A quantum encryption communication method, a communication system, a storage medium and an electronic device
By dynamically matching encryption algorithms and updating keys in real time, and using quantum random numbers as keys, the problems of technical complexity, high cost, and poor compatibility in quantum communication are solved, achieving high security and compatibility while reducing implementation costs.
Patent Information
- Application Number
- CN202510594210.6
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2025-05-09
- Publication Date
- 2026-03-03
- Estimated Expiration
- 2045-05-09
AI Technical Summary
Existing quantum communication suffers from technical complexity, high cost, poor compatibility, and insufficient security, especially when post-quantum cryptography algorithms are incompatible with traditional communication systems, and pseudo-random number generators are vulnerable to attack in quantum computing environments.
By dynamically matching encryption algorithms and updating keys in real time when establishing communication between clusters or between external network devices and clusters, using quantum random numbers as keys, and combining them with traditional public-key algorithms, compatibility and security are ensured.
It reduces implementation costs and complexity, improves key security and unpredictability, enhances resistance to quantum attacks, and is compatible with existing communication equipment and facilities without requiring large-scale modifications.
Smart Images

Figure CN120150950B_ABST
Abstract
Description
Technical Field
[0001] This disclosure relates to the field of quantum encrypted communication, and in particular to a quantum encrypted communication method, communication system, storage medium and electronic device. Background Technology
[0002] With the rapid development of quantum computing technology, traditional public-key encryption algorithms face unprecedented challenges. The security of traditional public-key encryption algorithms mainly relies on the complexity of specific mathematical problems. However, quantum computers can effectively solve these problems in polynomial time using quantum algorithms, rendering currently widely used encryption technologies insecure.
[0003] In practical applications, many network communication scenarios require secure key distribution, data transmission, and SMS verification code services. Quantum-resistant key distribution falls into two categories: one is key distribution via quantum key distribution networks (QKD), but this method is technically complex, costly, and still immature; the other is key distribution based on post-quantum cryptography (PQC). Existing technologies directly embed PQC algorithms into communication protocols, but due to significant differences between PQC and traditional cryptographic algorithms, incompatibility issues may arise with existing communication system architectures and protocol stacks. Alternatively, two key distribution algorithms can be used simultaneously, leveraging hybrid dual certificates to achieve quantum-resistant communication. However, this requires designing new key distribution algorithms and certificate management systems to support both algorithms and hybrid certificate verification. This approach increases computational and communication burdens, impacting system performance, and necessitates significant modifications to existing infrastructure to support hybrid certificates and both key distribution algorithms, potentially leading to compatibility issues and additional infrastructure modification costs. Furthermore, when generating keys, pseudo-random numbers generated using pseudo-random number generators may lack sufficient randomness in a quantum computing environment, making the generated random numbers easily predictable and vulnerable to attack, thus affecting security. Summary of the Invention
[0004] To address the shortcomings of existing quantum communication methods, this disclosure proposes a quantum encrypted communication method, communication system, storage medium, and electronic device, which reduces implementation costs and complexity, and improves key security and unpredictability.
[0005] To achieve the above objectives, this disclosure provides a quantum encrypted communication method, comprising:
[0006] Receive communication requests, the types of which include those for establishing communication connections between clusters or between external network-side devices and clusters;
[0007] Based on the type of the communication request, the corresponding communication mechanism is executed, wherein...
[0008] When the communication mechanism is an inter-cluster communication mechanism, a real-time updated or real-time valid symmetric key is selected for encrypted communication between the clusters.
[0009] When the communication mechanism is the communication mechanism between the external network side device and the cluster, a dynamic matching encryption algorithm is used to perform encrypted communication between the external network side device and the cluster.
[0010] Optionally, the method for selecting a symmetric key that is updated in real time includes: when the first device on the cluster information receiving side determines that the symmetric key is invalid, it initiates a key update request to the second device on the cluster information initiating side. The key update request is used to enable the second device to generate a new key, encrypt the new key, and send it to the first device. The first device and the second device then distribute the new key to the corresponding clusters to establish encrypted communication between the clusters.
[0011] Optionally, the method for dynamically matching encryption algorithms includes: the first device on the cluster information receiving side identifies the public key algorithm type in the communication request, and selects the corresponding type of traditional public key algorithm or post-quantum cryptography algorithm to establish encrypted communication between the external network side device and the cluster.
[0012] This disclosure also provides a quantum encrypted communication method for inter-cluster communication, wherein the first device on the cluster information receiving side includes the following steps:
[0013] Receive a communication request from the cluster information sending side, wherein the communication request is used to establish a communication connection between the clusters of the cluster information sending side and the cluster information receiving side;
[0014] Analyze the communication request to determine if a valid key exists.
[0015] If so, the communication request is sent to the cluster information receiving side so that the cluster information receiving side and the cluster information sending side can establish a communication connection using the valid key;
[0016] If not, a new key is obtained in real time, and a communication connection is established after the new key is obtained on both the cluster information receiving side and the cluster information sending side.
[0017] Optionally, the method for the first device to update and obtain the new key includes:
[0018] The first device on the cluster information receiving side initiates a key update request to the second device on the cluster information initiating side;
[0019] The update request is used to enable the second device to obtain a random number and generate a new key based on the random number. After encrypting the data using the public key of the first device, the encrypted data is sent to the first device, which then decrypts the encrypted data to obtain the new key.
[0020] Optionally, after establishing a communication connection between the cluster information receiving side and the cluster information sending side, data transmission is performed by matching the corresponding tunnel mode or transmission mode based on the data transmission scenario.
[0021] This disclosure also provides a quantum encrypted communication method for inter-cluster communication, comprising the following steps in a second device on the cluster information sending side:
[0022] A communication request is sent to the cluster information receiving side, wherein the communication request is used to establish a communication connection between the cluster information sending side and the cluster information receiving side.
[0023] The communication request is analyzed by the first device on the cluster information receiving side to determine whether a valid key exists;
[0024] If so, a communication connection is established between the cluster information receiving side and the cluster information sending side using the valid key;
[0025] If not, a new key is generated in real time, and a communication connection is established after the new key is obtained by the cluster information receiving side and the cluster information sending side.
[0026] Optionally, the method by which the second device generates a new key in real time includes:
[0027] The device receives a key update request sent by the first device. The update request is used to enable the second device to obtain a random number and generate a new key based on the random number. The second device then encrypts the data using the public key of the first device and sends the encrypted data to the first device. The first device then decrypts the encrypted data to obtain the new key.
[0028] Optionally, after establishing a communication connection between the cluster information receiving side and the cluster information sending side, data transmission is performed by matching the corresponding tunnel mode or transmission mode based on the data transmission scenario.
[0029] This disclosure also provides a quantum encrypted communication method for communication between an external network-side device and a cluster, wherein the first device on the cluster side includes the following steps:
[0030] Receive a communication request sent by an external network-side device, wherein the communication request is used to enable the external network-side device to establish a communication connection with the cluster;
[0031] The communication request is analyzed to identify the public key algorithm type in the communication request;
[0032] Based on the public key algorithm type, the corresponding traditional public key algorithm or post-quantum cryptography algorithm is dynamically selected to enable communication between the external network-side device and the cluster.
[0033] Optionally, when selecting a post-quantum cryptography algorithm based on the public key algorithm type, the method for establishing a communication connection between the cluster and the external network-side device includes:
[0034] The first device sends a key negotiation request to the external network-side device, the key negotiation request being used to enable the external network-side device to use the first device's public key to generate a session key using the post-quantum cryptography algorithm;
[0035] After receiving the encrypted session key and verifying its correctness, the decrypted session key is distributed to the cluster.
[0036] Optionally, after receiving the encrypted session key and verifying its correctness, the first device distributes the decrypted session key to the cluster and then clears the session key.
[0037] This disclosure also provides a quantum encrypted communication method for communication between an external network-side device and a cluster, wherein the method includes the following steps:
[0038] A communication request is sent to the cluster side, wherein the communication request is used to enable an external network-side device to establish a communication connection with the cluster, and is used to analyze the communication request on a first device on the cluster side to identify the public key algorithm type in the communication request, and to dynamically select the corresponding traditional public key algorithm or post-quantum cryptography algorithm according to the public key algorithm type so that the external network-side device and the cluster can establish communication.
[0039] Optionally, when selecting a post-quantum cryptography algorithm based on the public key algorithm type, the method for establishing a communication connection between the cluster and the external network-side device includes:
[0040] The external network-side device receives a key negotiation request sent by the first device. The key negotiation request is used to enable the external network-side device to use the public key of the first device to generate a session key using the post-quantum cryptography algorithm.
