module, configured to receive the first key ciphertext sent by the first key management system, and decrypt the first key ciphertext according to the first filling key to obtain the group key; the first key ciphertext is obtained by the first key management system encrypting the group key according to the first filling key after receiving the group key;

[0070] A message encryption module, configured to encrypt the group message according to the group key, and send the encrypted group message to the service system, so that the service system sends the encrypted group message to at least one second user terminal in the group.

[0071] Optionally, the device further includes:

[0072] A second request sending module, configured to send an identity authentication request to the first key management system;

[0073] A first token receiving module, configured to receive the token of the first user terminal sent by the first key management system;

[0074] The first request sending module includes:

[0075] A first token sending sub-module, configured to send the group key creation request to the first key management system, where the group key creation request includes the token of the first user terminal.

[0076] On the other hand, an embodiment of the present invention discloses a group key management device based on quantum key distribution and reverse authentication, which is applied to a first key management system. The device includes:

[0077] A first request receiving module, configured to call a quantum key distribution network to create a group key according to a group key creation request sent by a first user terminal;

[0078] A first key encryption module, configured to receive the group key sent by the quantum key distribution network, and encrypt the group key according to a first filling key to obtain a first key ciphertext;

[0079] A first ciphertext sending module, configured to send the first key ciphertext to the first user terminal, so that the first user terminal decrypts the first key ciphertext according to the first filling key to obtain the group key, encrypts a group message according to the group key, and sends the encrypted group message to a service system.

[0080] Optionally, the device further includes:

[0081] A second request receiving module, configured to receive an identity authentication request sent by the first user terminal;

[0082] A first token sending module, configured to perform identity authentication processing on the first user terminal according to the identity authentication request, and send a token to the first user terminal after the identity authentication processing passes;

[0083] The first request receiving module includes:

[0084] A first token obtaining sub-module, configured to parse the received group key creation request to obtain the token of the first user terminal; and identify the user information of the first user terminal according to the token of the first user terminal.

[0085] On the other hand, an embodiment of the present invention discloses a group key management device based on quantum key distribution and reverse authentication, which is applied to a second user terminal. The device includes:

[0086] A first message receiving module, configured to receive a group message encrypted by a group key sent by a service system;

[0087] A third request sending module, configured to send a group key acquisition request to the second key management system to which it belongs, so that after receiving the group key acquisition request, the second key management system sends an authentication request to the service system;

[0088] A ciphertext acquisition module, configured to receive a second encrypted ciphertext sent by the second key management system after obtaining an authentication result; the authentication result is sent by the service system to the second key management system after receiving the authentication request and determining whether the second user terminal has the right to obtain the group key; the second encrypted ciphertext is obtained by the second key management system encrypting the group key according to a second filling key after receiving the authentication result;

[0089] A second key acquisition module, configured to decrypt the second encrypted ciphertext according to the second filling key to obtain the group key;

[0090] A message decryption module, configured to decrypt the encrypted group message by using the group key.

[0091] Optionally, the device further includes:

[0092] A fourth request sending module, configured to send an identity authentication request to the second key management system;

[0093] A second token receiving module, configured to receive a token of the second user terminal sent by the second key management system;

[0094] The third request sending module includes:

[0095] A second token sending sub-module, configured to send the group key acquisition request to the second key management system, where the group key acquisition request includes a token of the second user terminal.

[0096] On the other hand, an embodiment of the present invention discloses a group key management device based on quantum key distribution and reverse authentication, which is applied to a second key management system. The device includes:

[0097] A key receiving module, which receives a group key sent by a quantum key distribution network. The group key is generated by a first key management system to which a first user terminal belongs after receiving a group key creation request sent by the first user terminal and then invoking the quantum key distribution network.

[0098] A third request receiving module, which is used to receive a group key acquisition request sent by a second user terminal and send an authentication request to a service system. The group key acquisition request is sent by the second user terminal to a second key management system after receiving a group message encrypted by the group key sent by the service system.

[0099] A second key encryption module, which is used to receive an authentication result, encrypt the group key according to a second charging key to obtain a second encrypted ciphertext, and send the second encrypted ciphertext to the second user terminal, so that the second user terminal decrypts the second encrypted ciphertext according to the second charging key to obtain the group key, and decrypts the encrypted group message through the group key.

[0100] Optionally, the device further includes:

[0101] A fourth request receiving module, which is used to receive an identity authentication request sent by the second user terminal.

[0102] A second token sending module, which is used to perform identity authentication processing on the second user terminal according to the identity authentication request; and send a token to the second user terminal after the identity authentication processing passes.

[0103] The third request receiving module includes:

[0104] A first token acquisition sub-module, which parses the received group key acquisition request to obtain the token of the second user terminal; and identifies the user information of the second user terminal according to the token of the second user terminal.

[0105] On the other hand, an embodiment of the present invention discloses a group key management device based on quantum key distribution and reverse authentication, which is applied to a service system. The device includes:

[0106] A second message receiving module, which is used to receive a group message encrypted by a group key sent by a first user terminal.

[0107] A message sending module, which is used to send the encrypted group message to at least one second user terminal in the group.

[0108] An authentication module, configured to receive an authentication request sent by a second key management system, and determine whether the second user terminal has the permission to obtain the group key; the authentication request is sent by the second key management system to the service system after receiving a group key acquisition request sent by the second user terminal; the group key acquisition request is sent by the second user terminal to the second key management system to which it belongs after receiving the encrypted group message.

[0109] A result sending module, configured to send an authentication result to the second key management system, so that after obtaining the authentication result, the second key management system encrypts the group key with a second charging key to obtain a second encrypted ciphertext, and sends the second encrypted ciphertext to the second user terminal.

[0110] Optionally, the authentication request includes user information and group information of the second user terminal.

[0111] The authentication module includes:

[0112] A permission determination module, configured to determine whether the user of the second user terminal has the permission to obtain the group key corresponding to the group information according to the user information and group information of the second user terminal.

[0113] On the other hand, an embodiment of the present invention discloses an electronic device, including: a processor, a memory, and a computer program stored on the memory and capable of running on the processor, where when the computer program is executed by the processor, the steps of the group key management method based on quantum key distribution and reverse authentication as described above are implemented.

[0114] On the other hand, an embodiment of the present invention discloses a computer-readable storage medium, on which a computer program is stored, and when the computer program is executed by a processor, the steps of the group key management method based on quantum key distribution and reverse authentication as described above are implemented.

[0115] The embodiments of the present invention have the following advantages:

[0116] Before sending a group message, the user terminal sends a group key creation request to the key management system to obtain a group key, encrypts the group message with the group key and then sends it to the service system; the service system sends the encrypted group message to other user terminals; after receiving the encrypted group message, other user terminals send a group key creation request to the key management system to obtain a group key and decrypt the encrypted group message. In group communication, encrypting group messages with a group key reduces the possibility of group message leakage and improves the security of the system.

[0117] In addition, after receiving the group key acquisition request sent by the user terminal, the key management system sends an authentication request to the service system. After receiving the authentication request, the service system determines whether the user terminal has the permission to acquire the group key and sends the authentication result to the key management system. By transferring the transaction of authenticating the user terminal to the service system, the transaction complexity of the key management system is reduced, and the probability of errors and exceptions occurring during the operation of the system is decreased, thereby further improving the security of the system. BRIEF DESCRIPTION OF THE DRAWINGS

[0118] In order to more clearly illustrate the technical solutions of the embodiments of the present invention, the following will briefly introduce the drawings required for the description of the embodiments of the present invention. Obviously, the drawings in the following description are only some embodiments of the present invention, and those of ordinary skill in the art can obtain other drawings based on these drawings without creative efforts.

[0119] Figure 1 is a schematic structural diagram of a group key management system based on quantum key distribution and reverse authentication provided by an embodiment of the present invention;

[0120] Figure 2 is a flowchart of the steps of a group key management method based on quantum key distribution and reverse authentication provided by an embodiment of the present invention;

[0121] Figure 3 is a flowchart of the steps of another group key management method based on quantum key distribution and reverse authentication provided by an embodiment of the present invention;

[0122] Figure 4 is a flowchart of the steps of another group key management method based on quantum key distribution and reverse authentication provided by an embodiment of the present invention;

[0123] Figure 5 is a flowchart of the steps of another group key management method based on quantum key distribution and reverse authentication provided by an embodiment of the present invention;

[0124] Figure 6 is a flowchart of the steps of another group key management method based on quantum key distribution and reverse authentication provided by an embodiment of the present invention;

[0125] Figure 7 is a flowchart of the steps of another group key management method based on quantum key distribution and reverse authentication provided by an embodiment of the present invention;

[0126] Figure 8 is a schematic diagram of a group key management device based on quantum key distribution and reverse authentication provided by an embodiment of the present invention;

[0127] Figure 9 It is a schematic diagram of another group key management device provided by an embodiment of the present invention based on quantum key distribution and reverse authentication;

[0128] Figure 10 It is a schematic diagram of another group key management device provided by an embodiment of the present invention based on quantum key distribution and reverse authentication;

[0129] Figure 11 It is a schematic diagram of another group key management device provided by an embodiment of the present invention based on quantum key distribution and reverse authentication;

[0130] Figure 12 It is a schematic diagram of another group key management device provided by an embodiment of the present invention based on quantum key distribution and reverse authentication. Detailed implementation manners

[0131] To make the above objects, features, and advantages of the present invention more obvious and understandable, the present invention will be further described in detail below in conjunction with the accompanying drawings and specific implementation manners. Obviously, the described embodiments are part of the embodiments of the present invention, rather than all of the embodiments. All other embodiments obtained by those of ordinary skill in the art based on the embodiments of the present invention without creative efforts shall fall within the protection scope of the present invention.

