Attachment file sending method, receiving method and equipment

Generating quantum keys and specifying decryption authority through the quantum cryptographic service platform has solved the problem that the attachment file encryption method in the existing technology cannot achieve specified encryption and permission control, and realized flexible attachment file encryption and differentiated permission management, improving security and resource utilization efficiency.

CN120238533APending Publication Date: 2025-07-01QUANTUMCTEK CO LTD +1
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202311871047.0
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2023-12-29
Publication Date
2025-07-01

AI Technical Summary

Technical Problem

Existing encryption methods cannot implement specified encryption and differentiated access permission management for attachment files, resulting in waste of computing resources and insufficient permission control.

Method used

Generate quantum keys through the quantum cryptographic service platform, encrypt the attachment file according to user needs, and specify the decryption authority to generate encryption guidelines to achieve flexible permission control.

Benefits of technology

It realizes flexible encryption of attachment files, meets personalized needs, improves security and computing resource utilization efficiency, and realizes differentiated permission management.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120238533A_ABST
    Figure CN120238533A_ABST
Patent Text Reader

Abstract

The invention belongs to the technical field of information communication, and provides an attachment file sending method, receiving method and equipment, and the sending method comprises the steps: receiving the designation of one or more to-be-encrypted attachment files for to-be-sent communication information, generating a key application, and sending the key application to a quantum cryptography service platform, the key application comprises quantum key quantity required by each attachment file to be encrypted; obtaining a quantum key generated for each to-be-encrypted attachment file and identification information of the quantum key from the quantum cryptography service platform; in response to an information sending confirmation instruction, encrypting each to-be-encrypted attachment file, generating an encryption guide, and sending the communication information and the encryption guide; the encryption guidance comprises quantum key identification information corresponding to each attachment file, so that the receiver terminal obtains a quantum key from the quantum cryptography service platform based on the identification information. Any one or more attachments can be encrypted according to the confidentiality requirement of a user on the attachment file.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention belongs to the field of information and communication technologies, and particularly relates to a method and device for sending and receiving attachment files. Background Art

[0002] The statements in this section merely provide background technical information related to the present invention and do not necessarily constitute prior art.

[0003] E-mail, instant messaging tools, etc. facilitate the transmission of files. However, once a file is transmitted, its security cannot be guaranteed, especially for internal files of enterprises and institutions or other files with confidentiality requirements. To ensure the security of files, the transmitted files can be encrypted.

[0004] In the file transmission scenario, the email body and attachments to be sent are globally encrypted through an encrypted email service, and only the sender and the recipient can read the email and attachments. If the amount of data to be encrypted is large (for example, the email body content is long or the attachment file is large), a long computing time is required. However, usually, not all contents of these email bodies and attachments need to be encrypted. For example, for a product recommendation email, the body may only introduce the product overview, and key information such as product parameters is sent in the form of attachments. Global encryption will result in waste of computing resources.

[0005] Moreover, in actual application scenarios, multiple email recipients can be specified, and instant messaging software also has functions such as group sending and multi-person conversations. For a certain attachment file, there may be a need for only some people to be able to view it. For example, for an internal email sent by an enterprise, everyone can view the body, but for a certain attachment, only people in a certain department are allowed to view it. The existing encryption schemes cannot meet such permission control requirements. Summary of the Invention

[0006] To overcome the deficiencies of the above-mentioned prior art, the present invention provides a method and device for sending and receiving attachment files, which can encrypt any one or more attachments according to the user's confidentiality requirements for the attachment files, and can open viewing permissions for specific recipients, with stronger flexibility and can meet the personalized needs of users.

[0007] To achieve the above object, a first aspect of the present invention provides an attachment file sending method, which is applied to a sender terminal and includes the following steps:

[0008] Receive communication information to be sent, where the communication information includes one or more attachment files;

[0009] Receiving the designation of one or more attachment files to be encrypted, and receiving the designation of one or more decryption authorized persons designated for one or more of the attachment files to be encrypted;

[0010] Generating a key application and sending it to the quantum cryptography service platform, where the key application includes the amount of quantum key required for each attachment file to be encrypted and the decryption authorized person information;

[0011] Obtaining the quantum key generated for each attachment file to be encrypted and the identification information of the quantum key from the quantum cryptography service platform;

[0012] In response to the information sending confirmation instruction, encrypting each attachment file to be encrypted with the corresponding quantum key, generating an encryption guide, and sending the communication information and the encryption guide, where the encryption guide includes the quantum key identification information corresponding to each attachment file; so that the receiving party terminal can perform identity authentication based on the designated receiving party information, and obtain the quantum key from the quantum cryptography service platform based on the identification information after the identity authentication passes.

[0013] In some embodiments, the amount of quantum key required for an attachment file to be encrypted is the same as the size of the attachment file or is a set value.

[0014] In some embodiments, after receiving the designation of one or more attachment files to be encrypted, the confidentiality level of each attachment file to be encrypted is also received, and the amount of quantum key required is determined according to the confidentiality level of each attachment file to be encrypted; the amount of quantum key required for the attachment file with the highest confidentiality level is the same as the size of the attachment file; the amount of quantum key required for the attachment file with a lower confidentiality level is a set value.

[0015] In some embodiments, if multiple attachment files to be encrypted are designated, the corresponding relationship between each quantum key and the attachment file is also obtained from the quantum cryptography service platform, and when encrypting the attachment file to be encrypted, the corresponding relationship is written into the key guide.

[0016] In some embodiments, multiple encryption algorithms are preset. When encrypting each attachment file to be encrypted, after receiving the designation of one or more attachment files to be encrypted, the designation of the encryption algorithm used for each attachment to be encrypted is also received; when encrypting the attachment file to be encrypted, the identification code of the encryption algorithm is written into the key guide.

[0017] In some embodiments, the encryption guidance includes a key identification tag and an encrypted content tag corresponding to each encrypted attachment. The key identification tag includes quantum key identification information of all encrypted attachment files. The encrypted content tag includes the serial number of the attachment file and the corresponding serial number of the quantum key in the key identification tag, or the serial number of the attachment file, the corresponding serial number of the quantum key in the key identification tag, and the identification code of the encryption algorithm used.

[0018] In some embodiments, a first shared quantum key with the quantum cryptography service platform is pre-stored, and the quantum key obtained from the quantum cryptography service platform is encrypted via the first shared quantum key, and the quantum key is obtained by decryption.

[0019] In some embodiments, a quantum key encrypted via a temporary key and the position information of the temporary key in the first shared quantum key are obtained from the quantum cryptography service platform; according to the position information of the temporary key and the first shared quantum key, the temporary key is obtained, and the quantum key is obtained by decryption.

