Quantum key communication method and device and related equipment

By using quantum random number generators to generate and store random number sequences in the quantum key distribution network, the capacity of the quantum key pool is expanded, the problem of insufficient quantum key generation rate is solved, and the security and efficiency improvement of large-scale data protection is achieved.

CN120378099AActive Publication Date: 2025-07-25CHINA TELECOM CORP LTD TECHNOLOGY INNOVATION CENTER +1

Patent Information

Application Number
CN202510705148.3
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-05-28
Publication Date
2025-07-25
Estimated Expiration
2045-05-28

AI Technical Summary

Technical Problem

The existing quantum key generation rate is limited, which is difficult to meet the needs of large-scale data protection, and classical cryptographic systems have the risk of being cracked when facing quantum computing.

Method used

Random number sequences are generated by quantum random number generators and stored in the local quantum key pool. The random number sequences are encrypted and decrypted using quantum key distribution networks to expand the capacity of the quantum key pool to meet the needs of large-scale data protection.

Benefits of technology

The number of available quantum keys available for data protection is increased, which meets the needs of large-scale data protection and improves the security and efficiency of data transmission.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120378099A_ABST
    Figure CN120378099A_ABST
Patent Text Reader

Abstract

The invention provides a quantum key communication method and device and related equipment, and relates to the technical field of network security. The method comprises the following steps: a first device starts a quantum random number generator to generate a first random number sequence, and stores the first random number sequence to a first local quantum key pool of the first device; the first device encrypts the first random number sequence by using the first quantum key to generate an encrypted random number data packet, and sends the encrypted random number data packet to the second device, so that the second device decrypts the encrypted random number data packet based on the first quantum key to obtain a first random number sequence, the first random number sequence is stored in a second local quantum key pool of the second device, and the first quantum key is distributed to the first device and the second device through a quantum key distribution network. According to the method and the device, the large-scale data protection requirement can be met by increasing the number of the available quantum keys for data protection.
Need to check novelty before this filing date? Find Prior Art

Description

Background Art

[0002] In today's digital age, data security is of utmost importance. As a key means to ensure data security, cryptographic techniques are widely used. Cryptographic techniques are adopted to ensure data security because they can perform operations such as encrypting and authenticating data, preventing data leakage and tampering. Among them, asymmetric cryptography is used for identity authentication and key exchange, and symmetric cryptography is used for data encryption. However, due to the threat of quantum computing to the classical cryptographic systems it relies on, there is a risk of being cracked, resulting in the inability to guarantee data confidentiality and integrity.

[0003] Therefore, quantum key technology is widely applied to data security protection. Quantum key technology generates and distributes keys using the principles of quantum mechanics, has unconditional security, and can effectively guarantee data security. However, the generation of quantum keys is restricted by physical conditions, resulting in a limited generation rate. The limited number of quantum keys is difficult to meet the needs of large-scale data protection.

[0004] It should be noted that the information disclosed in the above background art section is only used to enhance the understanding of the background of the present disclosure, and thus may include information that does not constitute the prior art known to those of ordinary skill in the art. Summary of the Invention

[0005] The present disclosure provides a quantum key communication method, apparatus, and related devices, which can meet the needs of large-scale data protection.

[0006] Other features and advantages of the present disclosure will become apparent through the following detailed description, or be learned in part through the practice of the present disclosure.

[0007] According to one aspect of the present disclosure, there is provided a quantum key communication method, the method including: a first device starts a quantum random number generator to generate a first random number sequence, and stores the first random number sequence in a first local quantum key pool of the first device; the first device encrypts the first random number sequence using a first quantum key to generate an encrypted random number data packet, and sends the encrypted random number data packet to a second device, so that the second device decrypts the encrypted random number data packet based on the first quantum key to obtain the first random number sequence, and stores the first random number sequence in a second local quantum key pool of the second device, wherein the first quantum key is distributed to the first device and the second device through a quantum key distribution network.

[0008] In some embodiments, the first random number sequence is used to encrypt service data when the first device or the second device acts as a sender to transmit service data; and decrypt service data when the first device or the second device acts as a receiver to transmit service data.

[0009] In some embodiments, encrypting the service data includes: obtaining the transmission rate of the service data; when the transmission rate is greater than a preset transmission rate, encrypting the service data by using the first random number sequence.

[0010] In some embodiments, encrypting the service data by using the first random number sequence includes: obtaining the identification information of the first random number sequence, where the identification information is used to indicate the unique number of the first random number sequence and the starting position of the first random number sequence; encrypting the service data according to the unique number of the first random number sequence and the starting position of the first random number sequence to generate an encrypted service data packet.

[0011] In some embodiments, decrypting the service data includes: obtaining the encrypted service data packet; parsing the encrypted service data packet to obtain the unique number of the first random number sequence and the starting position of the first random number sequence; decrypting the encrypted service data in the encrypted service data packet according to the unique number of the first random number sequence and the starting position of the first random number sequence to obtain the service data.

[0012] In some embodiments, the method further includes: obtaining a validity identifier for indicating the first random number sequence; when the validity identifier of the first random number sequence meets a preset condition, deleting the first random number sequence.

[0013] In some embodiments, the validity identifier for indicating the first random number sequence is the first timestamp when the first random number sequence is generated, and when the validity identifier of the first random number sequence meets a preset condition, deleting the first random number sequence includes: obtaining a second timestamp for indicating the current time; determining a time difference according to the first timestamp and the second timestamp; when the time difference is greater than a preset time difference, deleting the first random number sequence.

[0014] In some embodiments, if the first device and the second device are connected in a mesh networking mode, in response to the first device transmitting service data, the first device starts a quantum random number generator to generate a first random number sequence, and stores the first random number sequence in a first local quantum key pool of the first device; if the first device and the second device are connected in a central networking mode, when there is no service data transmission between the first device and the second device, the first device starts a quantum random number generator to generate a first random number sequence, and stores the first random number sequence in a first local quantum key pool of the first device.

[0015] According to another aspect of the present disclosure, there is also provided a quantum key communication device, which includes: a generating module, configured to start a quantum random number generator by a first device to generate a first random number sequence, and store the first random number sequence in a first local quantum key pool of the first device; a sending module, configured to encrypt the first random number sequence by the first device using a first quantum key to generate an encrypted random number data packet, and send the encrypted random number data packet to a second device, so that the second device decrypts the encrypted random number data packet based on the first quantum key to obtain the first random number sequence, and store the first random number sequence in a second local quantum key pool of the second device, wherein the first quantum key is distributed to the first device and the second device through a quantum key distribution network.

[0016] According to another aspect of the present disclosure, there is also provided an electronic device, which includes: a processor; and a memory, configured to store executable instructions of the processor; wherein, the processor is configured to execute the quantum key communication method according to any one of the above by executing the executable instructions.