[0132] In the related art, a group key management system usually manages the keys in a group and authenticates user terminals by a key management system. After the key management system determines that a user terminal has the permission to view group information through authentication, it sends the group key to the user terminal so that the user terminal can decrypt the encrypted group message through the group key and thus view the group message. Due to too many transactions to be processed, the logical complexity of the key management system increases, and the system is more likely to have errors and exceptions during operation, and it is also more likely to be discovered vulnerabilities and attacked, resulting in a reduction in the security of the system.

[0133] In an embodiment of the present invention, after receiving a group key acquisition request sent by a user terminal, the key management system sends an authentication request to the service system, and the service system determines whether the user terminal has the permission to acquire the group key. By transferring the transaction of authenticating the user terminal to the service system, the transaction complexity of the key management system is reduced.

[0134] The present invention provides a group key management system based on quantum key distribution and reverse authentication, and the system includes a first user terminal, a second user terminal, a first key management system, a second key management system, a service system, and a quantum key distribution network.

[0135] A group key management system is a complex system designed to ensure that multiple users within a group can securely share and exchange keys to meet the security requirements of group communication.

[0136] The group key is specifically generated for the group where the user terminal is located to ensure the encryption and security of internal group communication. The user terminal uses the group key to encrypt the group messages to be sent, making the encrypted group messages unreadable during transmission. Only the recipients with the same group key can decrypt and read them, that is, only group members can view the content of the group messages, preventing information leakage to unauthorized third parties and effectively improving the security of group messages.

[0137] In the group key management system, the user terminal can be an electronic device such as a mobile phone, a computer, or a tablet. The user uses this user terminal to send or receive group messages. The user terminal is built-in or externally connected with a quantum security chip.

[0138] A quantum security chip is a chip integrated with quantum security technology for storing quantum keys. Usually, the quantum keys stored in each quantum security chip and the quantum keys stored in the key management system are symmetric keys.

[0139] In the present invention, only to distinguish the sender and receiver of group messages, the user terminal that sends group messages is called the first user terminal, and the user terminal that receives group messages is called the second user terminal. In practical applications, each user terminal can be used to send and receive group messages.

[0140] The key management system can provide functions of encrypting and distributing quantum keys and authenticating user terminals. The key management system realizes data interaction with the user terminal and the service system through the network respectively.

[0141] The service system can receive group messages sent by group members and forward them to other group members. In practical applications, the service system can be an existing message receiving and sending platform, such as WeChat, DingTalk, and Feishu, etc., or other message receiving and sending service systems independently developed according to the group key management system. The present invention does not limit this.

[0142] The quantum key distribution network refers to a network composed of multiple quantum key distribution nodes connected by quantum key distribution links. In the quantum key distribution network, the two communicating parties can generate and share a random and secure key for encrypting and decrypting messages. This key distribution method is a secure communication protocol based on the principles of quantum mechanics. Utilizing the quantum no-cloning theorem and the uncertainty of quantum measurement, it ensures that the generated key cannot be stolen or copied during transmission. This feature makes it a theoretically uncrackable key distribution method.

[0143] During the group key generation process, the sender in the quantum key distribution network sends a series of qubits to the receiver through a quantum channel. Both parties randomly select measurement bases to receive and send qubits, and compare their base selections through a classical channel to retain the qubits with matching bases as potential keys. Finally, both parties extract the final, shorter, and secure key from the screened keys through information-theoretic methods.

[0144] Figure 1 It is a schematic structural diagram of a group key management system based on quantum key distribution and reverse authentication provided by an embodiment of the present invention.

[0145] The present invention provides a group key management system based on quantum key distribution and reverse authentication, as Figure 1 shown, the system includes: a first user terminal 10, a second user terminal 20, a first key management system 30, a second key management system 40, a service system 50, and a quantum key distribution network 60.

[0146] The first user terminal 10 is used to send a group key creation request to the affiliated first key management system 30, receive the first key ciphertext sent by the first key management system 30, and decrypt the first key ciphertext according to the first padding key to obtain the group key; encrypt the group message according to the group key, and send the encrypted group message to the service system 60;

[0147] The first key management system 20 is used to call the quantum key distribution network 60 to generate a group key according to the group key creation request, receive the group key sent by the quantum key distribution network 60, and encrypt the group key according to the first padding key to obtain the first key ciphertext, and send the first key ciphertext to the first user terminal 10;

[0148] The service system 30 is used to send the encrypted group message to at least one second user terminal 20 in the group, and determine whether the second user terminal 20 has the right to obtain the group key after receiving the authentication request sent by the second key management system 40 to which the second user terminal 20 belongs; send the authentication result to the second key management system 40;

[0149] The second user terminal 40 is used to send a group key acquisition request to the affiliated second key management system 40 after receiving the encrypted group message sent by the service system 50; receive the second encrypted ciphertext sent by the second key management system 40 after obtaining the authentication result; decrypt the second encrypted ciphertext according to the second padding key to obtain the group key; decrypt the encrypted group message through the group key;

[0150] The second key management system 50 is used to receive the group key sent by the quantum key distribution network 60; after receiving the group key acquisition request sent by the second user terminal 20, it sends an authentication request to the service system 50, and after receiving the authentication result, it encrypts the group key with the second infusion key to obtain the second encrypted ciphertext, and sends the second encrypted ciphertext to the second user terminal 20.

[0151] In the system provided by the embodiments of the present invention, before sending a group message, the user terminal sends a group key creation request to the key management system to obtain the group key, encrypts the group message with the group key and then sends it to the service system; the service system sends the encrypted group message to other user terminals; after receiving the encrypted group message, the other user terminals send a group key creation request to the key management system to obtain the group key and decrypt the encrypted group message. In group communication, encrypting the group message with the group key reduces the possibility of group message leakage and improves the security of the system.

[0152] In addition, after receiving the group key acquisition request sent by the user terminal, the key management system sends an authentication request to the service system. After receiving the authentication request, the service system determines whether the user terminal has the permission to obtain the group key and sends the authentication result to the key management system. By transferring the transaction of authenticating the user terminal to the service system, the transaction complexity of the key management system is reduced, and the probability of errors and exceptions occurring during the operation of the system is reduced, thereby further improving the security of the system.

[0153] Figure 2 It is a step flow chart of a group key management method based on quantum key distribution and reverse authentication provided by the embodiments of the present invention.

[0154] Combined with Figure 1 、 Figure 2 As shown, the first user terminal is used to send a group key creation request to the first key management system to which it belongs; the first key management system is used to call the quantum key distribution network to generate a group key according to the group key creation request;

[0155] In the group key management system, there are multiple key management systems, and one key management system can manage multiple user terminals. As Figure 2 shown, the first user terminal and the second user terminal belong to the first key management system and the second key management system respectively. In other embodiments, the first user terminal and the second user terminal may belong to the same key management system, and the present invention does not limit this.

[0156] In this embodiment, the first key management system distributes and manages the keys in the first user terminal. When the first user terminal needs to send a group message, it first sends a group key acquisition request to the first key management system to which it belongs to obtain the group key. The group message needs to be encrypted with the group key before it can be sent.

[0157] In some embodiments, the quantum key distribution network includes a first quantum key distribution network and a second quantum key distribution network; as Figure 2 shown, the first key management system and the second key management system belong to the first quantum key distribution network and the second quantum key distribution network respectively.

[0158] It should be noted that the naming of the first key management system and the second key management system in the present invention is only to distinguish the key management system to which the sending user belongs and the key management system to which the receiving user belongs. In actual applications, the sending user and the receiving user can belong to the same key management system, that is, the first key management system and the second key management system can be the same key management system, and the present invention does not limit this.

[0159] As described above, in other embodiments, the first key management system and the second key management system can belong to the same quantum key distribution network, and the present invention does not limit this.

[0160] In some embodiments, when the first key management system receives a group key creation request, it will call the first quantum key distribution network to generate the group key. After the first quantum key distribution network generates the group key, it sends the group key to the first key management system, and sends the group key to the second key management system to which at least one second user terminal in the group belongs through the second quantum distribution network node.

[0161] Specifically, the key management system first queries the business system for the key management systems to which all members of the group belong and the identification information of the key managers (Key Management, KM) to which they are connected. According to the KM identification information to which all members of the group belong, the KM to which it is connected initiates a key relay request to other KMs; the group key is securely relayed by the KM to the receiving KM through QKD, and then sent by the receiving KM to the corresponding key management system.

[0162] That is to say, both the first key management system and the second key management system will receive the group key sent by the quantum key distribution network.

[0163] In addition, the key management system will update the group key regularly to further enhance security and reduce the risk of the group key being cracked.

[0164] In this embodiment, whenever a user terminal needs to send a group message, it requests a group key once to enhance the security within the group. That is, the group key is updated every time a group message is sent. In other embodiments, the group key can also be updated at other frequencies, and the present invention does not limit this.

[0165] In some embodiments, the first key management system encrypts the group key according to the first injection key to obtain the first key ciphertext, and sends the first key ciphertext to the first user terminal; the first user terminal is used to receive the first key ciphertext sent by the first key management system and decrypt the first key ciphertext according to the first injection key to obtain the group key;

[0166] The first key ciphertext is obtained by encrypting the group key with the first injection key, so that the group key exists in the form of the first key ciphertext during transmission and is not easily directly obtained by interceptors.

[0167] In addition, the first key management system and the first user terminal share the first injection key. The injection key is securely injected into the quantum security chip and the quantum key management system by the quantum key injection module distributing (Quantum Key Distribution, QKD) the quantum key, so that the same injection key is securely stored in the user terminal and its affiliated key management system.

[0168] When the first user terminal receives the first key ciphertext, it also receives the relevant information of the first injection key. Therefore, the first user terminal can query and obtain the first injection key according to the relevant information of the first injection key, and then decrypt the first key ciphertext according to the first injection key to obtain the group key.

[0169] Specifically, when the first key management system sends the first key ciphertext to the first user terminal, it will send the key usage information of the first injection key to the first user terminal. The key usage information includes information such as the key identification block, key offset, and key length of the first injection key. So that the first user terminal can find the first injection key in the injection keys securely stored by it according to the received key usage information, and thus decrypt the first key ciphertext with the first injection key to obtain the group key.

