Secure communication system based on quantum key distribution

Through a secure communication system based on quantum key allocation, a single photon key is generated using a quantum light source, combined with the BB84 protocol and deception technology to monitor and eavesdrop, the communication security and reliability problems of the existing quantum key management system are solved, and efficient and secure data transmission and multi-user communication are achieved.

CN120342604APending Publication Date: 2025-07-18GUIYANG BUREAU OF CHINA SOUTHERN POWER GRID CO LTD EHV TRANSMISSION CO

Patent Information

Application Number
CN202510628343.0
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-05-15
Publication Date
2025-07-18

AI Technical Summary

Technical Problem

The existing quantum key management system has shortcomings in network state prediction, quantum channel noise processing, resource allocation, performance index evaluation and key quality evaluation, resulting in communication security and reliability problems.

Method used

A secure communication system based on quantum key allocation is adopted, a single photon key is generated using a quantum light source, combined with the BB84 protocol and deception technology to monitor eavesdropping, a timestamp mechanism and redundant verification error correction encoding are introduced, and data transmission is optimized through the scheduling unit, supporting multi-user communication and security management.

Benefits of technology

It realizes highly random and secure key generation, detects eavesdropping behavior in real time, ensures the security and accuracy of data transmission, improves transmission efficiency and system security and reliability, and supports multi-user communication.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120342604A_ABST
    Figure CN120342604A_ABST
Patent Text Reader

Abstract

The invention discloses a secure communication system based on quantum key distribution, and relates to the field of encrypted communication, and the system comprises a key generation module which is used for generating a quantum key and synchronously forwarding the currently generated quantum key to a distribution module; the distribution module is used for receiving the quantum key generated in the key generation module, distributing the quantum key to users of both communication parties, synchronously detecting the transmission quality of the quantum signal and monitoring whether an eavesdropping behavior exists or not; the encryption module is used for receiving plaintext data from a sender, performing encryption processing on the plaintext data by using a quantum key and a one-time password book encryption algorithm, and converting a plaintext into a ciphertext; according to the method, the highly random and safe secret key is generated by utilizing quantum mechanical characteristics, the confidentiality of communication is fundamentally guaranteed, and the secret key generation mode is based on the unique property of the quantum state, so that the secret key is difficult to crack or steal.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the technical field of encrypted communication, and specifically provides a secure communication system based on quantum key distribution. Background Art

[0002] Secure communication refers to the use of technologies and measures such as encryption, authentication, and access control during the process of information transmission, exchange, and processing to ensure the confidentiality, integrity, and availability of information, and prevent data leakage, tampering, and illegal access.

[0003] The invention patent application with the application number 202411818006.X discloses a secure encryption communication method based on quantum key management, including the following steps: Step S1, obtain the system state data of the communication network and construct a system state matrix; obtain the communication request data packet and generate a service demand matrix; read the real-time collected network state data and generate a network state scoring matrix; read the key pool state data of each node and generate a key resource distribution matrix; Step S2, construct and solve a multi-objective optimization model based on the system state matrix, service demand matrix, network state scoring matrix, and key resource distribution matrix to generate a scheduling strategy matrix, and verify the feasibility of the scheduling strategy matrix to generate a verification report; Step S3, construct and issue a scheduling instruction set according to the scheduling strategy matrix, collect performance index data for monitoring and evaluation, update the system historical data to obtain a data update log, and generate a comprehensive performance report. This application aims to solve the problems of "in actual use, the following technical problems are found: First, the existing Bayesian network model does not consider the impact of quantum state decoherence on network state prediction, resulting in insufficient prediction accuracy; Second, the key consumption prediction model only uses a simple exponential smoothing method and fails to fully consider the random fluctuation characteristics of quantum channel noise, affecting the accuracy of prediction; Third, in the multi-objective optimization process, the Shannon limit of quantum channel capacity is not used as a constraint condition, which may lead to unreasonable resource allocation; Fourth, the network state evaluation does not establish a clear update cycle mechanism and it is difficult to reflect network state changes in a timely manner; Fifth, in the process of collecting and analyzing performance index data, there is a lack of comprehensive evaluation of quantum characteristic parameters, affecting the effect of system performance optimization; Sixth, in the process of evaluating the health status of the key pool, the impact of quantum channel noise on key quality is not fully considered, reducing the accuracy of health evaluation. The existence of these technical problems restricts the performance and reliability of the quantum key management system".