[0041] After receiving and verifying the encrypted session key, the first device distributes the decrypted session key to the cluster.
[0042] Optionally, after the first device receives the encrypted session key and verifies its correctness, it distributes the decrypted session key to the cluster, and then the first device clears the session key.
[0043] This disclosure also provides a quantum-encrypted communication system suitable for communication between clusters, including:
[0044] The first device is located on the cluster information receiving side;
[0045] The second device, located on the cluster information sending side, is used to forward communication requests sent by the cluster information sending side to the first device.
[0046] The first device is used to analyze the communication request and determine whether a valid key exists.
[0047] If so, the communication request is sent to the cluster information receiving side so that the cluster information receiving side and the cluster information sending side can establish a communication connection using the valid key;
[0048] If not, a new key is obtained in real time, and a communication connection is established after the new key is obtained on both the cluster information receiving side and the cluster information sending side.
[0049] Optionally, both the first device and the second device include:
[0050] The key module is used to determine whether a valid key exists based on the communication request.
[0051] The communication management module is used to initiate a key update request when a valid key does not exist.
[0052] A random number generation module is used to obtain a random number according to the update request and send the random number to the key module, which then generates a new key.
[0053] An encryption / decryption and authentication module is used to encrypt the generated new key using the public key of the first device and then send the encrypted data to the communication management module, which then sends the encrypted data.
[0054] Used to decrypt the received encrypted data to obtain the new key;
[0055] The key negotiation module distributes the new key to the cluster information receiving side and the cluster information sending side, and establishes a communication connection after the cluster information receiving side and the cluster information sending side obtain the new key.
[0056] Optionally, the communication management module is further configured to, after establishing a communication connection between the clusters on the cluster information receiving side and the cluster information sending side, match the corresponding tunnel mode or transmission mode for data transmission based on the data transmission scenario.
[0057] Optionally, the first device and / or the second device are located between the core switch and the firewall of the cluster.
[0058] Optionally, the first device and / or the second device are hardware devices, or
[0059] The first device and / or the second device are implemented by setting up a random number generator on a general-purpose computer and cooperating with a software system.
[0060] This disclosure also provides a quantum encrypted communication system suitable for communication between external network-side devices and a cluster, including:
[0061] The first device, on the cluster side, is used to receive communication requests sent by the external network-side device;
[0062] The first device includes:
[0063] The communication management module dynamically selects either a traditional public key algorithm or a post-quantum cryptography algorithm based on the public key algorithm type to establish communication between the external network device and the cluster.
[0064] Optionally, when the first device selects to use a post-quantum cryptography algorithm according to the public key algorithm type, it sends a key negotiation request to the external network-side device. The key negotiation request is used to enable the network-side device to use the public key of the first device to encrypt and generate a session key using the post-quantum cryptography algorithm.
[0065] The first device also includes:
[0066] The encryption, decryption, and authentication module is used to obtain the session key after receiving the encrypted session key and verifying its correctness.
[0067] The key negotiation module is used to distribute the session key to the cluster side.
[0068] This disclosure also provides a computer-readable storage medium storing a computer program for running a communication method, wherein the computer program causes a computer to perform the communication method as described in any of the above technical solutions.
[0069] This disclosure also provides an electronic device disposed between the core switch and the firewall of the cluster, comprising:
[0070] One or more processors; memory; and
[0071] One or more programs, wherein the one or more programs are stored in the memory and configured to be executed by the one or more processors, the programs including methods for performing quantum encrypted communication methods and quantum encrypted communication systems as described in any of the above technical solutions.
[0072] The above technical solution has the following beneficial effects:
[0073] 1. By setting up a first or second device in the cluster, communication connections are established between the cluster or between external network devices and the cluster. A real-time updated or real-time valid quantum random number is selected as the key, and the quantum random number is updated at a set update period. The key update strategy is adjusted accordingly to avoid frequent negotiation processes, improve communication efficiency, dynamically match encryption algorithms, and encrypt the key through a quantum-resistant key distribution algorithm to conduct encrypted communication between external network devices and the cluster. While ensuring quantum-resistant communication, it is also compatible with traditional public key encryption, ensuring interoperability with existing communication equipment and infrastructure. No large-scale changes to existing equipment are required, reducing implementation costs and complexity.
[0074] 2. By using randomly generated quantum random numbers as keys or verification codes, the system dynamically adapts to encrypted communication or verification code requests between clusters and external network devices, reducing potential security risks and significantly enhancing resistance to quantum attacks. It stores a certain number of quantum random numbers, discards them, generates new quantum random numbers, and randomly selects them to ensure sufficient quantum random number resources, thereby improving the security and unpredictability of the keys. Attached Figure Description
[0075] To more clearly illustrate the technical solutions in the embodiments of this disclosure or the prior art, the drawings used in the description of the embodiments or the prior art will be briefly introduced below. Obviously, the drawings described below are only some embodiments of this disclosure. For those skilled in the art, other drawings can be obtained based on these drawings without creative effort.
[0076] Figure 1 This is a flowchart of the quantum encrypted communication method proposed in this disclosure;
[0077] Figure 2 This is a flowchart of the quantum encrypted communication method of the first device on the cluster side in this disclosure;
[0078] Figure 3 This is a flowchart of the quantum encrypted communication method for the second device on the cluster side in this disclosure;
[0079] Figure 4 This is a flowchart of the quantum encrypted communication method between the external network-side device and the first device of the cluster in this disclosure;
[0080] Figure 5 This is a schematic diagram of the quantum encrypted communication system proposed in this disclosure.
[0081] Figure 6 This is a schematic diagram of the structure of the first or second device in this disclosure.
[0082] Legend:
[0083] 1. Random number generation module; 2. Key module; 3. Key negotiation module; 4. Encryption / decryption and authentication module; 5. Verification code generation module; 6. Communication management module; 7. Alarm module. Detailed Implementation
[0084] The technical solutions of the embodiments of this disclosure will be clearly and completely described below with reference to the accompanying drawings. Obviously, the described embodiments are only some embodiments of this disclosure, and not all embodiments. Based on the embodiments of this disclosure, all other embodiments obtained by those of ordinary skill in the art without creative effort are within the scope of protection of this disclosure.
[0085] In existing technologies, embedding post-quantum cryptography algorithms into communication protocols or using two key distribution algorithms simultaneously to achieve quantum-resistant communication with the help of hybrid dual certificates suffers from poor compatibility. Furthermore, relying on pseudo-random number generators in quantum computing systems may result in generated random numbers that are easily predictable and vulnerable to attack, thus affecting security.
[0086] In some embodiments of this disclosure, reference is made to Figure 1 This disclosure provides a quantum encrypted communication method, comprising the following steps:
[0087] S1: Receive communication requests, the types of which include those used to establish communication connections between clusters or between external network devices and clusters;
[0088] S2: Based on the type of communication request, execute the corresponding communication mechanism, where,
[0089] When the communication mechanism is an inter-cluster communication mechanism, a real-time updated or real-time valid symmetric key is selected for encrypted communication between clusters.
[0090] When the communication mechanism is between the external network device and the cluster, the encryption algorithm is dynamically matched to perform encrypted communication between the external network device and the cluster.
[0091] Specifically, corresponding encrypted communication mechanisms are provided for both inter-cluster communication and communication between external network devices and clusters, making the entire communication encryption method compatible with different application scenarios. Secondly, by selecting the encryption mechanism, not only can quantum-resistant communication be achieved, but it is also compatible with traditional public-key encryption, ensuring interoperability with existing communication equipment and infrastructure without the need for large-scale changes to existing equipment, thus reducing implementation costs and complexity.
[0092] In some embodiments of this disclosure, when the communication mechanism is an inter-cluster communication mechanism, the method for selecting a symmetric key that is updated in real time includes: when the first device on the cluster information receiving side determines that the symmetric key is invalid, it initiates a key update request to the second device on the cluster information initiating side. The key update request is used to enable the second device to generate a new key and encrypt the new key before sending it to the first device. The first device and the second device then distribute the new key to the corresponding clusters to establish encrypted communication between the clusters.
[0093] Specifically, when the first device receives a communication request from the cluster, it checks whether it has a valid symmetric key. If no valid key exists, the first and second devices work together to update the key. If a valid symmetric key exists, the first device sends the key to the corresponding cluster information receiving side, and the second device distributes the key to the cluster information sending side, enabling the cluster information sending side and the cluster information receiving side to directly establish encrypted communication between the clusters. By possessing a valid symmetric key, the confidentiality, integrity, and authentication of the communication data are ensured.
