Data security transmission method and system based on homomorphic encryption and quantum key distribution
By using homomorphic encryption and quantum key distribution technologies in data transmission, the problems of low key transmission security and limited data encryption calculation are solved, and the secure transmission and integrity of data are achieved.
Patent Information
- Application Number
- CN202510415812.0
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-04-03
- Publication Date
- 2025-06-27
AI Technical Summary
In the prior art, the key transmission is low in security, data encryption and calculation are limited, transmission is susceptible to man-in-the-middle attacks and eavesdropping, and it is difficult to ensure data integrity and authenticity.
The method based on homomorphic encryption and quantum key distribution is adopted. By homomorphic encryption processing of plaintext data at the sending end, ciphertext data is generated, and quantum key is distributed using the quantum channel. The receiving end decrypts the ciphertext data through the quantum key.
It realizes secure encrypted transmission, reliable key distribution and accurate decryption of data during transmission, ensuring the security and integrity of data.
Smart Images

Figure CN120223286A_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the technical field of data secure transmission, and particularly to a data secure transmission method and system based on homomorphic encryption and quantum key distribution. Background Art
[0002] With the rapid development of information technology, the security problem of data in network transmission has become increasingly prominent. In the traditional data transmission process, the security of key distribution is difficult to be fully guaranteed, and it is vulnerable to man-in-the-middle attacks and eavesdropping, resulting in key leakage, and then the encrypted data loses protection. At the same time, traditional encryption algorithms may not support direct data calculation in the ciphertext state, which limits the flexibility and efficiency of data processing. In addition, the means for verifying the integrity and authenticity of transmitted data are not perfect enough, and it is difficult to ensure that the data obtained by the receiving end has not been tampered with.
[0003] The prior art has technical problems such as low security of key transmission, limited data encryption calculation, vulnerability to man-in-the-middle attacks and eavesdropping during transmission, and difficulty in guaranteeing data integrity and authenticity. Summary of the Invention
[0004] The present application provides a data secure transmission method and system based on homomorphic encryption and quantum key distribution, which are used to solve the technical problems in the prior art such as low security of key transmission, limited data encryption calculation, vulnerability to man-in-the-middle attacks and eavesdropping during transmission, and difficulty in guaranteeing data integrity and authenticity.
[0005] In view of the above problems, the present application provides a data secure transmission method and system based on homomorphic encryption and quantum key distribution.
[0006] In the first aspect of the present application, a data secure transmission method based on homomorphic encryption and quantum key distribution is provided, and the method includes:
[0007] Performing homomorphic encryption processing on the plaintext data at the sending end according to a predetermined encryption policy to obtain ciphertext data; activating a quantum channel, extracting the key distribution policy embedded in the quantum channel, distributing quantum keys according to the key distribution policy, and transmitting them to the receiving end; obtaining the ciphertext data sent by the sending end through a classical channel at the receiving end, and decrypting the ciphertext data by using the quantum keys to obtain decrypted data.
[0008] In the second aspect of the present application, a data secure transmission system based on homomorphic encryption and quantum key distribution is provided, and the system includes:
[0009] The ciphertext data acquisition module is used to perform homomorphic encryption processing on plaintext data at the sending end according to a predetermined encryption policy to obtain ciphertext data; the quantum channel activation module is used to activate the quantum channel, extract the key distribution policy embedded in the quantum channel, distribute quantum keys according to the key distribution policy, and transmit them to the receiving end; the decrypted data acquisition module is used to obtain the ciphertext data sent by the sending end through the classical channel at the receiving end, and decrypt the ciphertext data using the quantum key to obtain decrypted data.
[0010] In a third aspect of the present application, an electronic device is provided, and the device includes: a processor; a memory for storing executable instructions of the processor; wherein, the processor is used to execute the data security transmission method based on homomorphic encryption and quantum key distribution provided by the present application.
[0011] In a fourth aspect of the present application, a computer-readable storage medium is provided, storing a computer program, and the computer program is used to execute the data security transmission method based on homomorphic encryption and quantum key distribution provided by the present application.
[0012] One or more technical solutions provided in the present application have at least the following technical effects or advantages:
[0013] The ciphertext data acquisition module is used to perform homomorphic encryption processing on plaintext data at the sending end according to a predetermined encryption policy to obtain ciphertext data; the quantum channel activation module is used to activate the quantum channel, extract the key distribution policy embedded in the quantum channel, distribute quantum keys according to the key distribution policy, and transmit them to the receiving end; the decrypted data acquisition module is used to obtain the ciphertext data sent by the sending end through the classical channel at the receiving end, and decrypt the ciphertext data using the quantum key to obtain decrypted data. It achieves the technical effect of realizing secure encrypted transmission, reliable key distribution, and accurate decryption of data during the transmission process, and ensuring data security and transmission integrity. Description of the Drawings
[0014] In order to more clearly illustrate the technical solutions in the embodiments of the present invention, the following will briefly introduce the drawings required for the description of the embodiments. Obviously, the following drawings are only some embodiments of the present invention. For those of ordinary skill in the art, without creative efforts, other drawings can be obtained based on these drawings.
