File encryption authorization distribution method, device, computer equipment and readable storage medium based on IPFS and quantum key distribution
Through the dual-channel architecture of IPFS and quantum key distribution, the problems of insufficient security and resource waste of traditional file encryption methods under the threat of quantum computing are solved, and safe and efficient file encryption authorization distribution is achieved.
Patent Information
- Application Number
- CN202510392863.6
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2025-03-31
- Publication Date
- 2025-09-26
- Estimated Expiration
- 2045-03-31
AI Technical Summary
Traditional file encryption methods are not secure enough in the face of quantum computing threats, and there is serious waste of resources in multi-user scenarios. The IPFS network lacks a secure authorization mechanism.
A dual-channel architecture based on IPFS and quantum key distribution is adopted. Files are encrypted with symmetric keys and stored on the IPFS network to generate a unique identifier for the IPFS file. The QKD network is used to generate a quantum key shared by the file sender and receiver. The key and identifier are encrypted and the key information is transmitted only through the QKD channel. The receiver uses the quantum key to decrypt and obtain the file.
It improves the security of file transfer and resource utilization efficiency in multi-user scenarios, reduces storage and network burdens, and ensures the security of authorization key distribution.
Smart Images

Figure CN120320983B_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the field of file encryption processing, and in particular to a file encryption authorization distribution method, device, computer equipment and readable storage medium based on IPFS and quantum key distribution. Background Art
[0002] With the advancement of digitalization, the security of file transfer and authorized distribution has become increasingly important. Traditional methods often use asymmetric key pairs to encrypt data and distribute authorization keys, which poses the risk of being cracked by technologies such as quantum computing. In multi-user scenarios, files must be repeatedly encrypted, wasting storage and network resources. While IPFS, as a distributed storage network, provides efficient storage, it lacks a secure authorization mechanism. Summary of the Invention
[0003] The purpose of the present invention is to provide a file encryption authorization distribution method, device, computer equipment and readable storage medium based on IPFS and quantum key distribution.
[0004] In a first aspect, an embodiment of the present invention provides a file encryption authorization distribution method based on IPFS and quantum key distribution, which is applied to a file sending end of a file encryption authorization distribution system based on IPFS and quantum key distribution. The file encryption authorization distribution system based on IPFS and quantum key distribution also includes a file receiving end, including:
[0005] The original file is encrypted using a symmetric key to obtain an encrypted file, and the encrypted file is stored in the IPFS network. After the encrypted file is stored in the IPFS network, a corresponding IPFS file unique identifier is generated;
[0006] If the file sender is authorized, generating a common QKD quantum key for the file sender and the file receiver based on the QKD network, so that the file sender and the file receiver can capture the QKD quantum key at the same time;
[0007] The QKD quantum key is used to encrypt the symmetric key and the IPFS file unique identifier stored in the IPFS network, and the encrypted symmetric key and IPFS file unique identifier are sent to the file receiving end, so that the file receiving end uses the QKD quantum key to decrypt the encrypted symmetric key and IPFS file unique identifier, and downloads the encrypted file from the IPFS network based on the decryption result to obtain the original file.
[0008] In a possible implementation, when the file sending end is authorized, generating a common QKD quantum key between the file sending end and the file receiving end based on a QKD network so that the file sending end and the file receiving end simultaneously capture the QKD quantum key includes:
[0009] When the file sending end and the file receiving end monitor the QKD network simultaneously and the file sending end is authorized, generating a random key based on the QKD network;
[0010] The random key is used as the QKD quantum key, so that the file sending end and the file receiving end can capture the QKD quantum key at the same time.
[0011] In one possible implementation, the method for generating the symmetric key includes:
[0012] Generates a symmetric key that meets the preset standards through a preset key algorithm.
[0013] In one possible implementation, the using the QKD quantum key to encrypt the symmetric key and the IPFS file unique identifier stored in the IPFS network includes:
[0014] The symmetric key is split into n key shards, and each shard and the IPFS file identifier are quantum one-time pad encrypted using the QKD quantum key.
[0015] In a possible implementation manner, before the file sending end approves the authorization, the method further includes:
[0016] In one possible implementation, the method further includes:
[0017] Set a valid timestamp for each generated QKD quantum key, which contains the UTC standard time and the quantum clock synchronization signal;
[0018] When the file receiving end fails to complete the file authorization download within the preset time, the QKD network is automatically triggered to regenerate a new quantum key and resend the authorization.
[0019] In a second aspect, an embodiment of the present invention provides a file encryption authorization distribution method based on IPFS and quantum key distribution, which is applied to a file receiving end of a file encryption authorization distribution system based on IPFS and quantum key distribution, wherein the file encryption authorization distribution system based on IPFS and quantum key distribution also includes a file sending end. The method includes:
[0020] If the file sender is authorized, generating a common QKD quantum key for the file sender and the file receiver based on the QKD network, so that the file sender and the file receiver can capture the QKD quantum key at the same time;
[0021] Receive the symmetric key encrypted based on the QKD quantum key and the IPFS file unique identifier sent by the file sending end; the IPFS file unique identifier is the IPFS file unique identifier corresponding to the encrypted file obtained by the file sending end after encrypting the original file based on the symmetric key and storing it in the IPFS network;
[0022] Decrypt the encrypted symmetric key and the unique identifier of the IPFS file using the QKD quantum key to obtain the symmetric key and the unique identifier of the IPFS file;
[0023] The file receiving end downloads the encrypted file in the IPFS network through the IPFS file unique identifier, and uses the symmetric key to decrypt the encrypted file to obtain the original file.
[0024] In a third aspect, an embodiment of the present invention provides a file encryption authorization distribution device based on IPFS and quantum key distribution, which is applied to a file sending end of a file encryption authorization distribution system based on IPFS and quantum key distribution. The file encryption authorization distribution system based on IPFS and quantum key distribution also includes a file receiving end, including:
[0025] An encryption module is configured to encrypt the original file using a symmetric key to obtain an encrypted file, and store the encrypted file on the IPFS network; upon authorization by the file sender, generate a common QKD quantum key for the file sender and the file receiver based on the QKD network, so that the file sender and the file receiver can capture the QKD quantum key at the same time;
[0026] The distribution module is used to use the QKD quantum key to encrypt the symmetric key and the IPFS file unique identifier stored in the IPFS network, and send the encrypted symmetric key and IPFS file unique identifier to the file receiving end, so that the file receiving end uses the QKD quantum key to decrypt the encrypted symmetric key and IPFS file unique identifier, and download the encrypted file from the IPFS network based on the decryption result to obtain the original file.