[0004] Based on the above, in order to update communication technology and ensure communication security, a secure communication system based on quantum key distribution is proposed. Summary of the Invention

[0005] In view of the above-mentioned shortcomings of the prior art, the present invention provides a secure communication system based on quantum key distribution, which can effectively solve the problems of the prior art.

[0006] To achieve the above object, the present invention is implemented through the following technical solutions;

[0007] The present invention discloses a secure communication system based on quantum key distribution, including: a key generation module, configured to generate quantum keys and synchronously forward the currently generated quantum keys to a distribution module; a distribution module, configured to receive the quantum keys generated in the key generation module, distribute the quantum keys to both communicating users, synchronously detect the transmission quality of quantum signals, and monitor for any eavesdropping behavior; an encryption module, configured to receive plaintext data from a sender, use a quantum key and a one-time pad encryption algorithm to encrypt the plaintext data, and convert the plaintext into ciphertext; a transmission module, configured to use a communication channel to transmit the encrypted data from the sender to the receiver, and optimize the transmission process of the data on the communication channel during the transmission;

[0008] A scheduling unit is provided at a lower level of the transmission module, and the transmission module combines with the scheduling unit to optimize the transmission process of data on the communication channel;

[0009] The scheduling unit is configured to calculate a data scheduling weight based on the preset priority, timeliness, and real-time state parameters of the communication channel of the data, and apply the data scheduling weight to dynamically adjust the transmission rate and order of the encrypted data;

[0010] The data scheduling weight calculation logic in the scheduling unit is expressed as:

[0011]

[0012] In the formula: ω1, ω2, ω3, ω4, ω5 are weights, and P i is the priority of data i; T i is the timeliness requirement of data i; B is the real-time bandwidth of the channel; D is the channel delay; S i is the size of data i; L is the packet loss rate of the channel;

[0013] Among them, ω1, ω2, ω3, ω4, ω5 are all positive numbers, and the sum of them is 1. The larger the scheduling weight W i of data i, the faster the transmission rate and the more forward the transmission order;

[0014] A decryption module, configured to receive the ciphertext data transmitted by the transmission module, perform a decryption operation based on the same quantum key as the sender according to the inverse operation of the encryption algorithm, and restore the ciphertext to the original plaintext data; a message module, configured to record the operation information of the distribution module and the transmission module, generate a message based on the operation information of the distribution module and the transmission module, and transfer the generated message to a preset cloud database for storage.

[0015] Furthermore, the key generation module is integrated with a quantum light source, which uses a single-photon source and has a probability of generating single photons of not less than 95%;

[0016] Among them, the probability calculation formula for the quantum light source to generate single photons is:

[0017]

[0018] In the formula: P sp is the probability of single-photon generation; N sp is the actual number of single photons generated; N total is the total number of photons emitted by the light source.

[0019] Furthermore, during the operation phase of the distribution module, quantum key distribution is carried out using a quantum channel. During the quantum key distribution process, the BB84 protocol is applied to encode and decode quantum states such as the polarization state or phase of photons to achieve secure transmission of the key;

[0020] During the operation phase of the distribution module, based on decoy-state quantum key distribution is synchronized, and signal-state photons and decoy-state photons are simultaneously transmitted in the quantum channel to monitor the eavesdropping probability:

[0021]

[0022] In the formula: P e is the eavesdropping probability; N′ d is the actual number of detected decoy-state photons; N b is the error count caused by background noise; e e is the additional interference bit error rate introduced by the eavesdropper; N d is the theoretical detection number of decoy-state photons under the assumption of no eavesdropping; ν is the intensity parameter of the decoy-state photons; μ is the intensity parameter of the signal-state photons;

[0023] Among them, the eavesdropping probability P e After calculation, it is synchronized and compared with the preset eavesdropping determination threshold in the distribution module to determine whether there is an eavesdropping behavior.