[0015] Figure 1 It is a schematic flowchart of the data security transmission method based on homomorphic encryption and quantum key distribution provided by the embodiments of the present application.
[0016] Figure 2Schematic structural diagram of a data secure transmission system based on homomorphic encryption and quantum key distribution provided by an embodiment of the present application.
[0017] Figure 3 Schematic structural diagram of an electronic device provided by the present application.
[0018] Explanation of reference numerals: ciphertext data acquisition module 10, quantum channel activation module 20, decrypted data acquisition module 30, processor 21, memory 22, input device 23, output device 24. Detailed implementation manners
[0019] The present application provides a data secure transmission method and system based on homomorphic encryption and quantum key distribution, which are used to solve the technical problems in the prior art, such as low security of key transmission, limited data encryption calculation, vulnerability to man-in-the-middle attacks and eavesdropping during transmission, and difficulty in ensuring data integrity and authenticity.
[0020] Next, the technical solutions in the embodiments of the present application will be clearly and completely described in conjunction with the accompanying drawings in the embodiments of the present application. Obviously, the described embodiments are only a part of the embodiments of the present application, rather than all of the embodiments. All other embodiments obtained by those of ordinary skill in the art based on the embodiments of the present application without creative efforts shall fall within the protection scope of the present application.
[0021] Embodiment 1, as Figure 1 shown, the present application provides a data secure transmission method based on homomorphic encryption and quantum key distribution, and the method includes:
[0022] Step S100: Perform homomorphic encryption processing on plaintext data at the sending end according to a predetermined encryption policy to obtain ciphertext data.
[0023] Specifically, at the initial stage of data secure transmission, the sender safeguards the predetermined encryption strategy for the initial security of the data. Specifically, it adopts a fully homomorphic encryption scheme based on the learning with errors problem on lattices, leveraging the hardness of the learning with errors (LWE) problem on lattices to construct the encryption system. The sender first sorts out the plaintext data to be transmitted, which may contain various types of information, such as enterprise-sensitive business data, user privacy information, etc. Subsequently, the encryption algorithm starts to operate based on the principle of the learning with errors problem on lattices. The algorithm will select some parameters, such as secret vectors, public matrices, etc., on the mathematical structure of the lattice using a random number generation mechanism. By performing mathematical operations on the plaintext data with these parameters, such as matrix multiplication, modular arithmetic, etc., the plaintext is gradually transformed into ciphertext form. In this process, the ciphertext not only hides the content of the original data, but also, based on the characteristics of fully homomorphic encryption, supports directly performing specific algebraic operations, such as addition and multiplication, on the ciphertext without decryption, which provides great convenience for subsequent data processing in the ciphertext state. Finally, after the encryption step, the sender successfully obtains the ciphertext data. During the subsequent transmission process, even if these ciphertext data are illegally obtained, without the correct key, it is difficult for attackers to restore the original plaintext information, thus laying a solid foundation for data secure transmission.
[0024] Step S200: Activate the quantum channel, extract the key distribution strategy embedded in the quantum channel, distribute quantum keys according to the key distribution strategy, and transmit them to the receiving end.
[0025] Specifically, the quantum channel needs to be activated first. As a special channel for transmitting quantum keys, the quantum channel has unique physical characteristics and security guarantee mechanisms. After activating the quantum channel, the embedded key distribution strategy is extracted from it. This strategy is based on the continuous variable characteristics of quantum states and uses the principles of quantum mechanics to generate and distribute keys. According to the extracted key distribution strategy, the sending end starts to prepare coherent state photons. Coherent state photons are photons with specific quantum states, and their phases and amplitudes have a certain stability. After preparing the coherent state photons, Gaussian modulation is performed on them. Gaussian modulation adjusts the phases and amplitudes of photons by introducing Gaussian-distributed random noise, thereby increasing the randomness and security of the keys. The modulated target photons are transmitted to the receiving end through the quantum channel. During the transmission process, the quantum characteristics of the quantum channel can effectively resist eavesdropping because any measurement of the quantum state will inevitably interfere with the quantum state itself, which can be detected by both communication parties. After receiving the target photons, the receiving end measures them through balanced homodyne detection technology. Balanced homodyne detection uses the principle of optical interference to interfere the received optical signal with the local oscillator optical signal, thereby accurately measuring the phase and amplitude information of the target photons. By processing these measurement results, the receiving end can extract the quantum key. Throughout the process, the quantum channel can also be analyzed for eavesdropping countermeasures and attack countermeasures by reading the predetermined eavesdropping countermeasure characteristics and attack countermeasure characteristics, and a comprehensive security coefficient can be obtained to ensure the security of quantum key distribution and achieve the secure transmission of quantum keys from the sending end to the receiving end.
