Method for fusing HIP protocol with QKD key and communication system
By integrating quantum key distribution technology into the HIP protocol, the problem of network communication security in the quantum computing era is solved, and high-reliability key exchange and identity verification is achieved, ensuring the confidentiality and integrity of communication data.
Patent Information
- Application Number
- CN202510355843.1
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-03-25
- Publication Date
- 2025-06-27
AI Technical Summary
The existing network communication protocols face the problem of key leakage and identity verification processes threatened in the era of quantum computing, especially the traditional public key encryption algorithms are difficult to resist quantum computing attacks.
By integrating quantum key distribution (QKD) technology into the HIP protocol, a shared key cannot be cracked by quantum computing is generated, and quantum-secure key exchange and authentication are realized.
Significantly improve network security, ensure long-term security of communication processes, improve the reliability of identity verification, and maintain compatibility with existing communication standards.
Smart Images

Figure CN120223300A_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the field of communications, and in particular, to a method for integrating QKD keys into the HIP protocol and a communication system. Background Art
[0002] In existing network communication protocols, such as the HIP protocol, key exchange and authentication mainly rely on traditional public-key encryption algorithms, such as the Diffie-Hellman algorithm, which provide sufficient security in the current computing environment. However, with the rapid development of quantum computing, the security of these algorithms is being challenged unprecedentedly. Quantum computers have the potential to solve complex mathematical problems that are difficult for traditional computers to handle, such as large integer factorization and discrete logarithms, which may thus break existing encryption algorithms.
[0003] Therefore, traditional key exchange mechanisms, including public key infrastructure (PKI) and the Diffie-Hellman algorithm, may become vulnerable in the face of quantum computing, leading to key leakage and threats to the authentication process.
[0004] Existing communication standards, such as 3GPP protocols and TLS / SSL, although they define a set of communication and security protocols, have not fully considered the threat of quantum computing. Therefore, a major technical problem that urgently needs to be solved is how to maintain the security of network communication in the era of quantum computing, especially in terms of key exchange and authentication. One of the exploration directions to solve this problem is to use quantum key distribution (QKD) technology, which uses the principles of quantum mechanics to generate and distribute keys, providing a key exchange mechanism that cannot be eavesdropped even in the era of quantum computing. By integrating QKD technology into the HIP protocol, traditional public-key encryption algorithms can be replaced to achieve quantum-secure key exchange and authentication, thus ensuring the long-term security of the communication process. Summary of the Invention
[0005] The purpose of the present invention is to provide a method for integrating QKD keys into the HIP protocol and a communication system to improve the above problems.
[0006] To achieve the above purpose, the technical solutions adopted in the embodiments of the present invention are as follows:
[0007] In a first aspect, an embodiment of the present invention provides a method for integrating QKD keys into the HIP protocol, the method including:
[0008] The initiator sends a first data packet to the responder through a classical network, the first data packet including QKD parameters, the QKD parameters including the target QKD protocol type supported by the initiator;
[0009] After receiving the first data packet, the responder feeds back a second data packet to the initiator. The second data packet includes confusion information and a QKD matching identifier. The confusion information includes a first random number and a difficulty coefficient;
[0010] After receiving the second data packet, the initiator and the responder perform quantum key negotiation to generate a responder quantum key and an initiator quantum key;
[0011] The initiator generates a second random number that meets the difficulty coefficient and sends a third data packet to the responder through a classical network. The third data packet includes first random encrypted data obtained by encrypting the first random number and the second random number with the initiator quantum key;
[0012] After receiving the third data packet, the responder decrypts it with the responder quantum key and compares whether the decrypted first random number is the same as the first random number stored by it. If they are the same, the responder sends a fourth data packet to the initiator through a classical network. The fourth data packet includes second random encrypted data obtained by encrypting the decrypted second random number with the responder quantum key;
[0013] After receiving the fourth data packet, the initiator decrypts it with the initiator quantum key and compares whether the decrypted second random number is the same as the second random number stored by it. If they are the same, the initiator feeds back a quantum key matching success prompt message to the responder.