[0020] The second aspect of the present invention provides a method for receiving attachment files, which is applied to a receiving party terminal and includes the following steps:

[0021] Receive communication information and encryption guidance, where the encryption guidance includes identification information of the quantum key used for one or more encrypted attachment files;

[0022] In response to a viewing request for a certain encrypted attachment file, send the identification information of the quantum key used for the attachment file and the identity information of the receiving party terminal to the quantum cryptography service platform;

[0023] After the quantum cryptography service platform authenticates the identity information, obtain the quantum key found based on the identification information; the quantum cryptography service platform pre-stores the quantum key corresponding to the encrypted attachment file and its identification information, as well as the information of the designated decryption authority;

[0024] Decrypt the encrypted attachment file.

[0025] In some embodiments, the key guidance further includes the correspondence between each encrypted attachment file and the quantum key; in response to a viewing request for a certain encrypted attachment file, determine the quantum key identification information of the encrypted attachment file according to the correspondence.

[0026] In some embodiments, the key guidance further includes the identification code of the encryption algorithm used for each encrypted attachment file; when decrypting, obtain the encryption algorithm used for each encrypted attachment file according to the identification code.

[0027] In some embodiments, a second shared quantum key with the quantum cryptography service platform is pre-stored, and the quantum key obtained from the quantum cryptography service platform is a quantum key encrypted via the second shared quantum key, and the quantum key is obtained by decryption.

[0028] In some embodiments, a quantum key encrypted via a temporary key is obtained from the quantum cryptography service platform, and position information of the temporary key in the second shared quantum key; the temporary key is obtained according to the position information of the temporary key and the second shared quantum key, and the quantum key is obtained by decryption.

[0029] A third aspect of the present invention provides a key distribution method, which is applied to a quantum cryptography service platform and includes the following steps:

[0030] Receiving a key application sent by a sender terminal, where the key application includes the amount of quantum key required for one or more attachment files to be encrypted, and one or more decryption authorities designated for one or more of the attachment files to be encrypted;

[0031] For each of the attachment files to be encrypted, generating a quantum key and identification information of the quantum key, and associatively storing the quantum key, its identification information, and the corresponding decryption authority to obtain a record of the current key distribution;

[0032] Sending the quantum key and its identification information to the sender terminal.

[0033] In some embodiments, if multiple attachment files to be encrypted are specified, while generating quantum keys for the multiple attachment files to be encrypted, a corresponding relationship between each quantum key and the attachment file is also generated and sent to the sender terminal.

[0034] In some embodiments, a first shared quantum key with the sender terminal is pre-stored, and the generated quantum key is encrypted based on the first shared quantum key and then sent to the sender terminal.

[0035] In some embodiments, a temporary key is generated based on a part of the first shared quantum key, and position information of the temporary key in the first shared quantum key is recorded; the generated quantum key is encrypted based on the temporary key, and the encrypted quantum key and the position information of the temporary key are sent to the sender terminal.

[0036] In some embodiments, receiving identification information of one or more quantum keys and identity information of the receiving terminal sent by the receiving terminal;

[0037] According to each piece of the identification information, check whether there is a corresponding key distribution record. If there is, further determine whether there is a decryption permission person in the key distribution record whose identity information is consistent with that of the receiving party terminal. If there is, obtain one or more quantum keys associated with the decryption permission person and send them to the receiving party terminal.

[0038] In some embodiments, a second shared quantum key with the receiving party terminal is pre-stored, and the found quantum key is encrypted based on the second shared key and then sent to the receiving party terminal.

[0039] In some embodiments, a temporary key is generated based on a part of the second shared quantum key, and the position information of the temporary key in the second shared quantum key is recorded; the found quantum key is encrypted based on the temporary key, and the encrypted quantum key and the position information of the temporary key are sent to the receiving party terminal.

[0040] The fourth aspect of the present invention provides a communication device, which includes one or more processors; and a memory; wherein, one or more computer programs are stored in the memory, and the one or more computer programs include instructions that, when executed by the communication device, cause the communication device to execute the attachment file sending method, the attachment file receiving method, or the key distribution method.

[0041] The fifth aspect of the present invention provides a computer-readable storage medium, in which instructions are stored that, when run on a communication device, cause the communication device to execute the attachment file sending method, the attachment file receiving method, or the key distribution method.

[0042] The sixth aspect of the present invention provides an attachment file transmission system, which includes a sending party terminal, a receiving party terminal, and a quantum cryptography service platform, which are respectively configured to execute the attachment file sending method, the attachment file receiving method, and the key distribution method described above.

[0043] Based on the above one or more technical solutions, before sending an email or other communication information, a user can apply for a quantum key to encrypt any one or more of the attachments. Compared with the overall encryption of the email or other communication information, a highly secure quantum key is used to encrypt only the attachments with confidentiality requirements, which is more targeted and flexible. Moreover, through the application of the high-strength quantum key to the specified attachments, the security is also higher.

[0044] It is possible to specify the decryptor for the attachment file to be encrypted, so that only the specified decryptor among the recipients can obtain the quantum key, realizing permission control. In addition, different decryptors can be specified for different attachment files, realizing differentiated permission management. BRIEF DESCRIPTION OF THE DRAWINGS

[0045] The accompanying drawings forming a part of this invention are used to provide a further understanding of the invention. The schematic embodiments of the invention and their descriptions are used to explain the invention and do not unduly limit the invention.

[0046] Figure 1 It is a schematic block diagram of a communication system in an embodiment of the present invention;

[0047] Figure 2 It is a schematic block diagram of another communication system in an embodiment of the present invention;

[0048] Figure 3 It is the overall flowchart of the attachment file sending method in an embodiment of the present invention;

[0049] Figure 4 It is the overall flowchart of the attachment file receiving method in an embodiment of the present invention;

[0050] Figure 5 It is the overall flowchart of the attachment file sending method applied to the sender terminal in an embodiment of the present invention;

[0051] Figure 6 It is the overall flowchart of the attachment file receiving method applied to the recipient terminal in an embodiment of the present invention;

[0052] Figure 7 It is the overall flowchart of the key distribution method applied to the quantum cryptography service platform in an embodiment of the present invention;

[0053] Figure 8 It is a schematic diagram of the information transmission process in an embodiment of the present invention. DETAILED DESCRIPTION OF THE EMBODIMENTS

[0054] It should be noted that the following detailed description is exemplary and is intended to provide further explanation of the present invention. Unless otherwise specified, all technical and scientific terms used herein have the same meaning as commonly understood by those of ordinary skill in the technical field to which the present invention belongs.