[0024] Furthermore, the detection logic of the transmission quality of the quantum signal in the distribution module is expressed as:

[0025]

[0026] In the formula: Q is the transmission quality performance value of the quantum signal; α, β, γ, δ are weight coefficients, and satisfy α + β + γ + δ = 1; BER is the bit error rate; F is the quantum state fidelity; SNR is the signal-to-noise ratio; SNR max is the preset maximum signal-to-noise ratio; C is the entanglement degree;

[0027] Among them, after the transmission quality performance value Q of the quantum signal is calculated, it is compared with the preset security determination threshold in the synchronization and distribution module to determine whether the transmission of the quantum signal is secure;

[0028] When the eavesdropping behavior determination result obtained by running the distribution module is no, and the transmission determination results of the quantum signals are all secure, the encryption module is triggered to run. Otherwise, the operations of detection and monitoring in the distribution module are repeatedly refreshed until the conditions for triggering the operation of the encryption module are met.

[0029] Furthermore, the operation steps for converting the plaintext into ciphertext during the operation stage of the encryption module are as follows:

[0030] S1: Data preparation: Convert the plaintext data M into binary format, obtain the current timestamp T, and process it through a hash function to get H(T);

[0031] S2: Preliminary exclusive OR operation: Perform an exclusive OR operation on the plaintext data M and the quantum key K bit by bit to obtain an intermediate result M⊕K;

[0032] S3: Perform an exclusive OR operation on the intermediate result M⊕K and H(T) bit by bit to finally obtain the ciphertext C;

[0033] Among them, the quantum key K is in binary form, and its length should be the same as the length of the plaintext data. H(T) represents the result obtained after performing a hash process on the timestamp T.

[0034] Furthermore, before data transmission, the transmission module performs a redundancy check calculation on the encrypted ciphertext C:

[0035] R = C mod G(x);

[0036] In the formula: R is the redundancy check code; G(x) is the generating polynomial;

[0037] Among them, after the redundancy check code R is calculated, it is combined with the ciphertext C, and any one of the error correction coding methods such as Hamming code, Reed-Solomon code, and convolutional code is used to perform coding processing on it. After the receiver receives the data, the redundancy check code and error correction coding are used to check and correct the data.

[0038] Furthermore, a key verification mechanism is set in the decryption module:

[0039] Let the received quantum key be K r , the hash value obtained by calculating the key feature information pre-shared by the sender through the hash function H is H(K s ), and the hash value obtained by the receiver calculating K r is H(K r ). If the formula:

[0040] H(K r ) = H(K s );

[0041] If the key verification passes, before performing the decryption operation, first verify the received quantum key. By comparing it with the pre-shared key feature information of the sender, confirm the correctness and integrity of the key. If the key verification fails, reject the decryption operation and trigger the key re-distribution process;

[0042] Among them, the key feature information includes at least the key length, hash value, and format.

[0043] Furthermore, a quantum relay technology is adopted between the key generation module and the distribution module. When the transmission distance of the quantum channel is too long and the quantum signal attenuation is serious, the quantum repeater processes and forwards the quantum signal, extending the distribution distance of the quantum key and expanding the application scope of the system;

[0044] The system supports the multi-user communication mode. By allocating independent quantum keys and communication identifiers to each user, secure communication between multiple users is achieved.

[0045] Furthermore, the key generation module is connected to the distribution module and the encryption module through network interaction. The encryption module is connected to the transmission module through network interaction. The lower level of the transmission module is connected to the scheduling unit and the maintenance unit through network interaction. The transmission module is connected to the decryption module and the message module through network interaction. The message module is connected to the distribution module and the transmission module through the network.