[0170] In some embodiments, the first user terminal is used to encrypt the group message according to the group key and send the encrypted group message to the service system; the service system is used to send the encrypted group message to at least one second user terminal in the group;

[0171] Specifically, the business system packages the encrypted group messages into message packets and sends them to other user terminals in the group except the first user terminal, that is, the second user terminal, through a secure communication protocol. After receiving the message packet, the second user terminal sends a request to its affiliated second key management system to obtain the group key, and thus decrypts the content of the group message using the group key.

[0172] In practical applications, the business system can use technologies such as message authentication codes or digital signatures to sign and verify the encrypted group messages to ensure the reliability and integrity of message transmission. Before decrypting the group message, the second user terminal first verifies the integrity of the group message and the authenticity of the source, so as to avoid receiving tampered or forged group messages.

[0173] Through a series of encryption, packaging, and verification steps, the security of group messages during transmission is greatly enhanced.

[0174] In some embodiments, the second user terminal is configured to send a group key acquisition request to its affiliated second key management system after receiving the encrypted group message sent by the business system; the second key management system is configured to send an authentication request to the business system after receiving the group key acquisition request sent by the second user terminal;

[0175] In some embodiments, the business system is configured to determine whether the second user terminal has the permission to obtain the group key after receiving the authentication request sent by the second key management system affiliated to the second user terminal; send an authentication result to the second key management system; the second key management system is configured to encrypt the group key with the second injection key to obtain a second encrypted ciphertext after receiving the authentication result, and send the second encrypted ciphertext to the second user terminal;

[0176] In the group key management system, it is crucial to ensure that only user terminals with legitimate permissions can obtain the group key, which is directly related to the security and privacy protection of group messages. Therefore, before sending the group key, an authorization verification step is required to determine whether the user terminal has the permission to obtain the group key. If it is determined that the user terminal has the permission to obtain the group key, the encrypted group key will be securely transmitted to the user terminal so that the user terminal can read the corresponding group message.

[0177] In some embodiments, the authentication request includes the user information and group information of the second user terminal;

[0178] The authentication process is as follows: The service system parses the received authentication request to obtain the user information and group information of the second user terminal; based on the user information and group information of the second user terminal, it determines whether the user of the second user terminal has the permission to obtain the group key corresponding to the group information; if the user of the second user terminal has the permission to obtain the group key corresponding to the group information, the service system sends an authentication success message to the second key management system; if the user of the second user terminal does not have the permission to obtain the group key corresponding to the group information, the service system sends an authentication failure message to the second key management system.

[0179] Specifically, the service system will identify the member identifier of the second user terminal according to the user information of the second user terminal; according to the group information, identify the session identifier and group identifier, so as to verify whether the second user terminal belongs to the group and whether it has the permission to obtain the session. The verification process may involve calling the group management verification policy and user information library, etc., and finally determine whether the user of the second user terminal has the permission to obtain the group key corresponding to the group information.

[0180] If the user of the second user terminal has the permission to obtain the group key corresponding to the group information, the service system sends an authentication success message to the second key management system, so that the second key management system performs relevant instruction actions for subsequent group key distribution.

[0181] If the user of the second user terminal does not have the permission to obtain the group key corresponding to the group information, the service system sends an authentication failure message to the second key management system, so that the second key management system sends a group key acquisition failure notice to the second user terminal.

[0182] After receiving the authentication result, if the second key management system confirms that the user of the second user terminal has the permission to obtain the group key corresponding to the group information, it encrypts the group key with the second filling key to obtain the second encrypted ciphertext, and sends the second encrypted ciphertext to the second user terminal.

[0183] In some embodiments, the second user terminal is used to receive the second encrypted ciphertext sent by the second key management system after obtaining the authentication result; decrypt the second encrypted ciphertext according to the second filling key to obtain the group key; decrypt the encrypted group message with the group key;

[0184] The group key is encrypted by the second filling key to obtain the second encrypted ciphertext, so that the group key exists in the form of the second key ciphertext during transmission, and it is not easy for interceptors to directly obtain the group key.

[0185] Specifically, similar to the first user terminal decrypting the first key ciphertext, when the second key management system sends the second key ciphertext to the second user terminal, it will also send the key usage information of the second charging key to the second user terminal. The key usage information includes information such as the key identification block, key offset, and key length of the second charging key. This enables the second user terminal to find the second charging key in the charging keys securely stored by it according to the received key usage information, and thus decrypt the second key ciphertext through the second charging key to obtain the group key.

[0186] After the second user terminal obtains the group key, it decrypts the encrypted group message according to the group key to obtain the plaintext of the group message, so as to be able to read the message content sent by the first user terminal.

[0187] In some embodiments, the first user terminal is used to send an identity authentication request to the first key management system to obtain the token of the first user terminal sent by the first key management system after passing the identity authentication; the first key management system is used to receive the identity authentication request sent by the first user terminal; perform identity authentication processing on the first user terminal according to the identity authentication request, and send a token to the first user terminal after the identity authentication processing passes;

[0188] In order to securely access and use the key management system, the user terminal needs to perform identity authentication first to ensure that the user has the access right to obtain the key management system and the acquisition right to the corresponding resources.

[0189] The identity authentication request sent by the user terminal to the key management system contains information such as the terminal device identifier and the quantum security chip identifier. These information are packaged and encrypted to prevent being intercepted or tampered with during the transmission process. In other embodiments, the identity authentication request may also contain other identity information, and the present invention does not limit this.

[0190] After receiving the identity authentication request, the key management system will perform a series of identity authentication processing procedures to strictly verify the accuracy and validity of the identity information sent by the user terminal to ensure the correct user identity. After the user's identity information passes the identity authentication, the key management system generates a unique token and sends it to the user terminal.

[0191] The token is a security credential that represents the user's identity and access rights. The user can save the token and use it in subsequent interactions with the key management system to prove their identity and rights for operations such as obtaining and storing keys. This identity authentication mechanism not only improves the security of the system but also provides a convenient and efficient key management service for users.

[0192] In some embodiments, the first user terminal is used to send a group key creation request to the first key management system. The group key creation request includes a token of the first user terminal. The first key management system is used to parse the received group key creation request to obtain the token of the first user terminal, and identify the user information of the first user terminal according to the token of the first user terminal.

[0193] The group key creation request sent by the first user terminal to the first key management system includes the above-mentioned token of the first user terminal, enabling the first key management system to identify the user information of the first user terminal to authenticate its identity. Thus, while ensuring the communication security of the first key management system, the identity of the first user terminal can be quickly identified to complete the corresponding instruction actions in the group key creation request.

[0194] In some embodiments, the second user terminal is used to send an identity authentication request to the second key management system to obtain a token of the second user terminal sent by the second key management system after passing the identity authentication. The second key management system is used to receive the identity authentication request sent by the second user terminal, perform identity authentication processing on the second user terminal according to the identity authentication request, and send a token to the second user terminal after the identity authentication processing passes.

[0195] The second user terminal is used to send a group key acquisition request to the second key management system. The group key acquisition request includes a token of the second user terminal. The second key management system is used to parse the received group key acquisition request to obtain the token of the second user terminal, and identify the user information of the second user terminal according to the token of the second user terminal.

[0196] Similar to the identity authentication process between the above-mentioned first user terminal and the first key management system, it will not be elaborated here. After obtaining the token, the second user terminal sends a group key acquisition request to the second key management system. The group key acquisition request includes the token of the second user terminal, thereby ensuring the communication security of the second key management system while quickly identifying the identity of the second user terminal to complete the corresponding instruction actions in the group key acquisition request.

[0197] Figure 3 This is a step flowchart of a group key management method based on quantum key distribution and reverse authentication provided by an embodiment of the present invention.

[0198] As Figure 3 shown, an embodiment of the present invention provides a group key management method based on quantum key distribution and reverse authentication, which is applied to the first user terminal. The method includes:

[0199] Step 101: Send a group key creation request to the first key management system to which it belongs, so that the first key management system calls the quantum key distribution network to generate a group key according to the group key creation request.

[0200] When the first user terminal needs to send a group message, it will first send a group key acquisition request to the first key management system to which it belongs to obtain the group key, so that it can encrypt the group message with the group key and then send it.

[0201] Before step 101, this method further includes:

[0202] Send an identity authentication request to the first key management system; receive the token of the first user terminal sent by the first key management system;

[0203] The group key creation request sent to the first key management system includes the token of the first user terminal;

[0204] As an example, the identity authentication process includes:

[0205] 1) Securely load and store the same loading key in the user terminal and the key management system to which it belongs;

[0206] 2) The user terminal constructs network access identity identification information according to information such as the terminal device identifier and the quantum security chip identifier, selects the key Km in the quantum security chip to encrypt the network access identity identification information, and sends it to the key management system to which it belongs;

[0207] 3) The key management system reads the key Km according to the information sent by the user terminal, decrypts and verifies the received information; after the verification passes, the quantum key management system selects a new key Kn and generates verification data A at the same time, encrypts the verification data A with Kn, and sends the selected key Kn information and the ciphertext of the verification data A to the user terminal;

[0208] 4) The user terminal reads the key Kn according to the information sent by the key management system and decrypts it, so as to verify the verification data A returned by the key management system; after the verification passes, the terminal device generates verification data B, encrypts the verification data A and the verification data B with the key Kn to obtain verification data C, and sends the network access identity information and the verification data C to the key management system;

[0209] 5) The key management system uses the key Kn to verify the received verification data C. After the verification passes, it generates a token, encrypts the verification data A and the verification data B with the key Kn to obtain verification data D, generates a token integrity verification value according to the token with the key Kn, and sends the token, the verification data D and the token integrity verification value to the user terminal;

[0210] 6) The user terminal verifies the received verification data D and the token integrity verification value using the key Kn. After successful verification, the token is saved.