[0055] It should be noted that the terms used herein are only for describing specific embodiments and are not intended to limit the exemplary embodiments according to the present invention. As used herein, unless the context clearly indicates otherwise, the singular forms are also intended to include the plural forms. In addition, it should be understood that when the terms "comprising" and / or "including" are used in this specification, they specify the presence of features, steps, operations, devices, components, and / or combinations thereof.

[0056] In the case of no conflict, the embodiments in the present invention and the features in the embodiments may be combined with each other.

[0057] As described in the background art, the existing encryption methods cannot achieve the encryption of specified attachments and the differential management of attachment access permissions. The present invention encrypts only the attachments to be encrypted specified by the user, and can specify the decryption permission holders for the encrypted attachments, making the encryption more flexible and capable of meeting more detailed email confidentiality requirements.

[0058] Figure 1 A schematic block diagram of an exemplary communication system in which the embodiments of the present application can be implemented is shown. As shown in the figure, the communication system may include a sender terminal, a receiver terminal, and a quantum cryptography service platform. It can be understood that the sender terminal and the receiver terminal can both be a personal computer, a mobile phone (also known as a cell phone), a tablet computer, a television (also known as a smart screen or a large screen device), an ultra-mobile personal computer (UMPC), a handheld computer, a netbook, a personal digital assistant (PDA), a vehicle-mounted device (also known as a car computer), a wearable electronic device, a virtual reality device, etc. The embodiments of the present application do not make any restrictions on this.

[0059] The sender terminal, the receiver terminal, and the quantum cryptography service platform can establish connections through wired, wireless, or a combination of both. In the actual application process, there are no restrictions on the specific devices corresponding to the sender terminal and the receiver terminal. For example, communication can be carried out between a client and a server, between two servers, or between two clients via a server, as Figure 2 shown. In the specific application process, there are no restrictions on the information sending scenario, which will not be elaborated here.

[0060] For example, if the communication information to be sent is an email, the sending terminal and the receiving terminal transmit information via a mail server; or if the communication information to be sent is instant messaging information, the sending terminal and the receiving terminal transmit information via an instant messaging server. In such application scenarios, the sending terminal and the receiving terminal need to install email services or instant messaging software. In the following, the methods for sending and receiving information will be described with respect to the data interaction among the sending terminal, the receiving terminal, and the quantum cryptography service platform.

[0061] It can be understood that in one or more embodiments of the present invention, the so-called "attachment file" is not limited to the file sent with an email, but can also be a file sent with a message in instant messaging software, or a file attached to the information published within a specific social scope, and no specific limitation is made here. The attachment file can be any type of file, including documents, images, videos, and audios, etc., and its format can be any standard file format, such as PDF, JPEG, MP3, or Word document, etc.

[0062] In one or more embodiments of the present invention, the so-called "decryption authorized person" refers to the recipient designated by the sender terminal from one or more recipients for a certain attachment file and having the decryption permission for this attachment file. In special cases, when there is only one recipient, or when all recipients are designated as the decryption authorized person for a certain attachment file, the recipient and the decryption authorized person can be equivalent.

[0063] Figure 3 Fig. shows an overall flowchart of a method for sending an attachment file, including steps S301 - S304, and the method includes the following steps:

[0064] S301: The sending terminal receives the communication information to be sent, and the communication information includes one or more attachment files;

[0065] S302: Receive the designation of one or more attachment files to be encrypted, and receive the designation of one or more decryption authorized persons for one or more of the attachment files to be encrypted;

[0066] S303: Generate a key application and send it to the quantum cryptography service platform, and the key application includes the amount of quantum key required for each attachment file to be encrypted and the decryption authorized person information;

[0067] S304: The quantum cryptography service platform receives the key application, generates a quantum key for each attachment file, and the identification information of the quantum key, associates and stores the quantum key and its identification information, and the corresponding decryption authorized person, and obtains the current key distribution record;

[0068] S305: Send the quantum key and its identification information to the sender terminal;

[0069] S306: The sender terminal obtains the quantum key and its identification information, encrypts each of the attachment files with the corresponding quantum key in response to the information sending confirmation instruction, generates an encryption guide, and sends the communication information and the encryption guide; the encryption guide includes the quantum key identification information corresponding to each attachment file.

[0070] Based on this, the user can arbitrarily specify the attachment files to be encrypted and specify the decryption permission holders for any specified attachment files, which can meet the user's personalized encryption requirements.

[0071] In step S302, the sender terminal can receive the specification of the attachment files to be encrypted via the communication software interface. Specifically, the attachment files to be encrypted are selected by clicking with the mouse.

[0072] In some embodiments according to different security levels, at least two security levels are set. The highest security level is for the files with the highest security requirements, and the idea of "one-time pad" is adopted to apply for quantum keys with the same data volume as the attachment files to be encrypted. The lower security level is for the files with relatively lower security requirements, and quantum keys with a set data volume are applied for. Wherein, the data volume is the byte size occupied by the attachment file. For example, two security levels are set, and the amounts of quantum keys to be applied for are respectively: the same as the file data volume, and a set key volume of 16 bytes. It can be understood that more security levels can be set according to the requirements of the actual application scenario.

[0073] In some embodiments, the security level of each attachment file is specified by the user. For example, after the user uploads the attachment, selects an attachment file to be encrypted, and triggers the encryption function through operations such as menu selection, the user is reminded to specify the security level of the attachment file. As a specific implementation method, in step S302, after the sender terminal receives the specification of one or more attachment files to be encrypted, it also receives the security level of each of the attachment files, generates a key application and sends it to the quantum cryptography service platform, where the key application includes the data volume size and its security level of each attachment file; in step S303, the quantum cryptography service platform receives the key application, determines the required amount of quantum keys according to the security level of each attachment file, generates quantum keys and the identification information of the quantum keys, and sends the quantum keys and their identification information to the sender terminal.

[0074] In step S302, receiving the specification of one or more decryption permission holders for one or more of the attachment files to be encrypted can be understood as:

[0075] (1) Designate the same one or more decryption authorized persons for all or part of the attachment files to be encrypted. For example, for multiple attachments, designate users A and B among the recipients as the decryption authorized persons.

[0076] (2) Designate different one or more decryption authorized persons for different attachment files to be encrypted. For example, for the first attachment file, user A can be designated as the decryption authorized person; for the second attachment file, users A and B can be designated as the decryption authorized persons; for the third attachment file, users B, C, and D can be designated as the decryption authorized persons.