[0014] In a second aspect, an embodiment of the present invention provides a communication system. The communication system includes an initiator and a responder. The communication system is used to execute the method for fusing QKD keys with the HIP protocol described above.
[0015] Compared with the prior art, a method and a communication system for integrating QKD keys in the HIP protocol provided by the embodiments of the present invention are as follows: The initiating end sends a first data packet to the responding end through a classical network, and the first data packet includes QKD parameters; after receiving the first data packet, the responding end feeds back a corresponding second data packet to the initiating end, and the second data packet includes confusion information and a QKD matching identifier, and the confusion information includes a first random number and a difficulty coefficient; after receiving the second data packet, the initiating end and the responding end perform quantum key negotiation to generate a responding party quantum key and an initiating party quantum key; the initiating end generates a second random number that meets the difficulty coefficient, and sends a third data packet to the responding end through the classical network, and the third data packet includes first random encrypted data obtained by encrypting the first random number and the second random number with the initiating party quantum key; after receiving the third data packet, the responding end decrypts it with the responding party quantum key, and compares whether the decrypted first random number is the same as the first random number stored by it. If they are the same, it sends a fourth data packet to the initiating end through the classical network, and the fourth data packet includes second random encrypted data obtained by encrypting the decrypted second random number with the responding party quantum key; after receiving the fourth data packet, the initiating end decrypts it with the initiating party quantum key, and compares whether the decrypted second random number is the same as the second random number stored by it. If they are the same, it feeds back a quantum key matching success prompt message to the responding end. By integrating the quantum key distribution (QKD) technology with the HIP protocol, the network security is significantly improved in the key exchange and authentication phases. By using the principles of quantum mechanics, a shared key that cannot be cracked by quantum computing is generated, effectively resisting the threat of quantum computing. The reliability of authentication is improved, and the confidentiality and integrity of communication data are ensured. At the same time, compatibility with existing communication standards is maintained, facilitating practical deployment, and providing a technologically leading security guarantee for communication protocols in the quantum era.
[0016] To make the above objects, features, and advantages of the present invention more obvious and understandable, the following specific preferred embodiments are given in conjunction with the accompanying drawings and described in detail as follows. BRIEF DESCRIPTION OF THE DRAWINGS
[0017] To more clearly illustrate the technical solutions of the embodiments of the present invention, the following briefly introduces the drawings required to be used in the embodiments. It should be understood that the following drawings only show some embodiments of the present invention, and therefore should not be regarded as limiting the scope. For those of ordinary skill in the art, other relevant drawings can be obtained based on these drawings without creative efforts.
[0018] Figure 1 It is a signaling interaction schematic diagram of the method for integrating QKD keys in the HIP protocol provided by the embodiments of the present invention.
[0019] Figure 2One of the flow diagrams of the method for integrating QKD keys with the HIP protocol provided by the embodiments of the present invention.
[0020] Figure 3 One of the flow diagrams of the method for integrating QKD keys with the HIP protocol provided by the embodiments of the present invention.
[0021] Figure 4 One of the flow diagrams of the method for integrating QKD keys with the HIP protocol provided by the embodiments of the present invention.
[0022] Figure 5 One of the flow diagrams of the method for integrating QKD keys with the HIP protocol provided by the embodiments of the present invention. Detailed implementation manners
[0023] To make the objectives, technical solutions and advantages of the embodiments of the present invention clearer, the technical solutions in the embodiments of the present invention will be clearly and completely described below with reference to the accompanying drawings in the embodiments of the present invention. Obviously, the described embodiments are some but not all of the embodiments of the present invention. Generally, the components of the embodiments of the present invention described and illustrated in the accompanying drawings here can be arranged and designed in various different configurations.
[0024] Therefore, the detailed description of the embodiments of the present invention provided in the accompanying drawings below is not intended to limit the scope of the claimed present invention, but merely represents selected embodiments of the present invention. All other embodiments obtained by those of ordinary skill in the art based on the embodiments of the present invention without making creative efforts fall within the scope of protection of the present invention.