[0211] In the above process, the key management system binds the terminal device identifier of the user terminal to the chip identifier of the quantum security chip by storing the network access identifier information of the user terminal, thereby determining a unique user identifier and completing the identity authentication.

[0212] The verification data is used by the user terminal or the key management system to confirm the identity of the sender when receiving a message, and to confirm whether the information has been tampered with during transmission.

[0213] The identity authentication request sent by the user terminal to the key management system contains information such as the terminal device identifier and the quantum security chip identifier. This information is packaged and encrypted to prevent interception or tampering during transmission. In other embodiments, the identity authentication request may also contain other identity information, which is not limited in this invention.

[0214] The group key creation request sent by the first user terminal to the first key management system includes the above token of the first user terminal, thereby ensuring the communication security of the first key management system while being able to quickly identify the identity of the first user terminal and complete the corresponding instruction actions in the group key creation request.

[0215] After receiving the identity authentication request, the key management system performs a series of identity authentication processing procedures to strictly verify the accuracy and validity of the identity information sent by the user terminal, ensuring the correct user identity. After the user's identity information passes the identity authentication, the key management system generates a unique token and sends it to the user terminal.

[0216] The user proves their identity and permissions in subsequent interactions with the key management system by saving the token to perform operations such as obtaining and storing keys. This identity authentication mechanism not only improves the security of the system but also provides convenient and efficient key management services for users.

[0217] The group key creation request sent by the first user terminal to the first key management system includes the above token of the first user terminal, thereby ensuring the communication security of the first key management system while being able to quickly identify the identity of the first user terminal and complete the corresponding instruction actions in the group key creation request.

[0218] Step 102: Receive the first key ciphertext sent by the first key management system, and decrypt the first key ciphertext according to the first filling key to obtain the group key;

[0219] Among them, the first key ciphertext is obtained by the first key management system encrypting the group key according to the first filling key after receiving the group key.

[0220] The first key ciphertext is obtained by encrypting the group key with the first charging key, so that the group key exists in the form of the first key ciphertext during transmission and is not easily directly obtained by interceptors.

[0221] It should be noted that the first key management system and the first user terminal share the first charging key. The charging key is securely injected into the quantum security chip and the quantum key management system by the quantum key charging module distributing the quantum key generated by quantum key distribution, so that the user terminal and its affiliated key management system securely store the same charging key.

[0222] When the first user terminal receives the first key ciphertext, it also receives relevant information about the first charging key. Therefore, the first user terminal can query and obtain the first charging key according to the relevant information of the first charging key, and then decrypt the first key ciphertext according to the first charging key to obtain the group key.

[0223] Step 103, encrypt the group message according to the group key and send the encrypted group message to the service system, so that the service system sends the encrypted group message to at least one second user terminal in the group.

[0224] The first user terminal sends the encrypted group message to the service system, and the service system forwards it to the second user terminal in the group, so that the second user terminal responds to the received encrypted group message and performs subsequent instructions to decrypt the encrypted group message with the group key.

[0225] Figure 4 This is a step flowchart of a group key management method based on quantum key distribution and reverse authentication provided by an embodiment of the present invention.

[0226] As Figure 4 shown, an embodiment of the present invention provides a group key management method based on quantum key distribution and reverse authentication, which is applied to the first key management system. The method includes:

[0227] Step 201, according to the group key creation request sent by the first user terminal, call the quantum key distribution network to create a group key;

[0228] When the first key management system receives the group key creation request, it will call the quantum key distribution network to generate a group key. In the quantum key distribution network, the group key is generated through the transmission and measurement of quantum states. This process has unconditional security, and any attempt to eavesdrop will destroy the quantum state and thus be detected. Therefore, the group key generated through the quantum key distribution network has high security.

[0229] In addition, the group key generated by the quantum key distribution network will be sent to the key management system for further processing and management by the key management system.

[0230] Before step 201, the method further includes:

[0231] Receiving an identity authentication request sent by the first user terminal;

[0232] Performing identity authentication processing on the first user terminal according to the identity authentication request, and after the identity authentication processing is passed, sending a token to the first user terminal;

[0233] Parsing the received group key creation request to obtain the token of the first user terminal;

[0234] Identifying the user information of the first user terminal according to the token of the first user terminal.

[0235] In order to securely access and use the key management system, the user terminal needs to perform identity authentication first to ensure that the user has the access permission to the key management system and the acquisition permission for the corresponding resources.

[0236] After the first key management system receives the identity authentication request from the first user terminal, the identity authentication request usually contains the user's identity identification information. Then, the key management system will strictly verify this information to confirm the authenticity and legality of the user identity of the first user terminal. After the user's identity is confirmed, the first key management system will generate a unique token, which serves as a credential for the user to access the service subsequently, contains key information such as the user's identity information, access permission, and validity period, and is encrypted to ensure its security.

[0237] Subsequently, the first key management system sends the token back to the first user terminal through a secure communication channel. After receiving the token, the first user terminal will save it in the local secure storage and present the token when accessing the service subsequently to prove its identity and permission.

[0238] In this way, the key management system can not only ensure the authenticity of the user identity, but also quickly confirm the user's access permission through the token mechanism. This provides a secure and convenient access experience for the user, and at the same time avoids unauthorized access and potential security threats.

[0239] The token is a security credential that represents the user's identity and access permission. By introducing the token, the security of the system can be improved, and at the same time, a more convenient and efficient key management service can be provided for the user.

[0240] The group key creation request sent by the first user terminal to the first key management system includes the token of the first user terminal, so as to quickly identify the identity of the first user terminal while ensuring the communication security of the first key management system, and complete the corresponding instruction actions in the group key creation request.

[0241] Step 202: Receive the group key sent by the quantum key distribution network, and encrypt the group key according to the first filling key to obtain the first key ciphertext.

[0242] Specifically, the same filling key is securely stored in the first user terminal and its affiliated first key management system.

[0243] When the first key management system sends the first key ciphertext to the first user terminal, it will also send the key usage information of the first filling key to the first user terminal. The key usage information includes information such as the key identification block, key offset, and key length of the first filling key. This enables the first user terminal to find the first filling key in the securely stored filling key according to the received key usage information, and thus decrypt the first key ciphertext with the first filling key to obtain the group key.

[0244] Encrypting the group key with the first filling key makes the group key exist in the form of the first key ciphertext during transmission, and it is not easy for interceptors to directly obtain the group key, improving the security of the system.

[0245] Step 203: Send the first key ciphertext to the first user terminal, so that the first user terminal decrypts the first key ciphertext according to the first filling key to obtain the group key, encrypts the group message according to the group key, and sends the encrypted group message to the service system.

[0246] The first key management system sends the first key ciphertext to the first user terminal, so that the first user terminal can perform subsequent processing on the group message after obtaining the group key.

[0247] In this embodiment, whenever a user terminal needs to send a group message, it requests a group key once to enhance the security within the group. That is, different group keys are used for each sending of a group message. In other embodiments, other frequencies can also be adopted to update the group key, and the present invention does not limit this.

[0248] Figure 5 This is the step flowchart of a group key management method based on quantum key distribution and reverse authentication provided by an embodiment of the present invention.

[0249] As Figure 5As shown in the figure, an embodiment of the present invention provides a group key management method based on quantum key distribution and reverse authentication, which is applied to a second user terminal. The method includes:

[0250] Step 301: Receive a group message encrypted with a group key sent by a service system;

[0251] The encrypted group message is encrypted with the group key obtained by the above-mentioned first user terminal through a group key creation request.

[0252] In some embodiments, the second user terminal also receives the key identification information of the group key sent by the service system. The key identification information is used for the second key management system to identify the specific group key that the second user terminal requests to obtain when the second user terminal sends a group key acquisition request to the second key management system.

[0253] Step 302: Send a group key acquisition request to the second key management system to which it belongs, so that after receiving the group key acquisition request, the second key management system sends an authentication request to the service system;

[0254] The group key acquisition request sent by the second user terminal includes the token of the second user terminal and the key identification information of the group key, so that the second key management system can identify the user information of the second user terminal through the token of the second user terminal and identify the group information of the group key according to the key identification information of the group key.

[0255] The user information of the second user terminal is sent by the second key management system to the service system. The service system identifies the user identifier of the second user terminal according to the user information of the second user terminal, and identifies the group identifier and session identifier of the group key according to the group information, so as to determine whether the group and session to which the second user terminal belongs are consistent with the group and session to which the group key belongs, and determine whether the second user terminal has the right to obtain the group key.

[0256] Before step 302, the method further includes:

[0257] Send an identity authentication request to the second key management system; receive the token of the second user terminal sent by the second key management system.

[0258] In addition, the group key acquisition request sent to the second key management system includes the token of the second user terminal.

[0259] Similar to the identity authentication process of the first user terminal, it will not be elaborated here.

[0260] After obtaining the token, the second user terminal sends a group key acquisition request to the second key management system. The group key acquisition request includes the token of the second user terminal, ensuring the communication security of the second key management system while enabling quick identification of the identity of the second user terminal to complete the corresponding instruction actions in the group key acquisition request.

[0261] Step 303: Receive the second encrypted ciphertext sent by the second key management system after obtaining the authentication result.

[0262] Among them, the authentication result is sent by the service system to the second key management system after receiving the authentication request and determining whether the second user terminal has the permission to obtain the group key. The second encrypted ciphertext is obtained by the second key management system encrypting the group key with the second infusion key after receiving the authentication result.

[0263] Only after the second key management system receives the authentication result and determines that the second user terminal has the permission to obtain the group key, will it send the second encrypted ciphertext to the second key management system.

[0264] Step 304: Decrypt the second encrypted ciphertext with the second infusion key to obtain the group key.

[0265] Similar to the first key ciphertext, the second key ciphertext is obtained by encrypting the group key with the second infusion key, making the group key exist in the form of the second key ciphertext during transmission and not easily being directly obtained by interceptors.

[0266] When the second user terminal receives the second key ciphertext, it also receives the relevant information of the second infusion key. Therefore, the second user terminal can query the second infusion key based on the relevant information of the second infusion key and then decrypt the second key ciphertext with the second infusion key to obtain the group key.