[0027] In a fourth aspect, an embodiment of the present invention provides a file encryption authorization distribution device based on IPFS and quantum key distribution, which is applied to a file receiving end of a file encryption authorization distribution system based on IPFS and quantum key distribution, wherein the file encryption authorization distribution system based on IPFS and quantum key distribution also includes a file sending end, and the method includes:
[0028] an encryption module, configured to generate, based on a QKD network, a common QKD quantum key for the file sending end and the file receiving end, if the file sending end is authorized, so that the file sending end and the file receiving end can capture the QKD quantum key at the same time;
[0029] The receiving module is used to receive the symmetric key and IPFS file unique identifier sent by the file sending end after encryption based on the QKD quantum key; the IPFS file unique identifier is the IPFS file unique identifier corresponding to the encrypted file obtained by the file sending end after encrypting the original file based on the symmetric key and storing it in the IPFS network; use the QKD quantum key to decrypt the encrypted symmetric key and IPFS file unique identifier to obtain the symmetric key and the IPFS file unique identifier; the file receiving end downloads the encrypted file in the IPFS network through the IPFS file unique identifier, and uses the symmetric key to decrypt the encrypted file to obtain the original file.
[0030] In a fifth aspect, an embodiment of the present invention provides a computer device, comprising a processor and a non-volatile memory storing computer instructions, wherein when the computer instructions are executed by the processor, the computer device executes the method described in the first aspect or the second aspect.
[0031] In a sixth aspect, an embodiment of the present invention provides a readable storage medium, wherein the readable storage medium includes a computer program, and when the computer program is running, the computer device where the readable storage medium is located is controlled to execute the method described in the first aspect or the second aspect.
[0032] Compared to existing technologies, the present invention offers the following advantages: A file encryption authorization distribution method, apparatus, computer device, and readable storage medium based on IPFS and quantum key distribution, disclosed herein, includes: the sending end first encrypts the original file with a symmetric key and stores it on the IPFS network; after authorization is approved, a shared QKD quantum key is generated with the receiving end using the QKD network; the symmetric key and the unique IPFS file identifier are then encrypted with this quantum key and sent to the receiving end. The receiving end then uses the quantum key to decrypt the file, downloading it from the IPFS network and decrypting it to obtain the original file. This design separates file transmission from authorized distribution, conserving resources, improving efficiency in multi-user scenarios, and ensuring the security of authorized key distribution. BRIEF DESCRIPTION OF THE DRAWINGS
[0033] To more clearly illustrate the technical solutions of the embodiments of the present invention, the following briefly describes the drawings required for use in the embodiments. It should be understood that the following drawings illustrate only certain embodiments of the present invention and should not be construed as limiting the scope of the present invention. Those skilled in the art can, without inventive effort, derive other relevant drawings from these drawings.
[0034] Figure 1 A schematic diagram of the steps of the file encryption authorization distribution method based on IPFS and quantum key distribution provided in an embodiment of the present invention;
[0035] Figure 2 Schematic diagram of the dual-channel framework of IPFS and quantum key distribution provided by an embodiment of the present invention;
[0036] Figure 3 A schematic block diagram of the structure of a file encryption authorization distribution device based on IPFS and quantum key distribution provided by an embodiment of the present invention;
[0037] Figure 4 A schematic block diagram of the structure of a computer device provided in an embodiment of the present invention. DETAILED DESCRIPTION
[0038] To make the objectives, technical solutions, and advantages of the embodiments of the present invention more apparent, the technical solutions of the embodiments of the present invention will be described clearly and completely below in conjunction with the accompanying drawings of the embodiments of the present invention. It should be understood that the described embodiments are only a portion of the embodiments of the present invention, not all of them. Generally, the components of the embodiments of the present invention described and illustrated in the drawings herein may be arranged and designed in a variety of different configurations.
[0039] The specific embodiments of the present invention are described in detail below with reference to the accompanying drawings.
[0040] In order to solve the technical problems in the above background technology, Figure 1 A flow chart of a file encryption authorization distribution method based on IPFS and quantum key distribution is provided for an embodiment of the present disclosure. The method is applied to the file sending end of a file encryption authorization distribution system based on IPFS and quantum key distribution. The file encryption authorization distribution system based on IPFS and quantum key distribution also includes a file receiving end. The file encryption authorization distribution method based on IPFS and quantum key distribution is introduced in detail below.
[0041] Step S201: Encrypt the original file using a symmetric key to obtain an encrypted file, and store the encrypted file in the IPFS network. After the encrypted file is stored in the IPFS network, a corresponding IPFS file unique identifier will be generated;
[0042] Step S202: If the file sender is authorized, a QKD quantum key common to the file sender and the file receiver is generated based on the QKD network, so that the file sender and the file receiver can capture the QKD quantum key at the same time;
[0043] Step S203: Use the QKD quantum key to encrypt the symmetric key and the IPFS file unique identifier stored in the IPFS network, and send the encrypted symmetric key and IPFS file unique identifier to the file receiving end, so that the file receiving end uses the QKD quantum key to decrypt the encrypted symmetric key and IPFS file unique identifier, and downloads the encrypted file from the IPFS network based on the decryption result to obtain the original file.
[0044] In an embodiment of the present invention, for example, a file encryption authorization distribution system based on IPFS and quantum key distribution is mainly composed of a file sender and a file receiver. The file sender is responsible for encrypting the original file and storing it on the IPFS network. After authorization is passed, it generates a common QKD quantum key with the file receiver through the QKD network, encrypts the symmetric key and the IPFS file unique identifier, and sends it to the file receiver. The file receiver uses the received QKD quantum key to decrypt the relevant information, downloads and decrypts the file from the IPFS network, and obtains the original file content.
[0045] Assume that the R&D department of a group's Beijing branch (as the file sender) has an important new product development report containing detailed technical plans, design drawings and other sensitive information, which needs to be securely distributed to the sales department of the Shanghai branch (as the file receiver).
[0046] The Beijing branch's R&D department node uses the system-provided encryption tools and selects a symmetric encryption algorithm (such as SM4). The key is generated and stored only on the department manager's local device and is not transmitted over the network. The department manager imports the original new product development report into the system, and the system's encryption tool uses the generated symmetric key to perform a byte-by-byte conversion of the file's contents. For example, for each data block in the file, the SM4 algorithm performs complex mathematical operations based on the symmetric key, converting the original data into ciphertext. After encryption, the original file becomes an encrypted file, making the file's contents inaccessible. Even if illegally obtained, its true meaning remains incomprehensible.