[0025] It should be noted that: similar reference numerals and letters denote similar items in the following drawings. Therefore, once an item is defined in one drawing, it does not need to be further defined and explained in subsequent drawings. At the same time, in the description of the present invention, the terms "first", "second", etc. are only used for descriptive distinction and cannot be understood as indicating or implying relative importance.
[0026] It should be noted that in this text, relational terms such as first and second are only used to distinguish one entity or operation from another entity or operation, and do not necessarily require or imply any actual relationship or order between these entities or operations. Moreover, the term "comprising", "including" or any other variant thereof is intended to cover non-exclusive inclusion, such that a process, method, article or device comprising a series of elements not only includes those elements but also includes other elements not expressly listed, or elements inherent to such process, method, article or device. Without further limitation, an element defined by the phrase "comprising a..." does not exclude the presence of additional identical elements in the process, method, article or device comprising the element.
[0027] In the description of the present invention, it should be noted that the orientation or positional relationship indicated by terms such as "upper", "lower", "inner", "outer", etc. is based on the orientation or positional relationship shown in the drawings, or the orientation or positional relationship in which the inventive product is customarily placed during use. This is only for the convenience of describing the present invention and simplifying the description, and does not indicate or imply that the device or element referred to must have a specific orientation, be constructed and operated in a specific orientation, and thus should not be construed as a limitation of the present invention.
[0028] In the description of the present invention, it should also be noted that unless otherwise clearly specified and limited, the terms "arranged" and "connected" should be understood in a broad sense. For example, it can be a fixed connection, a detachable connection, or an integral connection; it can be a mechanical connection or an electrical connection; it can be directly connected or indirectly connected through an intermediate medium, and it can be the communication inside two elements. For those of ordinary skill in the art, the specific meanings of the above terms in the present invention can be understood according to specific circumstances.
[0029] The following will describe in detail some embodiments of the present invention with reference to the accompanying drawings. Without conflict, the following embodiments and the features in the embodiments can be combined with each other.
[0030] First, the nouns in the embodiments of the present invention will be explained:
[0031] The HIP protocol (Host Identity Protocol), a network protocol used to provide end-to-end authentication and encryption above the network layer.
[0032] QKD (Quantum Key Distribution), a technology for key distribution using the principles of quantum mechanics to ensure the security of key exchange.
[0033] An embodiment of the present invention provides a method for integrating QKD keys into the HIP protocol. The purpose is to design and implement a network communication protocol method that integrates quantum key distribution (QKD) technology to significantly enhance the security of existing protocols such as the HIP protocol in the key exchange and authentication phases. It aims to generate a shared key that cannot be cracked by quantum computing through the principles of quantum mechanics, thereby replacing traditional public key encryption algorithms that are vulnerable to quantum attacks. In addition, it also endeavors to improve the reliability of the authentication process, ensure the confidentiality and integrity of communication data, while maintaining compatibility with existing communication standards for easy practical deployment and application. By providing a flexible solution, it can not only adapt to diverse network environments and application scenarios, but also promote the application of quantum communication technology in a wider range of fields, and ensure that the communication protocol maintains a technological lead in the era of quantum computing, providing users with the highest level of security protection.
[0034] The method for integrating QKD keys into the HIP protocol provided by the embodiment of the present invention is applied to a communication system including an initiating end and a responding end. Please refer to Figure 1 , the method for integrating QKD keys into the HIP protocol includes: S21, S22, S23, S24, S25, and S26, which are specifically described as follows.
[0035] S21, the initiating end sends a first data packet to the responding end through a classical network.
[0036] Among them, the first data packet includes QKD parameters, and the QKD parameters include the target QKD protocol type supported by the initiating end.
[0037] Optionally, a QKD Parameters field is set in the first data packet, and the QKD Parameters field is used to store QKD parameters. The target QKD protocol type can be, but is not limited to, BB84.
[0038] S22, after receiving the first data packet, the responding end feeds back a second data packet to the initiating end. The second data packet includes confusion information and a QKD matching identifier. The confusion information includes a first random number and a difficulty coefficient; the QKD matching identifier is used to indicate that the responding end supports the target QKD protocol type.