[0077] As a specific implementation manner, after the user selects an attachment file to be encrypted, the user is also reminded to select or manually input the decryption authorized persons. For example, if the communication information is in the form of an email, and the recipient information has been input in advance, the user is reminded to select the decryption authorized persons from the already input recipients, or manually input other decryption authorized persons. If the manually input decryption authorized person's recipient information is not in the already input recipient information, it is appended to the recipient information and a reminder is given. Another example is that if the communication information is instant messaging information, the user is reminded to designate the decryption authorized persons from the group members of the chat group.

[0078] In the first case, it can meet the requirement that only some people have the viewing permission in the scenario of multiple recipients. In the second case, it can meet the requirement that different recipients have the viewing permission for different attachments in the scenario of multiple recipients. For example, for the information issued by an enterprise, only department A has the reading permission for attachment A, and only department B has the reading permission for attachment B, realizing the differential management of the reading permission.

[0079] Here, the form of the recipient information is not specifically limited. For example, if the communication information is an email, the recipient's address is sent to the quantum cryptography service platform. If the communication information is instant messaging information, the recipient's account is sent to the quantum cryptography service platform.

[0080] In step S304, if quantum keys are generated for multiple attachment files, the corresponding relationships between the quantum keys and the multiple attachment files are also generated and sent to the sender terminal, and in step 306, the corresponding relationships are written into the encryption guide. By generating the corresponding relationships between each quantum key and the attachment file, it is convenient for the subsequent sender and recipient to confirm the corresponding relationships between the multiple quantum keys and the multiple attachment files.

[0081] In step 306, both the sender terminal and the receiver terminal are pre - set with multiple encryption algorithms, and each encryption algorithm is provided with a unique identification code. Specifically, multiple encryption algorithms can be pre - set in an email service or instant messaging software. In some embodiments, the encryption algorithm adopted for each attachment file is specified by the user. For example, after the user specifies the confidentiality level of the attachment file, the user is also reminded to specify the encryption algorithm to be adopted. As a specific implementation manner, in step S302, the sender terminal is also received for the encryption algorithm adopted for the attachment file to be encrypted, and the identification code of the adopted encryption algorithm is written into the encryption guidance. Since only the sender and the receiver know the index of the encryption algorithm, even if a third party intercepts the communication information, it is difficult to crack the encrypted part of the content.

[0082] As a specific form of the encryption guidance, the encryption guidance serves as the message header of the communication information to be sent, including an encryption content label and a key identification label. The number of the encryption content labels is the same as the number of attachment files to be encrypted. The key identification label includes the quantum key identification information of all attachment files to be encrypted; each encryption content label includes the serial number of the corresponding attachment file, the serial number corresponding to the adopted quantum key in the key identification label. If both the sender terminal and the receiver terminal are pre - set with multiple encryption algorithms, the encryption content label also includes the identification code of the encryption algorithm.

[0083] As an example, the message header can adopt the following form:

[0084] Encryption content label: [serial number of the attachment file, serial number corresponding to the adopted quantum key in the key identification label, identification code of the adopted encryption algorithm];

[0085] Key identification label: Quantum key identification message. For example:

[0086] X - attachmentEncrypt: [3,1,401]

[0087] X - attachmentEncrypt: [4,2,401]

[0088] X - attachmentEncrypt: [5,3,401]

[0089] X - group: 0a395b37400ea5f8,1f8bcb31d2d29ef4,0eed1a3fd437724f

[0090] It is indicated that the attachments numbered 3, 4, and 5 need to be encrypted, and quantum keys k1, k2, and k3 are respectively applied for. The encryption algorithm corresponding to the identification code 401 is the SM4-ECB algorithm. The content following the X-group tag is respectively the identification information of the quantum keys k1, k2, and k3.

[0091] The encryption guidance is used to indicate to the receiving party which attachment file is encrypted with which quantum key and which encryption algorithm is used, and to provide a path to obtain the quantum key. Based on this, the receiving party can decrypt the attachment file.

[0092] In some application scenarios, in step S304, if the decryptors of multiple attachment files are exactly the same, the same quantum key is generated for the multiple attachment files.

[0093] As an example, the communication information is an email, and there are 5 attachments in the email that need to be encrypted. Among them, the 1st, 3rd, and 5th attachments are for user A (a@quantum-info.com) to view, the 2nd and 4th attachments are for user B (b@quantum-info.com) to view, and the content of the email body and the remaining attachments are visible to all recipients. Then the sender s can apply to the quantum cryptography service platform p for 2 quantum keys. k1 is used to encrypt the 1st, 3rd, and 5th attachments, and k2 is used to encrypt the 2nd and 4th attachments. At the same time, when applying, report to the quantum cryptography service platform that the user who has the permission to apply for the quantum key k1 is user A (a@quantum-info.com), and the user who has the permission to apply for the quantum key k2 is user B (b@quantum-info.com).

[0094] Based on the above attachment file sending method, Figure 4 The overall flowchart of an attachment file receiving method is shown, including steps S401 - S403, specifically including the following steps:

[0095] S401: Receive communication information and encryption guidance, where the encryption guidance includes the identification information of one or more quantum keys used to encrypt the attachment files;

[0096] S402: In response to a viewing request for a certain encrypted attachment file, send the identification information of the quantum key used by the attachment file and the identity information of the receiving party's terminal to the quantum cryptography service platform;

[0097] S403: The quantum cryptography service platform searches for whether there is a corresponding key distribution record according to each piece of the identification information. If so, further determine whether there is a decryptor in the key distribution record that is consistent with the identity information of the receiving party's terminal. If so, obtain one or more quantum keys associated with the decryptor and send them to the receiving party's terminal;

[0098] S404: The receiving party terminal receives the quantum key and decrypts the attached file.

[0099] If there are multiple encrypted attached files, the encryption guidance further includes the correspondence between each attached file and the identification information of the quantum key used. If the receiving party terminal and the sending party terminal preset the same multiple encryption algorithms, the encryption guidance further includes the identification code of the encryption algorithm.

[0100] It can be understood that after the user receives the communication information, for the attached files therein, the user can choose to download them to the local for on-demand viewing, or can choose to view them online. If an online view is performed on a certain attached file, the attached file will be downloaded to the cache and then opened. Taking the opening of the encrypted attached file by the user as the timing of requesting the key, regardless of whether the encrypted attached file is downloaded to the local or not, the security before being opened can be guaranteed.

