Information sending method, receiving method and equipment based on quantum key
Through the information transmission method based on quantum key, quantum keys are generated and distributed using the quantum cryptographic service platform to encrypt any local content in the communication information, solving the problems of insufficient encryption and high computing resource consumption in the prior art, and achieving high security and low resource consumption encryption effects.
Patent Information
- Application Number
- CN202311871131.2
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2023-12-29
- Publication Date
- 2025-07-01
AI Technical Summary
Existing encryption technologies cannot achieve high security encryption of specific local contents in communication information, and global encryption has the problem of excessive computing resources consumption.
Using a quantum key-based information transmission method, quantum keys are generated and distributed through the quantum cryptographic service platform, encrypt any local content in the communication information, and generate encryption guidelines for the receiver to decrypt.
High security encryption of any local content in communication information is realized, reducing the consumption of computing resources and improving the targeted and secure encryption.
Smart Images

Figure CN120238293A_ABST
Abstract
Description
Technical Field
[0001] The present invention belongs to the field of information and communication technologies, and particularly relates to an information sending method, a receiving method, and a device based on quantum keys. Background Art
[0002] The statements in this part merely provide background technical information related to the present invention, and do not necessarily constitute prior art.
[0003] E-mails and instant messaging services often contain personal privacy or other sensitive information, such as ID numbers, bank card numbers, etc. To prevent sensitive information from being illegally obtained, it can be encrypted. However, current encryption is mostly global encryption, that is, the entire e-mail or instant messaging information is encrypted. For some communication information, often only a part of the content has an encryption requirement, and global encryption results in unnecessary consumption of computing resources.
[0004] Patent document CN102740246A discloses a local encryption method for media messages. The sender encrypts the media content to be encrypted, uses a symmetric encryption method for local encryption of media messages, and uses an asymmetric encryption method to encrypt the encryption key. However, with the upgrade of the attacker's computing power or the emergence of quantum computers, the public-private key system based on mathematical complexity has the possibility of being cracked. Moreover, the local encryption in this patent document targets media content such as pictures and audio, which are independent media contents, and cannot be accurate to individual sensitive information in the message text, such as a few words, and cannot meet the user's personalized encryption requirements. Summary of the Invention
[0005] To overcome the deficiencies of the above-mentioned prior art, the present invention provides an information sending method, a receiving method, and a device based on quantum keys, which can achieve high-security encryption for any local content of the communication information to be sent.
[0006] To achieve the above object, the first aspect of the present invention provides an information sending method based on quantum keys, which is applied to a sender terminal and includes the following steps:
[0007] Receiving a specification for one or more encrypted segments in the communication information to be sent, generating a key application and sending it to a quantum cryptography service platform, where the key application includes the amount of quantum keys required for each encrypted segment;
[0008] Obtaining, from the quantum cryptography service platform, the quantum keys generated for each of the encrypted segments, and the identification information of the quantum keys;
[0009] In response to the information sending confirmation instruction, each encrypted segment is encrypted using a corresponding quantum key, and an encryption guide is generated, and the encrypted communication information and the encryption guide are sent; the encryption guide includes the position information of each encrypted segment and the identification information of the corresponding quantum key, so that the receiving party terminal can obtain the quantum key from the quantum cryptography service platform based on the identification information.
[0010] In some embodiments, in the key application, the amount of quantum key required for each encrypted segment is the same as the byte length of the encrypted segment or is a set value.
[0011] In some embodiments, after receiving the designation of one or more encrypted segments, the confidentiality level of each encrypted segment is also received, and according to the confidentiality level, the amount of quantum key required for each encrypted segment is determined; the amount of quantum key required for the encrypted segment with the highest confidentiality level is the byte length of the encrypted segment; the amount of quantum key required for the attachment file with a lower confidentiality level is a set value.
[0012] In some embodiments, before generating the key application, if an editing operation on a designated encrypted segment is detected, the encrypted segment is updated or cancelled.
[0013] In some embodiments, if multiple encrypted segments are designated, the correspondence between each quantum key and the encrypted segment is also obtained from the quantum cryptography service platform, and when each encrypted segment is encrypted, the correspondence is written into the key guide.
[0014] In some embodiments, multiple encryption algorithms are preset. After receiving the designation of one or more encrypted segments, the designation of the encryption algorithm used for each encrypted segment is also received; when each encrypted segment is encrypted, the identification code of the encryption algorithm is written into the key guide.
[0015] In some embodiments, the encryption index includes an encryption content label and a key identification label; the encryption content label includes a key identification label and an encryption content label corresponding to each encrypted segment, the key identification label includes the quantum key identification information of all encrypted segments, and the encryption content label includes the serial number of the encrypted segment and the serial number corresponding to the quantum key used in the key identification label, or, the serial number of the encrypted segment, the serial number corresponding to the quantum key used in the key identification label, and the identification code of the encryption algorithm used.
[0016] In some embodiments, after receiving the designation of one or more encrypted segments in the communication information to be sent, one or more decryption authorities designated for one or more of the encrypted segments are also received and sent to the quantum cryptography service platform, and the one or more decryption authorities are a subset of the recipients of the communication information, so that the receiving party terminal can perform identity authentication when applying for the quantum key from the quantum cryptography service platform.
[0017] In some embodiments, a specification for one or more attachment files to be encrypted in the communication information to be sent is further received, and the key application further includes the amount of quantum key required for each attachment file to be encrypted.
[0018] Obtain the quantum keys generated for each encrypted segment and each attachment file to be encrypted, and the identification information of the quantum keys, from the quantum cryptography service platform.
[0019] In response to the information sending confirmation instruction, each attachment file to be encrypted is further encrypted using the corresponding quantum key, and an encryption guide is generated; the encryption index of the attachment file includes the quantum key identification information corresponding to each attachment file.
[0020] In some embodiments, a first shared quantum key with the quantum cryptography service platform is pre-stored, and the quantum key obtained from the quantum cryptography service platform is the quantum key encrypted via the first shared quantum key, and the quantum key is obtained by decryption.
[0021] In some embodiments, the quantum key encrypted via a temporary key, and the position information of the temporary key in the first shared quantum key are obtained from the quantum cryptography service platform; the temporary key is obtained according to the position information of the temporary key and the first shared quantum key, and the quantum key is obtained by decryption.
[0022] A second aspect of the present invention provides a quantum key-based information receiving method, which is applied to a receiving party terminal and includes the following steps:
[0023] Receive the encrypted communication information and the encryption guide; the encryption guide includes the position information of one or more encrypted segments in the communication information and the identification information of the corresponding quantum keys.
[0024] Send the identification information of the quantum keys corresponding to the one or more encrypted segments to the quantum cryptography service platform.
[0025] Obtain one or more quantum keys found based on the identification information of the quantum keys from the quantum cryptography service platform.
[0026] Locate each of the encrypted segments according to the position information of the one or more encrypted segments, and decrypt based on the corresponding quantum key.
[0027] In some embodiments, the key guide further includes the correspondence between a plurality of encrypted segments and a plurality of quantum keys; the quantum key for each encrypted segment is obtained according to the correspondence during decryption.
[0028] In some embodiments, the key guidance further includes an identification code of the encryption algorithm used for each encrypted segment; during decryption, the encryption algorithm used for each encrypted segment is obtained according to the identification code.
[0029] In some embodiments, when sending the identification information of the quantum key corresponding to the one or more encrypted segments to the quantum cryptography service platform, the identity information of the receiving party terminal is sent simultaneously, which is used for the quantum cryptography service platform to authenticate whether the identity information is the decryption authority designated by the sending party terminal for the one or more encrypted segments. If the authentication is passed, the quantum key of the one or more encrypted segments is obtained.
[0030] In some embodiments, the encryption guidance further includes the identification information of the quantum key used for one or more encrypted attachment files in the communication information; the identification information of the quantum key corresponding to the one or more encrypted attachment files is sent to the quantum cryptography service platform;
[0031] One or more quantum keys found based on the identification information of the quantum key are obtained from the quantum cryptography service platform; each encrypted attachment file is decrypted using the corresponding quantum key.