[0047] After encryption is complete, the department administrator clicks the upload button in the system to upload the encrypted file to the IPFS network. During the upload process, the IPFS network will generate a unique identifier for the encrypted file (IPFS file unique identifier), which is actually a hash value. This identifier is generated based on the content of the file and will not change as long as the file content remains unchanged. For example, the IPFS network may store encrypted files on different nodes such as nodes A, B, and C, while recording these storage locations and the unique identifiers of the files. After the department administrator's device uploads the encrypted file to the IPFS network, it will receive the IPFS file unique identifier returned by the IPFS network. The department administrator will record this identifier and will use it for authorized distribution later.
[0048] Assuming that a complete QKD network has been established within the group, the R&D department of the Beijing branch and the sales department of the Shanghai branch are equipped with corresponding QKD node equipment.
[0049] Before initiating QKD quantum key generation, the system will verify the authorization of the file sender (the R&D department of the Beijing branch). For example, the group may have set up a strict authority management mechanism, and only specific departments can perform authorized file distribution operations after obtaining corresponding approvals. The department administrator of the R&D department of the Beijing branch submits an authorization request in the system, and the system will query the authority database to verify the identity and authority of the department administrator. If the department administrator has authorization authority and the authorization request is approved by the relevant leader, the system will allow subsequent operations to proceed; if the authorization is not passed, the system will prompt an error message to prevent the operation from being carried out.
[0050] Once authorization is granted, the QKD node in the R&D department of the Beijing branch initiates a communication request with the QKD node in the sales department of the Shanghai branch. The two QKD nodes simultaneously monitor the quantum channel and, leveraging properties of quantum mechanics such as quantum entanglement and quantum superposition, generate a random QKD quantum key between the two nodes. For example, the quantum channel may emit a series of quantum photons, and the QKD nodes at both the transmitting and receiving ends simultaneously measure the states of these photons. Due to the uncertainty and non-cloning properties of quantum states, a third party cannot obtain the key information without interfering with the quantum state. After a series of measurements and negotiation, the two QKD nodes simultaneously capture the same QKD quantum key, which is used for subsequent encryption operations.
[0051] After the department administrator of the R&D department of the Beijing branch obtains the QKD quantum key, the system automatically uses the quantum key to encrypt the previously generated symmetric key and the recorded IPFS file unique identifier. The encryption process also uses a specific encryption algorithm to convert the symmetric key and IPFS file unique identifier into ciphertext. For example, the system uses the SM4 algorithm (this is just an example of encryption method, and other algorithms may be selected based on system design), inputs the symmetric key and IPFS file unique identifier as plaintext, and uses the QKD quantum key as the encryption key to generate the encrypted symmetric key and IPFS file unique identifier ciphertext.
[0052] By separating encrypted files from keys and adopting a dual-channel distribution architecture, security is ensured. Encrypted files are transmitted via the IPFS channel, from the Beijing branch's R&D department's IPFS node to the Shanghai branch's sales department's IPFS node. The encrypted symmetric key and IPFS file's unique identifier are transmitted via the QKD channel, from the Beijing branch's R&D department's QKD node to the Shanghai branch's sales department's QKD node. The authorization process requires only a small amount of key data to be transmitted via QKD, reducing the I / O burden on the IPFS network while ensuring data security. Because the IPFS network only transmits encrypted files, while sensitive key information is transmitted via the quantum mechanical principles of QKD, leveraging the uncertainty and unclonability of quantum states, it is difficult for third parties to steal the key. Even if the encrypted file is intercepted during transmission on the IPFS network, it cannot be decrypted without the correct key, significantly enhancing data security.
[0053] The Shanghai branch's sales department's equipment (equipped with the appropriate receiving software and QKD node) receives the encrypted symmetric key and unique IPFS file identifier sent by the Beijing branch's R&D department over the network. The receiving software verifies the received data, checking its integrity and the legitimacy of its source. For example, the receiving software might check the packet's checksum to ensure that no errors occurred during transmission; it also verifies the sender's identity to ensure that the data originated from the legitimate file sender (the Beijing branch's R&D department).
[0054] The QKD node device in the Shanghai branch's sales department already stores the QKD quantum key generated jointly with the Beijing branch's R&D department. The department administrator uses this QKD quantum key to decrypt the received encrypted symmetric key and IPFS file identifier. The decryption process uses the same algorithm as the encryption process to convert the ciphertext back into plaintext. For example, if the sender used the SM4 algorithm for encryption, the receiver uses the same SM4 algorithm, using the QKD quantum key as the decryption key, to restore the encrypted symmetric key and IPFS file identifier to the original symmetric key and IPFS file identifier.
[0055] After obtaining the decrypted IPFS file's unique identifier, the Shanghai branch's sales department administrator uses the system's download tool to download the encrypted file from the IPFS network using the IPFS file's unique identifier. Based on the file's unique identifier, the IPFS network locates the file's small pieces stored on various nodes, reassembles these small pieces into the complete encrypted file, and downloads it to the Shanghai branch's sales department administrator's device. For example, based on the file's unique identifier, the IPFS network locates the file's small pieces previously stored on nodes A, B, and C, and transfers these small pieces to the department administrator's device, which then reassembles these small pieces into the encrypted file in the correct order.
[0056] After downloading the encrypted file, the manager of the Shanghai branch's sales department uses the symmetric key obtained after decryption to decrypt the file using the system-provided decryption tool. The decryption tool then uses the symmetric key to perform reverse mathematical operations on each data block in the encrypted file, converting the ciphertext back into the original plaintext data. For example, for a file previously encrypted using the SM4 algorithm, the decryption tool uses the same symmetric key to decrypt the encrypted file block by block, ultimately obtaining the original new product development report. The manager can then review the report's contents and formulate marketing strategies.
[0057] In multi-user authorization scenarios, this solution's advantage of separating file encryption from key authorization distribution is fully demonstrated. For example, suppose that within a group, in addition to the Shanghai branch's sales department, multiple other departments, such as production and finance, need to receive new product development reports. The Beijing branch's R&D department only needs to symmetric-encrypt the original file once and store the encrypted file on the IPFS network. During authorization, a shared QKD quantum key is generated with each department via the QKD network. The symmetric key and the IPFS file's unique identifier are encrypted and sent to the appropriate department. This effectively conserves storage space, avoids duplicate file encryption, and improves overall system efficiency in multi-user scenarios.