[0267] Step 305: Decrypt the encrypted group message with the group key.

[0268] After the second user terminal obtains the group key, it decrypts the encrypted group message with the group key to obtain the plaintext of the group message, so as to be able to read the message content sent by the first user terminal.

[0269] Figure 6 This is the step flowchart of a group key management method based on quantum key distribution and reverse authentication provided by an embodiment of the present invention.

[0270] As Figure 6 shown, an embodiment of the present invention provides a group key management method based on quantum key distribution and reverse authentication, which is applied to the second key management system. The method includes:

[0271] Step 401: Receive the group key sent by the quantum key distribution network;

[0272] The group key is generated by the first key management system to which the first user terminal belongs after receiving the group key creation request sent by the first user terminal and then invoking the quantum key distribution network.

[0273] Step 402: Receive the group key acquisition request sent by the second user terminal and send an authentication request to the business system;

[0274] The group key acquisition request is sent by the second user terminal to the second key management system after receiving the group message encrypted by the group key sent by the business system.

[0275] After receiving the group key acquisition request sent by the second user terminal, the second key management system sends an authentication request to the business system. After receiving the authentication request, the business system determines whether the second user terminal has the permission to obtain the group key and sends the authentication result to the second key management system.

[0276] By transferring the transaction of authenticating the user terminal to the business system, the transaction complexity of the key management system is reduced, and the probability of errors and exceptions occurring during the operation of the system is decreased, thereby improving the security of the system.

[0277] Before step 402, the method further includes:

[0278] Receive the identity authentication request sent by the second user terminal; perform identity authentication processing on the second user terminal according to the identity authentication request; after the identity authentication processing is passed, send a token to the second user terminal.

[0279] The group key acquisition request received by the second key management system includes the token of the second user terminal, so that the user information of the second user terminal can be identified according to the token of the second user terminal.

[0280] Step 403: Receive the authentication result, obtain the second encrypted ciphertext by encrypting the group key with the second padding key, and send the second encrypted ciphertext to the second user terminal, so that the second user terminal decrypts the second encrypted ciphertext with the second padding key to obtain the group key and decrypts the encrypted group message with the group key.

[0281] When the second key management system sends the second key ciphertext to the second user terminal, it will also send the key usage information of the second charging key to the second user terminal. The key usage information includes information such as the key identification block, key offset, and key length of the second charging key. This enables the second user terminal to find the second charging key in the charging key securely stored by it according to the received key usage information, and thus decrypt the second key ciphertext through the second charging key to obtain the group key.

[0282] Encrypt the group key with the second charging key, so that the group key exists in the form of the second key ciphertext during transmission, and it is not easy for the interceptor to directly obtain the group key, improving the security of the system.

[0283] Figure 7 It is a step flow chart of a group key management method based on quantum key distribution and reverse authentication provided by an embodiment of the present invention.

[0284] As Figure 7 shown, an embodiment of the present invention provides a group key management method based on quantum key distribution and reverse authentication, which is applied to a service system. The method includes:

[0285] Step 501, receive the group message encrypted by the group key sent by the first user terminal;

[0286] After receiving the encrypted group message sent by the first user terminal, the service system packs the encrypted group message into a message packet and sends it to other user terminals in the group except the first user terminal, that is, the second user terminal, through a secure communication protocol.

[0287] After receiving the message packet, the second user terminal will send a request to its affiliated second key management system to obtain the group key, so as to decrypt and obtain the content of the group message by using the group key.

[0288] Step 502, send the encrypted group message to at least one second user terminal in the group;

[0289] In practical applications, the service system can use technologies such as message authentication codes or digital signatures to authenticate or sign the encrypted group message to ensure the reliability and integrity of message transmission. Before decrypting the group message, the second user terminal first verifies its message authentication code or digital signature to ensure the integrity and authenticity of the source of the group message, so as to avoid receiving tampered or forged group messages.

[0290] Step 503, receive the authentication request sent by the second key management system and determine whether the second user terminal has the permission to obtain the group key;

[0291] Among them, after the second key management system receives the group key acquisition request sent by the second user terminal, it sends an authentication request to the service system. The group key acquisition request is sent by the second user terminal to the second key management system to which it belongs after receiving the encrypted group message.

[0292] In some embodiments, the authentication request includes the user information and group information of the second user terminal; step 503 includes:

[0293] According to the user information and group information of the second user terminal, determine whether the user of the second user terminal has the permission to obtain the group key corresponding to the group information.

[0294] Specifically, the service system will identify the member identifier of the second user terminal according to the user information of the second user terminal; according to the group information, identify the session identifier and group identifier, so as to verify whether the second user terminal belongs to the group and whether it has the permission to obtain the session. The verification process may involve calling the group management verification policy and user information library, etc., and finally determine whether the user of the second user terminal has the permission to obtain the group key corresponding to the group information.

[0295] If the user of the second user terminal has the permission to obtain the group key corresponding to the group information, the service system sends an authentication success message to the second key management system, so that the second key management system performs subsequent related instructions for group key distribution.

[0296] If the user of the second user terminal does not have the permission to obtain the group key corresponding to the group information, the service system sends an authentication failure message to the second key management system, so that the second key management system sends a group key acquisition failure notice to the second user terminal.

[0297] Step 504, send the authentication result to the second key management system, so that after obtaining the authentication result, the second key management system encrypts the group key with the second charging key to obtain the second encrypted ciphertext, and sends the second encrypted ciphertext to the second user terminal.

[0298] After receiving the authentication result, if the second key management system confirms that the user of the second user terminal has the permission to obtain the group key corresponding to the group information, it encrypts the group key with the second charging key to obtain the second encrypted ciphertext, and sends the second encrypted ciphertext to the second user terminal.

[0299] In the embodiment of the present invention, after the second key management system receives the group key acquisition request sent by the second user terminal, it sends an authentication request to the service system. After receiving the authentication request, the service system determines whether the second user terminal has the permission to obtain the group key, and sends the authentication result to the second key management system.

[0300] By transferring the transaction of authenticating the user terminal to the service system, the transaction complexity of the key management system is reduced, and the probability of errors and exceptions occurring during the operation of the system is decreased, thereby improving the security of the system. In addition, the key management system encrypts the group key according to the authentication result and sends it to the user terminal, and the user terminal can obtain the group key only after decryption, further enhancing the security of the system.

[0301] It should be noted that, for the method embodiments, for the sake of simple description, they are all expressed as a series of action combinations. However, those skilled in the art should know that the embodiments of the present invention are not limited by the described action sequences, because according to the embodiments of the present invention, some steps can be carried out in other sequences or simultaneously. Secondly, those skilled in the art should also know that the embodiments described in the specification are all preferred embodiments, and the actions involved are not necessarily essential for the embodiments of the present invention.

[0302] Figure 8 It is a schematic diagram of a group key management device based on quantum key distribution and reverse authentication provided by an embodiment of the present invention.

[0303] As Figure 8 shown, an embodiment of the present invention provides a group key management device based on quantum key distribution and reverse authentication, which is applied to a first user terminal. The device includes:

[0304] A first request sending module 601, configured to send a group key creation request to the first key management system to which it belongs, so that the first key management system calls a quantum key distribution network to generate a group key according to the group key creation request;

[0305] When the first user terminal needs to send a group message, it will first send a group key acquisition request to the first key management system to which it belongs to obtain the group key, so that it can encrypt the group message with the group key and then send it.

[0306] A first key acquisition module 602, configured to receive the first key ciphertext sent by the first key management system, and decrypt the first key ciphertext according to the first filling key to obtain the group key; the first key ciphertext is obtained by the first key management system encrypting the group key according to the first filling key after receiving the group key;

[0307] When the first user terminal receives the first key ciphertext, it will also receive the relevant information of the first filling key. Therefore, the first user terminal can query the first filling key according to the relevant information of the first filling key, and then decrypt the first key ciphertext according to the first filling key to obtain the group key.

[0308] A message encryption module 603, configured to encrypt group messages according to the group key and send the encrypted group messages to a service system, so that the service system sends the encrypted group messages to at least one second user terminal in the group.

[0309] The first user terminal sends the encrypted group messages to the service system, and the service system forwards them to the second user terminals in the group, so that the second user terminals perform subsequent instructions in response to the received encrypted group messages, thereby obtaining the group key to decrypt the encrypted group messages.

[0310] In some embodiments, the apparatus further includes:

[0311] A second request sending module, configured to send an identity authentication request to the first key management system;

[0312] A first token receiving module, configured to receive the token of the first user terminal sent by the first key management system;

[0313] The identity authentication request sent by the user terminal to the key management system includes information such as the terminal device identifier and the quantum security chip identifier. These information are packaged and encrypted to prevent being intercepted or tampered with during transmission. In other embodiments, the identity authentication request may further include other identity information, which is not limited in the present invention.

[0314] In some embodiments, the first request sending module 601 includes:

[0315] A first token sending sub-module, configured to send the group key creation request to the first key management system, where the group key creation request includes the token of the first user terminal.

[0316] The group key creation request sent by the first user terminal to the first key management system includes the above-mentioned token of the first user terminal, so as to ensure the communication security of the first key management system while being able to quickly identify the identity of the first user terminal and complete the corresponding instruction actions in the group key creation request.

[0317] Figure 9 It is a schematic diagram of another group key management device based on quantum key distribution and reverse authentication provided by an embodiment of the present invention.

[0318] As Figure 9 shown, an embodiment of the present invention provides a group key management device based on quantum key distribution and reverse authentication, which is applied to a first key management system. The device includes:

[0319] The first request receiving module 701 is configured to call a quantum key distribution network to create a group key according to a group key creation request sent by a first user terminal;

[0320] When the first key management system receives a group key creation request, it will call a quantum key distribution network to generate a group key. In the quantum key distribution network, the group key is generated through the transmission and measurement of quantum states. This process has unconditional security, and any attempt to eavesdrop will destroy the quantum state and thus be detected. Therefore, the group key generated by the quantum key distribution network has high security.