[0032] In some embodiments, a second shared quantum key with the quantum cryptography service platform is pre-stored, and the quantum key obtained from the quantum cryptography service platform is encrypted by the second shared quantum key, and the quantum key is obtained by decryption.
[0033] In some embodiments, a quantum key encrypted by a temporary key and the position information of the temporary key in the second shared quantum key are obtained from the quantum cryptography service platform; the temporary key is obtained according to the position information of the temporary key and the second shared quantum key, and the quantum key is obtained by decryption.
[0034] The third aspect of the present invention provides a key distribution method applied to a quantum cryptography service platform, including the following steps:
[0035] Receive a key application sent by a sending party terminal, where the key application includes the amount of quantum key required for each encrypted segment;
[0036] For each encrypted segment, generate a corresponding quantum key and the identification information of the quantum key;
[0037] Send the quantum key and its identification information to the sending party terminal.
[0038] In some embodiments, if multiple encrypted segments are specified, when generating quantum keys for the multiple encrypted segments, the corresponding relationship between each quantum key and the encrypted segment is also generated.
[0039] In some embodiments, one or more decryptors specified for one or more encrypted segments sent by the sender terminal are also received, and each encrypted segment information, quantum key, and its identification information, as well as the specified decryptors, are associated and stored to obtain the current key distribution record.
[0040] In some embodiments, if the decryptors of multiple encrypted segments are exactly the same, the same quantum key is generated for the multiple encrypted segments.
[0041] In some embodiments, the key application further includes the amount of quantum key required for one or more attachment files;
[0042] For each of the attachment files, a corresponding quantum key and identification information of the quantum key are generated;
[0043] The quantum key and its identification information are sent to the sender terminal.
[0044] In some embodiments, a first shared quantum key with the sender terminal is pre-stored, and the generated quantum key is encrypted based on the first shared quantum key and then sent to the sender terminal.
[0045] In some embodiments, a temporary key is generated based on a part of the first shared quantum key, and the position information of the temporary key in the first shared quantum key is recorded; the generated quantum key is encrypted based on the temporary key, and the encrypted quantum key and the position information of the temporary key are sent to the sender terminal.
[0046] In some embodiments, the identification information of one or more quantum keys sent by the receiver terminal is received, and the corresponding quantum key is found and sent to the receiver terminal.
[0047] In some embodiments, the identification information of one or more quantum keys sent by the receiver terminal and the identity information of the receiver terminal are received;
[0048] According to each of the identification information, it is checked whether there is a corresponding key distribution record. If there is, it is further determined whether the identity information of the receiver terminal is consistent with the receiver information in the key distribution record. If they are consistent, the quantum key in the key distribution record is obtained and sent to the receiver terminal.
[0049] In some embodiments, the identification information of one or more quantum keys sent by the receiver terminal and the identity information of the receiver terminal are received;
[0050] According to each piece of the identification information, check whether there is a corresponding key distribution record. If there is, further determine whether there is a decryption authority person in the key distribution record whose identity information is consistent with that of the receiving party terminal. If there is, obtain one or more quantum keys associated with the decryption authority person and send them to the receiving party terminal.
[0051] In some embodiments, a second shared quantum key with the receiving party terminal is pre-stored, and the found quantum key is encrypted based on the second shared key and then sent to the receiving party terminal.
[0052] In some embodiments, a temporary key is generated based on part of the second shared quantum key, and the position information of the temporary key in the second shared quantum key is recorded; the found quantum key is encrypted based on the temporary key, and the encrypted quantum key and the position information of the temporary key are sent to the receiving party terminal.
[0053] A fourth aspect of the present invention provides a communication device, which includes one or more processors; and a memory; wherein, one or more computer programs are stored in the memory, and the one or more computer programs include instructions, when the instructions are executed by the communication device, the communication device is caused to execute the information sending, information receiving or key distribution method described above.
[0054] A fifth aspect of the present invention provides a computer-readable storage medium, in which instructions are stored, when the instructions run on a communication device, the communication device is caused to execute the information sending, information receiving or key distribution method described above.
[0055] A sixth aspect of the present invention provides an information transmission system based on quantum keys, which includes a sending party terminal, a receiving party terminal and a quantum cryptography service platform, which are respectively configured to execute the information sending method, the information receiving method and the key distribution method described above.
[0056] Based on one or more of the above technical solutions, before sending the communication information to be sent, the user can arbitrarily specify the local key information to be encrypted and apply for a quantum key for encryption, with higher flexibility, and realizes the high-intensity application of limited quantum keys on local key content, with stronger encryption pertinence and further improved security.
[0057] By specifying the recipient for the local key information to be encrypted, only the specified recipient can obtain the quantum key, realizing permission control. In addition, in the application scenario facing multiple receiving parties, different decryption authority persons can be specified for different local key information, realizing differentiated permission management. BRIEF DESCRIPTION OF THE DRAWINGS
[0058] The accompanying drawings forming a part of this invention are used to provide a further understanding of the invention. The schematic embodiments of the invention and their descriptions are used to explain the invention and do not constitute an improper limitation of the invention.
[0059] Figure 1 It is a schematic block diagram of a communication system in an embodiment of the present invention;
[0060] Figure 2 It is a schematic block diagram of another communication system in an embodiment of the present invention;
[0061] Figure 3 It is the overall flowchart of the information sending method based on quantum key in an embodiment of the present invention;
[0062] Figure 4 It is the overall flowchart of the information receiving method based on quantum key in an embodiment of the present invention;
[0063] Figure 5 It is the overall flowchart of the information sending method applied to the sending terminal in an embodiment of the present invention;
[0064] Figure 6 It is the overall flowchart of the information receiving method applied to the receiving terminal in an embodiment of the present invention;
[0065] Figure 7 It is the overall flowchart of the key distribution method applied to the quantum cryptography service platform in an embodiment of the present invention;
[0066] Figure 8 It is the schematic diagram of the information transmission process in an embodiment of the present invention. Detailed implementation manners
[0067] It should be noted that the following detailed descriptions are all exemplary and are intended to provide further explanations of the present invention. Unless otherwise specified, all technical and scientific terms used herein have the same meaning as commonly understood by those of ordinary skill in the technical field to which the present invention belongs.
[0068] It should be noted that the terms used herein are only for describing the specific implementation manners and are not intended to limit the exemplary embodiments according to the present invention. As used herein, unless the context clearly indicates otherwise, the singular forms are also intended to include the plural forms. In addition, it should be understood that when the terms "comprising" and / or "including" are used in this specification, they indicate the presence of features, steps, operations, devices, components, and / or combinations thereof.
[0069] Without conflict, the embodiments in the present invention and the features in the embodiments can be combined with each other.
[0070] As described in the background art, the existing methods for encrypting communication information cannot achieve fine-grained security control. Based on this, one or more embodiments of the present invention introduce a quantum cryptography service platform. A user can specify local key information (collectively referred to as "encrypted segments" in this application) for the communication information to be sent via the sender terminal, apply to the quantum cryptography service platform for a quantum key that matches the digital quantity of the encrypted segment, and the identification information of the quantum key. After encryption, both the communication information and the identification information of the quantum key used are sent to the receiver terminal. After receiving, the receiver terminal obtains the quantum key from the quantum cryptography service platform based on the identification information of the quantum key, so as to decrypt and obtain the plaintext of the encrypted segment in the communication information. The quantum key for each encrypted segment is applied before the communication information is sent, and the quantum keys between multiple encrypted segments in the same communication information are also different, which can strengthen the security of the information for any local key information in the communication information.
[0071] Figure 1 FIG. shows a schematic block diagram of an exemplary communication system in which embodiments of the present application can be implemented. As Figure 1 shown, the communication system may include a sender terminal, a receiver terminal, and a quantum cryptography service platform. It can be understood that the sender terminal and the receiver terminal can both be a personal computer, a mobile phone (also known as a cell phone), a tablet computer, a television (also known as a smart screen or a large screen device), an ultra-mobile personal computer (UMPC), a handheld computer, a netbook, a personal digital assistant (PDA), a vehicle-mounted device (also known as a car computer), a wearable electronic device, a virtual reality device, etc. The embodiments of the present application do not make any restrictions on this.