[0017] According to another aspect of the present disclosure, there is also provided a computer-readable storage medium, on which a computer program is stored, and the computer program realizes the quantum key communication method according to any one of the above when being executed by a processor.

[0018] According to another aspect of the present disclosure, there is also provided a computer program product, including: a computer program or instruction, and the computer program or instruction realizes the quantum key communication method according to any one of the above when being executed by a processor.

[0019] A quantum key communication method, device and related equipment provided in an embodiment of the present disclosure, the method includes: starting, by a first device, a quantum random number generator to generate a first random number sequence, and storing the first random number sequence in a first local quantum key pool of the first device; encrypting, by the first device, the first random number sequence using a first quantum key to generate an encrypted random number data packet, and sending the encrypted random number data packet to a second device, so that the second device decrypts the encrypted random number data packet based on the first quantum key to obtain the first random number sequence, and stores the first random number sequence in a second local quantum key pool of the second device, wherein the first quantum key is distributed to the first device and the second device through a quantum key distribution network. By continuously generating a large number of random number sequences with the help of a quantum random number generator, encrypting and transmitting the random number sequences using a quantum key and decrypting and storing them at the receiving end, the number of available quantum keys for data protection is indirectly increased, meeting the requirements for large-scale data protection.

[0020] It should be understood that the above general description and subsequent detailed description are only exemplary and explanatory, and cannot limit the present disclosure. BRIEF DESCRIPTION OF THE DRAWINGS

[0021] The drawings herein are incorporated into and constitute a part of this specification, showing embodiments consistent with the present disclosure, and are used together with the specification to explain the principles of the present disclosure. Obviously, the drawings in the following description are only some embodiments of the present disclosure, and those of ordinary skill in the art can obtain other drawings based on these drawings without creative efforts.

[0022] Figure 1 Schematic diagram showing the system architecture of a quantum key communication method in an embodiment of the present disclosure;

[0023] Figure 2 Schematic diagram showing the system architecture of another quantum key communication method in an embodiment of the present disclosure;

[0024] Figure 3 Schematic diagram showing a quantum key communication system in an embodiment of the present disclosure;

[0025] Figure 4 Flowchart showing a quantum key communication method in an embodiment of the present disclosure;

[0026] Figure 5A Schematic diagram showing a system for encrypting service data in an embodiment of the present disclosure;

[0027] Figure 5B Flowchart showing a method for encrypting service data in an embodiment of the present disclosure;

[0028] Figure 6 Flowchart showing a quantum key communication method in an embodiment of the present disclosure;

[0029] Figure 7 Schematic diagram showing encrypting service data based on a first random number sequence in an embodiment of the present disclosure;

[0030] Figure 8 Flowchart showing a method for decrypting service data in an embodiment of the present disclosure;

[0031] Figure 9 Flowchart showing a quantum key communication method in an embodiment of the present disclosure;

[0032] Figure 10 Schematic diagram showing a group-based quantum key communication system in an embodiment of the present disclosure;

[0033] Figure 11 Schematic diagram showing a group-based quantum key communication system in an embodiment of the present disclosure;

[0034] Figure 12Schematic diagram of a quantum key communication device in an embodiment of the present disclosure;

[0035] Figure 13 Block diagram of the structure of an electronic device in an embodiment of the present disclosure. Detailed implementation manners

[0036] Example embodiments will now be described more fully with reference to the accompanying drawings. However, the example embodiments can be implemented in various forms and should not be construed as limited to the examples set forth herein; rather, these embodiments are provided so that this disclosure will be more complete and comprehensive, and will fully convey the concept of the example embodiments to those skilled in the art. The features, structures, or characteristics described may be combined in any suitable manner in one or more embodiments.

[0037] In addition, the accompanying drawings are only schematic illustrations of the present disclosure and are not necessarily drawn to scale. The same reference numerals in the drawings denote the same or similar parts, and thus repeated descriptions thereof will be omitted. Some of the block diagrams shown in the drawings are functional entities and do not necessarily correspond to physically or logically independent entities. These functional entities may be implemented in software form, or in one or more hardware modules or integrated circuits, or in different networks and / or processor devices and / or microcontroller devices.

[0038] For ease of understanding, before introducing the embodiments of the present disclosure, several terms involved in the embodiments of the present disclosure are first explained as follows:

[0039] Quantum Key Distribution Network (QKDN): Ensures communication security based on the characteristics of quantum mechanics. Characteristics of quantum mechanics such as the superposition of quantum states and the uncertainty principle make it difficult for eavesdroppers to obtain key information without being detected. In QKDN, the two communicating parties rely on the quantum channel and use quantum carriers such as single photons to generate keys. Due to the unique properties of quantum, once a third party attempts to eavesdrop, the quantum state will change, and the two communicating parties can immediately detect it. At the same time, QKDN also includes a classical channel, which is used to assist in information interaction and key negotiation and other operations. After generating and sharing a random and secure key through the quantum channel, the two communicating parties use this key to encrypt and decrypt messages, thereby ensuring the security of the communication process and effectively resisting potential eavesdropping and attacks.

[0040] Quantum Random Number Generator (QRNG): Generates true random numbers based on the principles of quantum physics. In the quantum world, the states of microscopic particles are uncertain. For example, a quantum bit (qubit) can be in the state of 0, 1, or a superposition of both, and its measurement result is unpredictable. QRNG utilizes this quantum property to generate random numbers. When measuring a quantum system, the result obtained each time is random and is not affected by previous or subsequent measurements, thus ensuring the "true" randomness of the random numbers. Different from traditional random number generators, traditional methods are often based on algorithms or physical processes and may have certain patterns or predictability. However, QRNG is based on the fundamental principles of quantum mechanics and can provide random numbers with higher security and unpredictability.

[0041] The following will describe in detail the specific implementation manners of the embodiments of the present disclosure with reference to the accompanying drawings.

[0042] Figure 1 FIG. shows an exemplary application system architecture diagram to which the quantum key communication method in the embodiments of the present disclosure can be applied. As Figure 1 shown, the system architecture may include a terminal device 101, a network 102, a server 103, and a quantum random number generator 104.

[0043] The network 102 is used to provide a medium for the communication link between the terminal device 101 and the server 103, and can be a wired network or a wireless network.

[0044] Optionally, the above-mentioned wireless network or wired network uses standard communication technologies and / or protocols. The network is usually the Internet, but can also be any network, including but not limited to any combination of a local area network (LAN), a metropolitan area network (MAN), a wide area network (WAN), a mobile, wired or wireless network, a private network or a virtual private network). In some embodiments, technologies and / or formats including Hypertext Mark-up Language (HTML), Extensible Markup Language (XML), etc. are used to represent the data exchanged through the network. In addition, conventional encryption technologies such as Secure Socket Layer (SSL), Transport Layer Security (TLS), Virtual Private Network (VPN), Internet Protocol Security (IPSec), etc. can be used to encrypt all or some of the links. In other embodiments, customized and / or dedicated data communication technologies can also be used to replace or supplement the above data communication technologies.