[0046] Adopting the technical solution provided by the present invention, compared with the known prior art, it has the following beneficial effects:

[0047] The present invention provides a secure communication system based on quantum key distribution. This system uses the characteristics of quantum mechanics to generate highly random and secure keys, fundamentally ensuring the confidentiality of communication. Its key generation method is based on the unique properties of quantum states, making the key difficult to be cracked or stolen;

[0048] In the key distribution link, technologies such as decoy states are used to detect eavesdropping behaviors in real time to ensure the security of key transmission. When encrypting data, a timestamp mechanism is introduced, and the encryption results of the same plaintext are different at different times, effectively resisting replay attacks. During the data transmission process, redundant checks, error correction coding, and innovative scheduling algorithms are used to ensure accurate and efficient data transmission, reduce the bit error rate, and improve the transmission efficiency;

[0049] In addition, the system supports multi-user communication and sets up a security management center to achieve fine management of user permissions, can promptly respond to various security threats, greatly expands the application scenarios and security reliability of the system, and brings a brand-new and effective solution to the field of information security. Brief Description of the Drawings

[0050] In order to more clearly illustrate the technical solutions in the embodiments of the present invention or the prior art, the following will briefly introduce the drawings required for use in the description of the embodiments or the prior art. Obviously, the drawings in the following description are only some embodiments of the present invention, and for those of ordinary skill in the art, other drawings can be obtained based on these drawings without creative efforts.

[0051] Figure 1 It is a schematic structural diagram of a secure communication system based on quantum key distribution. Detailed Embodiments

[0052] To make the objectives, technical solutions, and advantages of the embodiments of the present invention clearer, the following will clearly and completely describe the technical solutions in the embodiments of the present invention with reference to the drawings in the embodiments of the present invention. Obviously, the described embodiments are some, but not all, of the embodiments of the present invention. All other embodiments obtained by those of ordinary skill in the art based on the embodiments of the present invention without creative efforts fall within the scope of protection of the present invention.

[0053] The following further describes the present invention with reference to the embodiments.

[0054] Embodiment:

[0055] A secure communication system based on quantum key distribution in this embodiment, as Figure 1 shown, includes:

[0056] A key generation module, used to generate quantum keys and synchronously forward the currently generated quantum keys to the distribution module;

[0057] The key generation module is integrated with a quantum light source. The quantum light source adopts a single-photon source, and the probability of generating a single photon is not less than 95%;

[0058] Among them, the probability calculation formula for the quantum light source to generate a single photon is:

[0059]

[0060] In the formula: P sp is the probability of generating a single photon; N sp is the actual number of single photons generated; N total is the total number of photons emitted by the light source;

[0061] The calculation formula for the probability of generating single photons by the quantum light source is defined by the above logical formula;

[0062] A distribution module, which is used to receive the quantum key generated by the key generation module, distribute the quantum key to the two communicating users, synchronously detect the transmission quality of the quantum signal, and monitor whether there is any eavesdropping behavior;

[0063] During the operation stage of the distribution module, quantum channel is adopted for quantum key distribution. During the quantum key distribution process, the BB84 protocol is applied, and the secure transmission of the key is realized by encoding and decoding quantum states such as the polarization state or phase of photons;

[0064] During the operation stage of the distribution module, based on the decoy state quantum key distribution, signal state photons and decoy state photons are simultaneously transmitted in the quantum channel to monitor the eavesdropping probability:

[0065]

[0066] In the formula: P e is the eavesdropping probability; N′ d is the number of decoy state photons actually detected; N b is the false count caused by background noise; e e is the additional interference bit error rate introduced by the eavesdropper; N d is the theoretical detection number of decoy state photons under the assumption of no eavesdropping; ν is the intensity parameter of the decoy state photons; μ is the intensity parameter of the signal state photons;

[0067] Among them, the eavesdropping probability P e After calculation, it is synchronously compared with the preset eavesdropping determination threshold in the distribution module to determine whether there is any eavesdropping behavior;

[0068] The detection logic of the transmission quality of the quantum signal in the distribution module is expressed as:

[0069]

[0070] In the formula: Q is the performance value of the transmission quality of the quantum signal; α, β, γ, δ are weight coefficients, and satisfy α + β + γ + δ = 1; BER is the bit error rate; F is the quantum state fidelity; SNR is the signal-to-noise ratio; SNR max is the preset maximum signal-to-noise ratio; C is the entanglement degree;