[0101] In response to the user's viewing request for a certain encrypted attached file, the receiving party terminal initiates a process of requesting the quantum key from the quantum cryptography service platform, and decrypts the attached file after obtaining the quantum key.

[0102] In step S402, if the key guidance further includes the correspondence between each encrypted attached file and the quantum key; in response to the viewing request for a certain encrypted attached file, determine the quantum key identification information of the encrypted attached file according to the correspondence.

[0103] In step S404, if the key guidance further includes the identification code of the encryption algorithm, also obtain the encryption algorithm used for this attached file. As described above, the encryption guidance includes the key identification tag and the encryption content tag for each encrypted attached file, and its specific form will not be elaborated here.

[0104] By specifying the decryption permission person for each attached file, the differential permission management of multiple attached files in the same communication information is realized, so that the encryption granularity can be finely controlled, with high flexibility, and can meet the customized encryption requirements of users.

[0105] As an example, the communication information is an email, and the information reported by the sender s to the quantum cryptography service platform p when applying for the quantum key is specifically: 1. The number of quantum keys applied for; 2. The length of each quantum key; 3. For each quantum key, the recipients who have the permission to apply for the key.

[0106] For example, reporting data in the following JSON format indicates an application for 3 quantum keys, each with a length of 16 bytes. Quantum key 1 only allows a@sina.com as the recipient to apply for this quantum key from the quantum key service platform; Quantum key 2 only allows b@163.com as the recipient to apply for this quantum key from the quantum key service platform: Quantum key 3 allows a@163.com, b@163.com, and c@sohu.com as recipients to apply.

[0107]

[0108] The quantum cryptography service platform p will record the reported information it receives, generate 3 quantum keys k1, k2, k3, and return them to the sender s together with the tags token1, token2, token3 corresponding to the 3 quantum keys. The quantum cryptography service platform p records the corresponding relationships between the three quantum keys, their tags, and the allowed recipients in the key information table it maintains:

[0109] k1 —— eb4511d6ae6646fd (token1) —— a@sina.com

[0110] k2 —— 83c43f6d9177b4b6 (token2) —— b@163.com

[0111] k3 —— ca93aa80bcab8ced (token3) —— a@sina.com, b@163.com, c@sohu.com

[0112] When the recipient r with the email account b@163.com applies to the quantum cryptography service platform for a quantum key, the information reported is: the number of quantum keys applied for, 2, the recipient's email account; 3, the identifier corresponding to the quantum key;

[0113] For example, reporting data in the following JSON format indicates that b@163.com is the recipient, applying for 2 quantum keys, and attaching the identifiers corresponding to these two quantum keys.

[0114]

[0115] After the quantum cryptography service platform p receives the application from the recipient r, it retrieves the data in the key information table, finds the allowed recipients based on the two tags described by keyToken, compares them with account, and after confirming that b@163.com described by account has the application permission for these two quantum keys, it distributes the quantum keys k2 and k3 corresponding to the two tags to the recipient r.

[0116] To prevent eavesdroppers from impersonating the recipient's identity to obtain communication information, for example, an eavesdropper illegally obtains the recipient's communication software login account through hacking. In some embodiments, the sender terminal and the quantum cryptography service platform both pre-store a first shared quantum key for encrypting and decrypting communication information between the two. The recipient terminal and the quantum cryptography service platform both pre-store a second shared quantum key for encrypting and decrypting communication information between the two.

[0117] More specifically, in step S303, the quantum cryptography service platform encrypts the generated quantum key with the first shared quantum key and then sends it to the sender terminal.

[0118] In step S403, the quantum cryptography service platform encrypts the found quantum key with the second shared quantum key and then sends it to the recipient terminal.

[0119] In this way, even if an eavesdropper illegally obtains the encryption guidance by cracking the communication software account, since it uses the shared key between the recipient terminal and the quantum cryptography service platform, the eavesdropper cannot crack it.

[0120] To further improve security, in some embodiments, the quantum cryptography service platform encrypts based on a part of the first shared quantum key or the second shared quantum key, denoted as a temporary key. When sending the encrypted information to the sender terminal or the recipient terminal, the position information of the temporary key in the first shared quantum key or the second shared quantum key is sent at the same time. Specifically, the part of the key can be a continuous segment of the first shared quantum key or the second shared quantum key, or a combination of multiple discontinuous segments of the key. As an example, the first shared quantum key or the second shared quantum key is a continuous segment of binary data. The 2048 - 2064th bytes can be intercepted for encryption, or multiple position intervals can be specified, such as the 600 - 1000th and 2504 - 2720th bytes spliced together for encryption.

[0121] Based on this, the temporary key used to encrypt the quantum key to be transmitted uses one-time pad encryption. Even if the recipient terminal is stolen, since it is not known how the previous key was used, the communication data before the theft is still secure. In addition, since each applied quantum key is encrypted and protected by different parts of the shared key, if only the position information of the key is eavesdropped during transmission, since the key itself is not transmitted, the communication data cannot be cracked.

[0122] As an example, as Figure 8 shown, the sender s and the recipient r respectively obtain the shared keys k ps and kpr . The sender s processes the email attachments to be sent, selects the attachments to be encrypted, such as the first attachment.

[0123] As shown in step ①, the sender s applies to the quantum cryptography service platform p for the quantum key required for encrypting this email, and at the same time informs the quantum cryptography service platform p of the recipient information.

[0124] As shown in step ②, after receiving the application, the quantum cryptography service platform p saves the application information, generates the quantum key k1, and uses the shared key k with the sender s ps to encrypt k1 to obtain k ps (k1), and as shown in step ②, sends k ps (k1) and the quantum key identifier token1 corresponding to k1 to the sender s.

[0125] The sender s receives token1 and k ps (k1), and uses the shared key k with the quantum cryptography service platform p ps to decrypt k ps (k1) to obtain the quantum key k1.

[0126] The sender s uses the quantum key k1 to encrypt the first attachment to generate the ciphertext file of the first attachment.

[0127] The sender adds the following information to the email header:

[0128] X-attachmentEncrypt:[1,1,401]

[0129] X-group:0a395b37400ea5f8

[0130] Explanation: The content after the X-attachmentEncrypt label is [attachment serial number, key selection, encryption algorithm code]. It means that the first attachment is encrypted using the first quantum key, and the encryption algorithm is the ECB encryption mode of the SM4 algorithm (here, the definition of the national cryptography standard GM / T 0006-2012 is used, and 401 refers to SM4-ECB).

[0131] The content after the X-group label is the quantum key identifier, that is, the content of token1. It is a string composed of hexadecimal digital symbols, randomly generated by the quantum cryptography service platform p, and each quantum key identifier is unique.