[0045] The terminal device 101 can be various electronic devices, including but not limited to smartphones, tablets, laptop computers, desktop computers, smart speakers, smart watches, wearable devices, augmented reality devices, virtual reality devices, etc.

[0046] Optionally, the clients of the application programs installed in different terminal devices 101 are the same, or the clients of the same type of application programs based on different operating systems. Depending on the different terminal platforms, the specific form of the client of the application program can also be different. For example, the client of the application program can be a mobile client, a PC client, etc.

[0047] The server 103 can be a quantum key distribution network server. The quantum key distribution network server can act as a node in the network and is responsible for processing the distribution, management and storage of quantum keys. On the one hand, it needs to communicate with other nodes in the network (such as user terminals, other servers) to achieve efficient key transmission. On the other hand, it is necessary to ensure the security and integrity of the keys to prevent them from being stolen or tampered with. The server 103 has the corresponding hardware and software conditions and can support the operation of protocols and algorithms related to quantum key distribution. By working in cooperation with other related devices, a complete quantum key distribution network is built to provide secure communication guarantees for users.

[0048] Optionally, the server can be an independent physical server, a server cluster or a distributed system composed of multiple physical servers, or a cloud server.

[0049] The quantum random number generator 104 can be a device that generates truly random numbers based on quantum physical processes. The generated random numbers are used to provide high-entropy seeds for encryption operations in the system, such as key generation, initialization vector generation, and selection of asymmetric encryption parameters. In this embodiment, the quantum random number generator 104 is used to generate quantum random numbers. In quantum key communication, random numbers are crucial as they provide high randomness for key generation, enhancing the security and unpredictability of the keys, and cooperating with other parts to ensure the secure and efficient quantum key communication.

[0050] Optionally, the quantum random number generator 104 can be directly connected to the terminal through a physical interface (such as a Universal Serial Bus (USB) interface, a Peripheral Component Interconnect Express (PCIe) interface, or other high-speed interfaces). This method can ensure low latency and high security of data transmission because the data does not need to pass through an external network, reducing the risk of being intercepted. If the quantum random number generator 104 needs to be placed at a location far from the terminal, it can be connected through a Local Area Network (LAN). This configuration is suitable for the case where the quantum random number generator 104 serves multiple terminals, allowing resource sharing. However, this method requires ensuring the security of the network to prevent data from being eavesdropped during transmission. For applications with extremely high security requirements, even within the same LAN, a dedicated secure channel can be established to transmit random numbers to add an extra layer of security.

[0051] Those skilled in the art can understand that Figure 1 the numbers of the terminal devices, networks, servers, and quantum random number generators in

[0052] Figure 2 are merely illustrative. According to actual needs, there can be any number of terminal devices, networks, and servers. The embodiments of the present disclosure do not limit this. Figure 2 shows a schematic diagram of an exemplary application system architecture to which the quantum key communication method in the embodiments of the present disclosure can be applied. As

[0053] The cryptographic machine 105 is a hardware device specifically designed for encryption operations and key management, deployed on the terminal device 101. It provides functions such as secure storage, invocation, and management of quantum keys, ensuring the security of the quantum key pool.

[0054] Optionally, the cryptographic machine 105 can be connected to the terminal device through an internal local area network or a wider wide area network. This method allows the terminal device to be flexibly placed within a certain range without the need for a direct physical proximity to the cryptographic machine. When connected through a network, an encrypted communication protocol (such as TLS / SSL) is usually adopted to ensure the security of data transmission and prevent key information from being eavesdropped or tampered with during network transmission. In some scenarios with high security requirements, the cryptographic machine 105 may be directly connected to the terminal device through a physical interface (such as USB, serial port, PCIe, etc.). This connection method reduces intermediate links and theoretically provides a higher level of security. For terminal devices with extremely high security requirements and relatively fixed physical locations, direct connection may be a better choice.

[0055] Those skilled in the art can be aware that Figure 2 the number of terminal devices, networks, servers, and quantum random number generators in

[0056] is merely illustrative. According to actual needs, there can be any number of terminal devices, networks, and servers. The embodiments of the present disclosure do not limit this.

[0057] Under the above system architecture, an embodiment of the present disclosure provides a quantum key communication method, which can be executed by any electronic device with computing and processing capabilities.

[0058] Figure 3 is a schematic diagram of a quantum key communication system provided by an embodiment of the present disclosure. Figure 4 shows a flowchart of a quantum key communication method in an embodiment of the present disclosure. Combining Figure 3 、 Figure 4 as shown, the quantum key communication method provided by an embodiment of the present disclosure includes the following steps:

[0059] S402, the first device starts the quantum random number generator to generate a first random number sequence and stores the first random number sequence in the first local quantum key pool of the first device.

[0060] In this embodiment, the first device refers to a terminal device participating in the construction of a quantum key pool, which may include mobile phones, tablet computers, laptop computers, desktop computers, smart watches, smart bracelets, smart glasses, in-vehicle terminals of smart cars, control terminals of smart home appliances, sensor node devices in industrial Internet of Things, security monitoring cameras, drones, etc. A quantum random number generator is a device that generates true random numbers based on the principles of quantum mechanics. Its output has unpredictability and unbiasedness, and its security far exceeds that of classical pseudo-random number generators. The first random number sequence refers to a set of true random numbers generated by the quantum random number generator, which is used to expand the capacity of the quantum key pool. Its length and update frequency are dynamically adjusted according to system security requirements. The first local quantum key pool refers to a secure storage area in the first device for storing random number sequences. The random numbers in the key pool can be dynamically called as preliminary keys or encryption seeds for subsequent communication.

[0061] The quantum random number generator can be equipped on the first device in an integrated manner or in an external connection manner; the quantum random number generator can be connected to the first device through a physical interface or through a network. The embodiments of the present disclosure do not limit the manner in which the quantum random number generator is equipped on the first device.

[0062] Refer to Figure 3 As shown, the first device can be terminal A or terminal B. Taking the first device being terminal A as an example, terminal A starts the quantum random number generator equipped on itself, generates the first random number sequence, and then stores the first random number sequence in its own first local quantum key pool, providing expandable key resources for the first local quantum key pool. It can be understood that the first local quantum key pool is a dynamic key pool.

[0063] In some embodiments, to enhance the security and management efficiency of the first quantum key pool, a dedicated cryptographic machine can be deployed beside the first devices such as terminal A and terminal B. The cryptographic machine is connected to the terminal device through a secure interface (such as PCIe or an intranet dedicated line) to achieve the secure storage and efficient management of the quantum key pool; inside the cryptographic machine, a hardware-level encryption chip (such as TPM 2.0) and a physically isolated storage area are used to protect the random number sequence in the first local quantum key pool, and the key access permission is restricted through a multi-factor authentication mechanism. At the same time, a key scheduling engine is built in to dynamically extract random numbers on demand and convert them into directly usable encryption keys, supporting key lifecycle management and automatically triggering the QRNG to supplement new keys.

