Quantum key communication method, device and related equipment
The quantum key pool is expanded by generating and encrypting random number sequences using a quantum random number generator, which solves the problem of insufficient quantum key generation rate and improves the security and efficiency of large-scale data protection.
Patent Information
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2025-05-28
- Publication Date
- 2026-04-07
AI Technical Summary
The existing quantum key generation rate is limited and cannot meet the needs of large-scale data protection, resulting in the inability to guarantee data confidentiality and integrity.
A random number sequence is generated by a quantum random number generator and stored in a local quantum key pool. The random number sequence is then encrypted and decrypted using quantum keys, expanding the number of available quantum keys and meeting the needs of large-scale data protection.
The number of quantum keys available for data protection has increased, meeting the needs of large-scale data protection and improving the security and efficiency of data transmission.
Smart Images

Figure CN120378099B_ABST
Abstract
Description
Technical Field
[0001] This disclosure relates to the field of network security technology, and in particular to a quantum key communication method, apparatus and related equipment. Background Technology
[0002] In today's digital age, data security is paramount, and cryptography is widely used as a key means to ensure it. Cryptography is employed to protect data because it can encrypt and authenticate data, preventing leakage and tampering. Asymmetric cryptography is used for authentication and key exchange, while symmetric cryptography is used for encryption. However, the classical cryptographic systems upon which these systems are based are vulnerable to cracking by quantum computing, compromising data confidentiality and integrity.
[0003] Therefore, quantum key distribution technology is widely used for data security protection. Utilizing quantum mechanics principles to generate and distribute keys, it possesses unconditional security and can effectively guarantee data security. However, the generation of quantum keys is limited by physical conditions, resulting in a finite generation rate. The limited number of quantum keys is insufficient to meet the needs of large-scale data protection.
[0004] It should be noted that the information disclosed in the background section above is only used to enhance the understanding of the background of this disclosure, and therefore may include information that does not constitute prior art known to those skilled in the art. Summary of the Invention
[0005] This disclosure provides a quantum key communication method, apparatus, and related equipment that can meet the needs of large-scale data protection.
[0006] Other features and advantages of this disclosure will become apparent from the following detailed description, or may be learned in part from practice of this disclosure.
[0007] According to one aspect of this disclosure, a quantum key distribution method is provided, the method comprising: a first device activating a quantum random number generator to generate a first random number sequence and storing the first random number sequence in a first local quantum key pool of the first device; the first device encrypting the first random number sequence using a first quantum key to generate an encrypted random number data packet and sending it to a second device, such that the second device decrypts the encrypted random number data packet based on the first quantum key to obtain the first random number sequence and stores the first random number sequence in a second local quantum key pool of the second device, wherein the first quantum key is distributed to the first device and the second device through a quantum key distribution network.
[0008] In some embodiments, the first random number sequence is used to encrypt service data when the first device or the second device transmits service data as a sender, and to decrypt service data when the first device or the second device transmits service data as a receiver.
[0009] In some embodiments, encrypting the service data includes: obtaining the transmission rate of the service data; and when the transmission rate is greater than a preset transmission rate, encrypting the service data using the first random number sequence.
[0010] In some embodiments, encrypting business data using the first random number sequence includes: obtaining identification information of the first random number sequence, the identification information being used to indicate the unique number of the first random number sequence and the starting position of the first random number sequence; encrypting the business data according to the unique number of the first random number sequence and the starting position of the first random number sequence to generate an encrypted business data packet.
[0011] In some embodiments, decrypting the business data includes: acquiring the encrypted business data packet; parsing the encrypted business data packet to obtain the unique identifier of the first random number sequence and the starting position of the first random number sequence; and decrypting the encrypted business data in the encrypted business data packet according to the unique identifier of the first random number sequence and the starting position of the first random number sequence to obtain the business data.
[0012] In some embodiments, the method further includes: obtaining a validity identifier for the first random number sequence; and deleting the first random number sequence when the validity identifier of the first random number sequence meets a preset condition.