[0071] Among them, after the performance value Q of the transmission quality of the quantum signal is calculated, it is synchronously compared with the preset security determination threshold in the distribution module to determine whether the transmission of the quantum signal is secure;

[0072] The calculation method of the wiretapping probability is defined by the above logical formula, which provides support for the triggering and operation of the system modules in this embodiment, ensures the secure operation of the system, and secures the encrypted data transmission environment;

[0073] When the wiretapping behavior determination result obtained by the distribution module operation is no, and the transmission determination results of the quantum signals are all secure, the encryption module is triggered to operate. Otherwise, the operations of detection and monitoring in the distribution module are repeatedly refreshed until the conditions for triggering the operation of the encryption module are met;

[0074] The encryption module is used to receive the plaintext data from the sender, and uses the quantum key and the one-time pad encryption algorithm to encrypt the plaintext data and convert the plaintext into ciphertext;

[0075] The operation steps for converting the plaintext into ciphertext during the operation stage of the encryption module are as follows:

[0076] S1: Data preparation: Convert the plaintext data M into binary format, obtain the current timestamp T, and process it through a hash function to get H(T);

[0077] S2: Preliminary exclusive OR operation: Perform an exclusive OR operation on the plaintext data M and the quantum key K bit by bit to obtain an intermediate result M⊕K;

[0078] S3: Perform an exclusive OR operation on the intermediate result M⊕K and H(T) bit by bit to finally obtain the ciphertext C;

[0079] Among them, the quantum key K is in binary form, and its length should be the same as the length of the plaintext data. H(T) represents the result obtained after hashing the timestamp T;

[0080] The transmission module is used to transmit the encrypted data from the sender to the receiver using a communication channel, and optimize the data transmission process on the communication channel during the transmission;

[0081] Before data transmission, the transmission module performs a redundancy check calculation on the obtained ciphertext C:

[0082] R = C mod G(x);

[0083] In the formula: R is the redundancy check code; G(x) is the generating polynomial;

[0084] Among them, after calculating the redundancy check code R, it is combined with the ciphertext C, and any one of the error correction coding methods such as Hamming code, Reed-Solomon code, and convolutional code is used to perform coding processing on it. After the receiver receives the data, the redundancy check code and error correction coding are used to check and correct the data;

[0085] A scheduling unit is set under the transmission module, and the transmission module combines the scheduling unit to optimize the data transmission process on the communication channel;

[0086] The scheduling unit is used to calculate the data scheduling weight according to the preset priority, timeliness of the data and the real-time state parameters of the communication channel, and apply the data scheduling weight to dynamically adjust the transmission rate and order of the encrypted data;

[0087] The data scheduling weight calculation logic in the scheduling unit is expressed as:

[0088]

[0089] In the formula: ω1, ω2, ω3, ω4, ω5 are weights, and P i is the priority of data i; T i is the timeliness requirement of data i; B is the real-time bandwidth of the channel; D is the channel delay; S i is the size of data i; L is the packet loss rate of the channel;

[0090] Among them, ω1, ω2, ω3, ω4, ω5 are all positive numbers, and the sum of them is 1. The larger the scheduling weight W i of data i, the faster the transmission rate and the more forward the transmission order;

[0091] The data scheduling weight is calculated through the above logical formula to realize the reasonable regulation of the data transmission rate and transmission order;

[0092] The decryption module is used to receive the ciphertext data transmitted by the transmission module, decrypt it based on the same quantum key as the sender according to the inverse operation of the encryption algorithm, and restore the ciphertext to the original plaintext data;

[0093] A key verification mechanism is set in the decryption module:

[0094] Let the received quantum key be K r , the hash value obtained by calculating the key feature information pre-shared by the sender through the hash function H is H(K s ), the hash value calculated by the receiver for K r is H(K r ). If the formula:

[0095] H(K r ) = H(K s );