[0064] In some embodiments, the cryptographic machine can be directly connected to a quantum random number generator (QRNG), receive and verify the generated random numbers in real time and then store them in the key pool to ensure continuous key update, achieve high-speed one-time pad encryption, and break through the bandwidth limitation of the QKD network.

[0065] S404, the first device encrypts the first random number sequence using the first quantum key to generate an encrypted random number data packet and sends it to the second device, so that the second device decrypts the encrypted random number data packet based on the first quantum key to obtain the first random number sequence and stores the first random number sequence in the second local quantum key pool of the second device, where the first quantum key is distributed to the first device and the second device through a quantum key distribution network.

[0066] In this embodiment, the first quantum key is a shared key negotiated and generated between the first device and the second device through a quantum key distribution network, which has information-theoretic security and can resist computational attacks and eavesdropping. The encrypted random number data packet is a ciphertext data packet obtained by the first device encrypting the random number sequence using the first quantum key, and usually uses a symmetric encryption algorithm or a one-time pad method for encryption. The one-time pad method means encrypting the plaintext using a random key of the same length as the plaintext, and each key is used only once. The second device is the terminal device that receives the encrypted data packet and needs to establish a shared key with the first device in advance through a quantum key distribution network. The second local quantum key pool refers to the key storage pool synchronized with the first device in the second device, which is used to store the decrypted random number sequence to ensure the consistency of the key pools at both ends.

[0067] In some embodiments, the first random number sequence is used to encrypt service data when the first device or the second device acts as a sender to transmit service data; and decrypt service data when the first device or the second device acts as a receiver to transmit service data.

[0068] Refer to Figure 3 As shown, the second device can be Terminal A or Terminal B. It can be understood that when the first device is Terminal A, the second device is Terminal B; conversely, when the first device is Terminal B, the second device is Terminal A. Terminal A and Terminal B are respectively connected to the nodes QKD-A and QKD-B of the quantum key distribution network. Taking the first device being Terminal A as an example, Terminal A extracts the first quantum key from the local quantum key pool, encrypts the first random number sequence using the first quantum key, generates an encrypted data packet and sends it to Terminal B; after Terminal B decrypts it using the same first quantum key, it stores the random number sequence in the local key pool of Terminal B, that is, the second local quantum key pool. In subsequent communications, Terminal A and Terminal B can extract this random number sequence from their respective local key pools as keys to achieve high-security data encryption transmission.

[0069] In some embodiments, to enhance the security and management efficiency of the second quantum key pool, a dedicated cryptographic machine can also be deployed beside the second devices such as terminal A and terminal B. The cryptographic machine is connected to the terminal device through a secure interface (such as PCIe or an intranet dedicated line) to achieve the secure storage and efficient management of the quantum key pool. Inside the cryptographic machine, a hardware-level encryption chip (such as TPM2.0) and a physically isolated storage area are used to protect the random number sequence in the second local quantum key pool, and the key access permission is restricted through a multi-factor authentication mechanism. At the same time, a key scheduling engine is built in to dynamically extract random numbers on demand and convert them into directly usable encryption keys.

[0070] It should be noted that due to the limited key generation rate of the quantum key distribution network, in high-rate service scenarios, the key generation rate of the quantum key distribution network is difficult to support the requirement of encrypting service data with one-time pad encryption for each data block, resulting in insufficient performance. In this embodiment, in the case of a limited key generation rate of the quantum key distribution network, the capacity of the quantum key pool is expanded through a quantum random number generator, and the transmission process is protected by quantum keys, so that the overall key supply capacity of the system is increased to the generation rate of the quantum random number generator (such as in the order of Gbps), supporting the one-time pad encryption requirement for high-speed service scenarios.

[0071] In some embodiments, since the first quantum key is continuously generated, during the idle time period when no service occurs, the first quantum key will be directly discarded by the first device, resulting in waste of device performance. Therefore, when the service is not started, the first device can execute S402 - S404 to avoid the key being discarded without reason, reasonably utilize the device resources, improve the utilization rate of the device during the idle period, and at the same time may more efficiently call the key when the subsequent service is started, ensuring the timeliness and stability of communication encryption.

[0072] In some embodiments, Figure 5A The schematic diagram of a system for encrypting service data in the embodiments of the present disclosure is shown. Figure 5B The flowchart of a method for encrypting service data in the embodiments of the present disclosure is shown. Combining Figure 5A 、 Figure 5B As shown, the steps for encrypting service data provided in the embodiments of the present disclosure are as follows:

[0073] S502, obtain the transmission rate of the service data.

[0074] In this embodiment, the service data refers to the actual service traffic of users that needs to be encrypted and transmitted through quantum keys, including but not limited to data such as video conferencing and financial transactions. Since in high-rate service scenarios (such as 5G network transmission, 4K / 8K video live broadcast, etc.), the transmission rate of service data can often reach hundreds of Mbps or even several Gbps. However, the key generation rate of current quantum key distribution network (QKD) devices is usually on the order of 10 Mbps. This order-of-magnitude gap makes it difficult for the QKD system to meet the encryption requirement of "one-time-one-key" for service data. Specifically, the replenishment speed of the quantum key pool cannot keep up with the encryption consumption speed of service data, resulting in encryption delay or key exhaustion, and ultimately leading to system performance bottlenecks and security degradation. Therefore, when transmitting service data between the first device and the second device in this embodiment, when either the first device or the second device acts as the sender to send service data, the transmission rate of the service data is first obtained.

[0075] S504, when the transmission rate is greater than the preset transmission rate, encrypt the service data using the first random number sequence.

[0076] In this embodiment, the preset transmission rate can be the rate at which the quantum key distribution network (QKD) device generates quantum keys. The first random number sequence is pre-stored in the local quantum key pools of the first device and the second device. When the transmission rate of the service data is greater than the preset transmission rate, it means that relying on the quantum key distribution network to distribute quantum keys can no longer meet the transmission requirements of the service data. Therefore, the service data is encrypted using the first random number sequence pre-stored in the local quantum key pools of the first device and the second device. Since the generation rate of the first random number sequence generated by the quantum random number generator is much higher than the QKD key distribution rate, it can effectively relieve the consumption pressure of the key pool. At the same time, the first random number sequence is generated by the quantum random number generator, which has true randomness and unpredictability and can meet the high-security requirements.

[0077] In some embodiments, the first device or the second device acting as the sender can monitor the remaining amount of the local quantum key pool in real time. When the quantum key reserve is lower than the security threshold, the quantum key can be dynamically replenished.