[0026] Step S300: Obtain the ciphertext data sent by the sending end through the classical channel at the receiving end, and decrypt the ciphertext data by using the quantum key to obtain decrypted data.
[0027] Specifically, in the data transmission link, the sending end has obtained the ciphertext data through homomorphic encryption processing and completed the distribution of the quantum key through the quantum channel. At this time, the receiving end receives the ciphertext data sent by the sending end through the classical channel. The classical channel, as a conventional data transmission channel, is responsible for transmitting the ciphertext data and the distribution characteristic parameters of the quantum key. After successfully obtaining the ciphertext data, the receiving end will call the quantum key received and saved through the quantum channel before. According to the decryption rules of the homomorphic encryption algorithm, the quantum key and the ciphertext data are subjected to corresponding operations, such as performing inverse transformation operations on the ciphertext data according to the specific information contained in the key, etc., to restore the encrypted ciphertext to the original plaintext form, and finally obtain the decrypted data. After obtaining the decrypted data, the receiving end will also perform an integrity check on it. Once the check result does not meet the predetermined decryption constraints, a warning instruction will be issued and emergency intervention for the leakage of the plaintext data will be implemented to ensure the security and integrity of the data.
[0028] In a possible implementation manner, step S100 further includes:
[0029] Step S110: The predetermined encryption strategy refers to a fully homomorphic encryption scheme based on the learning with errors problem over lattices.
[0030] Specifically, in the encryption link of data secure transmission, the adopted predetermined encryption strategy is clarified, that is, a fully homomorphic encryption scheme based on the learning with errors problem over lattices. This scheme constructs an encryption system based on lattice theory and the learning with errors problem. A lattice is a discrete vector space structure, and its special properties provide a solid mathematical foundation for encryption. The learning with errors problem has computational complexity, and it is difficult for attackers to solve it by conventional means, which guarantees the security of encryption. Fully homomorphic encryption means that in the ciphertext state, specific algebraic operations such as addition and multiplication can be performed on data without decryption, which greatly expands the flexibility of encrypted data in practical applications. When performing encryption, the sender first randomly selects some vectors and matrices in the lattice as encryption parameters. Then, these parameters are used to perform mathematical transformations on the plaintext data. By combining the plaintext with the elements in the lattice and adding noise that conforms to the distribution of the learning with errors problem, the plaintext is converted into ciphertext. Throughout the process, the algebraic structure of the lattice ensures that after the ciphertext is operated on, the decryption result can be consistent with the result of directly performing the same operation on the plaintext, and the security of the encryption process depends on the difficulty of the learning with errors problem, ensuring that even if the ciphertext is intercepted during transmission and processing, the plaintext information cannot be obtained without the correct key, thus laying a solid foundation for data secure transmission.
[0031] In a possible implementation manner, step S200 further includes:
[0032] Step S210: The key distribution strategy refers to a scheme for generating and distributing keys by using the continuous variable characteristics of quantum states.
[0033] Specifically, in a data security transmission system based on homomorphic encryption and quantum key distribution, the key distribution strategy is a scheme that uses the continuous variable characteristics of quantum states to generate and distribute keys. This scheme is based on the basic principles of quantum mechanics and makes full use of the unique properties of quantum states to ensure the security and randomness of key distribution. The continuous variable characteristics of quantum states are reflected in some physical quantities (such as phase, amplitude), and these variables can take values within a continuous range. In the key generation stage, the sender uses quantum optical devices to prepare an optical field with a specific quantum state, such as a coherent state optical field. A coherent state is a quantum state close to classical light, and its phase and amplitude have a definite relationship. The sender randomly modulates the phase or amplitude of the coherent state optical field, which is realized based on a quantum random number generator. The generation of random numbers has true randomness and is not affected by any deterministic algorithm. The modulated optical field then carries the key information. During the distribution process, the optical field carrying the key information is transmitted to the receiver through a quantum channel. The quantum channel uses media such as optical fibers to transmit photons. During the transmission process, the characteristics of the quantum state make any measurement or eavesdropping behavior on the quantum state inevitably interfere with the quantum state itself, thus being detected by both communication parties. The receiver uses techniques such as balanced homodyne detection to measure the continuous variables such as the phase and amplitude of the received optical field, and then extracts the original key information from the measurement results in combination with the information processing method previously agreed upon by the sender and the receiver. This key distribution scheme that utilizes the continuous variable characteristics of quantum states can maximize the security and non-eavesdroppability of the key during the key generation and distribution processes, providing secure and reliable key support for subsequent data decryption.