[0058] By combining IPFS and QKD technology, in the above-mentioned multi-department authorization scenario, files can be repeatedly authorized for access without the need to store multiple different encrypted versions. For example, after the R&D department of the Beijing branch stores the encrypted files on the IPFS network, each department can download the encrypted files from the IPFS network by obtaining the correct authorization information (the decrypted symmetric key and the IPFS file unique identifier). At the same time, the authorization process only requires the transmission of a small amount of key data through QKD, reducing the I / O burden of the IPFS network. Compared with traditional solutions, which may require the transmission of a large number of encrypted file copies on the network, this solution reduces storage costs and network transmission pressure, making the system more advantageous in processing large files and multi-user authorization scenarios.
[0059] In summary, the file encryption authorization distribution system based on IPFS and quantum key distribution achieves secure and efficient file encryption authorization distribution through the detailed operational processes and innovations described above, especially the unique dual-channel architecture design, meeting the requirements for data security and resource utilization efficiency in the modern digital environment. On the one hand, encrypted files are transmitted through the IPFS channel. As a distributed storage network, the IPFS network divides encrypted files into multiple small blocks and stores them in different nodes in the network. After the file sender (such as the R&D department of a group's Beijing branch) uploads the encrypted file to the IPFS network, the file receiver (such as the sales department of the Shanghai branch) can download it from the network using the unique IPFS file identifier. During this process, the IPFS network primarily undertakes the functions of file storage and transmission, focusing on providing efficient file access services.
[0060] On the other hand, the key is transmitted through the QKD channel. After authorization is approved, the QKD node devices at the file sender and receiver use quantum mechanical properties (such as quantum entanglement and quantum superposition) to generate a QKD quantum key. The sender uses this quantum key to encrypt the symmetric key and the unique identifier of the IPFS file, and then sends it to the receiver through the QKD channel. Due to the uncertainty and non-cloning nature of the quantum state, it is difficult for a third party to steal the key information without interfering with the quantum state. Even if the encrypted file is intercepted during transmission on the IPFS network, the file content cannot be decrypted without the correct key, thus effectively ensuring the security of the data.
[0061] Furthermore, this dual-channel architecture offers advantages in resource utilization. The authorization process requires only a small amount of key data to be transmitted via QKD, significantly reducing the I / O burden on the IPFS network compared to traditional solutions that may require the transmission of numerous encrypted file copies. This not only reduces storage costs but also alleviates network transmission pressure, enabling the system to maintain data security while balancing efficiency and resource utilization when handling large volumes of files and multi-user authorization scenarios. In short, the dual-channel architecture, through the separate transmission of encrypted files and keys, optimizes resource utilization while ensuring data security, providing a reliable and efficient solution for file encryption authorization distribution.
[0062] In an embodiment of the present invention, when the file sender is authorized, a common QKD quantum key of the file sender and the file receiver is generated based on the QKD network, so that the file sender and the file receiver can capture the QKD quantum key at the same time, which can be implemented through the following examples.
[0063] When the file sending end and the file receiving end monitor the QKD network simultaneously and the file sending end is authorized, generating a random key based on the QKD network;
[0064] The random key is used as the QKD quantum key, so that the file sending end and the file receiving end can capture the QKD quantum key at the same time.
[0065] In an embodiment of the present invention, for example, assume a large financial institution whose internal risk management department, acting as the file sender, needs to send a file containing important market risk assessment data to the investment decision-making department (file receiver). First, after preparing the original market risk assessment data file, the risk management department encrypts the original file using a symmetric key according to the previously described process to obtain an encrypted file. The encrypted file is then stored on the IPFS network, obtaining the corresponding IPFS file unique identifier. Next, the process begins with generating a common QKD quantum key based on the QKD network. The server, acting as the executing entity, continuously monitors the monitoring status of both the risk management department (file sender) and the investment decision-making department (file receiver) when both devices are connected to the QKD network. Upon detecting that both the file sender and the file receiver are monitoring the QKD network simultaneously, and the system successfully verifies the file sender's authorization (for example, if a risk management department staff member submits an authorization application in the system and, after a rigorous permission approval process, the system confirms that the department has the authority to send the file), the server initiates a random key generation operation based on the QKD network. The server leverages the properties of quantum mechanics in the QKD network, such as quantum entanglement and quantum superposition, to generate a series of quantum photons in the quantum channel between the QKD node devices in the risk management and investment decision-making departments. Through a complex process involving measurement and negotiation of the states of these quantum photons, a random key is generated. The server then uses this random key as the QKD quantum key. Due to the characteristics of the QKD network, the QKD node devices in the risk management and investment decision-making departments simultaneously capture this QKD quantum key. During this capture process, the QKD node devices measure the quantum photons emitted in the quantum channel. Based on the measurement results and a negotiation mechanism between the two parties, they ultimately obtain the same QKD quantum key and store it in their respective devices. At this point, the risk management department and the investment decision-making department have a common QKD quantum key. The risk management department can subsequently use this quantum key to encrypt the symmetric key previously used to encrypt the file and the IPFS file unique identifier, and send it to the investment decision-making department. The investment decision-making department can then use the obtained QKD quantum key to perform subsequent operations such as decryption to obtain the original market risk assessment data file content and complete the file's secure authorization distribution process.
[0066] In the embodiment of the present invention, the method for generating the symmetric key can be implemented through the following examples.
[0067] Generates a symmetric key that meets the preset standards through a preset key algorithm.
[0068] In the embodiment of the present invention, for example, still taking a large financial institution as an example, the risk management department needs to send a market risk assessment document to the investment decision-making department. In this scenario, the server is responsible for performing the symmetric key generation operation.
[0069] The symmetric key can be generated using the SM4 algorithm, which is not limited here. The risk management department uses this generated symmetric key to encrypt the original market risk assessment file. The encrypted file is stored in the IPFS network, laying the foundation for the subsequent authorization distribution process.
[0070] In an embodiment of the present invention, the symmetric key and the encrypted file are stored in the IPFS network using the QKD quantum key to encrypt the IPFS file unique identifier, which can be implemented through the following examples.
[0071] The symmetric key is split into n key shards, and each shard and the IPFS file identifier are quantum one-time pad encrypted using the QKD quantum key.
[0072] In an embodiment of the present invention, for example, in the scenario of a large financial institution, the risk management department has generated a symmetric key and encrypted the market risk assessment file to the IPFS network, and jointly owns the QKD quantum key with the investment decision-making department. At this time, the server begins to execute the encryption operation of the symmetric key and the IPFS file unique identifier using the QKD quantum key.
[0073] The server first processes the symmetric key. Assuming the generated symmetric key is a fixed-length binary string, the server splits it into n key shards according to specific rules. For example, if the symmetric key is 256 bits long, the server might split it into eight key shards, each containing 32 bits. This splitting method ensures the security and flexibility of subsequent encryption.