[0078] In some embodiments, when the transmission rate is less than or equal to the preset transmission rate, encrypt the service data using the quantum keys generated by the quantum key distribution network (QKD) device.

[0079] In this embodiment, in high-speed transmission, a pre-stored high-security random number sequence is used to cope with it, and in low-speed transmission, quantum keys are distributed in real time, which not only ensures communication security but also ensures the encryption requirements under different transmission rates, achieving a balance between efficiency and security.

[0080] In some embodiments, Figure 6Shows a flowchart of a quantum key communication method in an embodiment of the present disclosure, as Figure 6 shown, the quantum key communication method provided in the embodiment of the present disclosure includes the following steps:

[0081] S602, obtain the identification information of the first random number sequence, where the identification information is used to indicate the unique number of the first random number sequence and the starting position of the first random number sequence.

[0082] In this embodiment, the identification information of the first random number sequence includes two key elements: one is the unique number of the first random number sequence, which is used to distinguish different random number sequences in the key pool; the other is the starting position of the first random number sequence, which is used to locate the specific starting point of the sequence. For example, the unique number can be "QK-2023-001", and the starting position can be the 1024th bit of the sequence.

[0083] S604, encrypt the service data according to the unique number of the first random number sequence and the starting position of the first random number sequence to generate an encrypted service data packet.

[0084] In this embodiment, according to the obtained unique number and starting position, extract the corresponding random number sequence from the quantum key pool. Then, use a quantum encryption algorithm (such as the BB84 protocol or the E91 protocol) to encrypt the service data to generate an encrypted service data packet containing encrypted data and check information. For example, the first random number sequence can be used as a one-time pad to perform bitwise exclusive OR encryption on the "Hello World" service data. The entire process ensures the information security and anti-eavesdropping characteristics of the communication process through the uniqueness and non-replicability of the quantum key.

[0085] Figure 7 Is a schematic diagram of encrypting service data based on the first random number sequence provided in the embodiment of the present disclosure. As shown in the figure, the key used in the one-time pad encryption mechanism consists of a key unique identifier and key data (i.e., the first random number sequence). The structure of the communication data packet includes other message information, key information, and the original data. The specific encryption process is as follows: by performing a 1:1 bitwise exclusive OR operation on the first random number sequence and the original data, the finally generated encrypted data packet includes other message information, the key identifier (i.e., the identification information of the first random number sequence), and the encrypted data after the exclusive OR operation.

[0086] It should be noted that the identification information of the first random number sequence is important data associated with the first random number sequence and includes two key parts. One is the "unique identifier", which can ensure that each random number sequence has a unique identifier, facilitating the management and differentiation of different encryption operations. The other is the "starting position", which indicates the specific position at which this sequence starts to be applied when using the random number sequence for encryption. This is crucial for accurately and orderly encrypting the service data to be transmitted. By carrying the identification information of the first random number sequence in the encrypted service data packet, the receiving end can correctly restore the encrypted data, ensuring the security and accuracy of communication.

[0087] In some embodiments, Figure 8 The flowchart of a method for decrypting service data in an embodiment of the present disclosure is shown. As Figure 8 shown, the method for decrypting service data provided in the embodiment of the present disclosure includes the following steps:

[0088] S802, Obtain the encrypted service data packet.

[0089] S804, Analyze the encrypted service data packet to obtain the unique identifier of the first random number sequence and the starting position of the first random number sequence.

[0090] S806, Decrypt the encrypted service data in the encrypted service data packet according to the unique identifier of the first random number sequence and the starting position of the first random number sequence to obtain the service data.

[0091] In some embodiments, in order to ensure the freshness of the quantum keys in the quantum key pool, Figure 9 The flowchart of a quantum key communication method in an embodiment of the present disclosure is shown. As Figure 9 shown, the quantum key communication method provided in the embodiment of the present disclosure further includes the following steps:

[0092] S902, Obtain the validity identifier for representing the first random number sequence.

[0093] In this embodiment, the validity identifier for representing the first random number sequence is a symbol or information that marks whether the first random number sequence is valid and can reflect the current state of this sequence, such as whether it has expired or is damaged.

[0094] In some embodiments, to ensure the freshness of the key, a validity period is set for each random number sequence when generating the random number sequence. When the validity period is exceeded, the validity identifier will change. For example, initially the identifier is "valid", and it becomes "invalid" when it times out.

[0095] In some embodiments, the validity identifier for representing the first random number sequence can be the first timestamp when the first random number sequence is generated.

[0096] S904, when the validity flag of the first random number sequence meets the preset condition, delete the first random number sequence.

[0097] In this embodiment, in the process, the system obtains this flag. If the flag shows "invalid" (meeting the preset condition), the corresponding first random number sequence will be deleted to avoid affecting communication security by encrypting with an expired sequence.

[0098] In some embodiments, when the validity flag of the first random number sequence is the first timestamp at the time of generating the first random number sequence, a second timestamp representing the current time can be obtained; the time difference is determined according to the first timestamp and the second timestamp; when the time difference is greater than the preset time difference, delete the first random number sequence.

[0099] For example, if the preset time difference is 1 hour, the sequence is generated at 1:00, and the current time is 2:30, the time difference is 1.5 hours, exceeding the preset value, and the sequence will be deleted to ensure that the random number sequence used in communication is always valid and secure.

[0100] In some embodiments, considering the group communication scenario, the group may include multiple terminal devices. When the network scale is small and the security requirement for information output between terminals is high, a mesh networking mode can be adopted, that is, the terminals are interconnected pairwise. Figure 10 Schematic diagram of a group-based quantum key communication system provided by an embodiment of the present disclosure. Combining Figure 10 As shown, taking the group-based quantum key communication system including 3 terminals as an example, namely terminal A, terminal B, and terminal C, terminal A, terminal B, and terminal C are respectively connected to the QKD nodes QKD-A, QKD-B, and QKD-C of the quantum key distribution network, and a cipher machine and a quantum random number generator are respectively equipped for terminal A, terminal B, and terminal C.

[0101] When any two terminals in the group need to perform high-security point-to-point communication, for example, high-security communication between terminal A and terminal B in the group, when terminal A and terminal B are idle in services, terminal A or terminal B can be used as the first device to construct a quantum key pool by encrypting the random number sequence generated by QRNG with the QKD key, and then in subsequent actual services, select and call the QKD key or the key in the key pool for one-time pad communication according to the data transmission rate in the manner described above.