[0039] Optionally, a confusion function is used to generate the first random number and the difficulty coefficient in the confusion information (Puzzle).
[0040] S23, after receiving the second data packet, the initiating end and the responding end perform quantum key negotiation to generate a responder quantum key and an initiator quantum key.
[0041] S24, the initiating end generates a second random number that meets the difficulty coefficient and sends a third data packet to the responding end through a classical network.
[0042] Among them, the third data packet includes first random encrypted data obtained by encrypting a first random number and a second random number using the initiator's quantum key.
[0043] Optionally, the initiator uses the opposite function of the confusion function to generate a second random number that meets the difficulty coefficient.
[0044] S25. After receiving the third data packet, the responder decrypts it using the responder's quantum key, and compares whether the decrypted first random number is the same as the first random number stored by it. If they are the same, the responder sends a fourth data packet to the initiator through the classical network.
[0045] Among them, the fourth data packet includes second random encrypted data obtained by encrypting the decrypted second random number using the responder's quantum key.
[0046] If the decrypted first random number is not the same as the first random number stored by it, it means that the verification fails.
[0047] S26. After receiving the fourth data packet, the initiator decrypts it using the initiator's quantum key, and compares whether the decrypted second random number is the same as the second random number stored by it. If they are the same, the initiator feeds back a prompt message indicating successful quantum key matching to the responder.
[0048] If the decrypted second random number is not the same as the second random number stored by it, it means that the verification fails.
[0049] When the responder receives the prompt message indicating successful quantum key matching, it means that the initiator and the responder have completed quantum key distribution. By integrating quantum key distribution (QKD) technology with the HIP protocol, the network security is significantly improved in the key exchange and authentication phases. Using the principles of quantum mechanics, a shared key that cannot be cracked by quantum computing is generated, effectively resisting the threat of quantum computing. The reliability of authentication is improved, and the confidentiality and integrity of communication data are ensured. At the same time, compatibility with existing communication standards is maintained, facilitating practical deployment, and providing a technologically leading security guarantee for communication protocols in the quantum era.
[0050] In an alternative embodiment, the first data packet further includes a preset time window for quantum bits. S23. After receiving the second data packet, the initiator and the responder perform quantum key negotiation to generate a responder's quantum key and an initiator's quantum key, including: S231, S232, S233, S234, and S235, which are specifically described as follows.
[0051] S231. The initiator generates a preset number of quantum bits according to the target QKD protocol type, and within the preset time window, sends the generated quantum bits to the responder through the quantum channel.
[0052] It should be understood that the target QKD protocol type corresponds to multiple groups of bases, and a preset number of qubits are generated according to the multiple groups of bases.
[0053] S232, at the preset time window, the responder performs quantum reception measurement according to the target QKD protocol type.
[0054] S233, the responder performs basis reconciliation with the initiator to obtain the basis reconciliation result, and the basis reconciliation result includes the bases that are consistent between the responder and the initiator.
[0055] S234, the responder generates the responder's quantum key according to the basis reconciliation result and the received qubits.
[0056] S235, the initiator generates the initiator's quantum key according to the basis reconciliation result and the qubits it sends.
[0057] In an alternative embodiment, after generating the responder's quantum key and the initiator's quantum key, error correction can also be performed.
[0058] In an alternative embodiment, the first data packet further includes a list of Diffie-Hellman group IDs supported by the initiator, and the list of Diffie-Hellman group IDs includes multiple groups of DH parameters, such as {3, 4, 5}. On this basis, please refer to Figure 2 , the method for HIP protocol to fuse QKD keys further includes: S28A, S28B, and S29, which are specifically described as follows.
[0059] S28A, after receiving the first data packet, the responder selects a target DH parameter from the list of Diffie-Hellman group IDs.
[0060] S28B, the responder generates an alternative traditional shared key according to the target DH parameter.
[0061] Optionally, the second data packet further includes the target DH parameter; in the case where the quantum key is not applicable, communication can be based on this traditional shared key.
[0062] S29, after receiving the second data packet, the initiator generates an alternative traditional shared key according to the target DH parameter.