[0034] In a possible implementation manner, step S200 further includes:
[0035] Step S210: Prepare coherent state photons at the sender according to the key distribution strategy.
[0036] Step S220: Perform Gaussian modulation on the photons to obtain target photons and transmit them to the receiver through the quantum channel.
[0037] Step S230: The receiver measures the target photons through balanced homodyne detection to obtain the quantum key.
[0038] Specifically, at the sending end, according to the determined key distribution strategy that utilizes the characteristics of continuous variable quantum states, the preparation of coherent state photons begins. The sending end constructs an experimental setup with the help of quantum optical instruments such as lasers, optical modulators, and beam splitters. First, a stable laser beam is generated by the laser, which has specific frequency, power, and polarization characteristics. Then, the laser beam is finely adjusted through the optical modulator, making the quantum state of the laser beam gradually approach the coherent state. In this process, the optical modulator changes the quantum characteristics such as the phase and amplitude of the laser beam according to the preset parameters. The beam splitter then appropriately splits the laser beam to obtain the number of photons that meet the requirements for subsequent key distribution. Through the coordinated action of a series of optical elements, coherent state photons that meet the requirements are finally prepared. These coherent state photons lay the foundation for the subsequent generation and distribution of quantum keys. They carry the key quantum information that can be used for encryption and decryption, and the stability and controllability of their quantum states are important guarantees for the security and reliability of the entire quantum key distribution process.
[0039] After the sending end prepares the coherent state photons, Gaussian modulation is performed on these photons to obtain the target photons. Gaussian modulation is a key operation. Its principle is to superimpose random noise that conforms to the Gaussian distribution on the phase or amplitude of the photons. The sending end uses a modulation device to generate a series of random numbers that follow the Gaussian distribution based on a quantum random number generator. These random numbers are converted into electrical signals and loaded onto the optical modulator. When the coherent state photons pass through the optical modulator, the phase or amplitude of the photons will change randomly according to the change of the electrical signal, thus completing the Gaussian modulation and obtaining the target photons. The information carried by the target photons after Gaussian modulation has a high degree of randomness, greatly increasing the security of the key and making it difficult for eavesdroppers to obtain useful information from the photons. Subsequently, these target photons are transmitted to the receiving end through the quantum channel. The quantum channel usually uses media such as optical fibers. It utilizes the basic principles of quantum mechanics, such as the quantum no-cloning theorem and the measurement collapse characteristics of quantum states, to ensure the security of photons during transmission. Once an eavesdropper attempts to intercept or measure these photons, it will inevitably interfere with the quantum state of the photons, causing the state of the photons received by the receiving end to change, which will be detected by both communication parties, effectively preventing the key from being stolen during transmission and ensuring the security of quantum key distribution.
[0040] During the quantum key distribution process, after the receiving end receives the target photons transmitted through the quantum channel, a balanced heterodyne detection method is adopted to obtain the quantum key. Balanced heterodyne detection is a high-sensitivity measurement technique based on the principle of light interference. The receiving end is equipped with a local oscillator that generates a local oscillation light beam with a frequency close to that of the target photons. The target photons and the local oscillation light meet and interfere in a beam splitter, and the interfered optical signal is split into two paths, which are respectively detected by two photodetectors. These two photodetectors convert the optical signal into an electrical signal. Due to the interference between the target photons and the local oscillation light, these two electrical signals contain the phase and amplitude information of the target photons. The signal processing system at the receiving end performs a differential operation on these two electrical signals to remove the common-mode noise, thereby extracting the phase difference and amplitude difference information between the target photons and the local oscillation light. These information are closely related to the parameters used by the sending end in preparing and modulating the photons and the agreed key extraction rules. The receiving end processes and analyzes the extracted phase difference and amplitude difference information according to the key extraction algorithm previously agreed with the sending end. Through mathematical operations and data conversion, the quantum key is demodulated from these measurement data. During the whole process, the high-precision characteristic of the balanced heterodyne detection technology ensures that the key information carried by the target photons can be accurately obtained, and further ensures that the receiving end can reliably obtain the quantum key, providing security guarantee for the subsequent decryption work.
[0041] In a possible implementation manner, step S210 further includes:
[0042] Step S211: Read the predetermined eavesdropping countermeasure feature.
[0043] Step S212: Perform eavesdropping countermeasure analysis on the quantum channel based on the predetermined eavesdropping countermeasure feature to obtain eavesdropping countermeasure information.
[0044] Step S213: Read the predetermined attack countermeasure feature.