[0102] In some embodiments, to avoid maintaining an excessive number of local quantum key pools in the terminals within a group, which may affect the terminal performance, a method of constructing a local quantum key pool and parallelly invoking keys can be adopted for one-time pad communication. That is, if the first device and the second device are connected in a mesh networking mode, in response to the first device transmitting service data, the first device starts a quantum random number generator to generate a first random number sequence, and stores the first random number sequence in the first local quantum key pool of the first device. In this embodiment, at the beginning of the service, QKD keys are directly used to pairwise transmit a small number of QRNG random number sequences between terminals as keys for one-time pad communication between terminals, that is, key synchronization is performed with a small number of times and a large amount. It can be understood that the small number of QRNG random number sequences means that the number of random numbers transmitted between the first device and the second device at the beginning for key synchronization is small. And performing key synchronization with a small number of times and a large amount means that subsequently, using quantum key distribution (QKD) keys, a large number of key synchronization operations are carried out between terminals for a large amount of data.

[0103] At the beginning of the service, directly using QKD keys to pairwise transmit a small number of QRNG random number sequences between terminals as keys for one-time pad communication is to quickly establish an initial key. Subsequently, relying on the established connection and QKD keys, key synchronization for a large amount of data is frequently performed to continuously update and expand the local quantum key pool, meet the requirement of a large number of keys for one-time pad communication, and at the same time avoid the performance impact caused by maintaining an excessive number of local quantum key pools within the terminal.

[0104] In this embodiment, the service data will be parallelly subjected to one-time pad encapsulation for several times and then transmitted to other terminals for one-time pad decryption. Since one-time pad encryption and decryption are different from using algorithm encryption and decryption, its mechanism that only requires one exclusive OR operation makes the encryption and decryption speed very fast and the resource consumption very small. Therefore, multiple one-time pad encryption and decryption operations can be performed in parallel between terminals.

[0105] In some embodiments, considering the group communication scenario, the group may include multiple terminal devices. When the network scale is large, a central networking mode can be adopted, that is, any one terminal in the group (such as terminal A) is used as a key service management unit, responsible for distributing the first random number sequence to all communication terminals in the group. Figure 11 Schematic diagram of a group-based quantum key communication system provided by an embodiment of the present disclosure. Combining Figure 11 As shown, taking the group-based quantum key communication system including 4 terminals as an example, namely terminal A, terminal B, terminal C, and terminal D, terminal A, terminal B, terminal C, and terminal D are respectively connected to QKD nodes QKD-A, QKD-B, QKD-C, QKD-D of the quantum key distribution network, and cryptographic machines are respectively equipped for terminal A, terminal B, and terminal C, and at least a quantum random number generator is equipped for terminal A.

[0106] In some embodiments, if the first device and the second device are connected in a central group networking mode, when there is no service data transmission between the first device and the second device, the first device starts a quantum random number generator to generate a first random number sequence, and stores the first random number sequence in the first local quantum key pool of the first device.

[0107] In some embodiments, during idle time without services, the terminal A, as the first device, distributes the first random number sequence generated by the QRNG to other terminals in the group, such as terminal B, terminal B, terminal C, and terminal D, which act as the second device, in an encrypted manner. At this time, the same quantum key pool K is maintained in all terminals in the group. all , and uses the quantum key pool K for group services. all for one-time pad communication. In this embodiment, by maintaining the same quantum key pool K in each terminal in the group all , it is ensured that each terminal in the group uses the same key resources, which is convenient for unified management; and when performing group services, one-time pad communication is carried out using the keys in the quantum key pool, meeting the requirements for large-scale data protection in the group scenario, greatly enhancing the security of group service communication, and ensuring the confidentiality and integrity of communication content.

[0108] In some embodiments, considering the high-security point-to-point communication requirements between two terminals in the group, for example, there is an independent high-security communication requirement between terminal B and terminal C, terminal B and terminal C request an independent quantum key pool K from terminal A. BC , during idle time of the service, terminal A encrypts and transmits the second random number sequence to terminal B and terminal C in an encrypted manner, so that terminal B and terminal C respectively construct local quantum key pools K based on the second random number sequence. BC , terminal B and terminal C select and call QKD keys or K according to the data transmission rate in the manner described above. BC for one-time pad communication. This embodiment not only meets the high-security point-to-point communication requirements, but also improves the communication efficiency and security by using idle time transmission and reasonable key selection, and also reduces the QKD resource occupation and communication cost.

[0109] It should be noted that in the technical solution of the present disclosure, the acquisition, storage, use, processing, etc. of data all comply with the relevant regulations of national laws and regulations. In the embodiments of the present disclosure, various types of data such as personal identity data, operation data, and behavior data related to individuals, customers, and groups have been authorized.

[0110] Based on the same inventive concept, embodiments of the present disclosure also provide a quantum key communication device as described in the following embodiments. Since the principle of solving problems in the device embodiments is similar to that in the above method embodiments, the implementation of the device embodiments can refer to the implementation of the above method embodiments, and the repeated parts will not be described again.

[0111] Figure 12 Schematic diagram of a quantum key communication device in an embodiment of the present disclosure is shown as Figure 12 As shown, the device includes: a generation module 121 and a sending module 122; the generation module 121 is configured to start a quantum random number generator of a first device to generate a first random number sequence, and store the first random number sequence in a first local quantum key pool of the first device; the sending module 122 is configured to use a first quantum key by the first device to encrypt the first random number sequence, generate an encrypted random number data packet, and send it to a second device, so that the second device decrypts the encrypted random number data packet based on the first quantum key, obtains the first random number sequence, and stores the first random number sequence in a second local quantum key pool of the second device, where the first quantum key is distributed to the first device and the second device through a quantum key distribution network.

[0112] In some embodiments, the first random number sequence is used to encrypt service data when the first device or the second device is used as a sending end to transmit service data; and decrypt service data when the first device or the second device is used as a receiving end to transmit service data.

[0113] In some embodiments, the device includes: an encryption module, configured to obtain a transmission rate of the service data; when the transmission rate is greater than a preset transmission rate, encrypt the service data by using the first random number sequence.

[0114] In some embodiments, the encryption module is configured to obtain identification information of the first random number sequence, where the identification information is used to indicate a unique number of the first random number sequence and a starting position of the first random number sequence; encrypt the service data according to the unique number of the first random number sequence and the starting position of the first random number sequence to generate an encrypted service data packet.

[0115] In some embodiments, the device includes: a decryption module, configured to obtain the encrypted service data packet; analyze the encrypted service data packet to obtain the unique number of the first random number sequence and the starting position of the first random number sequence; decrypt the encrypted service data in the encrypted service data packet according to the unique number of the first random number sequence and the starting position of the first random number sequence to obtain service data.

[0116] In some embodiments, the generating module is further configured to: obtain a validity identifier for representing the first random number sequence; and when the validity identifier of the first random number sequence meets a preset condition, delete the first random number sequence.

[0117] In some embodiments, the validity identifier for representing the first random number sequence is the first timestamp when the first random number sequence is generated. The generating module is further configured to: obtain a second timestamp for representing the current time; determine a time difference according to the first timestamp and the second timestamp; and when the time difference is greater than a preset time difference, delete the first random number sequence.