[0063] Please continue to refer to Figure 1 , in an alternative embodiment, the first data packet further includes the first host identifier of the initiator, and the second data packet further includes the second host identifier of the responder. After the initiator feeds back a quantum key matching success prompt message to the responder, the method for HIP protocol to fuse QKD keys further includes: S27, which is specifically described as follows.
[0064] S27. The initiator and the responder complete HIP association based on the first host identifier and the second host identifier, and perform encrypted communication using the responder's quantum key and the initiator's quantum key.
[0065] The responder's quantum key and the initiator's quantum key are used as the shared QKD key to protect the communication between them. The data packet is encrypted and sent over the network, and ESP or other mechanisms are used to encrypt and authenticate the data.
[0066] Please refer to Figure 3 When an update is needed, the HIP protocol's method of integrating QKD keys further includes S31 and S32, which are described in detail as follows.
[0067] S31. The first device encrypts the update data using QKD key A to generate an encrypted update data packet, and sends the update data packet and the signature information of the first device to the second device via the classical network.
[0068] Among them, the signature information of the first device is generated based on QKD key B, and the update data packet includes update association parameters.
[0069] S32. After receiving the data, the second device verifies the signature information using the corresponding QKD key B. If the verification passes, the second device decrypts the update data packet using the corresponding QKD key A to obtain the update data.
[0070] Among them, the first device is either the initiator or the responder, the second device is the other of the initiator and the responder, QKD key A is the first interval of the quantum keys successfully negotiated by the initiator and the responder, and QKD key B is the second interval of the quantum keys successfully negotiated by the initiator and the responder.
[0071] The quantum keys successfully negotiated by the initiator and the responder are the responder's quantum key and the initiator's quantum key mentioned above.
[0072] In an alternative embodiment, for example, when the quantum key is insufficient and an update is needed, the HIP protocol's method of integrating QKD keys further includes S33 and S34, which are described in detail as follows.
[0073] S33. The first device encrypts the update data using the public key of the second device to generate an update data packet, and sends the update data packet and the signature information of the first device to the second device via the classical network.
[0074] Among them, the signature information of the first device is generated based on the private key of the first device, and the update data packet includes update association parameters.
[0075] S34. The second device uses the public key of the first device to verify the signature information. If the verification is passed, the second device uses its private key to decrypt the update data packet to obtain the update data.
[0076] Based on the above, regarding how to generate the host identifier, an optional implementation manner is further provided in an embodiment of the present invention. Please refer to Figure 4 , the method for fusing the QKD key in the HIP protocol further includes: S11 and S12, which are specifically described as follows.
[0077] S11. The initiating end uses a pre-configured key generation algorithm to generate a first public key and a first private key, and performs a hash operation on the first public key to obtain a first host identifier.
[0078] Among them, the key generation algorithm can be but is not limited to using the RSA, DSA or ECDSA algorithm. The first public key and the first private key can form a 2048-bit RSA key pair. The first host identifier (HIT_A) is, for example: 2001:db8:1234:0:0:0:0:1. The 128-bit HIT is used in the HIP header to identify the initiating end in the communication.
[0079] S12. The responding end uses a pre-configured key generation algorithm to generate a second public key and a second private key, and performs a hash operation on the second public key to obtain a second host identifier.
[0080] Among them, the second public key and the second private key can form a 2048-bit RSA key pair. The second host identifier (HIT_B) is, for example: 2001:db8:1234:0:0:0:0:1. The 128-bit HIT is used in the HIP header to identify the responding end in the communication.
[0081] In an optional implementation manner, the method for fusing the QKD key in the HIP protocol further includes: the party that detects an error sends an error notification data packet to the other party in the communication system through the classical network to transmit the error problem information.
[0082] Please refer to Figure 5 , in an optional implementation manner, the method for fusing the QKD key in the HIP protocol further includes: S41 and S42, which are specifically described as follows.
[0083] S41. When the communication ends, the initiating end sends a close data packet to the responding end through the classical network and stops running the QKD device in the initiating end.