[0132] As shown in step ③, the sender s sends the processed email (including at least the email header and all attachments) to the mail server.

[0133] As shown in step ④, the recipient r pulls the email from the mail server to the local.

[0134] The recipient r reads the key selection, quantum key identifier, encryption range (attachment serial number), and encryption algorithm code information in the email header. As shown in step ⑤, the recipient r sends the quantum key identifier token1 (content: 0a395b37400ea5f8) indicated by the X-group tag to the quantum cryptography service platform p to apply for the corresponding quantum key k1.

[0135] After receiving the application, the quantum cryptography service platform p first checks whether the applicant is the legitimate recipient reported by the sender s in step 3. If so, as shown in step ⑥, the quantum cryptography service platform p encrypts the quantum key k1 using the shared key k between the platform p and the recipient r pr to obtain k pr (k1), and as shown in step ⑤, sends k pr (k1) to the recipient r.

[0136] The recipient r decrypts k pr using the shared key k between the recipient r and the quantum cryptography service platform p pr for (k1) to obtain the quantum key k1.

[0137] The recipient uses the first quantum key k1 to decrypt the first attachment of the email using the SM4-ECB algorithm to obtain the attachment plaintext file, replacing the attachment ciphertext file at the same position, and the decryption process ends.

[0138] According to the above technical solution, for different users' different confidentiality requirements for attachment files, differential permission control of multiple attachments in the same communication information can be achieved. The differentiation is reflected in the following aspects: (1) Encryption can be performed only on specified attachments among multiple attachments; (2) Among multiple attachments, quantum keys with different confidentiality levels can be used for encryption; (3) Among the encrypted multiple attachments, the specified recipients with permission to decrypt each attachment can be different.

[0139] Figure 5 Disclosed is a method for sending an attachment file based on a quantum key according to one or more embodiments of the present invention. The method is applied to a sender terminal and includes the following steps:

[0140] S501: Receive the communication information to be sent, where the communication information includes one or more attachment files;

[0141] S502: Receive the designation of one or more attachment files to be encrypted, and receive the designation of one or more decryption permission holders for one or more of the attachment files to be encrypted;

[0142] S503: Generate a key application and send it to the quantum cryptography service platform. The key application includes the amount of quantum key required for each attachment file to be encrypted and the information of the decryptor.

[0143] S504: Obtain the quantum keys generated for each attachment file to be encrypted and the identification information of the quantum keys from the quantum cryptography service platform.

[0144] S505: In response to the information sending confirmation instruction, encrypt each attachment file to be encrypted with the corresponding quantum key, generate an encryption guide, and send the communication information and the encryption guide. The encryption guide includes the quantum key identification information corresponding to each attachment file, so that the receiving party terminal can perform identity authentication based on the specified recipient information, and obtain the quantum key from the quantum cryptography service platform based on the identification information after the identity authentication passes.

[0145] In step S503, according to different confidentiality levels, if the confidentiality level is very high, the amount of quantum key required for the attachment file to be encrypted is the same as the size of the attachment file. If the confidentiality level is average, the amount of quantum key required for the attachment file to be encrypted is a set value.

[0146] The confidentiality level is specified by the user. Based on the specified confidentiality level, the required amount of key is determined. Specifically, after receiving the specification of one or more attachment files to be encrypted, the confidentiality level of each attachment file to be encrypted is also received. According to the confidentiality level of each attachment file to be encrypted, the required amount of quantum key is determined and sent to the quantum cryptography service platform. The amount of quantum key required for the attachment file with the highest confidentiality level is the same as the size of the attachment file. The amount of quantum key required for the attachment file with a lower confidentiality level is a set value.

[0147] In step S502, multiple encryption algorithms are preset in the sending party terminal. After receiving the specification of one or more attachment files to be encrypted, the encryption algorithm used for each attachment is also received. In step S505, when encrypting the attachment file to be encrypted, the identification code of the encryption algorithm is written into the key guide.

[0148] In step S504, if multiple attachment files to be encrypted are specified, the corresponding relationship between each quantum key and the attachment file is also obtained from the quantum cryptography service platform. In step S505, when encrypting the attachment file to be encrypted, the corresponding relationship is written into the key guide.

[0149] The encryption guidance includes a key identification label and an encrypted content label corresponding to each encrypted attachment. The key identification label includes the quantum key identification information of all encrypted attachment files. The encrypted content label includes the serial number of the attachment file and the corresponding serial number of the quantum key used in the key identification label, or the serial number of the attachment file, the corresponding serial number of the quantum key used in the key identification label, and the identification code of the encryption algorithm used.

[0150] To ensure the security during the transmission of quantum keys, the sending party terminal pre-stores a first shared quantum key with the quantum cryptography service platform. What is obtained from the quantum cryptography service platform is a quantum key encrypted by the first shared quantum key, and the quantum key is obtained by decryption.

[0151] More specifically, a quantum key encrypted by a temporary key and the position information of the temporary key in the first shared quantum key are obtained from the quantum cryptography service platform; the temporary key is obtained according to the position information of the temporary key and the first shared quantum key, and the quantum key is obtained by decryption.

[0152] Figure 6 A method for receiving an attachment file based on a quantum key provided by one or more embodiments of the present invention is shown. The method is applied to a receiving party terminal and includes the following steps:

[0153] S601: Receive communication information and encryption guidance. The encryption guidance includes the identification information of the quantum key used for one or more encrypted attachment files;

[0154] S602: In response to a viewing request for a certain encrypted attachment file, send the identification information of the quantum key used for the attachment file and the identity information of the receiving party terminal to the quantum cryptography service platform;

[0155] S603: After the quantum cryptography service platform authenticates the identity information, obtain the quantum key found based on the identification information; the quantum cryptography service platform pre-stores the quantum key corresponding to the encrypted attachment file and its identification information, as well as the information of the designated decryption permission person;

[0156] S604: Decrypt the encrypted attachment file.

[0157] In step S601, the key guidance further includes the correspondence between each encrypted attachment file and the quantum key; in step S602, in response to a viewing request for a certain encrypted attachment file, determine the quantum key identification information of the encrypted attachment file according to the correspondence.

[0158] In step S601, the key guidance further includes an identification code of the encryption algorithm used for each encrypted attachment file; in step S604, when decrypting, the encryption algorithm used for each encrypted attachment file is obtained according to the identification code.

[0159] To ensure the security during the quantum key transmission, a second shared quantum key with the quantum cryptography service platform is pre-stored, and the quantum key obtained from the quantum cryptography service platform is encrypted by the second shared quantum key, and the quantum key is obtained by decryption.