[0072] The sender terminal, the receiver terminal, and the quantum cryptography service platform can establish connections through wired, wireless, or a combination of both. In the actual application process, there are no restrictions on the specific devices corresponding to the sender terminal and the receiver terminal. For example, communication can be carried out between a client and a server, between two servers, or between two clients via a server. As Figure 2 shown, in the specific application process, there are no restrictions on the information sending scenario, which will not be elaborated here.
[0073] For example, if the communication information to be sent is an email, the sending terminal and the receiving terminal transmit information via a mail server; or if the communication information to be sent is instant messaging information, the sending terminal and the receiving terminal transmit information via an instant messaging server. In such application scenarios, the sending terminal and the receiving terminal need to install email services or instant messaging software. In the following text, the information sending and receiving methods will be described in terms of the data interaction between the sending terminal, the receiving terminal, and the quantum cryptography service platform.
[0074] Figure 3 Fig. shows an overall flowchart of an information sending method based on a quantum key, including steps S301 - S303. The method includes the following steps:
[0075] S301: The sending terminal receives a specification for one or more encrypted segments in the communication information to be sent, generates a key application and sends it to the quantum cryptography service platform. The key application includes the amount of quantum key required for each encrypted segment.
[0076] S302: The quantum cryptography service platform receives the key application, generates a quantum key for each encrypted segment, and the identification information of the quantum key, and sends the quantum key and its identification information to the sending terminal.
[0077] S303: The sending terminal obtains the quantum key and its identification information, in response to an information sending confirmation instruction, encrypts each encrypted segment with the corresponding quantum key, and generates an encryption guide, and sends the communication information and the encryption guide; the encryption guide includes the location information of each encrypted segment and the identification information of the corresponding quantum key.
[0078] Based on this, before sending the communication information to be sent, the user can arbitrarily specify the local key information to be encrypted, and apply for a quantum key based on the byte size of the local information. On the one hand, encrypting the communication information with the quantum key provides higher security. On the other hand, it can apply the limited quantum key intensively on the local key content, making the encryption more targeted and further improving the security.
[0079] In step S301, the sending terminal receiving the specification for the encrypted segment in the communication information to be sent can be realized via the communication software interface. Specifically, after the user inputs the communication information to be sent, the user selects the continuous local content to be encrypted, i.e., the encrypted segment, by clicking or dragging with the mouse. If there is more than one sensitive information in the communication information to be sent and the sensitive information at each place is not continuous, multiple encrypted segments can be specified.
[0080] After the sender terminal receives the specification for one or more encrypted segments in the communication information to be sent, it also analyzes each encrypted segment to obtain the position information and byte length of each encrypted segment. Specifically, the position information of the encrypted segment includes the starting position and byte length of the encrypted segment in the communication information to be sent, or includes the starting position and ending position of the encrypted segment in the communication information to be sent.
[0081] It can be understood that the encrypted segment can be for the text of the communication information body or for media content such as pictures, audio, and video inserted into the communication information. The whole of these media contents can be selected as the encrypted segment, or a partial content of these media contents can be selected as the encrypted segment. For example, for a picture, the user can select a partial area in the picture by framing it as the encrypted segment; for audio, the user can specify a time interval of the audio as the encrypted segment. The specific object targeted by the encrypted segment and the specific form of selection are not specifically limited here.
[0082] After specifying the encrypted segment, the user can edit the content of the encrypted segment as needed. For example, add or delete several consecutive characters at the starting position, or cancel the encrypted segment, etc. If the sender terminal detects an edit operation on the specified encrypted segment, it issues a reminder and updates or cancels the encrypted segment after the user confirms. Specifically, if it is detected that the starting or ending position of a certain encrypted segment changes, for example, the byte length of the encrypted segment is extended forward or backward, or some bytes are added or deleted in the encrypted segment, then reposition the starting or ending position of the encrypted segment; if there are other encrypted segments after the encrypted segment, also update the position information of the other encrypted segments. If it is detected that the content between two adjacent encrypted segments is deleted, combine the two encrypted segments into one encrypted segment; if there are other encrypted segments after the two encrypted segments, also update the position information of the other encrypted segments.
[0083] It can be understood that each time an encrypted segment is specified, it is distinguished and displayed for the user to view. If multiple encrypted segments are specified, they are also distinguished and displayed between each other, for example, using different highlight colors.
[0084] In the quantum key application, the amount of quantum key required for each encrypted segment is determined according to the security level of the encrypted segment. In some embodiments, at least two security levels are set. The highest security level adopts the idea of "one-time pad" and applies for a quantum key with the same byte size as the encrypted segment. The lower security level is for files with relatively lower security requirements and applies for a quantum key with a set byte size, such as 16 bytes. It can be understood that more security levels can be set according to the requirements of the actual application scenario.
[0085] In some embodiments, the confidentiality level of each encrypted segment is specified by the user. After the sender terminal receives the specification of one or more encrypted segments, it also receives the confidentiality level of each of the encrypted segments, determines the amount of quantum key required for the encrypted segment according to the confidentiality level, and generates a key application to be sent to the quantum cryptography service platform.
[0086] In step S302, the quantum cryptography service platform receives the key application, generates a quantum key for each encrypted segment according to the amount of quantum key required for each encrypted segment, and the identification information of the quantum key, and sends each quantum key and its identification information to the sender terminal.
[0087] In addition, in order to facilitate the sender and the receiver to confirm the correspondence between multiple quantum keys and multiple encrypted segments, the quantum cryptography service platform also generates the correspondence between each quantum key and the encrypted segment, such as the correspondence between the encrypted segment serial number and the quantum key serial number.
[0088] In some embodiments, both the sender terminal and the receiver terminal are pre - set with multiple encryption algorithms, and each encryption algorithm is provided with a unique identification code. Specifically, multiple encryption algorithms can be pre - set in an email service or an instant messaging software. In step S301, after the sender terminal receives the specification of one or more encrypted segments, it also receives the specification of the encryption algorithm adopted for each encrypted segment, and writes the identification code of the adopted encryption algorithm into the encryption index in step S303. Since only the sender and the receiver know the index of the encryption algorithm, even if a third party intercepts the communication information, it is difficult to crack the encrypted part of the content.
[0089] It can be understood that the confidentiality level of the encrypted segment is related to the adopted encryption algorithm. The association relationship between the confidentiality level and the encryption algorithm can be pre - stored. For example, when a general confidentiality level is selected, the system automatically selects the SM4 block encryption and confirms that 16 - byte quantum key is required.
[0090] As a specific implementation manner, the encryption index serves as the message header of the communication information to be sent, including an encrypted content tag and a key identification tag. The number of the encrypted content tags is the same as the number of encrypted segments. The key identification tag includes the quantum key identification information of all encrypted segments; each encrypted content tag includes the position information of the encrypted segment, the serial number corresponding to the adopted quantum key in the key identification tag. If both the sender terminal and the receiver terminal are pre - set with multiple encryption algorithms, the encrypted content tag further includes the identification code of the encryption algorithm.
[0091] As an example, assuming that 2 encrypted segments are encrypted, the generated encryption index can adopt the following form:
[0092] Encrypted content tag 1: [encryption start point, encryption length, adopted key serial number, encryption algorithm identification code];
[0093] Encryption content label 2: [encryption start point, encryption length, quantum key serial number used, encryption algorithm identification code];
[0094] Quantum key identification label: Quantum key identification information for encryption segment 1, quantum key identification information for encryption segment 2.
[0095] Among them, the encryption start point and encryption length are used to locate the interval where the encryption segment is located. For example, X-bodyEncrypt: [3, 10, 1, 1000], the encryption start point is 3, and the byte length is 10, that is, this encryption segment starts from the 3rd byte of the information to be communicated and has a length of 10. The quantum key serial number used is 1, indicating that the 1st quantum key is used for encryption; the algorithm identification code is 1000, and here 1000 is used to represent the exclusive OR algorithm. The quantum key identification label such as X-group: 0a395b37400ea5f8 is randomly generated by the quantum cryptography service platform p, and each quantum key identification is unique.
[0096] The encryption guidance is used to provide the receiving party with the location of the encryption segment, which quantum key is used, and which encryption algorithm is used, and provide the path to obtain the quantum key. Based on this, the receiving party can decrypt the local encrypted content.