[0084] S42. After receiving the close data packet, the responding end closes the HIP association and stops running the QKD device in the responding end.
[0085] Optionally, when a crash or state loss occurs at the initiating end or the responding end, the repeating initiating end sends a first data packet to the responding end through a classical network to generate a generative quantum key and re - establish the connection.
[0086] An embodiment of the present invention also provides a communication system, which includes an initiating end and a responding end, and is used to execute the method for fusing QKD keys in the above - mentioned HIP protocol.
[0087] In summary, for the method and communication system for fusing QKD keys in the HIP protocol provided by the embodiments of the present invention, the initiating end sends a first data packet to the responding end through a classical network, and the first data packet includes QKD parameters; after receiving the first data packet, the responding end feeds back a corresponding second data packet to the initiating end, and the second data packet includes confusion information and a QKD matching identifier, and the confusion information includes a first random number and a difficulty coefficient; after receiving the second data packet, the initiating end and the responding end perform quantum key negotiation to generate a responder quantum key and an initiator quantum key; the initiating end generates a second random number that meets the difficulty coefficient and sends a third data packet to the responding end through a classical network, and the third data packet includes first random encrypted data obtained by encrypting the first random number and the second random number with the initiator quantum key; after receiving the third data packet, the responding end decrypts it with the responder quantum key and compares whether the decrypted first random number is the same as the first random number stored by it. If they are the same, it sends a fourth data packet to the initiating end through a classical network, and the fourth data packet includes second random encrypted data obtained by encrypting the decrypted second random number with the responder quantum key; after receiving the fourth data packet, the initiating end decrypts it with the initiator quantum key and compares whether the decrypted second random number is the same as the second random number stored by it. If they are the same, it feeds back a quantum key matching success prompt message to the responding end. By fusing the quantum key distribution (QKD) technology with the HIP protocol, the network security is significantly improved in the key exchange and authentication phases. Utilizing the principles of quantum mechanics, a shared key that cannot be cracked by quantum computing is generated, effectively resisting the threat of quantum computing. The reliability of authentication is improved, and the confidentiality and integrity of communication data are ensured. At the same time, compatibility with existing communication standards is maintained, facilitating practical deployment, and providing a technologically leading security guarantee for communication protocols in the quantum era.
[0088] The above are only the preferred embodiments of the present invention and are not used to limit the present invention. For those skilled in the art, the present invention can have various changes and modifications. Any modification, equivalent replacement, improvement, etc. made within the spirit and principle of the present invention shall be included within the protection scope of the present invention.
[0089] It is obvious to those skilled in the art that the present invention is not limited to the details of the above-described exemplary embodiments, and that the present invention can be implemented in other specific forms without departing from the spirit or essential characteristics of the present invention. Therefore, in any respect, the embodiments should be regarded as exemplary and non-restrictive. The scope of the present invention is defined by the appended claims rather than the above description. Therefore, all changes falling within the meaning and scope of the equivalent elements of the claims are intended to be embraced within the present invention. Any reference signs in the claims should not be construed as limiting the claims involved.
Claims
1. A method for integrating QKD key with HIP protocol, characterized in that: The method comprises: The initiator sends a first data packet to the responder through a classic network, where the first data packet includes QKD parameters, and the QKD parameters include a target QKD protocol type supported by the initiator; After receiving the first data packet, the responding end feeds back a second data packet to the initiating end, wherein the second data packet includes confusion information and a QKD matching identifier, and the confusion information includes a first random number and a difficulty coefficient; After receiving the second data packet, the initiator performs quantum key negotiation with the responder to generate a responder quantum key and an initiator quantum key; The initiator generates a second random number that satisfies the difficulty coefficient, and sends a third data packet to the responder through a classical network, wherein the third data packet includes first random encrypted data obtained by encrypting the first random number and the second random number using the initiator's quantum key; After receiving the third data packet, the responding end decrypts it using the responding party's quantum key, and compares whether the first random number obtained by decryption is consistent with the first random number stored therein, and if they are consistent, sends a fourth data packet to the initiating end through the classical network, wherein the fourth data packet includes second random encrypted data obtained by encrypting the second random number obtained by decryption using the responding party's quantum key; After receiving the fourth data packet, the initiator uses the initiator's quantum key to decrypt it, and compares the decrypted second random number with the second random number stored therein to see if they are consistent. If they are consistent, the responder feeds back a prompt message indicating that the quantum key matches successfully.