[0118] In some embodiments, the generating module is configured to: if the first device and the second device are connected in a mesh networking mode, in response to the first device transmitting service data, the first device starts a quantum random number generator to generate a first random number sequence, and stores the first random number sequence into a first local quantum key pool of the first device; if the first device and the second device are connected in a central networking mode, when there is no service data transmission between the first device and the second device, the first device starts a quantum random number generator to generate a first random number sequence, and stores the first random number sequence into a first local quantum key pool of the first device.

[0119] It should be noted here that the examples and application scenarios implemented by each module in the above device embodiments are the same as the corresponding steps in the method embodiments, but are not limited to the content disclosed in the above method embodiments. It should be noted that the above modules, as part of a device, can be executed in a computer system such as a set of computer executable instructions.

[0120] Those skilled in the art can understand that various aspects of the present disclosure can be specifically implemented in the following forms, that is: a complete hardware implementation, a complete software implementation (including firmware, microcode, etc.), or an implementation combining hardware and software aspects, which can be collectively referred to as "circuit", "module" or "system" here.

[0121] Based on the same inventive concept, an electronic device is further provided in an embodiment of the present disclosure. The electronic device includes: a processor; and a memory for storing executable instructions of the processor; wherein the processor is configured to execute the quantum key communication method of any one of the above via executing the executable instructions. Since the principle of solving problems in this electronic device embodiment is similar to that of the above method embodiment, the implementation of this electronic device embodiment can refer to the implementation of the above method embodiment, and the repeated parts will not be described again.

[0122] Next, refer to Figure 13 to describe the electronic device 1300 according to this embodiment of the present disclosure. Figure 13The illustrated electronic device 1300 is merely an example and should not impose any limitation on the functionality and scope of use of the embodiments of the present disclosure.

[0123] As Figure 13 shown, the electronic device 1300 is presented in the form of a general-purpose computing device. The components of the electronic device 1300 may include, but are not limited to: at least one of the above-mentioned processing units 1310, at least one of the above-mentioned storage units 1320, and a bus 1330 that connects different system components (including the storage unit 1320 and the processing unit 1310).

[0124] Among them, the storage unit stores program code, and the program code can be executed by the processing unit 1310, so that the processing unit 1310 executes the steps according to various exemplary embodiments of the present disclosure described in the "Exemplary Method" section of the present specification above. For example, the processing unit 1310 may execute the following steps of the above method embodiment: The first device starts a quantum random number generator to generate a first random number sequence, and stores the first random number sequence in the first local quantum key pool of the first device; the first device encrypts the first random number sequence using the first quantum key to generate an encrypted random number data packet, and sends it to the second device, so that the second device decrypts the encrypted random number data packet based on the first quantum key to obtain the first random number sequence, and stores the first random number sequence in the second local quantum key pool of the second device, where the first quantum key is distributed to the first device and the second device through a quantum key distribution network.

[0125] The storage unit 1320 may include a readable medium in the form of a volatile storage unit, such as a random access storage unit (RAM) 13201 and / or a cache storage unit 13202, and may further include a read-only storage unit (ROM) 13203.

[0126] The storage unit 1320 may further include a program / utilities 13204 having a set (at least one) of program modules 13205. Such program modules 13205 include, but are not limited to: an operating system, one or more application programs, other program modules, and program data. Each or some combination of these examples may include the implementation of a network environment.

[0127] The bus 1330 may represent one or more of several types of bus structures, including a storage unit bus or a storage unit controller, a peripheral bus, a graphics acceleration port, a processing unit, or a local bus using any of the various bus structures.

[0128] The electronic device 1300 can also communicate with one or more external devices 1340 (such as a keyboard, a pointing device, a Bluetooth device, etc.), and can also communicate with one or more devices that enable a user to interact with the electronic device 1300, and / or communicate with any device (such as a router, a modem, etc.) that enables the electronic device 1300 to communicate with one or more other computing devices. Such communication can be carried out through the input / output (I / O) interface 1350. Moreover, the electronic device 1300 can also communicate with one or more networks (such as a local area network (LAN), a wide area network (WAN), and / or a public network, such as the Internet) through the network adapter 1360. As shown in the figure, the network adapter 1360 communicates with other modules of the electronic device 1300 through the bus 1330. It should be understood that although not shown in the figure, other hardware and / or software modules can be used in combination with the electronic device 1300, including but not limited to: microcode, device drivers, redundant processing units, external disk drive arrays, RAID systems, tape drives, and data backup storage systems, etc.

[0129] Through the description of the above embodiments, those skilled in the art can easily understand that the exemplary embodiments described herein can be implemented by software, or can be implemented by the way of software combined with necessary hardware. Therefore, the technical solutions according to the embodiments of the present disclosure can be embodied in the form of a software product, and the software product can be stored in a non-volatile storage medium (which can be a CD-ROM, a USB flash drive, a mobile hard disk, etc.) or on a network, including several instructions to enable a computing device (which can be a personal computer, a server, a terminal device, or a network device, etc.) to execute the method according to the embodiments of the present disclosure.

[0130] Based on the same inventive concept, an embodiment of the present disclosure also provides a computer-readable storage medium, on which a computer program is stored, and when the computer program is executed by a processor, it implements the quantum key communication method of any one of the above. Since the principle of solving the problem of the embodiment of the computer-readable storage medium is similar to that of the above method embodiment, the implementation of the embodiment of the computer-readable storage medium can refer to the implementation of the above method embodiment, and the repeated parts will not be described again.

[0131] More specific examples of the computer-readable storage medium in the present disclosure may include but are not limited to: an electrical connection having one or more wires, a portable computer disk, a hard disk, a random access memory (RAM), a read-only memory (ROM), an erasable programmable read-only memory (EPROM or flash memory), an optical fiber, a portable compact disk read-only memory (CD-ROM), an optical storage device, a magnetic storage device, or any suitable combination of the above.

[0132] In the present disclosure, a computer-readable storage medium may include a data signal propagated in a baseband or as part of a carrier wave, which carries readable program code. Such a propagated data signal may take various forms, including but not limited to electromagnetic signals, optical signals, or any suitable combination of the above. The readable signal medium may also be any readable medium other than the readable storage medium, which can send, propagate, or transmit a program for use by or in conjunction with an instruction execution system, apparatus, or device.

[0133] Optionally, the program code contained on the computer-readable storage medium may be transmitted using any appropriate medium, including but not limited to wireless, wired, optical fiber cable, RF, etc., or any suitable combination of the above.