[0321] The first key encryption module 702 is configured to receive the group key sent by the quantum key distribution network and encrypt the group key according to a first filling key to obtain a first key ciphertext;

[0322] When the first key management system sends the first key ciphertext to the first user terminal, it will also send the key usage information of the first filling key to the first user terminal. The key usage information includes information such as the key identification block, key offset, and key length of the first filling key. This enables the first user terminal to find the first filling key in the filling key securely stored by it according to the received key usage information, and thus decrypt the first key ciphertext with the first filling key to obtain the group key.

[0323] The first ciphertext sending module 703 is configured to send the first key ciphertext to the first user terminal, so that the first user terminal decrypts the first key ciphertext according to the first filling key to obtain the group key, encrypts a group message according to the group key, and sends the encrypted group message to a service system.

[0324] The first key management system sends the first key ciphertext to the first user terminal, so that the first user terminal can perform subsequent processing on the group message after obtaining the group key.

[0325] In some embodiments, the device further includes:

[0326] A second request receiving module, configured to receive an identity authentication request sent by the first user terminal;

[0327] A first token sending module, configured to perform identity authentication processing on the first user terminal according to the identity authentication request, and send a token to the first user terminal after the identity authentication processing passes;

[0328] In order to securely access and use the key management system, the user terminal needs to perform identity authentication first to ensure that the user has the access right to obtain the key management system and the acquisition right to the corresponding resources.

[0329] In some embodiments, the first request receiving module 701 includes:

[0330] A first token obtaining sub-module, configured to parse the received group key creation request to obtain the token of the first user terminal; and identify the user information of the first user terminal according to the token of the first user terminal.

[0331] The group key creation request sent by the first user terminal to the first key management system includes the above-mentioned token of the first user terminal, so as to quickly identify the identity of the first user terminal while ensuring the communication security of the first key management system, and complete the corresponding instruction actions in the group key creation request.

[0332] Figure 10 It is a schematic diagram of another group key management device based on quantum key distribution and reverse authentication provided by an embodiment of the present invention.

[0333] As Figure 10 shown, an embodiment of the present invention provides a group key management device based on quantum key distribution and reverse authentication, which is applied to a second user terminal. The device includes:

[0334] A first message receiving module 801, configured to receive a group message encrypted by a group key sent by a service system;

[0335] The encrypted group message is encrypted by the group key obtained by the above-mentioned first user terminal through a group key creation request.

[0336] A third request sending module 802, configured to send a group key obtaining request to the second key management system to which it belongs, so that after receiving the group key obtaining request, the second key management system sends an authentication request to the service system;

[0337] The group key obtaining request sent by the second user terminal includes the token of the second user terminal and the key identification information of the group key, so that the second key management system can identify the user information of the second user terminal through the token of the second user terminal, and identify the group information of the group key according to the key identification information of the group key.

[0338] A ciphertext obtaining module 803, configured to receive a second encrypted ciphertext sent by the second key management system after obtaining an authentication result; the authentication result is sent by the service system to the second key management system after receiving the authentication request and determining whether the second user terminal has the right to obtain the group key; the second encrypted ciphertext is obtained by the second key management system encrypting the group key according to a second charging key after receiving the authentication result;

[0339] After the second key management system receives the authentication result and determines that the second user terminal has the permission to obtain the group key, it will send the second encrypted ciphertext to the second key management system.

[0340] The second key acquisition module 804 is configured to decrypt the second encrypted ciphertext according to the second charging key to obtain the group key;

[0341] Similar to the first key ciphertext, the second key ciphertext is obtained by encrypting the group key with the second charging key, so that the group key exists in the form of the second key ciphertext during transmission and is not easily directly obtained by the interceptor.

[0342] When the second user terminal receives the second key ciphertext, it will also receive the relevant information of the second charging key. Therefore, the second user terminal can query and obtain the second charging key according to the relevant information of the second charging key, and then decrypt the second key ciphertext according to the second charging key to obtain the group key.

[0343] The message decryption module 805 is configured to decrypt the encrypted group message through the group key.

[0344] After the second user terminal obtains the group key, it decrypts the encrypted group message according to the group key to obtain the clear text of the group message, so as to be able to read the message content sent by the first user terminal.

[0345] In some embodiments, the device further includes:

[0346] The fourth request sending module is configured to send an identity authentication request to the second key management system;

[0347] The second token receiving module receives the token of the second user terminal sent by the second key management system.

[0348] In some embodiments, the third request sending module 802 includes:

[0349] The second token sending sub-module sends the group key acquisition request to the second key management system, and the group key acquisition request includes the token of the second user terminal.

[0350] Similar to the identity authentication process of the first user terminal, it will not be elaborated here.

[0351] After obtaining the token, the second user terminal sends a group key acquisition request to the second key management system. The group key acquisition request includes the token of the second user terminal, so as to ensure the communication security of the second key management system and be able to quickly identify the identity of the second user terminal to complete the corresponding instruction actions in the group key acquisition request.

[0352] Figure 11 It is a schematic diagram of another group key management device provided by an embodiment of the present invention based on quantum key distribution and reverse authentication.

[0353] As Figure 11 shown, an embodiment of the present invention provides a group key management device based on quantum key distribution and reverse authentication, which is applied to a second key management system. The device includes:

[0354] A key receiving module 901, which receives a group key sent by a quantum key distribution network. The group key is generated by a first key management system to which a first user terminal belongs after receiving a group key creation request sent by the first user terminal and invoking the quantum key distribution network.

[0355] A third request receiving module 902, which is used to receive a group key acquisition request sent by a second user terminal and send an authentication request to a service system. The group key acquisition request is sent by the second user terminal to the second key management system after receiving a group message encrypted by the group key sent by the service system.

[0356] After receiving the group key acquisition request sent by the second user terminal, the second key management system sends an authentication request to the service system. After receiving the authentication request, the service system determines whether the second user terminal has the right to acquire the group key and sends an authentication result to the second key management system.

[0357] A second key encryption module 903, which is used to receive the authentication result, encrypt the group key according to a second filling key to obtain a second encrypted ciphertext, and send the second encrypted ciphertext to the second user terminal, so that the second user terminal decrypts the second encrypted ciphertext according to the second filling key to obtain the group key, and decrypts the encrypted group message through the group key.

[0358] When the second key management system sends the second key ciphertext to the second user terminal, it will also send the key usage information of the second filling key to the second user terminal. The key usage information includes information such as the key identification block, key offset, and key length of the second filling key. So that the second user terminal can find the second filling key in the filling keys securely stored by it according to the received key usage information, and thus decrypt the second key ciphertext through the second filling key to obtain the group key.

[0359] In some embodiments, the device further includes:

[0360] A fourth request receiving module, which is used to receive an identity authentication request sent by the second user terminal;

[0361] A second token sending module, configured to perform identity authentication processing on the second user terminal according to the identity authentication request; and send a token to the second user terminal after the identity authentication processing is passed.

[0362] In some embodiments, the third request receiving module 902 includes:

[0363] A first token obtaining sub-module, configured to parse the received group key obtaining request to obtain the token of the second user terminal; and identify the user information of the second user terminal according to the token of the second user terminal.

[0364] Figure 12 It is a schematic diagram of another group key management device based on quantum key distribution and reverse authentication provided by an embodiment of the present invention.

[0365] As Figure 12 shown, an embodiment of the present invention provides a group key management device based on quantum key distribution and reverse authentication, which is applied to a service system. The device includes:

[0366] A second message receiving module 1001, configured to receive a group message encrypted by a group key sent by a first user terminal.

[0367] After the service system receives the encrypted group message sent by the first user terminal, it packages the encrypted group message into a message packet and sends it to other user terminals in the group except the first user terminal through a secure communication protocol, that is, the second user terminal.

[0368] A message sending module 1002, configured to send the encrypted group message to at least one second user terminal in the group.

[0369] In practical applications, the service system can use technologies such as message authentication codes or digital signatures to authenticate or sign the encrypted group message to ensure the reliability and integrity of message transmission. Before decrypting the group message, the second user terminal first verifies its message authentication code or digital signature to ensure the integrity and authenticity of the source of the group message, thereby avoiding receiving tampered or forged group messages.

[0370] An authentication module 1003, configured to receive an authentication request sent by a second key management system, and determine whether the second user terminal has the right to obtain the group key; the authentication request is sent by the second key management system to the service system after receiving the group key obtaining request sent by the second user terminal; the group key obtaining request is sent by the second user terminal to the second key management system to which it belongs after receiving the encrypted group message.

[0371] In some embodiments, the authentication request includes user information and group information of the second user terminal;

[0372] In some embodiments, the authentication module 1003 includes:

[0373] A permission determination module, configured to determine whether the user of the second user terminal has the permission to obtain the group key corresponding to the group information according to the user information and group information of the second user terminal.

[0374] Specifically, the service system will identify the member identifier of the second user terminal according to the user information of the second user terminal; and identify the session identifier and group identifier according to the group information, so as to verify whether the second user terminal belongs to the group and whether it has the permission to obtain the session. The verification process may involve invoking group management verification policies and user information databases, etc., and finally determine whether the user of the second user terminal has the permission to obtain the group key corresponding to the group information.

[0375] A result sending module 1004, configured to send an authentication result to the second key management system, so that after obtaining the authentication result, the second key management system encrypts the group key with the second charging key to obtain a second encrypted ciphertext, and sends the second encrypted ciphertext to the second user terminal.

[0376] If the user of the second user terminal has the permission to obtain the group key corresponding to the group information, the service system sends an authentication success message to the second key management system, so that the second key management system issues relevant instructions for subsequent group key distribution.

[0377] If the user of the second user terminal does not have the permission to obtain the group key corresponding to the group information, the service system sends an authentication failure message to the second key management system, so that the second key management system sends a group key acquisition failure notice to the second user terminal.