[0074] The server then uses the QKD quantum key to perform quantum one-time pad encryption on each key shard. Quantum one-time pad encryption is an encryption method based on the principles of quantum mechanics and is extremely secure. For each key shard, the server performs a bit-by-bit XOR operation with the QKD quantum key. For example, the first key shard is a 32-bit binary data string, and the QKD quantum key is also a binary data string of the same length. The server XORs each bit of these data to obtain the encrypted first key shard. Because the QKD quantum key is a truly random key generated through a quantum channel, each encryption key is unique, making it difficult for an attacker to decipher the true content of the encrypted key shard even if they intercept it.
[0075] While encrypting the key shards, the server also uses the QKD quantum key to encrypt the IPFS file's unique identifier. The IPFS file's unique identifier is typically a hash value that represents the encrypted file stored on the IPFS network. The server also performs a bit-by-bit XOR operation on this hash value with the QKD quantum key. For example, if the IPFS file's unique identifier is a 128-bit hash value, the server XORs the corresponding bits of the QKD quantum key to obtain the encrypted IPFS file's unique identifier.
[0076] Through the above steps, the server completes quantum one-time pad encryption of each shard of the symmetric key and the unique identifier of the IPFS file. The encrypted key shards and the unique identifier of the IPFS file are combined and subsequently sent by the risk management department to the investment decision-making department. Upon receiving this encrypted data, the investment decision-making department uses the same QKD quantum key to decrypt it, thereby obtaining the symmetric key and the unique identifier of the IPFS file. Finally, the original market risk assessment file can be downloaded and decrypted from the IPFS network.
[0077] In the embodiments of the present invention, the following implementation modes are also provided.
[0078] Set a valid timestamp for each generated QKD quantum key, which contains the UTC standard time and the quantum clock synchronization signal;
[0079] When the file receiving end fails to complete the file authorization download within the preset time, the QKD network is automatically triggered to regenerate a new quantum key and resend the authorization.
[0080] In the embodiment of the present invention, for example, in a file encryption authorization distribution system of a large financial institution, the server plays an important role in ensuring key security and file distribution timeliness.
[0081] The server first sets a valid timestamp for each generated QKD quantum key. For example, when the risk management department sends a market risk assessment document to the investment decision-making department, once the server generates a shared QKD quantum key for both parties based on the QKD network, it begins setting the timestamp. The server obtains the current UTC standard time, a globally unified time standard that ensures time accuracy and consistency. Simultaneously, the server communicates with a quantum clock to obtain a quantum clock synchronization signal. A quantum clock is a high-precision clock based on the principles of quantum mechanics, with extremely high time accuracy. The server combines the UTC standard time and the quantum clock synchronization signal to form a valid timestamp and stores it in association with the corresponding QKD quantum key. For example, the generated QKD quantum key is marked with valid timestamp information such as "2024-08-15T10:30:00Z (UTC standard time), quantum clock synchronization signal: File encryption authorization distribution device 110 based on IPFS and quantum key distribution."
[0082] Next, the server continuously monitors the file download status at the recipient (investment decision-making department). The server sets a preset time, such as 30 minutes. Within these 30 minutes, the investment decision-making department must complete a series of operations: download the encrypted file from the IPFS network and decrypt the relevant information using the QKD quantum key to retrieve the original file. If the investment decision-making department fails to complete the file download within the preset 30 minutes, the server automatically triggers the QKD network to regenerate a new quantum key.
[0083] The triggering process is as follows: The server's monitoring module periodically checks the investment decision-making department's file download status. If the investment decision-making department has not completed the download at the end of the preset time, the monitoring module sends a command to the QKD network. Upon receiving the command, the QKD network, based on the principles of quantum mechanics, restarts the random key generation process between the QKD nodes of the risk management and investment decision-making departments, leveraging quantum entanglement and quantum superposition to generate a new quantum key. The server then follows the subsequent process, using the newly generated quantum key to encrypt the relevant information and perform other operations. It also updates the effective timestamp to ensure the security and timeliness of the file encryption authorization distribution process, preventing the potential security risks associated with the prolonged exposure of old keys.
[0084] In an embodiment of the present invention, there is also a file encryption authorization distribution method based on IPFS and quantum key distribution, which is applied to the file receiving end of the file encryption authorization distribution system based on IPFS and quantum key distribution. The file encryption authorization distribution system based on IPFS and quantum key distribution also includes a file sending end. This scheme can be implemented through the following examples.
[0085] If the file sender is authorized, generating a common QKD quantum key for the file sender and the file receiver based on the QKD network, so that the file sender and the file receiver can capture the QKD quantum key at the same time;
[0086] Receive the symmetric key encrypted based on the QKD quantum key and the IPFS file unique identifier sent by the file sending end; the IPFS file unique identifier is the IPFS file unique identifier corresponding to the encrypted file obtained by the file sending end after encrypting the original file based on the symmetric key and storing it in the IPFS network;
[0087] Decrypt the encrypted symmetric key and the unique identifier of the IPFS file using the QKD quantum key to obtain the symmetric key and the unique identifier of the IPFS file;
[0088] The file receiving end downloads the encrypted file in the IPFS network through the IPFS file unique identifier, and uses the symmetric key to decrypt the encrypted file to obtain the original file.
[0089] In this embodiment of the present invention, a business scenario at a large financial institution is used as an example. The risk management department, acting as the file sender, holds a file containing important market trend analysis and risk assessment data, which needs to be securely distributed to the investment decision-making department (the file receiver). The file encryption authorization distribution system based on IPFS and quantum key distribution plays a key role in this process. The specific operational process of the file receiver is detailed below.
[0090] First, during the quantum key generation phase, the server leverages the properties of quantum mechanics within the QKD network to generate a series of quantum photon states on the quantum channel between the QKD node devices of the investment decision-making department and the risk management department. Through a complex process involving measurement and negotiation of these photon states, a random key is generated. The QKD node device in the investment decision-making department performs operations such as measurement on the quantum photons emitted by the quantum channel. Based on the measurement results and a mutual negotiation mechanism, it simultaneously captures the QKD quantum key with the risk management department and stores it locally. For example, the photons emitted by the quantum channel have different polarization states. The QKD node device measures these polarization states using a specific measurement basis. After multiple rounds of measurement and information exchange, both parties obtain the same QKD quantum key.