[0097] It can be understood that the above encryption method can also achieve full-text encryption and is fully compatible with the existing email encryption form. Just define the encryption position interval as the full text. For example, setting -1 means until the end of the text. When the content of the X-bodyEncrypt label is: [0, -1, 1, 401], it indicates that the encryption start position of the text is the beginning of the text (offset is 0), the length is the entire text part, the 1st key is used for encryption (which is also the only key), and the SM4-ECB encryption algorithm is used (here, the definition of the national cryptography standard GM / T 0006-2012 is used, and 401 represents SM4-ECB) for encryption.
[0098] In order to facilitate the user to confirm the designation of the encryption segment, after encrypting the encryption segment in response to the information sending confirmation instruction, the sending party terminal also forms a preview for the user to verify, and after the user's reconfirmation, the encrypted communication information and encryption guidance are sent.
[0099] Based on the above information sending method, Figure 4 The overall flowchart of an information receiving method based on quantum key is shown, including steps S401 - S403, specifically including the following steps:
[0100] S401: Receive the encrypted communication information and the encryption guidance; the encryption guidance includes the position information of one or more encrypted segments in the communication information and the identification information of the corresponding quantum keys, and send the identification information of the quantum keys corresponding to the one or more encrypted segments to the quantum cryptography service platform;
[0101] S402: The quantum cryptography service platform receives the identification information, obtains the corresponding quantum keys based on the identification information, and sends them to the receiving party terminal;
[0102] S403: The receiving party terminal receives the quantum keys, locates each of the encrypted segments according to the position information of the one or more encrypted segments, and decrypts each encrypted segment based on the corresponding quantum key.
[0103] To facilitate the receiving party terminal to confirm which quantum key is applied to which encrypted segment, in step S401, the encryption guidance further includes the correspondence between the encrypted segments and the quantum keys. After the receiving party terminal obtains the quantum keys corresponding to each identification information from the quantum cryptography service platform based on the identification information of the quantum keys, it can confirm the quantum key used for each encrypted segment according to the correspondence.
[0104] In some embodiments, the encryption guidance further includes the identification code of the encryption algorithm. In step S403, the encryption algorithm used for each encrypted segment is further determined according to the identification code, and then each encrypted segment is decrypted.
[0105] As an example, the communication information is the email body, and the information sending method includes:
[0106] (1) The sender s receives the communication information to be sent, receives the specification for the content to be encrypted in the communication information, determines multiple encrypted segments, which are 2 in this example; parses to obtain the position information of the 2 encrypted segments: the local content starting from the 3rd byte after the text and with a length of 10 bytes, and the local content starting from the 1024th byte after the text and with a length of 36 bytes, and sends the lengths of the 2 encrypted segments to the quantum cryptography service platform;
[0107] (2) The quantum cryptography service platform p generates quantum keys k1 and k2 for the 2 encrypted segments respectively, and k1 = 10 bytes, k2 = 36 bytes; at the same time, the quantum cryptography service platform p also generates the identification information token1 and token2 corresponding to these 2 quantum keys k1 and k2, and sends k1, k2, token1, and token2 to the sender s together.
[0108] (3) The sender s encrypts the two encrypted segments using k1 and k2 respectively. Assuming that the first encrypted segment is encrypted using the XOR algorithm based on k1 and the second encrypted segment is encrypted using the XOR algorithm based on k2, the generated encryption guidance includes:
[0109] X-bodyEncrypt:[3,10,1,1000],[1024,36,2,1000]
[0110] X-group:0a395b37400ea5f8,1f8bcb31d2d29ef4
[0111] The content following the X-group label is the key identifiers token1 and token2.
[0112] Use the encryption guidance as the message header of the email and send the email.
[0113] (4) After the recipient r receives the email, obtains the message header of the email, applies to the quantum cryptography service platform p for the quantum keys k1 and k2 corresponding to the two key identifiers based on the identification information vectors of the two quantum keys in the message header, and decrypts the two encrypted segments according to the algorithms specified by the encryption algorithm identification codes.
[0114] In actual application scenarios, there can be multiple email recipients, and instant messaging software also has functions such as group sending and multi-person conversations. Moreover, the sensitive information in the communication information to be sent may only require some of the recipients to have the decryption permission, or there may be multiple sensitive information parts in the communication information to be sent, and the objects to which each sensitive information is confidential may also be different. For example, for the information issued by an enterprise, different parts of the content have different reading permissions for different departments. To achieve differential management of reading permissions, in some embodiments, a decryption permission person is specified for each encrypted segment. When the recipient is the specified decryption permission person, the quantum cryptography service platform provides the quantum key of the encrypted segment to it.
[0115] In one or more embodiments of the present invention, the so-called "decryption permission person" refers to the recipient specified by the sender terminal from one or more recipients for a certain encrypted segment and having the decryption permission for this encrypted segment. In special cases, there is only one recipient, or when all recipients are specified as the decryption permission person for a certain encrypted segment, the recipient and the decryption permission person can be equivalent.
[0116] Specifically, after receiving the specification for one or more encrypted segments in the communication information to be sent in step S301, also receive one or more decryption permission persons specified for one or more of the encrypted segments and send them to the quantum cryptography service platform.
[0117] By specifying the decryptor for the encrypted segment, it is possible to specify the recipient who has the reading permission for a certain local content. An encrypted segment without specifying a specific decryptor is regarded as having the reading permission for all recipients. As a specific implementation, an encryption function is added to the communication software. After the user selects an encrypted segment, the encryption function is triggered through operations such as menu selection, and the user is reminded to select or manually enter the decryptor. For example, if the communication information is in the form of an email, if the recipient information has been entered in advance, the user is reminded to select the decryptor from the already entered recipients, or manually enter other decryptors. If the manually entered decryptor recipient information is not in the already entered recipient information, it is appended to the recipient information and a reminder is given; another example is that if the communication information is instant messaging information, the user is reminded to specify the decryptor from the group members of the chat group.
[0118] After completing the specification of the encrypted segment and its decryptor, a key application is generated and sent to the quantum cryptography service platform. Among them, the key application includes the required key amount for each encrypted segment and the decryptor specified for each encrypted segment.
[0119] In step S302, the quantum cryptography service platform receives the key application. For each encrypted segment, a quantum key and the identification information of the quantum key are generated, and the quantum key and its identification information are sent to the sender terminal; at the same time, the information of each encrypted segment, the decryptor, the quantum key and its identification information in the key application are associated and stored.
[0120] In step S401, the receiving terminal also reads the identity information of the receiving terminal and sends the identity information and the identification information to the quantum cryptography service platform.
[0121] In step S402, the quantum cryptography service platform receives the identity information and the identification information. Based on the identification information, it checks whether there is a corresponding key distribution record. If there is, it further determines whether there is a decryptor in the key distribution record that is the same as the identity information. If there is, one or more quantum keys associated with the decryptor are obtained and sent to the receiving terminal.
[0122] As an example, the communication information to be sent is the body of an email, and the information transmission process is as follows:
[0123] (1) The sender s selects the content starting from the 3rd byte and with a length of 10 in the email body to be sent as the encrypted segment, sends the byte length 10 to the quantum cryptography service platform p, and at the same time designates one or more recipient information as the decryptor for this encrypted segment and informs the quantum cryptography service platform p;
[0124] (2) After receiving the application, the quantum cryptography service platform p saves the application information, generates a quantum key k1, and sends k1 and the corresponding quantum key identifier token1 to the sender s.
[0125] (3) After receiving k1 and the corresponding quantum key identifier token1, the sender s uses the quantum key k1 to perform one-time pad encryption on the part starting from the 3rd byte and having a length of 10 in the plain text, replaces the original plain text content with the generated 10-byte ciphertext content, and embeds it at the same position in the email body; at the same time, generates an encryption guide as the message header:
[0126] X-bodyEncrypt:[3,10,1,1000]
[0127] X-group:0a395b37400ea5f8
[0128] The sender s sends the processed email to the mail server.
[0129] (4) The recipient r pulls the email from the mail server to the local, reads the message header of the email, obtains the location range of the encrypted segment, the encryption algorithm identification code, and the quantum key identifier used for the encrypted segment, and sends the quantum key identifier token1 (the content is 0a395b37400ea5f8) indicated by the X-group label to the quantum cryptography service platform p to apply for the corresponding quantum key k1.