[0096] Then it is determined that the key verification passes. Before performing the decryption operation, the received quantum key is first verified. By comparing with the key feature information pre-shared by the sender, the correctness and integrity of the key are confirmed. If the key verification fails, the decryption operation is rejected and the key re-distribution process is triggered;

[0097] Among them, the key feature information includes at least the key length, hash value, and format;

[0098] The message module is used to record the operation information of the distribution module and the transmission module, generate a message based on the operation information of the distribution module and the transmission module, and retransmit the generated message to a preset cloud database for storage;

[0099] Quantum relay technology is adopted between the key generation module and the distribution module. When the transmission distance of the quantum channel is too long and the quantum signal attenuation is serious, the quantum repeater processes and forwards the quantum signal to extend the distribution distance of the quantum key and expand the application scope of the system;

[0100] The system supports the multi-user communication mode. By allocating independent quantum keys and communication identifiers to each user, secure communication between multiple users is achieved;

[0101] The key generation module is connected to the distribution module and the encryption module through network interaction. The encryption module is connected to the transmission module through network interaction. The lower level of the transmission module is connected to the scheduling unit and the maintenance unit through network interaction. The transmission module is connected to the decryption module and the message module through network interaction. The message module is connected to the distribution module and the transmission module through the network.

[0102] In this embodiment, the operation of the system effectively solves the problems of communication security and transmission efficiency. Quantum keys are generated based on a single-photon source, and eavesdropping is monitored by combining the BB84 protocol and the decoy state technology to ensure communication security; redundant check, error correction coding, and the scheduling unit are used to optimize transmission to improve transmission reliability and efficiency; quantum relay technology expands the application scope and also supports multi-user communication, effectively enhancing the security and efficiency of communication and meeting the communication requirements of multiple scenarios;

[0103] During the system operation phase, the key generation module runs to generate quantum keys and forwards the currently generated quantum keys to the distribution module synchronously. The distribution module runs later to receive the quantum keys generated in the key generation module, distributes the quantum keys to the two communicating users, synchronously detects the transmission quality of the quantum signals, and monitors for eavesdropping behavior. The encryption module further receives the plaintext data from the sender, uses the quantum key and the one-time pad encryption algorithm to encrypt the plaintext data, converts the plaintext into ciphertext, and then the transmission module uses the communication channel to transmit the encrypted data from the sender to the receiver. During the transmission process, it optimizes the transmission process of the data on the communication channel. The scheduling unit synchronously calculates the data scheduling weight based on the preset priority, timeliness of the data, and the real-time state parameters of the communication channel, and applies the data scheduling weight to dynamically adjust the transmission rate and order of the encrypted data. The decryption module further receives the ciphertext data transmitted by the transmission module, performs a decryption operation based on the same quantum key as the sender according to the inverse operation of the encryption algorithm, restores the ciphertext to the original plaintext data, and finally the message module records the operation information of the distribution module and the transmission module, generates a message based on the operation information of the distribution module and the transmission module, and transfers the generated message to a preset cloud database for storage.

[0104] In summary, in the above embodiments, the system generates highly random and secure keys by utilizing the characteristics of quantum mechanics, fundamentally ensuring the confidentiality of communication. Its key generation method is based on the unique properties of quantum states, making the keys difficult to be cracked or stolen. In the key distribution link, technologies such as decoy states are used to detect eavesdropping behavior in real time to ensure the security of key transmission. When encrypting data, a timestamp mechanism is introduced, and the encryption results of the same plaintext are different at different times, effectively resisting replay attacks. During the data transmission process, redundant checks, error correction coding, and innovative scheduling algorithms are used to ensure accurate and efficient data transmission, reduce the bit error rate, and improve the transmission efficiency. In addition, the system supports multi-user communication and sets up a security management center to achieve fine management of user permissions, can promptly respond to various security threats, greatly expand the application scenarios and security reliability of the system, and bring a new and effective solution to the field of information security.