[0091] Next, the risk management department generates a QKD quantum key and uses it to encrypt the symmetric key used to encrypt the original file and the unique IPFS file identifier associated with the encrypted file after it is stored on the IPFS network. This encryption process involves splitting the symmetric key into n key shards, then using the QKD quantum key to perform a quantum one-time pad encryption on each shard and the IPFS file identifier. Once encrypted, the encrypted symmetric key and IPFS file identifier are sent over the network to the investment decision-making department.
[0092] The investment decision-making department's server receiving module then continuously monitors network connections. Upon receiving encrypted data from the risk management department, it immediately verifies the packet's integrity and source legitimacy. For example, it checks the packet's checksum to confirm that no errors occurred during transmission, and verifies the sender's IP address and identity to ensure the data originated from a legitimate file sender.
[0093] After obtaining the encrypted symmetric key and the IPFS file's unique identifier, the investment decision-making department performs decryption using the QKD quantum key stored on the local device. The server invokes the decryption algorithm, performing a bit-by-bit reverse XOR operation on each shard of the encrypted symmetric key and the IPFS file's unique identifier with the QKD quantum key. This is the reverse of the quantum one-time pad encryption used during encryption. Each shard of the symmetric key is decrypted and restored to its original key shard. The server then combines these shards in the correct order to obtain the complete symmetric key. Simultaneously, the encrypted IPFS file's unique identifier is decrypted, restoring its original content—the unique identifier of the encrypted file stored on the IPFS network.
[0094] The investment decision-making department's server then obtains the symmetric key and the IPFS file's unique identifier. Using the unique identifier, it downloads the encrypted file from the IPFS network via the IPFS network interface. The IPFS network uses the unique identifier to locate the file's small pieces stored on various nodes and transmits them to the investment decision-making department's device, which then assembles them into the complete encrypted file in the correct order.
[0095] After the download is complete, the investment decision-making department uses the symmetric key obtained from decryption to decrypt the encrypted file using the system's provided decryption tool. The decryption tool uses the symmetric key to perform reverse mathematical operations on each data block in the encrypted file, converting the ciphertext back into the original plaintext data, thereby obtaining the original market trend analysis and risk assessment file. At this point, the investment decision-making department staff can review the file contents and make investment decisions based on the data.
[0096] Throughout the entire process, the server strictly follows the system-defined steps to perform various operations. This solution utilizes a dual-channel distribution architecture by separating encrypted files from keys. Encrypted files are transmitted via the IPFS channel, which, based on the distributed storage and content-addressing characteristics of the IPFS network, ensures the redundancy and accessibility of file storage. Keys and authorization information are transmitted via the QKD channel, which utilizes the principles of quantum mechanics to ensure the security of key generation and transmission, making it difficult for third parties to steal the keys. Even if an encrypted file is intercepted while being transmitted on the IPFS network, it cannot be decrypted without the correct key, greatly improving the security of data transmission. At the same time, the authorization process only transmits a small amount of key data via QKD, reducing the I / O burden of the IPFS network. This improves the overall efficiency of the system while ensuring data security, fully demonstrating the significant advantages of the file encryption authorization distribution system based on IPFS and quantum key distribution in ensuring data security and transmission efficiency.
[0097] In order to more clearly describe the solution provided by the present invention, a relatively complete implementation method is provided below. Figure 2 , Figure 2 Schematic diagram of the dual-channel framework of IPFS and quantum key distribution provided by an embodiment of the present invention.
[0098] This paper proposes a file encryption authorization distribution system and method based on the InterPlanetary File System (IPFS) and quantum key distribution (QKD), aiming to address security and efficiency issues in file encryption transmission and authorization. By separating file encryption storage from key authorization distribution, and leveraging the distributed storage characteristics of IPFS and the quantum security features of QKD, a dual-channel file encryption authorization distribution architecture is constructed, enabling secure file storage, reliable transmission, and controllable authorized access.
[0099] This system mainly consists of two parties: the file generator (A) and the file user (B). Both parties are equipped with corresponding IPFS nodes and QKD node devices, as follows:
[0100] IPFS node: responsible for the storage and transmission of files. Based on the distributed storage mechanism of the IPFS network, the files are divided into multiple small blocks and stored in different nodes, and the accessibility and storage redundancy of the files are ensured through content addressing.
[0101] QKD node: used to generate and transmit quantum keys. It uses the principles of quantum mechanics (such as quantum entanglement and quantum superposition) to generate random quantum keys between two nodes to ensure the security of the key transmission process.
[0102] The specific process is as follows:
[0103] (1) File encryption and storage
[0104] Local encryption: File creator A encrypts the original file using a symmetric encryption algorithm (such as SM4). Symmetric encryption algorithms use a key generated by specific logic to transform the file content, encrypting the original data and ensuring data confidentiality during storage. Encryption generates the file ciphertext and the key plaintext, which is held by file creator A.
[0105] Storing on the IPFS network: The encrypted file is transmitted to the IPFSA node. The IPFS network, leveraging its distributed storage capabilities, caches the encrypted file across multiple nodes. During this process, the IPFS network generates a unique identifier for the encrypted file (an IPFS file unique identifier). This identifier is based on the file's content and remains unchanged as long as the file's content remains unchanged. This content-addressed approach ensures file accessibility and storage redundancy. Because the symmetric encryption key is held only by the file generator, A, the file's storage on IPFS is highly secure; only those with the correct key can decrypt the file.
[0106] (2) QKD Authorization Key Distribution
[0107] Quantum key generation: During the key distribution process, file generator A, the sender, and file user B, the receiver, collaborate to generate a shared quantum key through their respective QKD nodes. This process leverages the properties of quantum mechanics, such as quantum entanglement and quantum superposition, to generate a random key between the two nodes. Due to the uncertainty and non-cloning properties of quantum states, third parties cannot obtain this key information without interfering with the quantum state. Keys generated by quantum methods are referred to herein as quantum keys. It is worth noting that in regions with existing quantum networks, quantum key distribution can be achieved directly using those networks. For regions without quantum networks, quantum satellites can assist in quantum key distribution.
[0108] Authorization information encryption: File generator A uses the quantum key to encrypt information containing the file key plaintext and the IPFS file's unique identifier, generating authorization ciphertext. By using quantum key encryption, the transmission of authorization information is guaranteed to be secure, and even if eavesdropping occurs during communication, it can be detected in a timely manner.
[0109] Authorized ciphertext transmission: The authorized ciphertext is sent to the QKD node B of file user B through the network.
[0110] Authorization Information Decryption: QKD node B, upon receiving the authorization ciphertext, decrypts it using the quantum key generated in collaboration with node A, obtaining the key plaintext and the unique file identifier. This channel, which relies on QKD to transmit authorization information, is called a QKD channel and ensures the security of the key transmission process (which is also the file authorization process).