[0045] Step S214: Perform attack countermeasure analysis on the quantum channel based on the predetermined attack countermeasure feature to obtain attack countermeasure information.
[0046] Step S215: Perform normalized weighted analysis on the eavesdropping countermeasure information and the attack countermeasure information to obtain the comprehensive security coefficient of the quantum channel.
[0047] Step S216: Among them, the comprehensive security coefficient is used to characterize the security degree of the quantum key distributed by the quantum channel.
[0048] Specifically, a series of key information for guarding against eavesdropping, namely predetermined eavesdropping countermeasure features, are preset at the sending end or the receiving end. These features are stored in a specific database or configuration file of the system, and their sources are extensive and carefully screened and set. It includes various attribute descriptions of quantum states under the normal operating state of the quantum channel, such as the normal fluctuation ranges of quantum state parameters such as the phase and amplitude of specific photons; it also covers abnormal features summarized from past actual eavesdropping events or simulated eavesdropping experiments, such as the quantum state change patterns caused by eavesdropping behaviors, the abnormal change trends of signal intensities, etc. Reading these predetermined eavesdropping countermeasure features from the corresponding storage locations provides a key comparison basis for subsequent eavesdropping countermeasure analysis of the quantum channel, so as to timely detect potential eavesdropping threats and ensure the security of the quantum key distribution process.
[0049] To perform attack countermeasure analysis on the quantum channel to obtain attack countermeasure information, a variety of specific implementation means are used. First, a quantum monitoring device is used to monitor the quantum channel in real time, continuously collecting data such as quantum state information, signal intensity, and frequency. The collected data is compared with the predetermined attack countermeasure features, which may include information such as abnormal change patterns of quantum states and abnormal fluctuation ranges of signal frequencies under specific attack methods. For example, in the case of a man-in-the-middle attack, the phase and amplitude of the quantum state will show sudden changes that do not conform to the normal communication rules, and the monitoring device will capture these abnormal changes. At the same time, data analysis algorithms are used to deeply mine the monitoring data, and machine learning algorithms are used to learn and classify a large amount of historical data and real-time data to identify possible attack types and attack time points. If it is detected that the data pattern matches the known attack characteristics, the scope of influence of the attack is further analyzed, such as determining the number of qubits affected by the attack and the degree of influence on the accuracy of key distribution, and finally integrating this information to obtain comprehensive attack countermeasure information for subsequent measures to ensure the security of the quantum channel.
[0050] Read the predetermined attack countermeasure features from the database or configuration file storing security policies and feature data. These features are set based on past research, analysis of quantum channel attack methods, and the experience accumulated from a large number of simulated attack experiments. They cover a variety of key identification information for attacks on the quantum channel, such as specific change patterns of quantum states in quantum state interference attacks; abnormal manifestations of signal source characteristics in disguise attacks; abnormal steps or parameters that occur during the execution of the protocol in attacks against vulnerabilities in quantum key distribution protocols. Reading these predetermined attack countermeasure features is to provide a precise comparison standard and basis for subsequent judgment of whether the quantum channel has been attacked and identification of the attack type, so as to timely detect potential attack risks and maintain the security of distributing quantum keys through the quantum channel.
[0051] The support vector machine (SVM) algorithm in machine learning is used to analyze and counter quantum channel attacks. First, preprocess the predetermined attack countermeasure feature data to extract key feature vectors, such as the change amplitude of quantum states, the fluctuation frequency of signal intensity, etc. Use these feature vectors as training data, mark different attack type labels, and construct a training data set. Then, use the SVM algorithm to learn from the training data set. By finding an optimal classification hyperplane, separate the data of different attack types as much as possible. When monitoring the quantum channel in real time, collect the data in the quantum channel and convert it into feature vectors, and input them into the trained SVM model. The SVM model judges which attack type the current data belongs to according to the learned classification rules. If it does not belong to any known attack type, it is determined to be in a normal state. At the same time, further analyze the severity of the attack in combination with the attack type and relevant data, such as calculating the proportion of qubits affected by the attack, etc. Finally, integrate these results to obtain attack countermeasure information for subsequent operations to ensure the security of the quantum channel.