[0013] In some embodiments, the identifier for indicating the validity of the first random number sequence is a first timestamp when the first random number sequence was generated, and the step of deleting the first random number sequence when the validity identifier of the first random number sequence meets a preset condition includes: obtaining a second timestamp for indicating the current time; determining a time difference based on the first timestamp and the second timestamp; and deleting the first random number sequence when the time difference is greater than a preset time difference.
[0014] In some embodiments, if the first device and the second device are connected in a mesh networking mode, in response to the first device transmitting service data, the first device starts a quantum random number generator to generate a first random number sequence and stores the first random number sequence in the first device's first local quantum key pool; if the first device and the second device are connected in a central networking mode, when there is no service data transmission between the first device and the second device, the first device starts a quantum random number generator to generate a first random number sequence and stores the first random number sequence in the first device's first local quantum key pool.
[0015] According to another aspect of this disclosure, a quantum key communication device is also provided, the device comprising: a generation module, configured to: a first device start a quantum random number generator to generate a first random number sequence and store the first random number sequence in a first local quantum key pool of the first device; and a transmission module, configured to: the first device encrypt the first random number sequence using a first quantum key to generate an encrypted random number data packet and send it to a second device, such that the second device decrypts the encrypted random number data packet based on the first quantum key to obtain the first random number sequence and stores the first random number sequence in a second local quantum key pool of the second device, wherein the first quantum key is distributed to the first device and the second device through a quantum key distribution network.
[0016] According to another aspect of this disclosure, an electronic device is also provided, comprising: a processor; and a memory for storing executable instructions of the processor; wherein the processor is configured to perform the quantum key communication method described in any one of the preceding claims by executing the executable instructions.
[0017] According to another aspect of this disclosure, a computer-readable storage medium is also provided, on which a computer program is stored, which, when executed by a processor, implements the quantum key communication method described in any one of the preceding claims.
[0018] According to another aspect of this disclosure, a computer program product is also provided, comprising: a computer program or instructions that, when executed by a processor, implement the quantum key communication method of any one of the above.
[0019] This disclosure provides a quantum key distribution method, apparatus, and related devices. The method includes: a first device activating a quantum random number generator to generate a first random number sequence and storing the first random number sequence in a first local quantum key pool of the first device; the first device encrypting the first random number sequence using a first quantum key to generate an encrypted random number data packet and sending it to a second device, so that the second device decrypts the encrypted random number data packet based on the first quantum key to obtain the first random number sequence and stores the first random number sequence in a second local quantum key pool of the second device, wherein the first quantum key is distributed to the first device and the second device through a quantum key distribution network. By continuously generating a large number of random number sequences using a quantum random number generator, encrypting and transmitting the random number sequences using quantum keys, and decrypting and storing them at the receiving end, the number of available quantum keys for data protection is indirectly increased, meeting the needs of large-scale data protection.
[0020] It should be understood that the above general description and the following detailed description are exemplary and explanatory only, and are not intended to limit this disclosure. Attached Figure Description
[0021] The accompanying drawings, which are incorporated in and form part of this specification, illustrate embodiments consistent with this disclosure and, together with the description, serve to explain the principles of this disclosure. It is obvious that the drawings described below are merely some embodiments of this disclosure, and those skilled in the art can obtain other drawings based on these drawings without any inventive effort.
[0022] Figure 1 This diagram illustrates a system architecture of a quantum key communication method according to an embodiment of the present disclosure.
[0023] Figure 2 This diagram illustrates a system architecture of yet another quantum key communication method according to an embodiment of the present disclosure.
[0024] Figure 3 This diagram illustrates a quantum key communication system according to an embodiment of the present disclosure;
[0025] Figure 4 This diagram illustrates a flowchart of a quantum key communication method according to an embodiment of the present disclosure;
[0026] Figure 5A This diagram illustrates a system for encrypting business data according to an embodiment of the present disclosure.