[0130] (5) After receiving the application, the quantum cryptography service platform p searches for the application record according to the quantum key identifier token1, checks whether the applicant is the designated recipient reported by the sender s or one of them. If so, sends the quantum key to the recipient r.
[0131] (6) The recipient r decrypts the encrypted segment using the quantum key k1 with the XOR algorithm to obtain 10 bytes of plain text, replaces the ciphertext at the same position, and the decryption process ends.
[0132] As another example, assume that 3 encrypted segments are specified, and the information reported by the sender s to the quantum cryptography service platform p when applying for quantum keys is: 1. The number of quantum keys applied for, which is 3 in this example; 2. The length of each quantum key, for example, 10 bytes, 1024 bytes, and 16 bytes respectively; 3. For each quantum key, the decryption authority, for example, specifying a@sina.com as the decryption authority for encrypted segment 1, specifying b@163.com as the decryption authority for encrypted segment 2, and specifying a@163.com, b@163.com, and c@sohu.com as the decryption authorities for encrypted segment 3. The following json format is used to report data to apply for 3 quantum keys.
[0133]
[0134]
[0135] The quantum cryptography service platform p records the reported information received, generates three quantum keys k1, k2, k3, and returns them together with the tags token1, token2, token3 corresponding to the three quantum keys to the sender s. The quantum cryptography service platform p records the corresponding relationships between the three quantum keys, their identification information, and the decryption authorized persons in the key information table it maintains:
[0136] k1 —— eb4511d6ae6646fd (token1) —— a@sina.com
[0137] k2 —— 83c43f6d9177b4b6 (token2) —— b@163.com
[0138] k3 —— ca93aa80bcab8ced (token3) —— a@sina.com, b@163.com, c@sohu.com
[0139] When the recipient r with the email account b@163.com applies to the quantum cryptography service platform for quantum keys, the reported information is: 1. The number of quantum keys applied for, 2. The recipient's email account; 3. The identification corresponding to the quantum key;
[0140] For example, using the following json format to report data means that b@163.com is the recipient, applying for 2 quantum keys, and attaching the identifications corresponding to these two quantum keys.
[0141] {
[0142] "keyCount":"2",
[0143] "account":"b@163.com",
[0144] "keyToken":["83c43f6d9177b4b6","ca93aa80bcab8ced"]
[0145] }
[0146] After the quantum cryptography service platform p receives the application from the recipient r, it retrieves the data in the key information table, finds the corresponding records according to the two tags described by keyToken, compares them with account, and after confirming that b@163.com described by account has the application permission for these two quantum keys, it distributes the quantum keys k2 and k3 corresponding to the two tags to the recipient r.
[0147] It can be understood that receiving one or more decryption authorities designated for one or more of the encrypted segments in step S301 includes not only designating one or more decryption authorities for any one encrypted segment, but also designating one decryption authority for multiple encrypted segments.
[0148] In some embodiments, it can be considered that the confidentiality levels of the encrypted segments with the same decryption authority are the same. Specifically, in step S402, if there are multiple encrypted segments with exactly the same decryption authority, the same quantum key is generated for the multiple encrypted segments. Of course, whether this step is executed can be specified by the user.
[0149] As an example, the communication information to be sent is the body of an email. Suppose 5 encrypted segments are specified, where the decryption authorities for the 1st, 3rd, and 5th are user A (a@quantum-info.com), and the decryption authorities for the 2nd and 4th are user B (b@quantum-info.com). The rest of the body content can be viewed by all recipients. If the sender s sets the same confidentiality requirements for the exactly same decryption authorities, it can apply to the quantum cryptography service platform p for 2 quantum keys, k1 is used to encrypt the 1st, 3rd, and 5th, and k2 is used to encrypt the 2nd and 4th.
[0150] By designating decryption authorities for each encrypted segment, differential permission management of multiple sensitive information in the same communication information is achieved, thus enabling fine-grained control of the encryption granularity, having high flexibility, and being able to meet the customized encryption requirements of users.
[0151] In many cases, the transmitted communication information, such as emails, etc., has attachment files. In addition to the possible encryption requirement for the body of the communication information, the attachment files may also have encryption requirements. In some embodiments, in step S301, a designation of one or more attachment files to be encrypted is further received, and the key application also includes the amount of quantum key required for each attachment file to be encrypted; in step S302, the quantum cryptography service platform also generates a quantum key for each attachment file to be encrypted, as well as the identification information of the quantum key, and sends the designated encrypted segment and the quantum key and its identification information of the attachment file to be encrypted to the sending party terminal; in step S303, in response to the information sending confirmation instruction, each encrypted segment and each attachment file to be encrypted are encrypted using the corresponding quantum key, and an encryption guide is generated; for the encrypted attachment file, the encryption guide includes the quantum key identification information corresponding to each attachment file, and for the encrypted segment, the encryption guide includes the location information of each local content and the identification information of the corresponding quantum key.
[0152] Wherein, the amount of quantum key required for each attachment file to be encrypted may be the same as the number of bytes occupied by the attachment file, or a set value may be set. The specific setting method will not be elaborated here.
[0153] Correspondingly, after receiving the communication information and the encryption guide in step S401, the receiving party terminal sends the quantum key identification information corresponding to the encrypted attachment file in the encryption guide, as well as the quantum key identification information corresponding to the encrypted segment, to the quantum cryptography service platform; in step S402, for the obtained identification information, the quantum key distribution records for the attachment file and the encrypted segment are respectively searched.
[0154] As an example, the communication information is an email, and 2 sensitive information in the body and 1 attachment are encrypted simultaneously:
[0155] [Encrypted text 1] The starting position is after the 3rd byte of the text, and the length is 10 bytes;
[0156] [Encrypted text 2] The starting position is after the 1024th byte of the text, and the length is 36 bytes;
[0157] [Encrypted attachment] The 3rd attachment
[0158] The sender s requests 3 quantum keys k1 = 10 bytes, k2 = 36 bytes, k3 = 16 bytes from the quantum cryptography service platform p. The quantum cryptography service platform p generates three quantum keys k1, k2, k3 and the key identification token1 corresponding to k1, the key identification token2 corresponding to k2, and the key identification token3 corresponding to k3, and uses the shared key k with the sender s psAfter encrypting k1, k2, and k3 respectively, they are sent to the sender s together with their respective key identifiers token1, token2, and token3.
[0159] If k1 is used to encrypt the body part 1 using the XOR algorithm, k2 is used to encrypt the body part 2 using the XOR algorithm, and k3 is used to encrypt the attachment using the SM4-ECB algorithm, then the encrypted email header contains the following content:
[0160] X-bodyEncrypt:[3,10,1,1000],[1024,36,2,1000]
[0161] X-attachmentEncrypt:[3,3,401]
[0162] X-group:0a395b37400ea5f8,1f8bcb31d2d29ef4,0eed1 a3fd437724f
[0163] The content following the X-group label is the key identifiers token1, token2, and token3.
[0164] After the recipient r receives the email, obtains the above labels in the email header, applies to the quantum password service platform p in the manner described in Example 1 to obtain the quantum keys k1, k2, and k3 corresponding to the above three key identifiers respectively, and decrypts the two pieces of text and one attachment according to the algorithms specified in the labels.
[0165] To prevent eavesdroppers from impersonating the recipient's identity to obtain communication information, for example, if an eavesdropper illegally obtains the recipient's communication software login account through hacking means, in some embodiments, the sender terminal and the quantum password service platform both pre-store a first shared quantum key for encrypting and decrypting communication information between them. The recipient terminal and the quantum password service platform both pre-store a second shared quantum key for encrypting and decrypting communication information between them.
[0166] More specifically, in step S2, the quantum password service platform encrypts the generated quantum key using the first shared quantum key and then sends it to the sender terminal.
[0167] In step S5, the quantum password service platform encrypts the found quantum key using the second shared quantum key and then sends it to the recipient terminal.
[0168] In this way, even if an eavesdropper illegally obtains the encryption guidance by cracking the communication software account, since it uses the shared key between the recipient terminal and the quantum password service platform, the eavesdropper cannot crack it.