[0094] In some embodiments of this disclosure, when the communication mechanism is a communication mechanism between an external network-side device and a cluster, the method for dynamically matching encryption algorithms includes: a first device on the cluster information receiving side identifies the public key algorithm type in the communication request, and selects a traditional public key algorithm or a post-quantum cryptography algorithm of the corresponding type to establish encrypted communication between the external network-side device and the cluster.
[0095] Specifically, when the communication mechanism is between an external network device and the cluster, the first device receives a communication request initiated by the external network device to the cluster information receiving side. After receiving the communication request, the first device analyzes the public key algorithm in the communication request, identifies the type of public key algorithm, and dynamically matches the encryption algorithm. If it is a traditional public key algorithm, the first device only performs address translation on the data packet, modifying the source and destination addresses of the data packet to ensure correct transmission in different network environments. In this case, the first device converts the destination address of the communication request from the external network device to the address of the corresponding node within the cluster information receiving side, and then directly forwards it to the cluster information receiving side, without participating in the encryption and decryption process, which can improve the efficiency of data transmission. If it is a post-quantum cryptography algorithm, after determining that a post-quantum cryptography algorithm will be used, the first device sends a key negotiation request to the external network device. After receiving the key negotiation request, the external network device uses the first device's public key to encrypt and generate a session key using the post-quantum cryptography algorithm, and sends it to the first device. Through key negotiation, both parties can securely obtain a shared session key in an insecure network environment for subsequent encrypted communication. After obtaining the session key, the first device decrypts it and distributes the decrypted session key to the cluster information receiving side to establish communication. The communication between the external network side device and the cluster information receiving side will be encrypted using this session key. After that, the first device is responsible for address translation and data packet forwarding to ensure that the data can be transmitted accurately and securely between the external network side device and the cluster information receiving side.
[0096] In some embodiments of this disclosure, reference is made to Figure 2 This disclosure also provides a quantum encrypted communication method for inter-cluster communication, wherein the first device on the cluster information receiving side includes the following steps:
[0097] S11: Receive a communication request from the cluster information sending side, wherein the communication request is used to establish a communication connection between the clusters on the cluster information sending side and the cluster information receiving side.
[0098] S12: Analyze the communication request and determine if a valid key exists.
[0099] S13: If so, send a communication request to the cluster information receiving side so that the cluster information receiving side and the cluster information sending side can establish a communication connection using a valid key;
[0100] S14: If not, update and obtain a new key in real time. Establish a communication connection after both the cluster information receiving and sending sides obtain the new key. Specifically, when the cluster information sending side needs to communicate with the cluster information receiving side, it actively initiates a communication request. Upon receiving the request, the first device immediately analyzes it, verifies the identity of the cluster information sending side, and determines whether a valid key exists. If the key is valid, the first device forwards the communication request to the cluster information receiving side. Subsequently, data transmission between the cluster information sending and receiving sides will use this valid key. The valid key is a symmetric key, and encryption and decryption use the same key cryptographic algorithm, which has advantages such as simple implementation and fast encryption / decryption speed. The cryptographic algorithm uses a symmetric cryptographic algorithm (such as AES) for encryption and authentication to establish communication, thereby ensuring the confidentiality and integrity of the communication. If the key is invalid or does not exist, the first device updates and obtains a new key in real time and distributes the new key to the cluster information receiving side. Simultaneously, the second device also distributes the new key to the cluster information sending side, enabling the cluster information receiving and sending sides to establish a communication connection based on the new key.
[0101] In some embodiments of this disclosure, the method for the first device to update and obtain a new key includes: the first device on the cluster information receiving side initiates a key update request to the second device on the cluster information initiating side; the update request is used to enable the second device to obtain a random number and generate a new key based on the random number, and encrypt the data using the public key of the first device and send the encrypted data to the first device, and the first device decrypts the encrypted data to obtain the new key.
[0102] Specifically, when a key is invalid or does not exist, it needs to be updated. The first device sends a key update request to the second device. After receiving the update request, the second device performs the corresponding key update operation, obtains a random number, and generates a new key based on the random number. The random number is a quantum random number, generated based on the uncertainty principle of quantum mechanics, possessing true randomness and unpredictability. Compared with traditional pseudo-random number generation methods, quantum random numbers offer higher security in the field of cryptography. For example, traditional pseudo-random number generation algorithms are usually based on deterministic mathematical formulas and may be predictable in certain situations, while quantum random numbers do not have this risk.
[0103] The second device uses a quantum-resistant key distribution algorithm to encrypt the new key using the first device's public key, and then sends the encrypted data back to the first device. Public-key encryption is an asymmetric encryption method. The second device uses the first device's public key to encrypt the generated new key, ensuring that even if the encrypted key is intercepted during transmission, an attacker cannot decrypt it and obtain the original key without the first device's private key, thus preventing the attacker from sending the encrypted key back to the first device. During transmission, the encrypted key can be transmitted through a secure network channel, such as a network connection encrypted with SSL / TLS protocols, further enhancing transmission security.
[0104] After receiving the encrypted data, the first device first performs authentication to verify the legitimacy of the second device. Authentication can be achieved in various ways, such as using a digital certificate. When sending the encryption key, the second device attaches its own digital certificate. The first device verifies the validity of the digital certificate to confirm the identity of the second device. After authentication and key verification, if everything is normal, the first device uses its own private key to decrypt the encrypted key, thereby obtaining the new key generated by the second device.
[0105] In some embodiments of this disclosure, after a communication connection is established between the clusters on the cluster information receiving side and the cluster information sending side, data transmission is performed by matching the corresponding tunnel mode or transmission mode based on the data transmission scenario.
[0106] Specifically, after establishing communication, the system determines whether the transmitted communication data needs to be encrypted based on the data transmission scenario to match the corresponding data transmission mode. This determination is typically based on factors such as data sensitivity, the security of the communication environment, and relevant security policies. For example, data transmission containing sensitive content such as personal identification information and financial data is encrypted; while publicly available data that does not involve sensitive information is transmitted unencrypted.
[0107] Furthermore, the data transmission mode determines the specific method of communication data processing: In transmission mode, the first and second devices are only responsible for address translation and data forwarding, without encrypting or decrypting the data, thus significantly improving communication efficiency. When the key is valid, the first and second devices destroy it, retaining only its lifecycle information, further ensuring key security and preventing malicious acquisition and exploitation after communication ends, reducing security risks. Subsequently, data transmission between the cluster information sender and receiver will use this key and be encrypted and authenticated using symmetric cryptographic algorithms (such as AES). In tunnel mode, the key is encrypted and decrypted to ensure end-to-end data transmission security. This design pattern achieves an optimal balance between security and performance based on actual needs, meeting the requirements of different application scenarios and providing reliable technical support for high-security communication.
[0108] In some embodiments of this disclosure, reference is made to Figure 3 This disclosure also provides a quantum encrypted communication method for inter-cluster communication, wherein a second device on the cluster information sending side includes the following steps:
[0109] S21: Send a communication request to the cluster information receiving side, wherein the communication request is used to establish a communication connection between the cluster information sending side and the cluster information receiving side.
[0110] S22: The communication request is analyzed by the first device on the cluster information receiving side, and it is determined whether a valid key exists;
[0111] S23: If so, establish a communication connection between the cluster information receiving side and the cluster information sending side using a valid key;
[0112] S24: If not, generate a new key in real time, and establish a communication connection after obtaining the new key on the cluster information receiving side and the cluster information sending side.
[0113] Specifically, when the cluster information sender needs to communicate with the cluster information receiver, it actively initiates a communication request. This request first passes through a second device, which then sends it to the first device on the cluster information receiver side. This allows the first device to analyze the communication request, verify the identity of the cluster information sender, and check for the existence of a valid key.
[0114] If the key is valid, the first device will forward the communication request to the cluster information receiving side. Subsequently, the data transmission between the cluster information sending side and the cluster information receiving side will use the valid key. The valid key is a symmetric key, and the same key cryptographic algorithm is used for encryption and decryption. It has the advantages of simple implementation and fast encryption and decryption speed. The cryptographic algorithm uses a symmetric cryptographic algorithm (such as AES) for encryption and authentication to establish communication, thereby ensuring the confidentiality and integrity of the communication.
[0115] If the key is invalid or does not exist, the first device updates and obtains a new key in real time, and distributes the new key to the cluster information receiving side. At the same time, the second device also distributes the new key to the cluster information sending side, enabling the cluster information receiving side and the cluster information sending side to establish a communication connection based on the new key.