[0378] In the embodiments of the present invention, before sending a group message, the user terminal sends a group key creation request to the key management system to obtain the group key, encrypts the group message with the group key and then sends it to the service system; the service system sends the encrypted group message to other user terminals; after receiving the encrypted group message, other user terminals send a group key creation request to the key management system to obtain the group key and decrypt the encrypted group message. In group communication, encrypting group messages with group keys reduces the possibility of group message leakage and improves the security of the system.

[0379] In addition, after receiving the group key acquisition request sent by the user terminal, the key management system sends an authentication request to the service system. After receiving the authentication request, the service system determines whether the user terminal has the permission to acquire the group key and sends the authentication result to the key management system. By transferring the transaction of authenticating the user terminal to the service system, the transaction complexity of the key management system is reduced, and the probability of errors and exceptions occurring during the operation of the system is decreased, thereby further improving the security of the system.

[0380] An embodiment of the present invention further provides an electronic device, including a processor, a memory, and a computer program stored on the memory and capable of running on the processor. When the computer program is executed by the processor, it implements each process of the above-mentioned embodiment of the group key management method based on quantum key distribution and reverse authentication, and can achieve the same technical effects. To avoid repetition, it will not be elaborated here.

[0381] An embodiment of the present invention further provides a computer-readable storage medium. A computer program is stored on the computer-readable storage medium. When the computer program is executed by the processor, it implements each process of the above-mentioned embodiment of the group key management method based on quantum key distribution and reverse authentication, and can achieve the same technical effects. To avoid repetition, it will not be elaborated here.

[0382] Each embodiment in this specification is described in a progressive manner. The key point of each embodiment is to illustrate the differences from other embodiments. The same or similar parts among the embodiments can be referred to each other.

[0383] Those skilled in the art should understand that the embodiments of the present invention can be provided as a method, a device, or a computer program product. Therefore, the embodiments of the present invention can take the form of a complete hardware embodiment, a complete software embodiment, or an embodiment combining software and hardware aspects. Moreover, the embodiments of the present invention can take the form of a computer program product implemented on one or more computer-usable storage media (including but not limited to disk memories, CD-ROMs, optical memories, etc.) containing computer-usable program codes.

[0384] The embodiments of the present invention are described with reference to the flowcharts and / or block diagrams of the method, terminal device (system), and computer program product according to the embodiments of the present invention. It should be understood that each process and / or block in the flowcharts and / or block diagrams, and the combination of processes and / or blocks in the flowcharts and / or block diagrams can be implemented by computer program instructions. These computer program instructions can be provided to the processor of a general-purpose computer, a special-purpose computer, an embedded processor, or other programmable data processing terminal devices to generate a machine, so that the instructions executed by the processor of the computer or other programmable data processing terminal devices generate for implementing in the process Figure 1one or more processes and / or blocks Figure 1 a device for the functions specified in one or more blocks

[0385] These computer program instructions may also be stored in a computer-readable memory that can direct a computer or other programmable data processing terminal device to work in a specific manner, such that the instructions stored in the computer-readable memory produce a manufactured article including an instruction device that implements the functions in the process Figure 1 one or more processes and / or blocks Figure 1 specified in one or more blocks

[0386] These computer program instructions may also be loaded onto a computer or other programmable data processing terminal device, such that a series of operational steps are executed on the computer or other programmable terminal device to produce a computer-implemented process, thereby providing instructions for implementing the functions specified in the process Figure 1 one or more processes and / or blocks Figure 1 specified in one or more blocks

[0387] Although the preferred embodiments of the embodiments of the present invention have been described, those skilled in the art can make additional changes and modifications once they learn the basic creative concept. Therefore, the appended claims are intended to be construed as including the preferred embodiments and all changes and modifications falling within the scope of the embodiments of the present invention

[0388] Finally, it should also be noted that in this text, relational terms such as first and second are only used to distinguish one entity or operation from another entity or operation, and do not necessarily require or imply any such actual relationship or order between these entities or operations. Moreover, the term "comprising", "including" or any other variant thereof is intended to cover non-exclusive inclusion, such that a process, method, article or terminal device comprising a series of elements includes not only those elements but also other elements not expressly listed, or elements inherent to such process, method, article or terminal device. Without further limitation, an element defined by the statement "comprising an..." does not exclude the presence of additional identical elements in the process, method, article or terminal device comprising the element

[0389] The above has introduced in detail a group key management system, method, device, electronic device and computer-readable storage medium provided by the present invention. Specific examples are used in this article to elaborate on the principle and implementation manner of the present invention. The description of the above embodiments is only used to help understand the method of the present invention and its core idea; at the same time, for those of ordinary skill in the art, according to the idea of the present invention, there will be changes in the specific implementation manner and application scope. In summary, the content of this specification should not be construed as a limitation to the present invention.

Claims

1. A group key management system based on quantum key distribution and reverse authentication, characterized in that: include: A first user terminal, a second user terminal, a first key management system, a second key management system, a service system, and a quantum key distribution network; The first user terminal is configured to send a group key creation request to the first key management system to which it belongs, receive a first key ciphertext sent by the first key management system, decrypt the first key ciphertext according to a first charging key to obtain a group key; encrypt a group message according to the group key, and send the encrypted group message to the service system; The first key management system is configured to call the quantum key distribution network to generate the group key according to the group key creation request, receive the group key sent by the quantum key distribution network, encrypt the group key according to the first injection key to obtain the first key ciphertext, and send the first key ciphertext to the first user terminal; The service system is used to send the encrypted group message to at least one of the second user terminals in the group, and after receiving an authentication request sent by the second key management system to which the second user terminal belongs, determine whether the second user terminal has the authority to obtain the group key; Sending the authentication result to the second key management system; The second user terminal is configured to send a group key acquisition request to the second key management system to which it belongs after receiving the encrypted group message sent by the business system; and receive a second encrypted ciphertext sent by the second key management system after obtaining the authentication result; decrypting the second encrypted ciphertext according to the second charging key to obtain the group key; decrypting the encrypted group message using the group key; The second key management system is used to receive the group key sent by the quantum key distribution network; After receiving the group key acquisition request sent by the second user terminal, the authentication request is sent to the business system, and after receiving the authentication result, the group key is encrypting according to the second injection key to obtain the second encrypted ciphertext, and the second encrypted ciphertext is sent to the second user terminal.

2. The system according to claim 1, characterized in that The authentication request includes user information and group information of the second user terminal; The business system is used to parse the received authentication request to obtain user information and group information of the second user terminal; determining, according to the user information and group information of the second user terminal, whether the user of the second user terminal has permission to obtain the group key corresponding to the group information; If the user of the second user terminal has the authority to obtain the group key corresponding to the group information, the business system sends an authentication success message to the second key management system; If the user of the second user terminal does not have the authority to obtain the group key corresponding to the group information, the business system sends authentication failure information to the second key management system.

3. The system according to claim 1, characterized in that The first user terminal is used to send an identity authentication request to the first key management system, so as to obtain a token of the first user terminal sent by the first key management system after passing the identity authentication; Sending the group key creation request to the first key management system, wherein the group key creation request includes a token of the first user terminal; The first key management system is configured to receive an identity authentication request sent by the first user terminal; perform identity authentication processing on the first user terminal according to the identity authentication request, and send a token to the first user terminal after the identity authentication processing passes; Parsing the received group key creation request to obtain a token of the first user terminal; According to the token of the first user terminal, user information of the first user terminal is identified.

4. The system according to claim 1, characterized in that The second user terminal is used to send an identity authentication request to the second key management system, so as to obtain a token of the second user terminal sent by the second key management system after passing the identity authentication; Sending the group key acquisition request to the second key management system, where the group key acquisition request includes the token of the second user terminal; The second key management system is configured to receive an identity authentication request sent by the second user terminal; perform identity authentication processing on the second user terminal according to the identity authentication request, and send a token to the second user terminal after the identity authentication processing passes; Parsing the received group key acquisition request to obtain a token of the second user terminal; According to the token of the second user terminal, user information of the second user terminal is identified.

5. The system according to claim 1, characterized in that The quantum key distribution network includes a first quantum key distribution network and a second quantum key distribution network; The first quantum key distribution network is used to generate the group key, send the group key to the first key management system, and send the group key to a second key management system to which at least one second user terminal in the group belongs through a second quantum key distribution network node.

6. A group key management method based on quantum key distribution and reverse authentication, characterized in that: Applied to a first user terminal, the method includes: Sending a group key creation request to the first key management system to which it belongs, so that the first key management system calls a quantum key distribution network to generate a group key according to the group key creation request; receiving a first key ciphertext sent by the first key management system, and decrypting the first key ciphertext according to a first charging key to obtain the group key; the first key ciphertext is obtained by encrypting the group key according to the first charging key after the first key management system receives the group key; The group message is encrypted according to the group key, and the encrypted group message is sent to the service system, so that the service system sends the encrypted group message to at least one second user terminal in the group.

7. The method according to claim 6, characterized in that The method further comprises: Sending an identity authentication request to the first key management system; Receiving a token of the first user terminal sent by the first key management system; The sending a group key creation request to the first key management system includes: The group key creation request is sent to the first key management system, where the group key creation request includes a token of the first user terminal.

8. A group key management method based on quantum key distribution and reverse authentication, characterized in that: Applied to a first key management system, the method comprises: Invoke a quantum key distribution network to create a group key according to a group key creation request sent by the first user terminal; Receiving the group key sent by the quantum key distribution network, and encrypting the group key according to the first injection key to obtain a first key ciphertext; The first key ciphertext is sent to the first user terminal, so that the first user terminal decrypts the first key ciphertext according to the first charging key to obtain the group key, encrypts the group message according to the group key, and sends the encrypted group message to the service system.