[0169] To further improve security, in some embodiments, the quantum cryptography service platform encrypts based on a partial key of the first shared quantum key or the second shared quantum key, denoted as a temporary key. When sending the encrypted information to the sender terminal or the receiver terminal, the position information of the temporary key in the first shared quantum key or the second shared quantum key is sent simultaneously. Specifically, the partial key can be a continuous segment of the first shared quantum key or the second shared quantum key, or a combination of multiple discontinuous segments of keys. As an example, the first shared quantum key or the second shared quantum key is a continuous binary data segment. The 2048 - 2064th bytes can be intercepted for encryption, or multiple position intervals can be specified, such as the 600 - 1000th and 2504 - 2720th bytes, which are spliced together for encryption.
[0170] Based on this, the temporary key used to encrypt the quantum key to be transmitted is also one-time pad encryption. Even if the receiver terminal is stolen, since it is unknown how the previous key was actually used, the communication data before the theft remains secure. In addition, since each quantum key application is encrypted and protected by different parts of the shared key, if only the position information of the key is eavesdropped during transmission, since the key itself is not being transmitted, the communication data cannot be cracked.
[0171] As an example, the sender s and the receiver r respectively obtain the shared keys k ps and k pr in advance with the quantum cryptography service platform p. Figure 8 As shown, in step ①, the sender s obtains the segment to be encrypted and informs the quantum cryptography service platform p of the length of the segment to be encrypted; in step ②, the quantum cryptography service platform p generates the quantum key k1 and encrypts k1 using the shared key k ps between them to obtain k ps (k1), and sends k ps (k1) and the quantum key identifier token1 corresponding to k1 to the sender s; in step ③, the sender s receives token1 and k ps (k1), decrypts k ps using the shared key k ps between the sender s and the quantum cryptography service platform p to obtain the quantum key k1, encrypts the encrypted segment, and sends the encrypted email together with the identifier information token1 of the quantum key to the email server; in step ④, the receiver r obtains the email from the email server, in step ⑤, sends token1 to the quantum cryptography service platform p to apply for the quantum key, and in step ⑥, the quantum cryptography service platform p encrypts the quantum key k1 corresponding to token1 using the shared key k pr between the platform and the receiver r to obtain k pr(k1), send k pr (k1) to the recipient r. The recipient r uses the shared key k ps with the quantum cryptography service platform p to decrypt k ps (k1) to obtain the quantum key k1 and decrypt the encrypted segment.
[0172] Figure 5 The figure shows a method for sending information based on a quantum key provided by one or more embodiments of the present invention. The method is applied to a sender terminal and includes the following steps:
[0173] S501: Receive the designation of one or more encrypted segments in the communication information to be sent, generate a key application and send it to the quantum cryptography service platform. The key application includes the amount of quantum key required for each encrypted segment;
[0174] S502: Obtain the quantum key generated for each encrypted segment and the identification information of the quantum key from the quantum cryptography service platform;
[0175] S503: In response to the information sending confirmation instruction, encrypt each encrypted segment with the corresponding quantum key and generate an encryption guide, and send the encrypted communication information and the encryption guide; the encryption guide includes the position information of each encrypted segment and the identification information of the corresponding quantum key, so that the receiving party terminal can obtain the quantum key from the quantum cryptography service platform based on the identification information.
[0176] Among them, in step S501, in the key application, the amount of quantum key required for each encrypted segment is the same as the byte length of the encrypted segment or is a set value.
[0177] More specifically, after receiving the designation of one or more encrypted segments, the confidentiality level of each encrypted segment is also received. According to the confidentiality level, the amount of quantum key required for each encrypted segment is determined; the amount of quantum key required for the encrypted segment with the highest confidentiality level is the byte length of the encrypted segment; the amount of quantum key required for the attachment file with a lower confidentiality level is a set value.
[0178] In step S501, before generating the key application, if an editing operation on the designated encrypted segment is detected, update or cancel the encrypted segment.
[0179] In step S502, if multiple encrypted segments are designated, the corresponding relationship between each quantum key and the encrypted segment is also obtained from the quantum cryptography service platform, and when encrypting each encrypted segment, the corresponding relationship is written into the key guide.
[0180] A variety of encryption algorithms are preset. In step S501, after receiving the designation of one or more encryption segments, the designation of the encryption algorithm adopted for each of the encryption segments is also received; in step S503, when encrypting the encryption segment, the identification code of the encryption algorithm is written into the key guide.
[0181] The encryption index includes a key identification label and an encrypted content label corresponding to each encryption segment. The key identification label includes the quantum key identification information of all encryption segments. The encrypted content label includes the serial number of the encryption segment, and the corresponding serial number of the quantum key used in the key identification label, or the serial number of the encryption segment, the corresponding serial number of the quantum key used in the key identification label, and the identification code of the encryption algorithm adopted.
[0182] To implement the identity authentication of the receiving party, in step S501, after receiving the designation of one or more encryption segments in the communication information to be sent, the designated receiving party information is also received and sent to the quantum cryptography service platform, so that when the receiving party terminal applies for a quantum key to the quantum cryptography service platform, identity authentication is performed.
[0183] To implement the differential permission management for multiple encryption segments in the communication information, in step S501, after receiving the designation of one or more encryption segments in the communication information to be sent, one or more decryption permission holders designated for one or more of the encryption segments are also received and sent to the quantum cryptography service platform, and the one or more decryption permission holders are a subset of the receiving party of the communication information, so that when the receiving party terminal applies for a quantum key to the quantum cryptography service platform, identity authentication is performed.
[0184] According to the user's personalized requirements for confidentiality, if the decryption permission holders of multiple encryption segments are exactly the same, the same quantum key is generated for the multiple encryption segments.
[0185] The sending party terminal pre-stores a first shared quantum key with the quantum cryptography service platform. What is obtained from the quantum cryptography service platform is a quantum key encrypted by the first shared quantum key, and the quantum key is obtained by decryption. As a more specific implementation manner, a quantum key encrypted by a temporary key and the position information of the temporary key in the first shared quantum key are obtained from the quantum cryptography service platform; according to the position information of the temporary key and the first shared quantum key, the temporary key is obtained, and the quantum key is obtained by decryption.
[0186] Figure 6 A method for receiving information based on a quantum key provided by one or more embodiments of the present invention is shown. The method is applied to a receiving party terminal and includes the following steps:
[0187] S601: Receive the encrypted communication information and the encryption guidance; the encryption guidance includes the position information of one or more encrypted segments in the communication information and the identification information of the corresponding quantum keys;
[0188] S602: Send the identification information of the quantum keys corresponding to the one or more encrypted segments to the quantum cryptography service platform;
[0189] S603: Obtain one or more quantum keys found based on the identification information of the quantum keys from the quantum cryptography service platform;
[0190] S604: Locate each of the encrypted segments according to the position information of the one or more encrypted segments, and decrypt based on the corresponding quantum keys.
[0191] The key guidance further includes the correspondence between multiple encrypted segments and multiple quantum keys; when decrypting in step S604, obtain the quantum key for each encrypted segment according to the correspondence.
[0192] The key guidance further includes the identification code of the encryption algorithm used for each encrypted segment; when decrypting in step S604, obtain the encryption algorithm used for each encrypted segment according to the identification code.
[0193] When sending the identification information of the quantum keys corresponding to the one or more encrypted segments to the quantum cryptography service platform in step S601, simultaneously send the identity information of the receiving terminal, which is used by the quantum cryptography service platform to authenticate whether the identity information is the receiving party designated by the sending terminal. If the authentication passes, obtain the quantum key.
[0194] When sending the identification information of the quantum keys corresponding to the one or more encrypted segments to the quantum cryptography service platform in step S601, simultaneously send the identity information of the receiving terminal, which is used by the quantum cryptography service platform to authenticate whether the identity information is the decrypting authority for the one or more encrypted segments designated by the sending terminal. If the authentication passes, obtain the quantum keys for the one or more encrypted segments.