[0116] In some embodiments of this disclosure, the method for the second device to generate a new key in real time includes:
[0117] The second device receives a key update request from a first device. This request enables the second device to obtain a random number and generate a new key based on that number. The second device then encrypts the new key using the first device's public key and sends the encrypted data back to the first device, which decrypts the data to obtain the new key. Specifically, upon receiving the update request, the second device performs the corresponding key update operation, obtains a random number, and generates a new key based on that random number. This random number is a quantum random number, possessing true randomness and unpredictability. The second device uses a quantum-resistant key distribution algorithm to encrypt the new key using the first device's public key and sends the encrypted data back to the first device. Even if the encrypted key is intercepted during transmission, an attacker cannot decrypt it to obtain the original key without the first device's private key. During transmission, the encrypted key can be transmitted through a secure network channel, such as a network connection encrypted with SSL / TLS protocols, further enhancing transmission security.
[0118] After receiving the encrypted data, the first device first performs authentication to verify the legitimacy of the second device. Authentication can be achieved in various ways, such as using a digital certificate. When sending the encryption key, the second device attaches its own digital certificate. The first device verifies the validity of the digital certificate to confirm the identity of the second device. After authentication and key verification, if everything is normal, the first device uses its own private key to decrypt the encrypted key, thereby obtaining the new key generated by the second device.
[0119] In some embodiments of this disclosure, after a communication connection is established between the clusters on the cluster information receiving side and the cluster information sending side, data transmission is performed by matching the corresponding tunnel mode or transmission mode based on the data transmission scenario.
[0120] Specifically, after communication is established, the system determines whether the transmitted communication data needs encryption based on the data transmission scenario to match the corresponding data transmission mode. After communication is established, the data transmission mode determines the specific method of data processing: if a transmission mode is used, the first and second devices are only responsible for address translation and data forwarding. When the key is valid, the first and second devices destroy the key, retaining only its lifecycle information to further ensure key security and prevent malicious acquisition and exploitation after communication ends, thus reducing security risks. Subsequently, data transmission between the cluster information sending side and the cluster information receiving side will use this key and be encrypted and authenticated using a symmetric cryptographic algorithm. If a tunnel mode is used, the key is encrypted and decrypted to ensure end-to-end data transmission security, meeting different application scenarios and facilitating high-security communication.
[0121] In some embodiments of this disclosure, reference is made to Figure 4 This disclosure also provides a quantum-encrypted communication method for communication between an external network-side device and a cluster, wherein the first device on the cluster side includes the following steps:
[0122] S31: Receive a communication request sent by an external network-side device, wherein the communication request is used to enable the external network-side device to establish a communication connection with the cluster;
[0123] S32: Analyze the communication request to identify the public key algorithm type in the communication request;
[0124] S33: Dynamically select the corresponding traditional public key algorithm or post-quantum cryptography algorithm based on the public key algorithm type to enable communication between external network devices and the cluster.
[0125] Specifically, when an external network device establishes a communication connection, it sends a communication request to the first device on the cluster side to establish encrypted communication between the external network device and the cluster. The first device analyzes the public key algorithm in the security association payload of the communication request to identify the algorithm type. If it is a traditional public key algorithm, the first device converts the destination address of the external network device's communication request to the address of the corresponding node within the cluster side and then forwards it directly to the cluster side, improving data transmission efficiency. If it is a post-quantum cryptography algorithm, the first device sends a key negotiation request to the external network device, enabling the external network device to encrypt and generate a session key using the post-quantum cryptography algorithm. The session key is then obtained by the first device, decrypted, and distributed to the cluster side, establishing communication between the external network device and the cluster. This method is compatible with both post-quantum cryptography and traditional public key algorithms for encryption and can flexibly select the encryption algorithm according to the communication request, ensuring system security.
[0126] In some embodiments of this disclosure, when selecting a post-quantum cryptography algorithm based on the public key algorithm type, the method for establishing a communication connection between the cluster and an external network-side device includes:
[0127] The first device sends a key negotiation request to the external network device. The key negotiation request is used to enable the external network device to use the first device's public key to generate a session key using a post-quantum cryptography algorithm.
[0128] After receiving the encrypted session key and verifying its correctness, the decrypted session key is distributed to the cluster.
[0129] Specifically, after determining to use the post-quantum cryptography algorithm, the first device sends a key negotiation request to the external network device. The external network device uses the first device's public key to generate a session key using the post-quantum cryptography algorithm. Through key negotiation, both parties can securely obtain a shared session key in an insecure network environment. After receiving the encrypted session key, the first device first verifies it. Only after confirming the session key is correct will the first device perform the subsequent decryption operation. The first device then sends the decrypted session key to the cluster for subsequent encrypted communication. Thereafter, communication between the external network device and the cluster will be encrypted using this session key.
[0130] In some embodiments of this disclosure, after the first device receives the encrypted session key and verifies its correctness, it distributes the decrypted session key to the cluster and then clears the session key.
[0131] Specifically, after receiving the encrypted session key, the first device first checks and verifies the session key, including checking and verifying the integrity of the key, whether the format is correct, and whether the encryption algorithm matches. When the check and verification results indicate that the session key is valid, the format is correct, and the encryption algorithm matches, the session key is confirmed to be correct. The first device then performs the subsequent decryption operation. After the check passes, the first device uses its own private key to decrypt the encrypted session key, ensuring that only the first device can correctly decrypt and obtain the session key.
[0132] The first device sends the decrypted key to the cluster side. Within the cluster, each participating node obtains this key for subsequent communication with external network devices. During transmission, it is ensured that the key is accurately delivered to each node, guaranteeing secure encrypted communication between the cluster and external network devices. Through key distribution, nodes within the cluster can use the same key for encryption and decryption as external network devices, effectively preventing data theft or tampering during transmission and achieving secure data transmission. Communication between the external network device and the cluster uses this session key for encrypted communication. In this case, the first device is only responsible for address translation and packet forwarding. The first device clears the session key, retaining only its lifecycle information, further ensuring its security and preventing malicious acquisition and misuse after communication ends, thus reducing security risks.
[0133] In some embodiments of this disclosure, a quantum-encrypted communication method is also provided for communication between an external network-side device and a cluster. The method, implemented on the external network-side device, includes the following steps:
[0134] S41: Send a communication request to the cluster side, wherein the communication request is used to enable the external network side device to establish a communication connection with the cluster, and is used by the first device on the cluster side to analyze the communication request to identify the public key algorithm type in the communication request, and to dynamically select the corresponding traditional public key algorithm or post-quantum cryptography algorithm according to the public key algorithm type so that the external network side device and the cluster can establish communication.
[0135] In some embodiments of this disclosure, an external network-side device sends a communication request to the cluster side to enable a first device on the cluster side to identify the type of public key algorithm. The first device analyzes the public key algorithm in the Security Association Payload (SA Payload) of the communication request to identify the public key algorithm type. If the public key algorithm type is a traditional public key algorithm, the first device only performs address translation on the data packet, modifying the source and destination addresses of the data packet to convert them to the addresses of the corresponding nodes within the cluster side, enabling data to be transmitted correctly in different network environments and improving data transmission efficiency. If the public key algorithm type is a post-quantum cryptography algorithm, the external network-side device uses the post-quantum cryptography algorithm to encrypt and generate a session key, and then obtains the key through the first device, decrypts it, and distributes it to the cluster side, enabling communication between the external network-side device and the cluster. This method is compatible with both post-quantum cryptography algorithms and traditional public key algorithms for encryption, and can flexibly select the encryption algorithm according to the communication request to ensure system security.
[0136] In some embodiments of this disclosure, when selecting a post-quantum cryptography algorithm based on the public key algorithm type, the method for establishing a communication connection between the cluster and an external network-side device includes: the external network-side device receiving a key negotiation request sent by a first device, the key negotiation request being used to enable the external network-side device to use the public key of the first device to encrypt and generate a session key using a post-quantum cryptography algorithm; after receiving the encrypted session key and verifying its correctness, the first device distributing the decrypted session key to the cluster.
[0137] Specifically, after receiving the key negotiation request, the external network device uses the public key of the first device to generate a session key using a post-quantum cryptography algorithm. Through key negotiation, both parties can securely obtain a shared session key in an insecure network environment. After receiving the encrypted session key, the first device first verifies it. If the session key is correct, the first device performs a subsequent decryption operation and sends the decrypted session key to the cluster for subsequent encrypted communication. Thereafter, communication between the external network device and the cluster will be encrypted using this session key.
[0138] In some embodiments of this disclosure, after the first device receives the encrypted session key and verifies its correctness, it distributes the decrypted session key to the cluster and then clears the session key.