9. The method according to claim 8, characterized in that The method further comprises: Receiving an identity authentication request sent by the first user terminal; Performing identity authentication processing on the first user terminal according to the identity authentication request, and sending a token to the first user terminal after the identity authentication processing passes; The step of invoking a quantum key distribution network to create a group key according to a group key creation request sent by the first user terminal includes: The received group key creation request is parsed to obtain a token of the first user terminal; and user information of the first user terminal is identified according to the token of the first user terminal.

10. A group key management method based on quantum key distribution and reverse authentication, characterized in that: Applied to a second user terminal, the method includes: Receive a group message encrypted by a group key sent by a business system; Sending a group key acquisition request to the second key management system to which it belongs, so that the second key management system sends an authentication request to the business system after receiving the group key acquisition request; receiving a second encrypted ciphertext sent by the second key management system after obtaining an authentication result; the authentication result is sent to the second key management system by the service system after receiving the authentication request and determining whether the second user terminal has the authority to obtain the group key; the second encrypted ciphertext is obtained by the second key management system after receiving the authentication result and encrypting the group key according to the second charging key; decrypting the second encrypted ciphertext according to the second charging key to obtain the group key; The encrypted group message is decrypted by using the group key.

11. The method according to claim 10, characterized in that The method further comprises: Sending an identity authentication request to the second key management system; receiving a token of the second user terminal sent by the second key management system; The sending a group key acquisition request to the second key management system includes: The group key acquisition request is sent to the second key management system, where the group key acquisition request includes the token of the second user terminal.

12. A group key management method based on quantum key distribution and reverse authentication, characterized in that: Applied to the second key management system, the method comprises: Receiving a group key sent by a quantum key distribution network, where the group key is generated by a first key management system to which a first user terminal belongs, calling the quantum key distribution network after receiving a group key creation request sent by the first user terminal; receiving a group key acquisition request sent by a second user terminal, and sending an authentication request to the service system, wherein the group key acquisition request is sent by the second user terminal to the second key management system after receiving a group message encrypted by the group key sent by the service system; Receive the authentication result, encrypt the group key according to the second injection key to obtain a second encrypted ciphertext, send the second encrypted ciphertext to the second user terminal, so that the second user terminal decrypts the second encrypted ciphertext according to the second injection key to obtain the group key, and decrypts the encrypted group message by using the group key.

13. The method according to claim 12, characterized in that The method further comprises: receiving an identity authentication request sent by the second user terminal; Performing identity authentication processing on the second user terminal according to the identity authentication request, and sending a token to the second user terminal after the identity authentication processing passes; The receiving a group key acquisition request sent by the second user terminal includes: The received group key acquisition request is parsed to obtain a token of the second user terminal; and user information of the second user terminal is identified according to the token of the second user terminal.

14. A group key management method based on quantum key distribution and reverse authentication, characterized in that: Applied to a business system, the method comprises: receiving a group message encrypted by a group key and sent by a first user terminal; sending the encrypted group message to at least one second user terminal in the group; receiving an authentication request sent by a second key management system, and determining whether the second user terminal has the authority to obtain the group key; the authentication request is sent to the service system by the second key management system after receiving the group key acquisition request sent by the second user terminal; the group key acquisition request is sent to the second key management system to which the second user terminal belongs after receiving the encrypted group message; The authentication result is sent to the second key management system, so that after obtaining the authentication result, the second key management system encrypts the group key according to the second injection key to obtain a second encrypted ciphertext, and sends the second encrypted ciphertext to the second user terminal.

15. The method according to claim 14, characterized in that The authentication request includes user information and group information of the second user terminal; The receiving the authentication request sent by the second key management system and determining whether the second user terminal has the authority to obtain the group key includes: According to the user information and group information of the second user terminal, it is determined whether the user of the second user terminal has the authority to obtain the group key corresponding to the group information.

16. A group key management device based on quantum key distribution and reverse authentication, characterized in that: Applied to a first user terminal, the device includes: A first request sending module, configured to send a group key creation request to a first key management system to which it belongs, so that the first key management system calls a quantum key distribution network to generate a group key according to the group key creation request; a first key acquisition module, configured to receive a first key ciphertext sent by the first key management system, and decrypt the first key ciphertext according to a first charging key to obtain the group key; the first key ciphertext is obtained by encrypting the group key according to the first charging key after the first key management system receives the group key; The message encryption module is used to encrypt the group message according to the group key, and send the encrypted group message to the service system, so that the service system sends the encrypted group message to at least one second user terminal in the group.

17. The device according to claim 16, characterized in that The device also includes: A second request sending module, used to send an identity authentication request to the first key management system; A first token receiving module, configured to receive a token of the first user terminal sent by the first key management system; The first request sending module includes: The first token sending submodule is configured to send the group key creation request to the first key management system, where the group key creation request includes the token of the first user terminal.

18. A group key management device based on quantum key distribution and reverse authentication, characterized in that: Applied to a first key management system, the device comprises: A first request receiving module, configured to call a quantum key distribution network to create a group key according to a group key creation request sent by a first user terminal; A first key encryption module, used to receive the group key sent by the quantum key distribution network, and encrypt the group key according to a first injection key to obtain a first key ciphertext; The first ciphertext sending module is used to send the first key ciphertext to the first user terminal, so that the first user terminal decrypts the first key ciphertext according to the first charging key to obtain the group key, encrypts the group message according to the group key, and sends the encrypted group message to the service system.

19. The device according to claim 18, characterized in that The device also includes: A second request receiving module, used to receive an identity authentication request sent by the first user terminal; A first token sending module, configured to perform identity authentication processing on the first user terminal according to the identity authentication request, and send a token to the first user terminal after the identity authentication processing is passed; The first request receiving module includes: The first token acquisition submodule is used to parse the received group key creation request to obtain the token of the first user terminal; and identify the user information of the first user terminal according to the token of the first user terminal.

20. A group key management device based on quantum key distribution and reverse authentication, characterized in that: Applied to a second user terminal, the device includes: A first message receiving module, used to receive a group message encrypted by a group key sent by a business system; A third request sending module, used to send a group key acquisition request to the second key management system to which it belongs, so that the second key management system sends an authentication request to the business system after receiving the group key acquisition request; a ciphertext acquisition module, configured to receive a second encrypted ciphertext sent by the second key management system after obtaining an authentication result; the authentication result is sent to the second key management system by the service system after receiving the authentication request and determining whether the second user terminal has the authority to obtain the group key; the second encrypted ciphertext is obtained by the second key management system after receiving the authentication result and encrypting the group key according to the second charging key; A second key acquisition module, configured to decrypt the second encrypted ciphertext according to the second charging key to obtain the group key; The message decryption module is used to decrypt the encrypted group message using the group key.

21. The device according to claim 20, characterized in that The device also includes: A fourth request sending module, used to send an identity authentication request to the second key management system; A second token receiving module, receiving a token of the second user terminal sent by the second key management system; The third request sending module includes: The second token sending submodule sends the group key acquisition request to the second key management system, where the group key acquisition request includes the token of the second user terminal.

22. A group key management device based on quantum key distribution and reverse authentication, characterized in that: Applied to the second key management system, the device comprises: A key receiving module receives a group key sent by a quantum key distribution network, wherein the group key is generated by a first key management system to which a first user terminal belongs, after receiving a group key creation request sent by the first user terminal, by calling the quantum key distribution network; a third request receiving module, configured to receive a group key acquisition request sent by a second user terminal, and send an authentication request to the service system, wherein the group key acquisition request is sent by the second user terminal to the second key management system after receiving a group message encrypted by the group key sent by the service system; The second key encryption module is used to receive the authentication result, encrypt the group key according to the second injection key to obtain a second encrypted ciphertext, and send the second encrypted ciphertext to the second user terminal so that the second user terminal decrypts the second encrypted ciphertext according to the second injection key to obtain the group key, and decrypts the encrypted group message by the group key.

23. The device according to claim 22, characterized in that The device also includes: A fourth request receiving module, configured to receive an identity authentication request sent by the second user terminal; A second token sending module, configured to perform identity authentication processing on the second user terminal according to the identity authentication request; after the identity authentication processing is passed, send a token to the second user terminal; The third request receiving module includes: The first token acquisition submodule parses the received group key acquisition request to obtain a token of the second user terminal; and identifies user information of the second user terminal according to the token of the second user terminal.

24. A group key management device based on quantum key distribution and reverse authentication, characterized in that: Applied to a business system, the device comprises: A second message receiving module, configured to receive a group message encrypted by a group key and sent by a first user terminal; A message sending module, used to send the encrypted group message to at least one second user terminal in the group; an authentication module, configured to receive an authentication request sent by a second key management system, and determine whether the second user terminal has the authority to obtain the group key; the authentication request is sent to the business system by the second key management system after receiving the group key acquisition request sent by the second user terminal; the group key acquisition request is sent to the second key management system to which the second user terminal belongs after receiving the encrypted group message; The result sending module is used to send the authentication result to the second key management system, so that after obtaining the authentication result, the second key management system encrypts the group key according to the second injection key to obtain the second encrypted ciphertext, and sends the second encrypted ciphertext to the second user terminal.

25. The device according to claim 24, characterized in that The authentication request includes user information and group information of the second user terminal; The identification module comprises: The authority determination module is used to determine whether the user of the second user terminal has the authority to obtain the group key corresponding to the group information according to the user information and group information of the second user terminal.

26. An electronic device, characterized in that: include: A processor, a memory, and a computer program stored in the memory and capable of running on the processor, wherein when the computer program is executed by the processor, the steps of the group key management method based on quantum key distribution and reverse authentication as described in any one of claims 6-7 or 8-9 or 10-11 or 12-13 or 14-15 are implemented.

27. A computer-readable storage medium, characterized in that: The computer-readable storage medium stores a computer program, and when the computer program is executed by the processor, the steps of the group key management method based on quantum key distribution and reverse authentication as described in any one of claims 6-7 or 8-9 or 10-11 or 12-13 or 14-15 are implemented.

Citation Information

Cited By

  • Workflow authority control method and system based on quantum encryption mechanism

    CN121150950A