[0027] Figure 5B This diagram illustrates a method for encrypting business data according to an embodiment of the present disclosure.
[0028] Figure 6This diagram illustrates a flowchart of a quantum key communication method according to an embodiment of the present disclosure;
[0029] Figure 7 This diagram illustrates an embodiment of encrypting business data based on a first random number sequence.
[0030] Figure 8 This diagram illustrates a method for decrypting business data according to an embodiment of the present disclosure.
[0031] Figure 9 This diagram illustrates a flowchart of a quantum key communication method according to an embodiment of the present disclosure;
[0032] Figure 10 A schematic diagram of a group-based quantum key communication system is shown in an embodiment of this disclosure;
[0033] Figure 11 A schematic diagram of a group-based quantum key communication system is shown in an embodiment of this disclosure;
[0034] Figure 12 This diagram illustrates a quantum key communication device according to an embodiment of the present disclosure;
[0035] Figure 13 A structural block diagram of an electronic device according to an embodiment of the present disclosure is shown. Detailed Implementation
[0036] Exemplary embodiments will now be described more fully with reference to the accompanying drawings. However, these exemplary embodiments can be implemented in many forms and should not be construed as limited to the examples set forth herein; rather, they are provided so that this disclosure will be more comprehensive and complete, and will fully convey the concept of the exemplary embodiments to those skilled in the art. The described features, structures, or characteristics may be combined in any suitable manner in one or more embodiments.
[0037] Furthermore, the accompanying drawings are merely illustrative of this disclosure and are not necessarily drawn to scale. The same reference numerals in the drawings denote the same or similar parts, and therefore repeated descriptions of them will be omitted. Some block diagrams shown in the drawings are functional entities and do not necessarily correspond to physically or logically independent entities. These functional entities may be implemented in software, in one or more hardware modules or integrated circuits, or in different network and / or processor devices and / or microcontroller devices.
[0038] To facilitate understanding, before introducing the embodiments of this disclosure, the following explanations are provided for several terms involved in the embodiments of this disclosure:
[0039] Quantum Key Distribution Network (QKDN): Ensuring communication security based on the properties of quantum mechanics. The properties of quantum mechanics, such as the superposition of quantum states and the uncertainty principle, make it difficult for eavesdroppers to obtain key information undetected. In QKDN, the communicating parties use a quantum channel and quantum carriers such as single photons to generate keys. Due to the unique properties of quantum mechanics, if a third party attempts to eavesdrop, the quantum state will change, and the communicating parties can immediately detect it. Simultaneously, QKDN also includes a classical channel to assist in information exchange and key negotiation. After generating and sharing a random and secure key through the quantum channel, the communicating parties use this key to encrypt and decrypt messages, thereby ensuring the security of the communication process and effectively resisting potential eavesdropping and attacks.
[0040] Quantum Random Number Generator (QRNG): Generates truly random numbers based on the principles of quantum physics. In the quantum world, the state of microscopic particles is uncertain; for example, a qubit can be in a state of 0, 1, or a superposition of both, making its measurement results unpredictable. QRNG utilizes this quantum property to generate random numbers. When a quantum system is measured, the result is random each time, unaffected by previous or subsequent measurements, thus guaranteeing the "true" randomness of the random numbers. Unlike traditional random number generators, which are often based on algorithms or physical processes and may exhibit certain patterns or predictability, QRNG, based on the fundamental principles of quantum mechanics, provides random numbers with higher security and unpredictability.
[0041] The specific implementation methods of the embodiments of this disclosure will now be described in detail with reference to the accompanying drawings.
[0042] Figure 1 A schematic diagram of an exemplary application system architecture to which the quantum key communication method of the embodiments of this disclosure can be applied is shown. For example... Figure 1 As shown, the system architecture may include a terminal device 101, a network 102, a server 103, and a quantum random number generator 104.
[0043] Network 102 is a medium used to provide a communication link between terminal device 101 and server 103, and can be a wired network or a wireless network.