[0139] Specifically, after receiving the encrypted session key, the first device first checks and verifies the session key, including checking and verifying the integrity of the key, whether the format is correct, and whether the encryption algorithm matches. When the check and verification results show that the session key is valid, the format is correct, and the encryption algorithm matches, the session key is confirmed to be correct. The first device then performs the subsequent decryption operation. After the check passes, the first device uses its own private key to decrypt the encrypted session key, ensuring that only the first device can correctly decrypt and obtain the session key.
[0140] The first device sends the decrypted key to the corresponding cluster side. Within the cluster side, each participating node obtains this key for subsequent communication with external network devices. During transmission, it is ensured that the key is accurately delivered to each node, guaranteeing secure encrypted communication between the cluster side and the external network devices. Through key distribution, nodes within the cluster side can use the same key for encryption and decryption as external network devices, effectively preventing data theft or tampering during transmission and achieving secure data transmission. Communication between the external network devices and the cluster will use this session key for encrypted communication. At this point, the first device is only responsible for address translation and data packet forwarding. The first device clears the session key, retaining only its lifecycle information, further ensuring its security and preventing malicious acquisition and misuse after communication ends, thus reducing security risks.
[0141] In some embodiments of this disclosure, a quantum-encrypted communication method is also provided for encrypting verification codes between an external network-side device and a cluster. The external network-side device initiates a verification code request to the cluster side. The cluster side, as the receiver, forwards the received verification code request to a first device, enabling the first device to respond to the verification code request and authenticate the cluster side through the first device, thus preventing the verification code request from being lost or processed incorrectly. After receiving the verification code request, the first device obtains a random number and generates a verification code based on the random number according to a pre-set algorithm. After generating the verification code, to prevent the random number from being leaked and thus reducing the security of the verification code, these random numbers are immediately discarded to reduce potential security risks. The generated verification code is sent to the external network-side device. When the external network-side device receives the verification code, it can verify it, completing the entire verification code verification function. This effectively ensures the accuracy and security of the verification code verification and can be applied to scenarios such as identity verification and secure login, such as login verification for financial trading platforms and permission verification for accessing important data, effectively preventing malicious attacks and unauthorized access.
[0142] Depending on the type of communication request, the corresponding communication mechanism is executed. Different key update methods are set according to different communication mechanisms. For example, when the communication mechanism is between clusters, a fixed key update cycle is used, thus avoiding key negotiation for each communication and significantly improving the efficiency of inter-cluster communication. When the communication mechanism is between an external network device and the cluster, the same update method as the existing communication system is maintained to ensure the compatibility of the communication system.
[0143] In addition to a fixed key update cycle, key update methods can also dynamically adjust the update frequency based on network traffic and security events. For example, when network traffic exceeds a set threshold, the communication system can automatically trigger a key update to address potential security risks caused by high load. When abnormal behavior or security events are detected, such as frequent authentication failures or abnormal communication requests, the communication system can immediately perform a key update to reduce security threats.
[0144] The communication system can also integrate behavioral analysis and machine learning algorithms to dynamically optimize the key update method by analyzing communication patterns. For example, it can identify normal traffic characteristics based on historical data and adjust the update frequency when significant deviations are detected, thereby achieving intelligent key management.
[0145] In some embodiments of this disclosure, reference is made to Figures 5-6 This disclosure also provides a quantum encrypted communication system suitable for communication between clusters, including: a first device, which is located on the cluster information receiving side;
[0146] The second device, located on the cluster information sending side, forwards communication requests sent by the cluster information sending side to the first device. The first device analyzes the communication requests to determine whether a valid key exists. If so, it sends the communication request to the cluster information receiving side so that the cluster information receiving side and the cluster information sending side can establish a communication connection using a valid key. If not, it updates and obtains a new key in real time, and establishes a communication connection after the cluster information receiving side and the cluster information sending side obtain the new key.
[0147] Specifically, the first device is located at the back end of the core switch on the cluster information receiving side. It receives communication requests or keys, performs authentication and key detection on the cluster information sending side, determines whether a valid key exists, and distributes the valid key to the cluster information receiving side. The second device is located at the back end of the core switch on the cluster information sending side. It distributes the key to the first device or the cluster information sending side. When the key is invalid or does not exist, it is used to update the key. The first device and the second device work closely together to achieve efficient key distribution and security management.
[0148] When the cluster information sender communicates with the cluster information receiver, the sender initiates a communication request. This request first passes through the second device and then reaches the first device. Upon receiving the request, the first device immediately analyzes it, verifies the sender's identity, and determines if a valid key exists. If the key is valid, the first device forwards the communication request to the receiver. Subsequent data transmission between the sender and receiver will use this valid symmetric key and be encrypted and authenticated using a symmetric cryptographic algorithm to establish communication, thus ensuring confidentiality and integrity. If the key is invalid or does not exist, the first device updates and obtains a new key in real time and distributes it to the receiver. Simultaneously, the second device also distributes the new key to the sender, enabling a direct communication connection between the sender and receiver for encrypted inter-cluster communication.
[0149] In some embodiments of this disclosure, both the first device and the second device include: a key module 2, used to determine whether a valid key exists based on a communication request; a communication management module 6, used to initiate a key update request when no valid key exists; a random number generation module 1, used to obtain a random number based on the update request and send the random number to the key module 2, whereby the key module 2 generates a new key; an encryption / decryption and authentication module 4, used to encrypt the generated new key using the public key of the first device and send the encrypted data to the communication management module 6, whereby the communication management module 6 sends the encrypted data; and used to decrypt the received encrypted data to obtain the new key; and a key negotiation module 3, used to distribute the new key to the cluster information receiving side and the cluster information sending side, and establish a communication connection after the cluster information receiving side and the cluster information sending side obtain the new key.
[0150] Specifically, the random number generation module 1 integrates a quantum random number generator and a storage medium for the lifecycle management of quantum random numbers. This lifecycle management includes the generation, storage, destruction, and updating of quantum random numbers. The random number generation module 1 generates high-entropy random numbers using the quantum random number generator and securely stores them in the storage medium. When an update request is received, the random number generation module 1 outputs unused quantum random numbers to the key module 2 and securely destroys them immediately after use. Simultaneously, it generates and stores new quantum random numbers to ensure that the storage medium always has sufficient random number resources.
[0151] Key module 2 integrates quantum-resistant key distribution and authentication algorithms for efficient generation and management of various key materials, including authentication certificates, signature certificates, and symmetric keys. It determines whether a valid key exists based on the received communication request and generates a new key based on the received random number.
[0152] The key negotiation module 3 obtains the initial or updated key materials from the key module 2, sends the key to the cluster information receiving side and the cluster information sending side, and securely negotiates with both communicating parties based on the key negotiation protocol to generate a shared symmetric key. It also dynamically adjusts the key update method according to information such as communication objects, network traffic, and security events, and manages the storage and update of the key.
[0153] The encryption / decryption and authentication module 4 integrates quantum-resistant key distribution algorithms, quantum-resistant authentication algorithms, and efficient symmetric cryptographic algorithms. When establishing a communication connection, it encrypts the new key using the public key of the first device and decrypts the encrypted data using the private key to obtain the key, covering security functions such as key negotiation, identity authentication, and data encryption / decryption.
[0154] The communication management module 6 is used to send key update requests or encrypted data to the random number generation module 1 of the second device for key updates. It should be noted that the functional modules in the first and second devices are identical. However, depending on their location on the cluster side, the coordination between the modules of the first and second devices differs. This description uses the first device as the cluster information receiving side and the second device as the cluster information sending side. However, based on changes in the communication scenario—currently the cluster information receiving side becomes the cluster information sending side, and vice versa—the functions of the first and second devices are adaptively adjusted to meet the needs of the entire communication scenario.
[0155] In some embodiments of this disclosure, the communication management module 6 is also used to establish a communication connection between the clusters on the cluster information receiving side and the cluster information sending side, and then, based on the data transmission scenario, match the corresponding tunnel mode or transmission mode for data transmission.
[0156] Specifically, after communication is established, the communication management module 6 matches with the encryption / decryption and authentication module 4 to select the corresponding data transmission mode. The encryption / decryption and authentication module 4 provides tunnel mode and transmission mode. In tunnel mode, the encryption / decryption and authentication module 4 uniformly encrypts all transmitted data to ensure a high level of data security during transmission. In transmission mode, the encryption / decryption and authentication module 4 is only responsible for data forwarding, which is suitable for scenarios with high performance requirements, thereby improving communication efficiency while ensuring security.
[0157] In transmission mode, the first and second devices are only responsible for address translation and data forwarding. When the key is valid, both devices destroy it, retaining only its lifecycle information to further ensure key security and prevent malicious acquisition and exploitation after communication ends, thus reducing security risks. In tunnel mode, the encryption / decryption and authentication module 4 uniformly encrypts and decrypts the data, ensuring end-to-end data transmission security, meeting the needs of different application scenarios, and guaranteeing highly secure communication.