[0160] More specifically, a quantum key encrypted by a temporary key and the position information of the temporary key in the second shared quantum key are obtained from the quantum cryptography service platform; the temporary key is obtained according to the position information of the temporary key and the second shared quantum key, and the quantum key is obtained by decryption.

[0161] Figure 7 A key distribution method is shown. The method is applied to a quantum cryptography service platform and includes the following steps:

[0162] S701: Receive a key application sent by a sender terminal. The key application includes the amount of quantum key required for one or more attachment files to be encrypted and one or more decryptors designated for one or more of the attachment files to be encrypted.

[0163] S702: For each of the attachment files to be encrypted, generate a quantum key and the identification information of the quantum key, and associate and store the quantum key, its identification information, and the corresponding decryptor to obtain the current key distribution record.

[0164] S703: Send the quantum key and its identification information to the sender terminal.

[0165] In step S702, if multiple attachment files to be encrypted are specified, while generating quantum keys for the multiple attachment files to be encrypted, the corresponding relationships between the respective quantum keys and the attachment files are also generated.

[0166] To ensure the security during the quantum key transmission, the quantum cryptography service platform pre-stores a first shared quantum key with the sender terminal, and encrypts the generated quantum key based on the first shared quantum key and then sends it to the sender terminal.

[0167] More specifically, generate a temporary key based on part of the first shared quantum key, and record the position information of the temporary key in the first shared quantum key; encrypt the generated quantum key based on the temporary key, and send the encrypted quantum key and the position information of the temporary key to the sender terminal.

[0168] To achieve the distribution of quantum keys to the recipient, the method further includes:

[0169] S704: Receive the identification information of one or more quantum keys sent by the recipient terminal, and the identity information of the recipient terminal;

[0170] S705: According to each of the identification information, check whether there is a corresponding key distribution record. If there is, further execute step S706. If not, return an error reminder for the identification information;

[0171] S706: Determine whether there is a decryption authority person in the key distribution record who is consistent with the identity information of the recipient terminal. If there is, obtain one or more quantum keys associated with the decryption authority person and send them to the recipient terminal. If not, the identity authentication fails.

[0172] The quantum cryptography service platform prestores a second shared quantum key with the recipient terminal, and encrypts the found quantum key based on the second shared key and then sends it to the recipient terminal.

[0173] More specifically, generate a temporary key based on a part of the second shared quantum key, and record the position information of the temporary key in the second shared quantum key; encrypt the found quantum key based on the temporary key, and send the encrypted quantum key and the position information of the temporary key to the recipient terminal.

[0174] One or more embodiments of the present invention also provide a communication device, which can be used to implement the methods executed by the sender terminal, the recipient terminal, and the quantum cryptography service platform in the above embodiments. The electronic device includes one or more processors, one or more memories coupled to the processor, and a communication module coupled to the processor.

[0175] The memory may include one or more non-volatile memories and one or more volatile memories. Examples of non-volatile memories include, but are not limited to, at least one of the following: Read-Only Memory (ROM), Erasable Programmable Read Only Memory (EPROM), flash memory, hard disk, Compact Disc (CD), Digital Versatile Disc (DVD), or other magnetic storage and / or optical storage. Examples of volatile memories include, but are not limited to, at least one of the following: Random Access Memory (RAM), or other volatile memories that do not persist during a power outage duration. The computer program may be stored in the ROM. When the processor executes the computer program, it implements any one of the above-mentioned attachment file sending method, attachment file receiving method, and key distribution method.

[0176] In some embodiments, the program may be tangibly embodied in a computer-readable medium, which may be included in the device (such as in the memory) or other storage devices accessible by the device. The program can be loaded from the computer-readable medium into the RAM for execution. The computer-readable medium may include any type of tangible non-volatile memory, such as ROM, EPROM, flash memory, hard disk. The computer-readable storage medium stores a computer program, and when the computer program is executed by the processor, it implements any one of the above-mentioned attachment file sending method, attachment file receiving method, and key distribution method.

[0177] One or more embodiments of the present invention also provide an attachment file transmission system, including a sender terminal, a receiver terminal, and a quantum cryptography service platform.

[0178] Various embodiments of the present invention may be implemented in hardware or special-purpose circuits, software, logic, or any combination thereof. Some aspects may be implemented in hardware, while other aspects may be implemented in firmware or software, which may be executed by a controller, microprocessor, or other computing device. Although various aspects of the embodiments of the present disclosure are shown and described as block diagrams, flowcharts, or using some other graphical representation, it should be understood that the blocks, devices, systems, techniques, or methods described herein may be implemented as, by way of non-limiting example, hardware, software, firmware, special-purpose circuits or logic, general-purpose hardware or controllers or other computing devices, or some combination thereof.

[0179] Although the operations of the method of the present invention are depicted in a specific order in the accompanying drawings, this is not a requirement or implication that these operations must be performed in that specific order, or that all of the shown operations must be performed to achieve the desired result. On the contrary, the steps depicted in the flowchart may be changed in their order of execution. Additionally or alternatively, some steps may be omitted, multiple steps may be combined into one step for execution, and / or one step may be decomposed into multiple steps for execution. It should also be noted that the features and functions of two or more devices according to the present disclosure may be embodied in one device. Conversely, the features and functions of one device described above may be further divided and embodied by multiple devices.

Claims

1. An attachment file sending method, applied to a sender terminal, characterized in that, It includes the following steps: Receive the communication information to be sent, where the communication information includes one or more attachment files; Receive the designation of one or more attachment files to be encrypted, and receive the designation of one or more decryption authorities for the one or more attachment files to be encrypted; Generate a key application and send it to the quantum cryptography service platform, where the key application includes the amount of quantum key required for each attachment file to be encrypted and the decryption authority information; Obtain from the quantum cryptography service platform the quantum key generated for each attachment file to be encrypted and the identification information of the quantum key; In response to the information sending confirmation instruction, encrypt each attachment file to be encrypted with the corresponding quantum key, and generate an encryption guide, and send the communication information and the encryption guide, where the encryption guide includes the quantum key identification information corresponding to each attachment file; So that the receiving party terminal can perform identity authentication based on the designated receiving party information, and obtain the quantum key from the quantum cryptography service platform based on the identification information after the identity authentication is passed.

2. The attachment file sending method according to claim 1, characterized in that The amount of quantum key required for the attachment file to be encrypted is the same as the size of the attachment file or a set value.