[0044] Optionally, the aforementioned wireless or wired networks use standard communication technologies and / or protocols. The network is typically the Internet, but can also be any network, including but not limited to Local Area Networks (LANs), Metropolitan Area Networks (MANs), Wide Area Networks (WANs), mobile, wired or wireless networks, private networks, or any combination of virtual private networks. In some embodiments, technologies and / or formats, including Hypertext Markup Language (HTML), Etensible Markup Language (ML), etc., are used to represent data exchanged over the network. Furthermore, conventional encryption technologies such as Secure Socket Layer (SSL), Transport Layer Security (TLS), Virtual Private Networks (VPNs), and Internet Protocol Security (IPSec) can be used to encrypt all or some links. In other embodiments, custom and / or dedicated data communication technologies can be used to replace or supplement the aforementioned data communication technologies.
[0045] Terminal device 101 can be various electronic devices, including but not limited to smartphones, tablets, laptops, desktop computers, smart speakers, smartwatches, wearable devices, augmented reality devices, virtual reality devices, etc.
[0046] Optionally, the client of the application installed on different terminal devices 101 may be the same, or the client of the same type of application based on different operating systems. Depending on the terminal platform, the specific form of the application client may also be different; for example, the application client may be a mobile client, a PC client, etc.
[0047] Server 103 can be a quantum key distribution network server, acting as a node in the network responsible for the distribution, management, and storage of quantum keys. On one hand, it needs to communicate with other nodes in the network (such as user terminals and other servers) to achieve efficient key transmission. On the other hand, it must ensure the security and integrity of the keys, preventing them from being stolen or tampered with. Server 103 possesses the necessary hardware and software to support the operation of quantum key distribution-related protocols and algorithms. By working in conjunction with other relevant devices, a complete quantum key distribution network is constructed, providing users with secure communication guarantees.
[0048] Optionally, the server can be a standalone physical server, a server cluster or distributed system consisting of multiple physical servers, or a cloud server.
[0049] The quantum random number generator 104 can be a device that generates truly random numbers based on quantum physics processes. The generated random numbers are used to provide high-entropy seeds for encryption operations in the system, such as key generation, initialization vector generation, and selection of asymmetric encryption parameters. In this embodiment, the quantum random number generator 104 is used to generate quantum random numbers. Random numbers are crucial in quantum key communication; they provide high randomness for key generation, enhance key security and unpredictability, and work in conjunction with other components to ensure the secure and efficient operation of quantum key communication.
[0050] Optionally, the quantum random number generator 104 can be directly connected to the terminal via a physical interface (such as Universal Serial Bus (USB), Peripheral Component Interconnect Epress (PCIe), or other high-speed interfaces). This method ensures low latency and high security for data transmission because the data does not need to pass through an external network, reducing the risk of interception. If the quantum random number generator 104 needs to be placed far from the terminal, it can be connected via a Local Area Network (LAN). This configuration is suitable for situations where the quantum random number generator 104 serves multiple terminals, allowing resource sharing. However, this method requires ensuring network security to prevent data from being eavesdropped on during transmission. For applications with extremely high security requirements, even within the same LAN, a dedicated secure channel can be established to transmit random numbers, adding an extra layer of security.
[0051] Those skilled in the art will know that Figure 1 The number of terminal devices, networks, servers, and quantum random number generators shown is merely illustrative; any number of terminal devices, networks, and servers can be included depending on actual needs. This disclosure does not limit the scope of the embodiments.
[0052] Figure 2 A schematic diagram of an exemplary application system architecture to which the quantum key communication method of the embodiments of this disclosure can be applied is shown. For example... Figure 2 As shown, the system architecture may include a terminal device 101, a network 102 and a server 103, a quantum random number generator 104 and a cryptographic machine 105.
[0053] The cryptographic machine 105 is a hardware device specifically designed for encryption operations and key management. Deployed on the terminal device 101, it provides functions such as secure storage, retrieval, and management of quantum keys, ensuring the security of the quantum key pool.