[0158] In some embodiments of this disclosure, the first device and / or the second device are located between the core switch and the firewall of the cluster. Specifically, by placing the first device and / or the second device between the core switch and the firewall of the cluster, post-quantum encryption algorithms and key management mechanisms can be integrated during communication requests and key updates. This collaboratively constructs end-to-end secure communication, ensuring the security, reliability, and confidentiality of the communication process and effectively resisting potential network attacks and data leakage risks.
[0159] In some embodiments of this disclosure, the first device and / or the second device are hardware devices, or the first device and / or the second device are implemented by setting a random number generator on a general-purpose computer and cooperating with a software system.
[0160] Specifically, the first and / or second devices can be hardware devices, such as hardware boards, or random number generators can be set on general-purpose computers and implemented through software systems, which have strong adaptability. The communication system is set at the network access end of the server cluster to realize hybrid communication of traditional and quantum-resistant communication, thereby ensuring both quantum-resistant communication and compatibility with existing communication networks.
[0161] In some embodiments of this disclosure, a quantum cryptographic communication system is also provided, suitable for communication between an external network-side device and a cluster, comprising: a first device on the cluster side, used to receive communication requests sent by the external network-side device; the first device includes: a communication management module 6, which dynamically selects a traditional public key algorithm or a post-quantum cryptographic algorithm of the corresponding type according to the public key algorithm type to enable communication between the external network-side device and the cluster.
[0162] Specifically, the communication management module 6, as the core scheduling unit of the system, is responsible for coordinating the efficient operation of various modules. Based on the Security Association Payload (SA) information provided by the response side, the communication management module 6 can identify traditional public-key algorithms or post-quantum cryptography algorithms, dynamically assess communication security requirements, and make intelligent decisions. During the authentication phase, the communication management module 6 can intelligently determine whether to enable post-quantum encryption and authentication mechanisms to address potential quantum computing threats. During the data transmission phase, the communication management module 6 matches the encryption / decryption and authentication module 4 with the user-selected data transmission mode, flexibly adjusting its operating mode. If it is in transmission mode, it provides a symmetric key to the upper-layer application to ensure efficient data transmission; if it is in tunnel mode, it schedules the encryption / decryption and authentication module 4 to perform encryption and decryption operations on the data to ensure data security. Through this dynamic and intelligent management mechanism, the communication management module 6 achieves an optimal balance between security and performance, which is conducive to the efficient operation of the system. It should be noted that whether it is the first and second devices set up between clusters, or the first device set up on the cluster side corresponding to the external network side devices, the functional modules of the three are the same to match different communication scenarios.
[0163] In some embodiments of this disclosure, when the first device selects to use a post-quantum cryptography algorithm based on the public key algorithm type, it sends a key negotiation request to an external network-side device. The key negotiation request is used to enable the network-side device to use the public key of the first device to encrypt and generate a session key using the post-quantum cryptography algorithm. The first device further includes: an encryption / decryption and authentication module 4, used to obtain the session key after receiving the encrypted session key and verifying its correctness; and a key negotiation module 3, used to distribute the session key to the cluster side.
[0164] Specifically, during key negotiation, encryption / decryption and authentication module 4 employs a quantum-resistant key distribution algorithm to ensure the security of the key exchange process, effectively mitigating potential threats from quantum computing. During identity authentication, it utilizes a quantum-resistant authentication algorithm to verify the identities of both communicating parties, preventing man-in-the-middle attacks and identity forgery, ensuring the authenticity and trustworthiness of both parties. In the data transmission phase, if tunnel mode is used, encryption / decryption and authentication module 4 uses efficient symmetric cryptographic algorithms to encrypt and decrypt data, ensuring confidentiality, integrity, and immutability. If transmission mode is used, encryption / decryption and authentication module 4 is only responsible for forwarding data; data security is provided by the application layer, thus achieving higher communication efficiency. Encryption / decryption and authentication module 4 strikes a balance between high performance and high security, flexibly adapting to different application scenarios and guaranteeing highly secure communication.
[0165] Key negotiation module 3 distributes session keys to the cluster side through authentication and key exchange mechanisms, ensuring the confidentiality, integrity, and non-repudiation of the negotiation process. It also supports forward security to prevent the decryption of historical communications due to key leakage. The generated symmetric key is used for encryption and decryption of subsequent communications, which helps ensure data transmission.
[0166] In some embodiments of this disclosure, the first device and / or the second device are further provided with a verification code generation module 5 and an alarm module 7. When the verification code generation module 5 receives a verification code request, it obtains a high-entropy random number from the random number generation module 1 and generates a verification code based on the random number. The alarm module 7 monitors abnormal behavior in the authentication process, disconnects the current access connection and initiates an alarm notification, and records abnormal information.
[0167] Specifically, the verification code generation module 5 integrates a verification code generation algorithm to dynamically generate highly secure verification codes. When the communication management module 6 receives a verification code request, the verification code generation module 5 obtains a high-entropy random number from the random number generation module 1 and generates a unique verification code based on this quantum random number. The generated verification code is sent to the external network-side device through the communication management module 6, ensuring the unpredictability and one-time use nature of the verification code, thereby effectively preventing replay attacks and brute-force attacks, and improving the overall security of the system.
[0168] Alarm module 7 is one of the core security components of the system, used to monitor abnormal behavior during the authentication process in real time. When the encryption / decryption and authentication module 4 detects that the number of authentication errors exceeds a preset threshold, alarm module 7 immediately triggers a security mechanism, severing the current access connection and initiating an alarm notification. Simultaneously, detailed anomaly information, such as the number of errors, timestamps, and access sources, is recorded in the access log for subsequent auditing and querying. This not only effectively prevents brute-force attacks and unauthorized access but also facilitates comprehensive security incident tracking and analysis, further enhancing the system's security and manageability.
[0169] In some embodiments of this disclosure, the disclosure further includes a computer-readable storage medium storing a computer program for running a communication method, wherein the computer program causes a computer to perform the following steps: receiving a communication request, the type of which includes establishing a communication connection between clusters or between an external network device and a cluster; executing a corresponding communication mechanism according to the type of communication request, wherein, when the communication mechanism is an inter-cluster communication mechanism, a real-time updated or real-time valid symmetric key is selected for encrypted communication between clusters; and when the communication mechanism is an inter-cluster communication mechanism between an external network device and a cluster, an encryption algorithm is dynamically matched for encrypted communication between the external network device and the cluster.
[0170] Specifically, a computer-readable storage medium can be a computer storage medium or a communication medium. A communication medium includes any medium that transmits a computer program from one location to another. A computer storage medium can be any available medium accessible to a general-purpose or special-purpose computer. For example, a computer-readable storage medium is coupled to a processor, enabling the processor to read information from and write information to the computer-readable storage medium. Of course, a computer-readable storage medium can also be a component of the processor. The processor and the computer-readable storage medium can reside in an Application Specific Integrated Circuit (ASIC). Alternatively, the ASIC can reside in a user equipment. Of course, the processor and the computer-readable storage medium can also exist as discrete components in a communication device.
[0171] Specifically, the computer-readable storage medium can be implemented from any type of volatile or non-volatile storage device or a combination thereof, such as Static Random-Access Memory (SRAM), Electrically Erasable Programmable Read-Only Memory (EEPROM), Erasable Programmable Read Only Memory (EPROM), Programmable Read-Only Memory (PROM), Read-Only Memory (ROM), magnetic storage, flash memory, magnetic disk, or optical disk. The storage medium can be any available medium accessible to general-purpose or special-purpose computers.
[0172] In some embodiments of this disclosure, the disclosure also includes an electronic device disposed between the core switch of the cluster and the firewall, comprising: one or more processors; a memory; and
[0173] One or more programs, wherein the programs are stored in memory and configured to be executed by one or more processors, the programs comprising the steps of: receiving a communication request, the type of which includes establishing a communication connection between clusters or between an external network device and a cluster; executing a corresponding communication mechanism according to the type of communication request, wherein, when the communication mechanism is an inter-cluster communication mechanism, a real-time updated or real-time valid symmetric key is selected for encrypted communication between clusters; and when the communication mechanism is an inter-cluster communication mechanism between an external network device and a cluster, an encryption algorithm is dynamically matched for encrypted communication between the external network device and the cluster.
[0174] This device can improve key exchange efficiency and overall system performance by designing dedicated hardware circuits to optimize quantum cryptography algorithms (such as quantum-resistant key distribution algorithms and authentication algorithms).