[0105] The above embodiments are only used to illustrate the technical solutions of the present invention and are not intended to limit them. Although the present invention has been described in detail with reference to the foregoing embodiments, those of ordinary skill in the art should understand that they can still modify the technical solutions described in the foregoing embodiments, or perform equivalent replacements for some of the technical features; and these modifications or replacements will not cause the essence of the corresponding technical solutions to deviate from the spirit and scope of the technical solutions of the various embodiments of the present invention.

Claims

1. A secure communication system based on quantum key distribution, characterized in that, It includes: A key generation module, which is used to generate quantum keys and synchronously forward the currently generated quantum keys to the distribution module; A distribution module, which is used to receive the quantum keys generated in the key generation module, distribute the quantum keys to the two communicating users, synchronously detect the transmission quality of the quantum signals, and monitor whether there is any eavesdropping behavior; An encryption module, which is used to receive the plaintext data from the sender, use the quantum key and the one-time pad encryption algorithm to encrypt the plaintext data, and convert the plaintext into ciphertext; A transmission module, which is used to transmit the encrypted data from the sender to the receiver using the communication channel, and optimize the transmission process of the data on the communication channel during the transmission; A decryption module, which is used to receive the ciphertext data transmitted by the transmission module, perform decryption operations based on the same quantum key as the sender according to the inverse operation of the encryption algorithm, and restore the ciphertext to the original plaintext data; A message module, which is used to record the operation information of the distribution module and the transmission module, generate messages based on the operation information of the distribution module and the transmission module, and transfer the generated messages to a preset cloud database for storage.

2. The secure communication system based on quantum key distribution according to claim 1, characterized in that, The key generation module is integrated with a quantum light source, the quantum light source adopts a single-photon source, and the probability of generating single photons is not less than 95%; Among them, the probability calculation formula for the quantum light source to generate single photons is: Where: P sp is the probability of single-photon generation; N sp is the actual number of single photons generated; N total is the total number of photons emitted by the light source.

3. A secure communication system based on quantum key distribution according to claim 1, characterized in that, During the operation stage of the distribution module, a quantum channel is used for quantum key distribution. During the quantum key distribution process, the BB84 protocol is applied, and the security transmission of the key is realized by encoding and decoding quantum states such as the polarization state or phase of photons; During the operation stage of the distribution module, synchronously based on the decoy-state quantum key distribution, signal-state photons and decoy-state photons are simultaneously transmitted in the quantum channel to monitor the eavesdropping probability: Where: P e is the eavesdropping probability; N′ d is the number of decoy state photons actually detected; N b is the false count caused by background noise; e e is the additional interference bit error rate introduced by the eavesdropper; N d is the theoretical detection number of decoy state photons under the assumption of no eavesdropping; ν is the intensity parameter of the decoy state photons; μ is the intensity parameter of the signal state photons; Among them, the wiretapping probability P e After calculation, it is compared with the preset wiretapping determination threshold in the synchronization and distribution module to determine whether there is a wiretapping behavior.

4. A secure communication system based on quantum key distribution according to claim 1, characterized in that The detection logic of the transmission quality of the quantum signals in the distribution module is expressed as: In the formula: Q is the transmission quality performance value of the quantum signal; α, β, γ, δ are weight coefficients, and satisfy α + β + γ + δ = 1; BER is the bit error rate; F is the quantum state fidelity; SNR is the signal-to-noise ratio; SNR max is the preset maximum signal-to-noise ratio; C is the entanglement degree; Among them, after calculating the transmission quality performance value Q of the quantum signal, it is synchronously compared with the preset security determination threshold in the distribution module to determine whether the transmission of the quantum signal is secure; When the eavesdropping behavior determination result obtained during the operation of the distribution module is no, and the transmission determination results of the quantum signals are all secure, the encryption module is triggered to run. Otherwise, the operations of detection and monitoring in the distribution module are repeatedly refreshed until the conditions for triggering the encryption module to run are met.