3. The attachment file sending method according to claim 1, wherein After receiving the designation of one or more attachment files to be encrypted, also receive the confidentiality level of each attachment file to be encrypted, and determine the required amount of quantum key according to the confidentiality level of each attachment file to be encrypted; the amount of quantum key required for the attachment file with the highest confidentiality level is the same as the size of the attachment file; the amount of quantum key required for the attachment file with a lower confidentiality level is a set value.

4. The attachment file sending method according to claim 1, characterized in that, If multiple attachment files to be encrypted are designated, also obtain from the quantum cryptography service platform the correspondence between each quantum key and the attachment file, and write the correspondence into the key guide when encrypting the attachment file to be encrypted.

5. The attachment file sending method according to claim 1, characterized in that, Pre-set multiple encryption algorithms. When encrypting each attachment file to be encrypted, after receiving the designation of one or more attachment files to be encrypted, also receive the designation of the encryption algorithm used for each attachment file to be encrypted; when encrypting the attachment file to be encrypted, write the identification code of the encryption algorithm into the key guide.

6. The attachment file sending method according to claim 4 or 5, characterized in that The encryption guide includes a key identification label and an encrypted content label corresponding to each encrypted attachment. The key identification label includes the quantum key identification information of all encrypted attachment files. The encrypted content label includes the serial number of the attachment file and the serial number corresponding to the quantum key used in the key identification label, or, the serial number of the attachment file, the serial number corresponding to the quantum key used in the key identification label, and the identification code of the encryption algorithm used.

7. The attachment file sending method according to any one of claims 1-5, characterized in that Pre-store the first shared quantum key with the quantum cryptography service platform. What is obtained from the quantum cryptography service platform is the quantum key encrypted by the first shared quantum key, and decrypt to obtain the quantum key.

8. The attachment file sending method according to claim 7, wherein Obtain from the quantum cryptography service platform the quantum key encrypted by the temporary key and the position information of the temporary key in the first shared quantum key; according to the position information of the temporary key and the first shared quantum key, obtain the temporary key and decrypt to obtain the quantum key.

9. An accessory file receiving method, applied to a receiving party terminal, characterized in that It includes the following steps: Receive communication information and encryption guidelines, where the encryption guidelines include identification information of quantum keys used for one or more encrypted attachment files; In response to a viewing request for a certain encrypted attachment file, send the identification information of the quantum key used for the attachment file and the identity information of the receiving party's terminal to the quantum cryptography service platform; After the quantum cryptography service platform authenticates the identity information, obtain the quantum key found based on the identification information; the quantum cryptography service platform pre-stores the quantum key corresponding to the encrypted attachment file and its identification information, as well as the information of the designated decryption authority; Decrypt the encrypted attachment file.

10. The attachment file receiving method according to claim 9, wherein, The key guidelines further include the correspondence between each encrypted attachment file and the quantum key; in response to a viewing request for a certain encrypted attachment file, determine the quantum key identification information of the encrypted attachment file according to the correspondence.

11. The attachment file receiving method according to claim 9, wherein The key guidelines further include the identification code of the encryption algorithm used for each encrypted attachment file; obtain the encryption algorithm used for each encrypted attachment file according to the identification code during decryption.

12. The attachment file receiving method according to any one of claims 9-11, characterized in that, Pre-store the second shared quantum key with the quantum cryptography service platform. The quantum key obtained from the quantum cryptography service platform is encrypted via the second shared quantum key, and decrypt to obtain the quantum key.

13. The accessory file receiving method according to claim 12, wherein Obtain the quantum key encrypted via the temporary key from the quantum cryptography service platform, and the position information of the temporary key in the second shared quantum key; obtain the temporary key according to the position information of the temporary key and the second shared quantum key, and decrypt to obtain the quantum key.

14. A key distribution method, applied to a quantum cryptography service platform, characterized in that, Include the following steps: Receive a key application sent by the sending party's terminal. The key application includes the amount of quantum key required for each of one or more attachment files to be encrypted, and one or more decryption authorities designated for one or more of the attachment files to be encrypted; Generate a quantum key and its identification information for each of the attachment files to be encrypted, associate and store the quantum key, its identification information, and the corresponding decryption authority to obtain the current key distribution record; Send the quantum key and its identification information to the sending party's terminal.

15. The key distribution method according to claim 14, wherein, If multiple attachment files to be encrypted are specified, while generating quantum keys for the multiple attachment files to be encrypted, also generate the correspondence between each quantum key and the attachment file, and send it to the sending party's terminal.

16. The key distribution method according to any one of claims 14-15, characterized in that, Pre-store the first shared quantum key with the sending party's terminal, and encrypt the generated quantum key based on the first shared quantum key and then send it to the sending party's terminal.

17. The key distribution method according to claim 16, wherein Generate a temporary key based on part of the first shared quantum key, and record the position information of the temporary key in the first shared quantum key; encrypt the generated quantum key based on the temporary key, and send the encrypted quantum key and the position information of the temporary key to the sending party's terminal.

18. The key distribution method according to any one of claims 14 - 15, characterized in that Receive the identification information of one or more quantum keys sent by the receiving party's terminal, and the identity information of the receiving party's terminal; According to each of the said identification information, search for whether there is a corresponding key distribution record. If there is, further determine whether there is a decryption authority person in the key distribution record whose identity information is consistent with that of the receiving party terminal. If there is, obtain one or more quantum keys associated with the decryption authority person and send them to the receiving party terminal.

19. The key distribution method according to claim 18, wherein Pre-store the second shared quantum key with the receiving party terminal, and encrypt the found quantum key based on the second shared key and then send it to the receiving party terminal.

20. The key distribution method according to claim 19, wherein Generate a temporary key based on part of the second shared quantum key, and record the position information of the temporary key in the second shared quantum key; encrypt the found quantum key based on the temporary key, and send the encrypted quantum key and the position information of the temporary key to the receiving party terminal.

21. A communication device, characterized in that, The communication device includes one or more processors; and a memory; wherein, one or more computer programs are stored in the memory, and the one or more computer programs include instructions that, when executed by the communication device, cause the communication device to execute the method according to any one of claims 1-20.

22. A computer-readable storage medium storing instructions therein, characterized in that, When the instructions run on the communication device, cause the communication device to execute the method according to any one of claims 1-20.

23. An attachment file transfer system, characterized in that, It includes a sending party terminal, a receiving party terminal, and a quantum cryptography service platform, which are respectively configured to execute the attachment file sending method according to any one of claims 1-8, the attachment file receiving method according to any one of claims 9-13, and the key distribution method according to any one of claims 14-20.