[0175] In application scenarios with lower security requirements, data transmission between electronic devices and the proxied cluster can be conducted without encryption, communicating with the cluster in plaintext. Encryption can be enabled only for sensitive information transmission or between critical nodes, thereby improving system performance.
[0176] By utilizing dedicated hardware or efficient circuit design, the device can achieve higher encryption and decryption efficiency under low power consumption conditions, making large-scale deployment feasible.
[0177] Memory is used to store computer programs. This memory may include high-speed random access memory (RAM) and may also include non-volatile memory (NVM), such as at least one disk storage device, and may also be a USB flash drive, external hard drive, read-only memory, disk or optical disc, etc.
[0178] A processor is used to execute computer programs stored in memory. The processor can be a Central Processing Unit (CPU), or other general-purpose processors, digital signal processors (DSPs), application-specific integrated circuits (ASICs), etc. A general-purpose processor can be a microprocessor or any conventional processor. The steps of the method disclosed in this invention can be directly manifested as execution by a hardware processor, or execution by a combination of hardware and software modules within the processor.
[0179] Alternatively, the memory can be either standalone or integrated with the processor.
[0180] When memory is a device independent of the processor, electronic devices may also include a bus. This bus is used to connect the memory and the processor. This bus can be an Industry Standard Architecture (ISA) bus, a Peripheral Component Interconnect (PCI) bus, or an Extended Industry Standard Architecture (EISA) bus, etc. Buses can be categorized as address buses, data buses, control buses, etc.
[0181] It should be noted that, through the above description of the embodiments, those skilled in the art can clearly understand that each embodiment can be implemented by means of software plus necessary general-purpose hardware platforms. Based on this understanding, the above technical solutions, in essence or the parts that contribute to the prior art, can be embodied in the form of software products. These computer software products can be stored in computer-readable storage media, such as ROM / RAM, magnetic disks, optical disks, etc., and include several instructions to cause a computer device (which may be a personal computer, server, or network device, etc.) to execute the methods described in various embodiments or certain portions of the embodiments. In this document, relational terms such as "first" and "second" are used only to distinguish one entity or operation from another entity or operation, and do not necessarily require or imply any such actual relationship or order between these entities or operations. Furthermore, the terms "comprising," "including," or any other variations thereof are intended to cover non-exclusive inclusion, such that a process, method, article, or apparatus that comprises a list of elements includes not only those elements but also other elements not expressly listed, or elements inherent to such a process, method, article, or apparatus. In the absence of further restrictions, an element defined by the phrase "comprising a..." does not exclude the presence of other identical elements in the process, method, article, or apparatus that includes said element.
[0182] Finally, it should be noted that the above description is only a preferred embodiment of this disclosure and is not intended to limit this disclosure. Although this disclosure has been described in detail with reference to the foregoing embodiments, those skilled in the art can still modify the technical solutions described in the foregoing embodiments or make equivalent substitutions for some of the technical features. Any modifications, equivalent substitutions, improvements, etc., made within the spirit and principles of this disclosure should be included within the protection scope of this disclosure.
Claims
1. A quantum-encrypted communication method, characterized in that, Includes the following steps: Receive communication requests, the types of which include those for establishing communication connections between clusters or between external network-side devices and clusters; Based on the type of the communication request, the corresponding communication mechanism is executed, wherein... When the communication mechanism is an inter-cluster communication mechanism, a real-time updated or real-time valid symmetric key is selected for encrypted communication between the clusters. When the communication mechanism is the communication mechanism between the external network side device and the cluster, the first device on the cluster information receiving side identifies the public key algorithm type in the communication request and dynamically matches the encryption algorithm to perform encrypted communication between the external network side device and the cluster. The dynamic matching encryption algorithm includes: identifying the public key algorithm type in the communication request and matching it with a traditional public key algorithm or a post-quantum cryptography algorithm; If the traditional public key algorithm is used, the source and destination addresses of the data packets are modified so that the data packets can be transmitted correctly in different network environments, thereby sending the communication request of the external network device to the cluster, and establishing communication between the external network device and the cluster. If the post-quantum cryptography algorithm is used, the cluster sends a key negotiation request to the external network-side device, causing the external network-side device to generate a session key using the post-quantum cryptography algorithm, and send the session key to the cluster, so that the external network-side device and the cluster can communicate encryptedly using the session key.
2. The quantum encrypted communication method according to claim 1, characterized in that, The method for selecting a symmetric key that is updated in real time includes: when the first device on the cluster information receiving side determines that the symmetric key is invalid, it initiates a key update request to the second device on the cluster information initiating side. The key update request is used to enable the second device to generate a new key, encrypt the new key, and send it to the first device. The first device and the second device then distribute the new key to the corresponding clusters to establish encrypted communication between the clusters.
3. The quantum encrypted communication method according to claim 2, characterized in that, The method of dynamically matching encryption algorithms includes: the first device on the cluster information receiving side identifies the public key algorithm type in the communication request, and selects the corresponding traditional public key algorithm or post-quantum cryptography algorithm to establish encrypted communication between the external network side device and the cluster.
4. A quantum-encrypted communication method for inter-cluster communication, wherein a first device on the cluster information receiving side is characterized in that, Includes the following steps: Receive a communication request from the cluster information sending side, wherein the communication request is used to establish a communication connection between the clusters of the cluster information sending side and the cluster information receiving side; Analyze the communication request to determine if a valid key exists. If so, the communication request is sent to the cluster information receiving side so that the cluster information receiving side and the cluster information sending side can establish a communication connection using the valid key; If not, the new key is obtained in real time, and a communication connection is established after the new key is obtained on the cluster information receiving side and the cluster information sending side. For communication between external network-side devices and the cluster, the first device on the cluster side includes the following steps: Receive communication requests sent by external network devices; analyze the communication requests to identify the public key algorithm type in the communication requests; Dynamically matching encryption algorithms based on public key algorithm type, the dynamic matching encryption algorithm includes: identifying the public key algorithm type in the communication request and matching it with a traditional public key algorithm or a post-quantum cryptography algorithm; If the traditional public key algorithm is used, the source and destination addresses of the data packets are modified so that the data packets can be transmitted correctly in different network environments, thereby sending the communication request of the external network device to the cluster, and establishing communication between the external network device and the cluster. If the post-quantum cryptography algorithm is used, the cluster sends a key negotiation request to the external network-side device, causing the external network-side device to generate a session key using the post-quantum cryptography algorithm, and send the session key to the cluster, so that the external network-side device and the cluster can communicate encryptedly using the session key.
5. The quantum encrypted communication method according to claim 4, characterized in that, The method for the first device to update and obtain the new key includes: The first device on the cluster information receiving side initiates a key update request to the second device on the cluster information initiating side; The update request is used to enable the second device to obtain a random number and generate a new key based on the random number. After encrypting the data using the public key of the first device, the encrypted data is sent to the first device, which then decrypts the encrypted data to obtain the new key.
6. The quantum encrypted communication method according to claim 4, characterized in that, After establishing a communication connection between the cluster information receiving side and the cluster information sending side, data transmission is performed by matching the corresponding tunnel mode or transmission mode based on the data transmission scenario.
7. A quantum-encrypted communication method for inter-cluster communication, wherein a second device on the cluster information sending side is characterized in that, Includes the following steps: A communication request is sent to the cluster information receiving side, wherein the communication request is used to establish a communication connection between the cluster information sending side and the cluster information receiving side. The communication request is analyzed by the first device on the cluster information receiving side to determine whether a valid key exists; If so, a communication connection is established between the cluster information receiving side and the cluster information sending side using the valid key; If not, a new key is generated in real time, and a communication connection is established after the new key is obtained by the cluster information receiving side and the cluster information sending side. For communication between external network-side devices and the cluster, the external network-side devices include the following steps: A communication request is sent to the cluster side so that the first device on the cluster side can analyze the communication request to identify the public key algorithm type in the communication request; Dynamically matching encryption algorithms based on public key algorithm type, the dynamic matching encryption algorithm includes: identifying the public key algorithm type in the communication request and matching it with a traditional public key algorithm or a post-quantum cryptography algorithm; If the traditional public key algorithm is used, the source and destination addresses of the data packets are modified so that the data packets can be transmitted correctly in different network environments, thereby sending the communication request of the external network device to the cluster, and establishing communication between the external network device and the cluster. If the post-quantum cryptography algorithm is used, the cluster sends a key negotiation request to the external network-side device, causing the external network-side device to generate a session key using the post-quantum cryptography algorithm, and send the session key to the cluster, so that the external network-side device and the cluster can communicate encryptedly using the session key.