[0052] To accurately evaluate the security of the quantum channel, it is necessary to perform normalized weighted analysis on the eavesdropping countermeasure information and the attack countermeasure information to obtain a comprehensive security coefficient. First, since the data dimensions and magnitudes of the eavesdropping countermeasure information and the attack countermeasure information are different, in order to make them comparable, normalization processing is adopted. For example, use the min-max normalization method to map each item of data in the eavesdropping countermeasure information and the attack countermeasure information to the interval [0, 1] to eliminate the influence of data differences on the analysis results. Then, according to the importance of eavesdropping and attacks on the security of the quantum channel, different weights are assigned to the eavesdropping countermeasure information and the attack countermeasure information. Determine the weights through expert experience, historical data statistical analysis, etc. Suppose after evaluation, eavesdropping poses a greater threat to the security of the quantum channel, and a higher weight, such as 0.6, is assigned to the eavesdropping countermeasure information; the weight of the attack countermeasure information is 0.4. After that, according to the weighted formula, multiply the normalized eavesdropping countermeasure information by its weight, multiply the attack countermeasure information by its weight, and then add the two results. The obtained value is the comprehensive security coefficient of the quantum channel. This coefficient can intuitively reflect the security level of the quantum channel when distributing quantum keys, providing a quantitative basis for subsequent judgments on whether additional security measures are needed.
[0053] The comprehensive security coefficient, as an intuitive quantitative indicator, is used to accurately characterize the security level of the quantum keys distributed by the quantum channel. The higher the value, the lower the risk of the quantum channel being eavesdropped and attacked, and the higher the security of the quantum key distribution; conversely, the lower the value means that the security of the quantum key faces a greater threat, and the communication parties need to take corresponding measures to ensure the security of data transmission.
[0054] In a possible implementation manner, step S300 further includes:
[0055] Step S310: The classical channel is established between the sending end and the receiving end for transmitting the ciphertext data and the distribution characteristic parameters of the quantum key.
[0056] Specifically, a classical channel is established between the sending end and the receiving end. This channel is built using conventional communication technologies, such as wired networks (like optical fibers, twisted pairs, etc.) or wireless networks (such as Wi-Fi, 4G / 5G, etc.). Its main task is to transmit two types of key data: ciphertext data and the distribution characteristic parameters of the quantum key. The ciphertext data is the product of encrypting the plaintext data by the sending end according to a predetermined encryption strategy using a fully homomorphic encryption scheme based on the learning with errors problem over lattices. It carries the encrypted form of the original information, ensuring that even if the data is intercepted during transmission, the plaintext content cannot be obtained without the corresponding quantum key. The distribution characteristic parameters of the quantum key are important information generated during the quantum key distribution process, covering details such as the modulation of quantum states and key measurement parameters. These parameters are crucial for the receiving end to accurately receive, verify, and use the quantum key for decryption. The classical channel, through a reliable data transmission protocol, securely and accurately transmits the ciphertext data and the distribution characteristic parameters of the quantum key from the sending end to the receiving end, providing necessary support for the subsequent decryption of data by the receiving end and the verification of the integrity and authenticity of the data.
[0057] In a possible implementation manner, step S300 further includes:
[0058] Step S320: Perform an integrity check on the decrypted data to obtain a check result.
[0059] Step S330: If the check result does not meet the predetermined decryption constraints, issue a warning instruction, and perform a leakage emergency intervention on the plaintext data based on the warning instruction.
[0060] Specifically, after the receiving end completes the decryption operation of the ciphertext data using the quantum key, the integrity of the decrypted data is verified. The receiving end adopts a verification mechanism, such as the hash function verification method. First, the receiving end selects a suitable hash function that can convert input data of any length into a hash value of a fixed length. For the decrypted data, the receiving end uses the selected hash function to calculate it, thus obtaining a hash value. At the same time, the receiving end will obtain the hash value of the same plaintext data that has been calculated by the sending end before encryption and transmitted in a secure and reliable manner. For example, when sending the ciphertext data, this hash value is transmitted together with the ciphertext. Then, the receiving end compares these two hash values. If the two are exactly the same, it indicates that the decrypted data has not been tampered with or lost during the transmission from the sending end to the receiving end, and the integrity is good, and the verification result is that the data is complete; on the contrary, if there are differences between the two hash values, it means that there is a problem with the decrypted data during the transmission process, and the integrity is damaged, and the verification result is that the data is incomplete.
[0061] If it is found that the verification result does not meet the predetermined decryption constraint after verifying the integrity of the decrypted data, this indicates that the decrypted data may be abnormally tampered with, partially lost, etc., and the security and integrity of the data are threatened. At this time, a warning instruction is immediately issued to quickly trigger a series of preset emergency response mechanisms. Automatically notify relevant security management personnel and inform them of the data anomaly by means of email, text message or instant message within the system. At the same time, based on the warning instruction, leakage emergency intervention is carried out on the plaintext data. For example, quickly cut off the potentially risky network connection to prevent further leakage of data; start the data backup and recovery process and try to recover the plaintext data from the latest reliable backup to ensure the availability of the data; conduct a comprehensive security scan of the system to check for possible security vulnerabilities and determine whether the data anomaly is due to an error during the transmission process or a malicious attack. Through this series of emergency intervention measures, the loss caused by data leakage is minimized as much as possible, and the security of the data and the normal operation of the system are guaranteed.