[0111] (3) File acquisition and local decryption
[0112] After obtaining the decrypted key plaintext and the IPFS file unique identifier, file user B uses the system-provided download tool to download the file ciphertext from the IPFS network through the IPFS network interface using the IPFS file unique identifier. After the download is complete, the decrypted key plaintext is used to decrypt the file ciphertext using the system-provided decryption tool, converting the ciphertext back to the original plaintext data to obtain the original file content.
[0113] This solution innovatively separates encrypted files from keys, using an IPFS channel to transmit encrypted files and a QKD channel to transmit keys and authorization information. This dual-channel architecture not only reduces the I / O burden on the IPFS network but, more importantly, ensures the security of the entire authorization process through the security of quantum keys. Even if an encrypted file is intercepted during transmission, it cannot be decrypted without the correct quantum key, fundamentally enhancing the security of file encryption and authorization distribution. It combines the quantum security of quantum key distribution with the advantages of IPFS distributed storage. QKD, based on the principles of quantum mechanics, ensures absolute security in key generation and distribution. IPFS provides an efficient and reliable file storage and transmission method, ensuring file accessibility and redundancy through content-addressed and distributed storage. This combination ensures data confidentiality and authorization security while improving file storage and transmission efficiency, meeting the dual requirements of data security and resource efficiency in the modern digital environment.
[0114] Please refer to Figure 3 , Figure 3 An embodiment of the present invention provides a file encryption authorization distribution device 110 based on IPFS and quantum key distribution, which is applied to a file sending end of a file encryption authorization distribution system based on IPFS and quantum key distribution. The file encryption authorization distribution system based on IPFS and quantum key distribution also includes a file receiving end, including:
[0115] The encryption module 1101 is configured to encrypt the original file using a symmetric key to obtain an encrypted file, and store the encrypted file on the IPFS network; if the file sender is authorized, generate a QKD quantum key shared by the file sender and the file receiver based on the QKD network, so that the file sender and the file receiver can capture the QKD quantum key at the same time;
[0116] The distribution module 1102 is used to use the QKD quantum key to encrypt the symmetric key and the IPFS file unique identifier stored in the IPFS network, and send the encrypted symmetric key and IPFS file unique identifier to the file receiving end, so that the file receiving end uses the QKD quantum key to decrypt the encrypted symmetric key and IPFS file unique identifier, and downloads the encrypted file from the IPFS network based on the decryption result to obtain the original file.
[0117] The file encryption authorization distribution device based on IPFS and quantum key distribution can also be applied to the file receiving end of the file encryption authorization distribution system based on IPFS and quantum key distribution, including:
[0118] The encryption module 1101 is configured to generate a QKD quantum key shared by the file sending end and the file receiving end based on the QKD network when the file sending end is authorized, so that the file sending end and the file receiving end can capture the QKD quantum key at the same time;
[0119] The receiving module 1103 is used to receive the symmetric key and IPFS file unique identifier encrypted based on the QKD quantum key sent by the file sending end; the IPFS file unique identifier is the IPFS file unique identifier corresponding to the encrypted file obtained by the file sending end after encrypting the original file based on the symmetric key and storing it in the IPFS network; use the QKD quantum key to decrypt the encrypted symmetric key and IPFS file unique identifier to obtain the symmetric key and the IPFS file unique identifier; the file receiving end downloads the encrypted file in the IPFS network through the IPFS file unique identifier, and uses the symmetric key to decrypt the encrypted file to obtain the original file.
[0120] It should be noted that the implementation principles of the aforementioned file encryption authorization distribution device 110 based on IPFS and quantum key distribution can be referenced from the implementation principles of the aforementioned file encryption authorization distribution method based on IPFS and quantum key distribution, and will not be elaborated upon here. It should be understood that the division of the various modules of the above device is merely a division of logical functions. In actual implementation, they can be fully or partially integrated into a single physical entity, or physically separated. Furthermore, these modules can be implemented entirely as software invoked by a processing element; entirely as hardware; or partially as software invoked by a processing element, while others are implemented in hardware. For example, the file encryption authorization distribution device 110 based on IPFS and quantum key distribution can be a separate processing element, or integrated into a chip of the aforementioned device. Furthermore, it can be stored in the form of program code in the memory of the aforementioned device, and invoked and executed by a processing element of the aforementioned device. The implementation of the other modules is similar. Furthermore, these modules can be fully or partially integrated or implemented independently. The processing element described here can be an integrated circuit with signal processing capabilities. During implementation, each step of the above method or each module above may be completed by an integrated logic circuit of hardware in a processor element or by instructions in the form of software.
[0121] For example, the above modules may be one or more integrated circuits configured to implement the above methods, such as one or more application specific integrated circuits (ASICs), one or more digital signal processors (DSPs), or one or more field programmable gate arrays (FPGAs). For another example, when a module is implemented by scheduling program code on a processing element, the processing element may be a general-purpose processor, such as a central processing unit (CPU) or other processor that can call program code. For another example, these modules may be integrated together and implemented in the form of a system-on-a-chip (SOC).
[0122] The embodiment of the present invention provides a computer device 100, which includes a processor and a non-volatile memory storing computer instructions. When the computer instructions are executed by the processor, the computer device 100 executes the aforementioned file encryption authorization distribution device 110 based on IPFS and quantum key distribution. Figure 4 As shown, Figure 4This is a block diagram of the structure of a computer device 100 provided in an embodiment of the present invention. The computer device 100 includes a file encryption authorization distribution device 110 based on IPFS and quantum key distribution, a memory 111, a processor 112, and a communication unit 113.
[0123] In order to realize the transmission or interaction of data, the memory 111, the processor 112, and the communication unit 113 are electrically connected to each other directly or indirectly. For example, the electrical connection between these elements can be achieved through one or more communication buses or signal lines. The file encryption authorization distribution device 110 based on IPFS and quantum key distribution includes at least one software function module that can be stored in the memory 111 in the form of software or firmware or solidified in the operating system (OS) of the computer device 100. The processor 112 is used to execute the file encryption authorization distribution device 110 based on IPFS and quantum key distribution stored in the memory 111, such as the software function modules and computer programs included in the file encryption authorization distribution device 110 based on IPFS and quantum key distribution.
[0124] An embodiment of the present invention provides a readable storage medium, which includes a computer program. When the computer program is running, it controls the computer device where the readable storage medium is located to execute the aforementioned file encryption authorization distribution device 110 based on IPFS and quantum key distribution.