[0195] The receiving terminal pre-stores a second shared quantum key with the quantum cryptography service platform. What is obtained from the quantum cryptography service platform is the quantum key encrypted by the second shared quantum key, and the quantum key is obtained by decryption. As a more specific implementation, obtain the quantum key encrypted by a temporary key from the quantum cryptography service platform, as well as the position information of the temporary key in the second shared quantum key; obtain the temporary key according to the position information of the temporary key and the second shared quantum key, and decrypt to obtain the quantum key.
[0196] Figure 7A key distribution method is shown. The method is applied to a quantum cryptography service platform and includes the following steps:
[0197] S701: Receive a key application sent by a sender terminal. The key application includes the amount of quantum key required for each encryption segment.
[0198] S702: For each encryption segment, generate a corresponding quantum key and identification information of the quantum key.
[0199] S703: Send the quantum key and its identification information to the sender terminal.
[0200] If multiple encryption segments are specified, when generating quantum keys for the multiple encryption segments in step S702, the corresponding relationship between each quantum key and the encryption segment is also generated.
[0201] In step S701, the specified recipient information sent by the sender terminal is also received. After generating the quantum key in step S702, each encryption segment information, the quantum key and its identification information, and the recipient information are associated and stored to obtain the current key distribution record.
[0202] In step S701, one or more decryption authorities specified for one or more encryption segments sent by the sender terminal are also received. After generating the quantum key in step S702, each encryption segment information, the quantum key and its identification information, and the specified decryption authorities are associated and stored to obtain the current key distribution record.
[0203] According to the user's personalized requirements for confidentiality, in step S702, if the decryption authorities of multiple encryption segments are exactly the same, the same quantum key is generated for the multiple encryption segments.
[0204] The quantum cryptography service platform prestores a second shared quantum key with the sender terminal, and encrypts the generated quantum key based on the second shared secret key and then sends it to the sender terminal. As a more specific implementation method, a temporary key is generated based on part of the first shared quantum key, and the position information of the temporary key in the first shared quantum key is recorded; the generated quantum key is encrypted based on the temporary key, and the encrypted quantum key and the position information of the temporary key are sent to the sender terminal.
[0205] To implement the distribution of quantum keys to the recipient, the method further includes:
[0206] S704: Receive the identification information of one or more quantum keys sent by the recipient terminal, search for the corresponding quantum key and send it to the recipient terminal.
[0207] As a specific implementation manner, corresponding to the situation where the sending terminal designates a recipient information for one or more encrypted segments, in step S704, receive the identification information of one or more quantum keys sent by the receiving terminal, and the identity information of the receiving terminal; according to each of the identification information, check whether there is a corresponding key distribution record, if there is, further determine whether the identity information of the receiving terminal is consistent with the recipient information in the key distribution record, if they are consistent, obtain the quantum key in the key distribution record, and send it to the receiving terminal.
[0208] As another specific implementation manner, corresponding to the situation where the sending terminal designates one or more decryption authorities for one or more encrypted segments, in step S704, receive the identification information of one or more quantum keys sent by the receiving terminal, and the identity information of the receiving terminal; according to each of the identification information, check whether there is a corresponding key distribution record, if there is, further determine whether there is a decryption authority in the key distribution record that is consistent with the identity information of the receiving terminal, if there is, obtain one or more quantum keys associated with the decryption authority, and send them to the receiving terminal.
[0209] The quantum cryptography service platform pre-stores a second shared quantum key with the receiving terminal, and encrypts the found quantum key based on the second shared secret key and sends it to the receiving terminal. As a more specific implementation manner, generate a temporary key based on a part of the second shared quantum key, and record the position information of the temporary key in the second shared quantum key; encrypt the found quantum key based on the temporary key, and send the encrypted quantum key and the position information of the temporary key to the receiving terminal.
[0210] One or more embodiments of the present invention further provide a communication device, which can be used to implement the methods executed by the sending terminal, the receiving terminal, and the quantum cryptography service platform in the above embodiments. The electronic device includes one or more processors, one or more memories coupled to the processor, and a communication module coupled to the processor.
[0211] The memory may include one or more non-volatile memories and one or more volatile memories. Examples of non-volatile memories include, but are not limited to, at least one of the following: Read-Only Memory (ROM), Erasable Programmable Read Only Memory (EPROM), flash memory, hard disk, Compact Disc (CD), Digital Versatile Disc (DVD), or other magnetic storage and / or optical storage. Examples of volatile memories include, but are not limited to, at least one of the following: Random Access Memory (RAM), or other volatile memories that do not persist during a power outage duration. The computer program may be stored in the ROM. When the processor executes the computer program, any one of the above information sending method, information receiving method, and key distribution method is implemented.
[0212] In some embodiments, the program may be tangibly embodied in a computer-readable medium, which may be included in the device (such as in the memory) or other storage devices accessible by the device. The program may be loaded from the computer-readable medium into the RAM for execution. The computer-readable medium may include any type of tangible non-volatile memory, such as ROM, EPROM, flash memory, hard disk. The computer-readable storage medium stores a computer program, and when the computer program is executed by the processor, any one of the above information sending method, information receiving method, and key distribution method is implemented.
[0213] One or more embodiments of the present invention further provide an information transmission system based on quantum keys, including a sender terminal, a receiver terminal, and a quantum cryptography service platform.
[0214] Various embodiments of the present invention may be implemented in hardware or dedicated circuits, software, logic, or any combination thereof. Some aspects may be implemented in hardware, while other aspects may be implemented in firmware or software, which may be executed by a controller, a microprocessor, or other computing devices. Although various aspects of the embodiments of the present disclosure are shown and described as block diagrams, flowcharts, or using some other graphical representation, it should be understood that the blocks, devices, systems, techniques, or methods described herein may be implemented as, by way of non-limiting example, hardware, software, firmware, dedicated circuits or logic, general-purpose hardware or controllers or other computing devices, or some combination thereof.
[0215] Although the operations of the method of the present invention are depicted in a specific order in the drawings, this is not a requirement or an implication that these operations must be performed in that specific order, or that all of the shown operations must be performed to achieve the desired result. On the contrary, the steps depicted in the flowchart can be changed in the order of execution. Additionally or alternatively, certain steps may be omitted, multiple steps may be combined into one step for execution, and / or one step may be decomposed into multiple steps for execution. It should also be noted that the features and functions of two or more devices according to the present disclosure can be embodied in one device. Conversely, the features and functions of one device described above can be further divided and embodied by multiple devices.
Claims
1. An information sending method based on quantum key, which is applied to a sender terminal, and is characterized in that, It includes the following steps: Receiving the specification of one or more encrypted segments in the communication information to be sent, generating a key application and sending it to the quantum cryptography service platform, where the key application includes the amount of quantum key required for each encrypted segment; Obtaining from the quantum cryptography service platform the quantum key generated for each of the encrypted segments and the identification information of the quantum key; In response to the information sending confirmation instruction, encrypting each encrypted segment with the corresponding quantum key, generating an encryption guide, and sending the encrypted communication information and the encryption guide; the encryption guide includes the position information of each encrypted segment and the identification information of the corresponding quantum key, so that the receiving party terminal can obtain the quantum key from the quantum cryptography service platform based on the identification information.
2. The information sending method based on quantum key as claimed in claim 1, wherein In the key application, the amount of quantum key required for each encrypted segment is the same as the byte length of the encrypted segment or is a set value.
3. The information sending method based on quantum key according to claim 1, wherein After receiving the specification of one or more encrypted segments, the confidentiality level of each encrypted segment is also received, and based on the confidentiality level, the amount of quantum key required for each encrypted segment is determined; the amount of quantum key required for the encrypted segment with the highest confidentiality level is the byte length of the encrypted segment; the amount of quantum key required for the attachment file with a lower confidentiality level is a set value.
4. The information sending method based on quantum key according to claim 1, wherein, Before generating the key application, if an edit operation on the specified encrypted segment is detected, update or cancel the encrypted segment.
5. The information sending method based on quantum key as claimed in claim 1, wherein If multiple encrypted segments are specified, the correspondence between each quantum key and the encrypted segment is also obtained from the quantum cryptography service platform, and when encrypting each encrypted segment, the correspondence is written into the key guide.