5. A secure communication system based on quantum key distribution according to claim 1, characterized in that, The operation steps for converting the plaintext into ciphertext during the operation stage of the encryption module are: S1: Data preparation: Convert the plaintext data M into a binary format, obtain the current timestamp T, and process it through a hash function to get H(T); S2: Preliminary exclusive OR operation: Perform an exclusive OR operation on the plaintext data M and the quantum key K bit by bit to obtain an intermediate result M ⊕ K; S3: Perform an exclusive OR operation on the intermediate result M ⊕ K and H(T) bit by bit to finally obtain the ciphertext C; Among them, the quantum key K is in binary form, and its length should be the same as the length of the plaintext data. H(T) represents the result obtained after performing a hash process on the timestamp T.

6. A secure communication system based on quantum key distribution according to claim 5, characterized in that, Before data transmission, the transmission module performs a redundancy check calculation on the ciphertext C obtained after encryption: R = C mod G(x); In the formula: R is the redundancy check code; G(x) is the generating polynomial; Among them, after calculating the redundancy check code R, it is combined with the ciphertext C, and any one of the error correction coding methods such as Hamming code, Reed-Solomon code, and convolutional code is used to perform coding processing on it. After the receiver receives the data, the redundancy check code and error correction coding are used to check and correct the data.

7. A secure communication system based on quantum key distribution according to claim 1, characterized in that, A scheduling unit is set below the transmission module, and the transmission module combines with the scheduling unit to optimize the data transmission process on the communication channel; The scheduling unit is used to calculate the data scheduling weight according to the preset priority, timeliness of the data and the real-time state parameters of the communication channel, and apply the data scheduling weight to dynamically adjust the transmission rate and order of the encrypted data; The data scheduling weight calculation logic in the scheduling unit is expressed as: Where: ω1, ω2, ω3, ω4, ω5 are weights; P i is the priority of data i; T i is the timeliness requirement of data i; B is the real-time bandwidth of the channel; D is the channel delay; S i is the size of data i; L is the packet loss rate of the channel; Among them, ω1, ω2, ω3, ω4, and ω5 are all positive numbers, and their sum is 1. The scheduling weight W of data i i is larger, then the transmission rate is faster and the transmission order is more forward.

8. A secure communication system based on quantum key distribution according to claim 1, characterized in that, A key verification mechanism is set in the decryption module: Let the received quantum key be K r , the hash value obtained by calculating the key feature information pre-shared by the sender through the hash function H is H(K s ), and the hash value calculated by the receiver for K r is H(K r ). If the following formula is satisfied: H(K r ) = H(K s ); Then it is determined that the key verification is passed. Before performing the decryption operation, the received quantum key is first verified. By comparing it with the pre-shared key feature information of the sender, the correctness and integrity of the key are confirmed. If the key verification fails, the decryption operation is rejected and the key re-distribution process is triggered; Among them, the key feature information includes at least the key length, hash value, and format.

9. A secure communication system based on quantum key distribution according to claim 1, characterized in that, Quantum relay technology is adopted between the key generation module and the distribution module. When the transmission distance of the quantum channel is too long and the quantum signal attenuation is serious, the quantum repeater processes and forwards the quantum signal, extending the distribution distance of the quantum key and expanding the application scope of the system; The system supports the multi-user communication mode, and realizes secure communication between multiple users by allocating independent quantum keys and communication identifiers to each user.

10. A secure communication system based on quantum key distribution according to claim 1, characterized in that, The key generation module is connected to the distribution module and the encryption module through network interaction. The encryption module is connected to the transmission module through network interaction. The lower level of the transmission module is connected to the scheduling unit and the maintenance unit through network interaction. The transmission module is connected to the decryption module and the message module through network interaction. The message module interacts with the distribution module and the transmission module through the network.

Citation Information

Patent Citations

  • A secure encrypted communication method and system based on quantum key management

    CN119316138B

  • One-time pad transmission system for measurement and control signals between transformer stations based on quantum key distribution

    CN102820968A

  • Unmanned aerial vehicle communication system based on quantum security policy

    CN117857038A

  • Optical fiber safety communication method and system based on quantum technology

    CN118573372A

  • Quantum secure direct communication method and apparatus based on one-way transmission, device and system

    US20240322914A1

Cited By

  • Channel eavesdropping monitoring method and system

    CN122092984A