2. The method for integrating the HIP protocol with the QKD key according to claim 1, characterized in that: The first data packet also includes a preset time window of the quantum bit; after receiving the second data packet, the initiator performs quantum key negotiation with the responder to generate a responder quantum key and an initiator quantum key, including: The initiator generates a preset number of quantum bits according to the target QKD protocol type, and sends the generated quantum bits to the responder through a quantum channel in the preset time window; The responding end performs quantum reception measurement according to the target QKD protocol type in the preset time window; The responding end performs a basis comparison with the initiating end to obtain a basis comparison result, wherein the basis comparison result includes a consistent basis between the responding end and the initiating end; The responding end generates a responding party quantum key according to the basis result and the received quantum bits; The initiator generates an initiator quantum key according to the basis result and the quantum bits it sends.
3. The method for integrating QKD key with HIP protocol as claimed in claim 1, characterized in that: The first data packet also includes a Diffie-Hellman group ID list supported by the initiator, the Diffie-Hellman group ID list includes multiple groups of DH parameters, and the method further includes: After receiving the first data packet, the responder selects a target DH parameter from the Diffie-Hellman group ID list; The responder generates a standby traditional shared key according to the target DH parameter, and the second data packet also includes the target DH parameter; After receiving the second data packet, the initiator generates a spare traditional shared key according to the target DH parameter.
4. The method for integrating the HIP protocol with the QKD key according to claim 1, characterized in that: The first data packet further includes a first host identifier of the initiator, and the second data packet further includes a second host identifier of the responder. After the initiator feeds back quantum key matching success prompt information to the responder, the method further includes: The initiator and the responder complete HIP association according to the first host identifier and the second host identifier, and use the responder quantum key and the initiator quantum key to perform encrypted communication.
5. The method for integrating QKD key with HIP protocol as claimed in claim 4, characterized in that: When an update is required, the method further includes: The first device encrypts the update data using the QKD key A to generate an encrypted update data packet, and sends the update data packet and the signature information of the first device to the second device through the classic network; After receiving the data, the second device verifies the signature information using the corresponding QKD key B, and if the verification is successful, decrypts the update data packet using the corresponding QKD key A to obtain the update data; The first device is any one of the initiator and the responder, the second device is the other of the initiator and the responder, QKD key A is the first interval in the quantum key successfully negotiated by the initiator and the responder, and QKD key B is the second interval in the quantum key successfully negotiated by the initiator and the responder.
6. The method for integrating the HIP protocol with the QKD key according to claim 5, characterized in that: The method further comprises: The initiator uses a pre-configured key generation algorithm to generate a first public key and a first private key, and performs a hash operation on the first public key to obtain the first host identifier; The responder uses a preconfigured key generation algorithm to generate a second public key and a second private key, and performs a hash operation on the second public key to obtain the second host identifier.
7. The method for integrating QKD key with HIP protocol as claimed in claim 4, characterized in that: The method further comprises: The party that detects the error sends an error notification data packet to the other party in the communication system through the classic network to transmit error problem information.
8. The method for integrating the HIP protocol with the QKD key according to claim 4, characterized in that: The method further comprises: When the communication ends, the initiator sends a shutdown data packet to the responder through the classic network and stops running the QKD device in the initiator; After receiving the close data packet, the responder closes the HIP association and stops running the QKD device in the responder.
9. The method for integrating QKD key with HIP protocol as claimed in claim 1, characterized in that: When the initiator or the responder crashes or loses state, the initiator repeats sending the first data packet to the responder through the classical network to re-establish the connection using a generative quantum key.
10. A communication system, characterized in that: The communication system includes an initiator and a responder, and the communication system is used to execute the method of integrating the HIP protocol with the QKD key as described in any one of claims 1 to 9.