[0062] Embodiment 2, based on the same inventive concept as the data security transmission method based on homomorphic encryption and quantum key distribution in the foregoing embodiment, as Figure 2 shown, the present application provides a data security transmission system based on homomorphic encryption and quantum key distribution. The system in the embodiments of the present application and the method embodiments are based on the same inventive concept. Among them, the system includes:
[0063] A ciphertext data acquisition module 10, configured to perform homomorphic encryption processing on plaintext data at the sending end according to a predetermined encryption policy to obtain ciphertext data.
[0064] The quantum channel activation module 20 is used to activate the quantum channel, extract the key distribution strategy embedded in the quantum channel, distribute quantum keys according to the key distribution strategy, and transmit them to the receiving end.
[0065] The decrypted data acquisition module 30 is used to acquire the ciphertext data sent by the sending end through the classical channel at the receiving end, and decrypt the ciphertext data using the quantum key to obtain decrypted data.
[0066] Furthermore, the system is also used to implement the following functions:
[0067] The predetermined encryption strategy refers to a fully homomorphic encryption scheme based on the learning with errors problem on lattices.
[0068] Furthermore, the system is also used to implement the following functions:
[0069] The key distribution strategy refers to a scheme for generating and distributing keys by utilizing the continuous variable characteristics of quantum states.
[0070] Furthermore, the system is also used to implement the following functions:
[0071] According to the key distribution strategy, coherent state photons are prepared at the sending end; the photons are subjected to Gaussian modulation to obtain target photons, which are transmitted to the receiving end through the quantum channel; the receiving end measures the target photons through balanced homodyne detection to obtain the quantum key.
[0072] Furthermore, the system is also used to implement the following functions:
[0073] Read the predetermined eavesdropping countermeasure features; perform eavesdropping countermeasure analysis on the quantum channel based on the predetermined eavesdropping countermeasure features to obtain eavesdropping countermeasure information; read the predetermined attack countermeasure features; perform attack countermeasure analysis on the quantum channel based on the predetermined attack countermeasure features to obtain attack countermeasure information; perform normalized weighted analysis on the eavesdropping countermeasure information and the attack countermeasure information to obtain the comprehensive security coefficient of the quantum channel; wherein, the comprehensive security coefficient is used to characterize the security degree of the quantum key distributed by the quantum channel.
[0074] Furthermore, the system is also used to implement the following functions:
[0075] The classical channel is established between the sending end and the receiving end, and is used to transmit the ciphertext data and the distribution characteristic parameters of the quantum key.
[0076] Furthermore, the system is also used to implement the following functions:
[0077] Perform integrity verification on the decrypted data to obtain a verification result; if the verification result does not meet the predetermined decryption constraint, issue a warning instruction, and perform leakage emergency intervention on the plaintext data based on the warning instruction.
[0078] Embodiment III Figure 3 It is a schematic structural diagram of an electronic device provided in Embodiment III of the present application, and is a block diagram of an exemplary electronic device suitable for implementing the embodiments of the present invention. Figure 3 The displayed electronic device is only an example, and should not bring any limitation to the functions and usage scope of the embodiments of the present invention. As Figure 3 shown, the electronic device includes a processor 21, a memory 22, an input device 23, and an output device 24; the number of processors 21 in the electronic device can be one or more. Figure 3 Taking one processor 21 as an example, the processor 21, the memory 22, the input device 23, and the output device 24 in the electronic device can be connected through a bus or other means. Figure 3 Taking the connection through the bus as an example.
[0079] Embodiment IV, the memory 22, as a computer-readable storage medium, can be used to store software programs, computer-executable programs, and modules, such as program instructions / modules corresponding to the data security transmission method based on homomorphic encryption and quantum key distribution in the embodiments of the present application. The processor 21 executes various functional applications and data processing of the computer device by running the software programs, instructions, and modules stored in the memory 22, that is, implements the above-mentioned data security transmission method based on homomorphic encryption and quantum key distribution.
[0080] It should be noted that the above-mentioned sequence of the embodiments of the present application is only for description and does not represent the superiority or inferiority of the embodiments. And the above describes specific embodiments of this specification. In addition, the processes depicted in the drawings do not necessarily require the specific order or continuous order shown to achieve the desired result. In some embodiments, multitasking and parallel processing are also possible or may be advantageous.
[0081] The above are only the preferred embodiments of the present application and are not intended to limit the present application. Any modifications, equivalent replacements, improvements, etc. made within the spirit and principles of the present application shall be included in the protection scope of the present application.