[0125] For illustrative purposes, the foregoing description has been made with reference to specific embodiments. However, the above illustrative discussion is not intended to be exhaustive or to limit the present disclosure to the precise forms disclosed. Numerous modifications and variations are possible in light of the above teachings. These embodiments have been selected and described in order to best illustrate the principles of the present disclosure and its practical application, thereby enabling those skilled in the art to best utilize the present disclosure and to utilize various embodiments with various modifications as appropriate for the specific application contemplated.
Claims
1. A file encryption authorization distribution method based on IPFS and quantum key distribution, characterized in that: A file sending end is applied to a file encryption authorization distribution system based on IPFS and quantum key distribution, wherein the file encryption authorization distribution system based on IPFS and quantum key distribution also includes a file receiving end, including: The original file is encrypted using a symmetric key to obtain an encrypted file, and the encrypted file is stored in the IPFS network. After the encrypted file is stored in the IPFS network, a corresponding IPFS file unique identifier is generated; If the file sender is authorized, generating a common QKD quantum key for the file sender and the file receiver based on the QKD network, so that the file sender and the file receiver can capture the QKD quantum key at the same time; The QKD quantum key is used to encrypt the symmetric key and the IPFS file unique identifier stored in the IPFS network, and the encrypted symmetric key and IPFS file unique identifier are sent to the file receiving end, so that the file receiving end uses the QKD quantum key to decrypt the encrypted symmetric key and IPFS file unique identifier, and downloads the encrypted file from the IPFS network based on the decryption result to obtain the original file.
2. The method according to claim 1, characterized in that When the file sending end is authorized, generating a common QKD quantum key between the file sending end and the file receiving end based on the QKD network, so that the file sending end and the file receiving end can capture the QKD quantum key at the same time, including: When the file sending end and the file receiving end monitor the QKD network simultaneously and the file sending end is authorized, generating a random key based on the QKD network; The random key is used as the QKD quantum key, so that the file sending end and the file receiving end can capture the QKD quantum key at the same time.
3. The method according to claim 1, characterized in that The method for generating the symmetric key includes: Generates a symmetric key that meets the preset standards through a preset key algorithm.
4. The method according to claim 1, wherein The method of using the QKD quantum key to encrypt the symmetric key and the encrypted file stored in the IPFS network as a unique identifier of the IPFS file includes: The symmetric key is split into n key shards, and each shard and the IPFS file identifier are quantum one-time pad encrypted using the QKD quantum key.
5. The method according to claim 1, wherein The method further comprises: Set a valid timestamp for each generated QKD quantum key, which contains the UTC standard time and the quantum clock synchronization signal; When the file receiving end fails to complete the file authorization download within the preset time, the QKD network is automatically triggered to regenerate a new quantum key and resend the authorization.
6. A file encryption authorization distribution method based on IPFS and quantum key distribution, characterized in that: A file receiving end applied to a file encryption authorization distribution system based on IPFS and quantum key distribution, wherein the file encryption authorization distribution system based on IPFS and quantum key distribution also includes a file sending end, and the method includes: If the file sender is authorized, generating a common QKD quantum key for the file sender and the file receiver based on the QKD network, so that the file sender and the file receiver can capture the QKD quantum key at the same time; Receive the symmetric key encrypted based on the QKD quantum key and the IPFS file unique identifier sent by the file sending end; the IPFS file unique identifier is the IPFS file unique identifier corresponding to the encrypted file obtained by the file sending end after encrypting the original file based on the symmetric key and storing it in the IPFS network; Decrypt the encrypted symmetric key and the unique identifier of the IPFS file using the QKD quantum key to obtain the symmetric key and the unique identifier of the IPFS file; The file receiving end downloads the encrypted file in the IPFS network through the IPFS file unique identifier, and uses the symmetric key to decrypt the encrypted file to obtain the original file.
7. A file encryption authorization distribution device based on IPFS and quantum key distribution, characterized in that: A file sending end is applied to a file encryption authorization distribution system based on IPFS and quantum key distribution, wherein the file encryption authorization distribution system based on IPFS and quantum key distribution also includes a file receiving end, including: An encryption module is configured to encrypt the original file using a symmetric key to obtain an encrypted file, and store the encrypted file on the IPFS network; upon authorization by the file sender, generate a common QKD quantum key for the file sender and the file receiver based on the QKD network, so that the file sender and the file receiver can capture the QKD quantum key at the same time; The distribution module is used to use the QKD quantum key to encrypt the symmetric key and the IPFS file unique identifier stored in the IPFS network, and send the encrypted symmetric key and IPFS file unique identifier to the file receiving end, so that the file receiving end uses the QKD quantum key to decrypt the encrypted symmetric key and IPFS file unique identifier, and download the encrypted file from the IPFS network based on the decryption result to obtain the original file.
8. A file encryption authorization distribution device based on IPFS and quantum key distribution, characterized in that: A file receiving end applied to a file encryption authorization distribution system based on IPFS and quantum key distribution, wherein the file encryption authorization distribution system based on IPFS and quantum key distribution also includes a file sending end, and the method includes: an encryption module, configured to generate, based on a QKD network, a common QKD quantum key for the file sending end and the file receiving end, if the file sending end is authorized, so that the file sending end and the file receiving end can capture the QKD quantum key at the same time; The receiving module is used to receive the symmetric key and IPFS file unique identifier sent by the file sending end after encryption based on the QKD quantum key; the IPFS file unique identifier is the IPFS file unique identifier corresponding to the encrypted file obtained by the file sending end after encrypting the original file based on the symmetric key and storing it in the IPFS network; use the QKD quantum key to decrypt the encrypted symmetric key and IPFS file unique identifier to obtain the symmetric key and the IPFS file unique identifier; the file receiving end downloads the encrypted file in the IPFS network through the IPFS file unique identifier, and uses the symmetric key to decrypt the encrypted file to obtain the original file.
9. A computer device, characterized in that: The computer device includes a processor and a non-volatile memory storing computer instructions. When the computer instructions are executed by the processor, the computer device executes the method according to any one of claims 1 to 6.
10. A readable storage medium, characterized in that: The readable storage medium includes a computer program, and when the computer program is executed, the computer device where the readable storage medium is located is controlled to execute the method according to any one of claims 1 to 6.
Citation Information
Patent Citations
VPN (Virtual Private Network) key management system, method and equipment based on quantum key and computer readable medium
CN114707160A
One-time pad energy data transmission method based on quantum cryptography QVPN, storage device and intelligent terminal
CN117201052A