6. The information sending method based on quantum key as claimed in claim 1, wherein Multiple encryption algorithms are preset. After receiving the specification of one or more encrypted segments, the specification of the encryption algorithm used for each of the encrypted segments is also received; when encrypting each encrypted segment, the identification code of the encryption algorithm is written into the key guide.
7. The information sending method based on quantum key according to claim 5 or 6, characterized in that, The encryption index includes a key identification label and an encrypted content label corresponding to each encrypted segment. The key identification label includes the quantum key identification information of all encrypted segments. The encrypted content label includes the serial number of the encrypted segment, and the serial number corresponding to the used quantum key in the key identification label, or the serial number of the encrypted segment, the serial number corresponding to the used quantum key in the key identification label, and the identification code of the used encryption algorithm.
8. The information sending method based on quantum key according to claim 1, characterized in that, After receiving the specification of one or more encrypted segments in the communication information to be sent, the specification of one or more decryption authorities specified for one or more of the encrypted segments is also received and sent to the quantum cryptography service platform, so that the receiving party terminal can perform identity authentication when applying for the quantum key from the quantum cryptography service platform.
9. The information sending method based on quantum key according to claim 1, wherein The specification of one or more attachment files to be encrypted in the communication information to be sent is also received, and the key application also includes the amount of quantum key required for each attachment file to be encrypted; Obtaining from the quantum cryptography service platform the quantum key generated for each encrypted segment and each attachment file to be encrypted and the identification information of the quantum key; In response to the information sending confirmation instruction, each attachment file to be encrypted is also encrypted with the corresponding quantum key, and an encryption guide is generated; The encryption index of the attachment file includes the quantum key identification information corresponding to each attachment file.
10. The information sending method based on quantum key according to any one of claims 1-6 and 8-9, characterized in that, Pre-store a first shared quantum key with the quantum cryptography service platform. The quantum key obtained from the quantum cryptography service platform is encrypted via the first shared quantum key, and decrypt it to obtain the quantum key.
11. The information sending method based on quantum key according to claim 10, wherein Obtain from the quantum cryptography service platform a quantum key encrypted via a temporary key, and the position information of the temporary key in the first shared quantum key; obtain the temporary key according to the position information of the temporary key and the first shared quantum key, and decrypt it to obtain the quantum key.
12. An information receiving method based on quantum key, applied to a receiving party terminal, characterized in that, Include the following steps: Receive communication information and an encryption guide; the encryption guide includes the position information of one or more encrypted segments in the communication information and the identification information of the corresponding quantum key; Send the identification information of the quantum key corresponding to the one or more encrypted segments to the quantum cryptography service platform; Obtain from the quantum cryptography service platform one or more quantum keys found based on the identification information of the quantum key; Locate each of the encrypted segments according to the position information of the one or more encrypted segments, and decrypt them based on the corresponding quantum key.
13. The information receiving method based on quantum key according to claim 12, wherein The key guide further includes the correspondence between multiple encrypted segments and multiple quantum keys; obtain the quantum key for each encrypted segment according to the correspondence during decryption.
14. The information receiving method based on quantum key according to claim 12, wherein The key guide further includes the identification code of the encryption algorithm used for each encrypted segment; obtain the encryption algorithm used for each encrypted segment according to the identification code during decryption.
15. The information receiving method based on quantum key according to claim 12, wherein When sending the identification information of the quantum key corresponding to the one or more encrypted segments to the quantum cryptography service platform, simultaneously send the identity information of the receiving party terminal, which is used for the quantum cryptography service platform to authenticate whether the identity information is the decryption permission person specified by the sending party terminal for the one or more encrypted segments. If the authentication passes, obtain the quantum key for the one or more encrypted segments.
16. The information receiving method based on quantum key according to claim 12, wherein The encryption guide further includes the quantum key identification information used for one or more encrypted attachment files in the communication information; send the identification information of the quantum key corresponding to the one or more encrypted attachment files to the quantum cryptography service platform; Obtain from the quantum cryptography service platform one or more quantum keys found based on the identification information of the quantum key; decrypt each encrypted attachment file using the corresponding quantum key.
17. The information receiving method based on quantum key according to any one of claims 12-16, characterized in that, Pre-store a second shared quantum key with the quantum cryptography service platform. The quantum key obtained from the quantum cryptography service platform is encrypted via the second shared quantum key, and decrypt it to obtain the quantum key.
18. The information receiving method based on quantum key according to claim 17, wherein Obtain from the quantum cryptography service platform a quantum key encrypted via a temporary key, and the position information of the temporary key in the second shared quantum key; obtain the temporary key according to the position information of the temporary key and the second shared quantum key, and decrypt it to obtain the quantum key.
19. A key distribution method, applied to a quantum cryptography service platform, is characterized in that, Include the following steps: Receive a key application sent by the sending party terminal, where the key application includes the amount of quantum key required for one or more encrypted segments; For each of the encrypted segments, generate a corresponding quantum key and the identification information of the quantum key; Send the quantum key and its identification information to the sending party terminal.
20. The key distribution method according to claim 19, wherein If multiple encrypted segments are specified, while generating quantum keys for the multiple encrypted segments, a corresponding relationship between each quantum key and the encrypted segment is also generated.
21. The key distribution method according to claim 19, wherein, The communication device also receives one or more decryption authorities specified for one or more encrypted segments sent by the sender terminal, and associates and stores each encrypted segment information, the quantum key and its identification information, and the specified decryption authorities to obtain the current key distribution record.
22. The key distribution method according to claim 21, wherein If the decryption authorities for multiple encrypted segments are exactly the same, the same quantum key is generated for the multiple encrypted segments.
23. The key distribution method according to claim 19, wherein, The key application also includes the amount of quantum keys required for one or more attachment files; For each of the attachment files, a corresponding quantum key and identification information of the quantum key are generated; The quantum key and its identification information are sent to the sender terminal.
24. The key distribution method according to any one of claims 19-23, characterized in that, A first shared quantum key with the sender terminal is pre-stored, and the generated quantum key is encrypted based on the first shared quantum key and then sent to the sender terminal.
25. The key distribution method according to claim 24, wherein, A temporary key is generated based on part of the first shared quantum key, and the position information of the temporary key in the first shared quantum key is recorded; the generated quantum key is encrypted based on the temporary key, and the encrypted quantum key and the position information of the temporary key are sent to the sender terminal.
26. The key distribution method according to any one of claims 19-23, characterized in that, The communication device receives the identification information of one or more quantum keys sent by the receiver terminal, searches for the corresponding quantum keys and sends them to the receiver terminal.
27. The key distribution method according to claim 26, wherein The communication device receives the identification information of one or more quantum keys sent by the receiver terminal and the identity information of the receiver terminal; According to each of the identification information, it is searched whether there is a corresponding key distribution record. If there is, it is further determined whether there is a decryption authority in the key distribution record that is consistent with the identity information of the receiver terminal. If there is, one or more quantum keys associated with the decryption authority are obtained and sent to the receiver terminal.
28. The key distribution method according to claim 27, wherein, A second shared quantum key with the receiver terminal is pre-stored, and the found quantum keys are encrypted based on the second shared secret key and then sent to the receiver terminal.
29. The key distribution method according to claim 28, wherein A temporary key is generated based on part of the second shared quantum key, and the position information of the temporary key in the second shared quantum key is recorded; the found quantum keys are encrypted based on the temporary key, and the encrypted quantum keys and the position information of the temporary key are sent to the receiver terminal.
30. A communication device, characterized in that, The communication device includes one or more processors; and a memory; wherein, one or more computer programs are stored in the memory, and the one or more computer programs include instructions, when the instructions are executed by the communication device, the communication device is caused to execute the method according to any one of claims 1-29.
31. A computer-readable storage medium storing instructions therein, characterized in that, When the instructions run on the communication device, the communication device is caused to execute the method according to any one of claims 1-29.
32. An information transmission system based on quantum keys, characterized in that, Including a sender terminal, a receiver terminal, and a quantum cryptography service platform, which are respectively configured to execute the information sending method according to any one of claims 1-11, the information receiving method according to any one of claims 12-18, and the key distribution method according to any one of claims 19-29.
Citation Information
Patent Citations
Method, system, and device for processing media message
CN102740246A
Cited By
Drag data protection method, verification method and system based on quantum encryption
CN121485916A