[0134] In specific implementations, the program code for performing the operations of the present disclosure may be written in any combination of one or more programming languages, including object-oriented programming languages such as Java, C++, etc., and also including conventional procedural programming languages such as the "C" language or similar programming languages. The program code may be executed entirely on the user computing device, partially on the user device, executed as a stand-alone software package, partially on the user computing device and partially on a remote computing device, or entirely on a remote computing device or server. In the case of a remote computing device, the remote computing device may be connected to the user computing device through any type of network, including a local area network (LAN) or a wide area network (WAN), or may be connected to an external computing device (e.g., by connecting through the Internet using an Internet service provider).

[0135] Based on the same inventive concept, embodiments of the present disclosure also provide a computer program product, including: a computer program or instruction, which when executed by a processor implements the quantum key communication method in any one of the above method embodiments. Since the principle of solving problems in this computer program product embodiment is similar to that of the above method embodiments, the implementation of this computer program product embodiment can refer to the implementation of the above method embodiments, and the repeated parts will not be elaborated.

[0136] It should be noted that although several modules or units of devices for action execution are mentioned in the above detailed description, such a division is not mandatory. In fact, according to the embodiments of the present disclosure, the features and functions of the two or more modules or units described above may be embodied in one module or unit. Conversely, the features and functions of one module or unit described above may be further divided and embodied by multiple modules or units.

[0137] In addition, although the various steps of the methods in the present disclosure are described in a specific order in the drawings, this does not require or imply that the steps must be performed in that specific order, or that all of the steps shown must be performed to achieve the desired result. Additionally or alternatively, some steps may be omitted, multiple steps may be combined into one step for execution, and / or one step may be decomposed into multiple steps for execution, etc.

[0138] From the description of the above embodiments, those skilled in the art can easily understand that the exemplary embodiments described herein can be implemented by software, or by software in combination with necessary hardware. Therefore, the technical solutions according to the embodiments of the present disclosure can be embodied in the form of a software product, which can be stored in a non-volatile storage medium (such as a CD-ROM, USB flash drive, mobile hard disk, etc.) or on a network, and includes several instructions to enable a computing device (such as a personal computer, server, mobile terminal, or network device, etc.) to execute the methods according to the embodiments of the present disclosure.

[0139] After considering the specification and practicing the invention disclosed herein, those skilled in the art will readily conceive of other embodiments of the present disclosure. The present disclosure is intended to cover any variations, uses, or adaptations of the present disclosure, which follow the general principles of the present disclosure and include known common knowledge or conventional technical means in the technical field not disclosed in the present disclosure. The specification and examples are only regarded as exemplary, and the true scope and spirit of the present disclosure are pointed out by the appended claims.

Claims

1. A quantum key communication method, characterized in that, The method includes: The first device starts a quantum random number generator to generate a first random number sequence, and stores the first random number sequence in a first local quantum key pool of the first device; The first device encrypts the first random number sequence using a first quantum key to generate an encrypted random number data packet, and sends the encrypted random number data packet to a second device, so that the second device decrypts the encrypted random number data packet based on the first quantum key to obtain the first random number sequence, and stores the first random number sequence in a second local quantum key pool of the second device, where the first quantum key is distributed to the first device and the second device through a quantum key distribution network.

2. The quantum key communication method according to claim 1, wherein The first random number sequence is used to encrypt service data when the first device or the second device acts as a sender to transmit service data; and decrypt service data when the first device or the second device acts as a receiver to transmit service data.

3. The quantum key communication method according to claim 2, wherein The encrypting of the service data includes: Obtaining a transmission rate of the service data; When the transmission rate is greater than a preset transmission rate, encrypting the service data using the first random number sequence.

4. The quantum key communication method according to claim 3, characterized in that, The encrypting the service data using the first random number sequence includes: Obtaining identification information of the first random number sequence, where the identification information is used to indicate a unique number of the first random number sequence and a starting position of the first random number sequence; Encrypting the service data according to the unique number of the first random number sequence and the starting position of the first random number sequence to generate an encrypted service data packet.

5. The quantum key communication method according to claim 4, characterized in that The decrypting of the service data includes: Obtaining the encrypted service data packet; Analyzing the encrypted service data packet to obtain the unique number of the first random number sequence and the starting position of the first random number sequence; Decrypting the encrypted service data in the encrypted service data packet according to the unique number of the first random number sequence and the starting position of the first random number sequence to obtain the service data.

6. The quantum key communication method according to claim 1, wherein The method further includes: Obtaining a validity identifier for indicating the first random number sequence; When the validity identifier of the first random number sequence meets a preset condition, deleting the first random number sequence.

7. The quantum key communication method according to claim 6, characterized in that, The validity identifier for indicating the first random number sequence is a first timestamp when the first random number sequence is generated, and the deleting the first random number sequence when the validity identifier of the first random number sequence meets a preset condition includes: Obtaining a second timestamp for indicating the current time; Determining a time difference according to the first timestamp and the second timestamp; When the time difference is greater than a preset time difference, deleting the first random number sequence.

8. The quantum key communication method according to claim 1, characterized in that, If the first device and the second device are connected in a mesh networking mode, in response to the first device transmitting service data, the first device starts a quantum random number generator to generate a first random number sequence, and stores the first random number sequence in a first local quantum key pool of the first device; If the first device and the second device are connected in a central network mode, when there is no service data transmission between the first device and the second device, the first device starts a quantum random number generator to generate a first random number sequence, and stores the first random number sequence in a first local quantum key pool of the first device.

9. A quantum key communication device, characterized in that, The device includes: a generating module, configured to start a quantum random number generator of the first device to generate a first random number sequence, and store the first random number sequence in a first local quantum key pool of the first device; a sending module, configured to use a first quantum key by the first device to encrypt the first random number sequence, generate an encrypted random number data packet, and send the encrypted random number data packet to the second device, so that the second device decrypts the encrypted random number data packet based on the first quantum key, obtains the first random number sequence, and stores the first random number sequence in a second local quantum key pool of the second device, where the first quantum key is distributed to the first device and the second device through a quantum key distribution network.

10. An electronic device, characterized in that, It includes: a processor; and a memory, configured to store executable instructions of the processor; wherein, the processor is configured to execute the quantum key communication method according to any one of claims 1 to 8 by executing the executable instructions.

11. A computer-readable storage medium having a computer program stored thereon, characterized in that, The computer program, when executed by a processor, implements the quantum key communication method according to any one of claims 1 to 8.

12. A computer program product, comprising: A computer program or instruction, characterized in that the computer program or instruction, when executed by a processor, implements the quantum key communication method according to any one of claims 1 to 8.

Citation Information

Patent Citations

  • Data safety method and system based on quantum random numbers

    CN110620669A

  • High-speed quantum key distribution system and method

    CN113810187A

  • Internet of Things data interaction method, system and device based on quantum key and medium

    CN113922956A

  • Quantum random number application method and system

    CN115314223A

  • Data transmission method and data transmission system

    CN117389623A

Cited By

  • Encryption communication method, device, equipment, medium and product

    CN121418101A