8. The quantum encrypted communication method according to claim 7, characterized in that, The method for the second device to generate a new key in real time includes: The device receives a key update request sent by the first device. The update request is used to enable the second device to obtain a random number and generate a new key based on the random number. The second device then encrypts the data using the public key of the first device and sends the encrypted data to the first device. The first device then decrypts the encrypted data to obtain the new key.
9. The quantum encrypted communication method according to claim 7, characterized in that, After establishing a communication connection between the cluster information receiving side and the cluster information sending side, data transmission is performed by matching the corresponding tunnel mode or transmission mode based on the data transmission scenario.
10. A quantum-encrypted communication method for communication between an external network-side device and a cluster, wherein the first device on the cluster side is characterized in that... Includes the following steps: Receive a communication request sent by an external network-side device, wherein the communication request is used to enable the external network-side device to establish a communication connection with the cluster; The communication request is analyzed to identify the public key algorithm type in the communication request; Based on the public key algorithm type, the corresponding traditional public key algorithm or post-quantum cryptography algorithm is dynamically selected to establish communication between the external network device and the cluster. If the traditional public key algorithm is used, the source and destination addresses of the data packets are modified so that the data packets can be transmitted correctly in different network environments, thereby sending the communication request of the external network device to the cluster, and establishing communication between the external network device and the cluster. If the post-quantum cryptography algorithm is used, the cluster sends a key negotiation request to the external network-side device, causing the external network-side device to generate a session key using the post-quantum cryptography algorithm, and send the session key to the cluster, so that the external network-side device and the cluster can communicate encryptedly using the session key.
11. The quantum encrypted communication method according to claim 10, characterized in that, When selecting a post-quantum cryptography algorithm based on the public key algorithm type, the method for establishing a communication connection between the cluster and the external network-side device includes: The first device sends a key negotiation request to the external network-side device, the key negotiation request being used to enable the external network-side device to use the first device's public key to generate a session key using the post-quantum cryptography algorithm; After receiving the encrypted session key and verifying its correctness, the decrypted session key is distributed to the cluster.
12. The quantum encrypted communication method according to claim 11, characterized in that, After receiving the encrypted session key and verifying its correctness, the first device distributes the decrypted session key to the cluster and then clears the session key.
13. A quantum-encrypted communication method for communication between an external network-side device and a cluster, wherein the external network-side device is characterized in that... Includes the following steps: A communication request is sent to the cluster side, wherein the communication request is used to enable an external network-side device to establish a communication connection with the cluster, and to enable a first device on the cluster side to analyze the communication request to identify the public key algorithm type in the communication request, and to dynamically select a corresponding traditional public key algorithm or post-quantum cryptography algorithm based on the public key algorithm type to enable communication between the external network-side device and the cluster. If the traditional public key algorithm is used, the source and destination addresses of the data packets are modified so that the data packets can be transmitted correctly in different network environments, thereby sending the communication request of the external network device to the cluster, and establishing communication between the external network device and the cluster. If the post-quantum cryptography algorithm is used, the cluster sends a key negotiation request to the external network-side device, causing the external network-side device to generate a session key using the post-quantum cryptography algorithm, and send the session key to the cluster, so that the external network-side device and the cluster can communicate encryptedly using the session key.
14. The quantum encrypted communication method according to claim 13, characterized in that, When selecting a post-quantum cryptography algorithm based on the public key algorithm type, the method for establishing a communication connection between the cluster and the external network-side device includes: The external network-side device receives a key negotiation request sent by the first device. The key negotiation request is used to enable the external network-side device to use the public key of the first device to generate a session key using the post-quantum cryptography algorithm. After receiving and verifying the encrypted session key, the first device distributes the decrypted session key to the cluster.
15. The quantum encrypted communication method according to claim 14, characterized in that, After the first device receives the encrypted session key and verifies its correctness, it distributes the decrypted session key to the cluster, and then the first device clears the session key.
16. A quantum-encrypted communication system, suitable for communication between clusters, characterized in that, include: The first device is located on the cluster information receiving side; The second device, located on the cluster information sending side, is used to forward communication requests sent by the cluster information sending side to the first device; The first device is used to analyze the communication request and determine whether a valid key exists. If so, the communication request is sent to the cluster information receiving side so that the cluster information receiving side and the cluster information sending side can establish a communication connection using the valid key; If not, the new key is obtained in real time, and a communication connection is established after the new key is obtained on the cluster information receiving side and the cluster information sending side. It is also applicable to communication between external network-side devices and the cluster side, including: The first device, on the cluster side, is used to receive communication requests sent by the external network-side device; The first device dynamically selects either a traditional public-key algorithm or a post-quantum cryptography algorithm based on the public-key algorithm type, enabling communication between the external network device and the cluster. If the traditional public key algorithm is used, the source and destination addresses of the data packets are modified so that the data packets can be transmitted correctly in different network environments, thereby sending the communication request of the external network device to the cluster, and establishing communication between the external network device and the cluster. If the post-quantum cryptography algorithm is used, the cluster sends a key negotiation request to the external network-side device, causing the external network-side device to generate a session key using the post-quantum cryptography algorithm, and send the session key to the cluster, so that the external network-side device and the cluster can communicate encryptedly using the session key.
17. The quantum encrypted communication system according to claim 16, characterized in that, Both the first device and the second device include: The key module is used to determine whether a valid key exists based on the communication request. The communication management module is used to initiate a key update request when a valid key does not exist. A random number generation module is used to obtain a random number according to the update request and send the random number to the key module, which then generates a new key. An encryption / decryption and authentication module is used to encrypt the generated new key using the public key of the first device and then send the encrypted data to the communication management module, which then sends the encrypted data. Used to decrypt the received encrypted data to obtain the new key; The key negotiation module distributes the new key to the cluster information receiving side and the cluster information sending side, and establishes a communication connection after the cluster information receiving side and the cluster information sending side obtain the new key.
18. The quantum encrypted communication system according to claim 17, characterized in that, The communication management module is also used to establish a communication connection between the cluster information receiving side and the cluster information sending side, and then, based on the data transmission scenario, match the corresponding tunnel mode or transmission mode for data transmission.
19. The quantum encrypted communication system according to claim 16, characterized in that, The first device and / or the second device are located between the core switch and the firewall of the cluster.
20. The quantum encrypted communication system according to claim 16, characterized in that, The first device and / or the second device are hardware devices, or The first device and / or the second device are implemented by setting up a random number generator on a general-purpose computer and cooperating with a software system.
21. A quantum-encrypted communication system, suitable for communication between external network-side devices and a cluster side, characterized in that, include: The first device, on the cluster side, is used to receive communication requests sent by the external network-side device; The first device includes: The communication management module dynamically selects either a traditional public-key algorithm or a post-quantum cryptography algorithm based on the public-key algorithm type to establish communication between the external network device and the cluster. If the traditional public key algorithm is used, the source and destination addresses of the data packets are modified so that the data packets can be transmitted correctly in different network environments, thereby sending the communication request of the external network device to the cluster, and establishing communication between the external network device and the cluster. If the post-quantum cryptography algorithm is used, the cluster sends a key negotiation request to the external network-side device, causing the external network-side device to generate a session key using the post-quantum cryptography algorithm, and send the session key to the cluster, so that the external network-side device and the cluster can communicate encryptedly using the session key.
22. The quantum encrypted communication system according to claim 21, characterized in that, When the first device selects to use the post-quantum cryptography algorithm according to the public key algorithm type, it sends a key negotiation request to the external network side device. The key negotiation request is used to enable the external network side device to use the public key of the first device to encrypt and generate a session key using the post-quantum cryptography algorithm. The first device also includes: The encryption, decryption, and authentication module is used to obtain the session key after receiving the encrypted session key and verifying its correctness. The key negotiation module is used to distribute the session key to the cluster side.
23. A computer-readable storage medium, characterized in that, It stores a computer program for running a communication method, wherein the computer program causes a computer to perform the quantum encrypted communication method as described in any one of claims 1-3.
24. An electronic device, characterized in that, The electronic equipment is located between the core switch and the firewall of the cluster, including: One or more processors; memory; and One or more programs, wherein the one or more programs are stored in the memory and configured to be executed by the one or more processors, the programs being used to perform the quantum encrypted communication method as claimed in any one of claims 1-15 and the quantum encrypted communication system as claimed in any one of claims 16-22.
Citation Information
Patent Citations
Data synchronization method for Hadoop cluster
CN108540511A
Cluster talkback communication method and device, equipment and storage medium
CN116233767A
Anti-quantum secure communication method, device and equipment applied to public network channel
CN119402168A
Method of transmitting data in cluster business
CN1602091A