[0082] This specification and the drawings are only exemplary descriptions of the present application and are considered to cover any and all modifications, variations, combinations, or equivalents within the scope of the present application. Obviously, those skilled in the art can make various changes and modifications to the present application without departing from the scope of the present application. Thus, if these modifications and variations of the present application fall within the scope of the present application and its equivalent technologies, the present application is intended to include these changes and modifications.
Claims
1. A data security transmission method based on homomorphic encryption and quantum key distribution, characterized in that: include: Perform homomorphic encryption on the plaintext data at the sending end according to a predetermined encryption strategy to obtain ciphertext data; activating a quantum channel, extracting a key distribution strategy embedded in the quantum channel, distributing a quantum key according to the key distribution strategy, and transmitting the quantum key to a receiving end; The receiving end obtains the ciphertext data sent by the sending end through the classical channel, and uses the quantum key to decrypt the ciphertext data to obtain decrypted data.
2. The data security transmission method based on homomorphic encryption and quantum key distribution according to claim 1 is characterized in that: The predetermined encryption strategy refers to a fully homomorphic encryption scheme based on the learning error problem on a lattice.
3. The data security transmission method based on homomorphic encryption and quantum key distribution according to claim 1 is characterized in that: The key distribution strategy refers to a scheme for generating and distributing keys using the continuous variable characteristics of quantum states.
4. The data security transmission method based on homomorphic encryption and quantum key distribution according to claim 3 is characterized in that: Activating a quantum channel, extracting a key distribution strategy embedded in the quantum channel, distributing a quantum key according to the key distribution strategy, and transmitting the quantum key to a receiving end, including: According to the key distribution strategy, preparing coherent state photons at the transmitting end; Gaussian modulating the photons to obtain target photons, and transmitting the target photons to the receiving end through the quantum channel; The receiving end measures the target photon through balanced heterodyne detection to obtain the quantum key.
5. The data security transmission method based on homomorphic encryption and quantum key distribution according to claim 4 is characterized in that: Before activating the quantum channel, extracting the key distribution strategy embedded in the quantum channel, distributing the quantum key according to the key distribution strategy, and transmitting it to the receiving end, it also includes: Reading predetermined eavesdropping countermeasure features; Performing eavesdropping countermeasure analysis on the quantum channel based on the predetermined eavesdropping countermeasure feature to obtain eavesdropping countermeasure information; Read the predetermined attack countermeasure characteristics; Performing attack countermeasure analysis on the quantum channel based on the predetermined attack countermeasure feature to obtain attack countermeasure information; Performing normalized weighted analysis on the eavesdropping countermeasure information and the attack countermeasure information to obtain a comprehensive security factor of the quantum channel; The comprehensive security factor is used to characterize the security level of the quantum key distributed through the quantum channel.
6. According to claim 1, the data security transmission method based on homomorphic encryption and quantum key distribution is characterized in that: The classical channel is established between the transmitting end and the receiving end, and is used to transmit the ciphertext data and the distribution characteristic parameters of the quantum key.
7. The data security transmission method based on homomorphic encryption and quantum key distribution according to claim 1 is characterized in that: The receiving end obtains the ciphertext data sent by the sending end through the classical channel, and decrypts the ciphertext data using the quantum key to obtain the decrypted data, further comprising: Performing integrity check on the decrypted data to obtain a check result; If the verification result does not meet the predetermined decryption constraint, a warning instruction is issued, and based on the warning instruction, an emergency intervention is performed on the leakage of the plaintext data.
8. A data security transmission system based on homomorphic encryption and quantum key distribution, characterized in that: The system is used to implement the data security transmission method based on homomorphic encryption and quantum key distribution according to any one of claims 1 to 7, and the system includes: The ciphertext data acquisition module is used to perform homomorphic encryption processing on the plaintext data at the sending end according to a predetermined encryption strategy to obtain ciphertext data; A quantum channel activation module, used to activate the quantum channel, extract the key distribution strategy embedded in the quantum channel, distribute the quantum key according to the key distribution strategy, and transmit it to the receiving end; The decrypted data acquisition module is used to acquire the ciphertext data sent by the sending end through the classical channel at the receiving end, and decrypt the ciphertext data using the quantum key to obtain decrypted data.
9. An electronic device comprising a memory, a processor and a computer program stored in the memory and executable on the processor, characterized in that: When the processor executes the computer program, the method for secure data transmission based on homomorphic encryption and quantum key distribution as described in any one of claims 1 to 7 is implemented.
10. A computer-readable storage medium having a computer program stored thereon, characterized in that: When the program is executed by a processor, the method for secure data transmission based on homomorphic encryption and quantum key distribution as described in any one of claims 1 to 7 is implemented.
Citation Information
Cited By
Rail transit quantum communication system data transmission method, device, system and medium
CN120785532A