[0054] Optionally, the cipher machine 105 can connect to the terminal device via an internal local area network (LAN) or a wider wide area network (WAN). This method allows the terminal device to be flexibly placed within a certain range without requiring direct physical proximity to the cipher machine. When connecting via a network, encrypted communication protocols (such as TLS / SSL) are typically used to ensure the security of data transmission and prevent key information from being eavesdropped on or tampered with during network transmission. In some high-security scenarios, the cipher machine 105 may connect directly to the terminal device via a physical interface (such as USB, serial port, PCIe, etc.). This connection method reduces intermediate steps and theoretically provides higher security. For terminal devices with extremely high security requirements and relatively fixed physical locations, direct connection may be a better choice.
[0055] Those skilled in the art will know that Figure 2 The number of terminal devices, networks, servers, and quantum random number generators shown is merely illustrative; any number of terminal devices, networks, and servers can be included depending on actual needs. This disclosure does not limit the scope of the embodiments.
[0056] Under the above system architecture, this disclosure provides a quantum key communication method that can be executed by any electronic device with computing capabilities.
[0057] In some embodiments, the quantum key communication method provided in this disclosure can be executed by a terminal device of the system architecture described above; in other embodiments, the quantum key communication method provided in this disclosure can be executed by a server in the system architecture described above; in still other embodiments, the quantum key communication method provided in this disclosure can be implemented by the terminal device and the server in the system architecture described above through interaction.
[0058] Figure 3 This is a schematic diagram of a quantum key communication system provided in an embodiment of the present disclosure. Figure 4 A flowchart of a quantum key communication method according to an embodiment of this disclosure is provided. (Combined with...) Figure 3 , Figure 4 As shown, the quantum key communication method provided in this embodiment includes the following steps:
[0059] S402, the first device starts the quantum random number generator to generate the first random number sequence and stores the first random number sequence in the first device's first local quantum key pool.
[0060] In this embodiment, the first device refers to the terminal device participating in the construction of the quantum key pool, which may include mobile phones, tablets, laptops, desktop computers, smartwatches, smart bracelets, smart glasses, in-vehicle terminals of smart cars, control terminals of smart home appliances, sensor node devices in the Industrial Internet of Things, security monitoring cameras, drones, etc. The quantum random number generator is a device that generates truly random numbers based on the principles of quantum mechanics. Its output is unpredictable and unbiased, and its security far exceeds that of classical pseudo-random number generators. The first random number sequence refers to the set of truly random numbers generated by the quantum random number generator, used to expand the capacity of the quantum key pool. Its length and update frequency are dynamically adjusted according to system security requirements. The first local quantum key pool refers to the secure storage area in the first device used to store the random number sequence. The random numbers in the key pool can be dynamically called as reserve keys or encryption seeds for subsequent communication.
[0061] The quantum random number generator can be integrated into the first device or externally connected to it. The quantum random number generator can be connected to the first device via a physical interface or via a network. This disclosure does not limit the way the quantum random number generator is integrated into the first device.
[0062] Reference Figure 3 As shown, the first device can be either terminal A or terminal B. Taking terminal A as an example, terminal A starts its own quantum random number generator to generate a first random number sequence, and then stores the first random number sequence into its own first local quantum key pool, providing scalable key resources for the first local quantum key pool. It can be understood that the first local quantum key pool is a dynamic key pool.
[0063] In some embodiments, to enhance the security and management efficiency of the first quantum key pool, a dedicated cryptographic machine can be deployed next to the first devices such as terminal A and terminal B. The cryptographic machine is connected to the terminal devices through a secure interface (such as PCIe or a private intranet line) to achieve secure storage and efficient management of the quantum key pool. The cryptographic machine uses a hardware-level encryption chip (such as TPM 2.0) and a physically isolated storage area to protect the random number sequence in the first local quantum key pool, and restricts key access permissions through a multi-factor authentication mechanism. At the same time, the built-in key scheduling engine dynamically extracts random numbers on demand and converts them into directly usable encryption keys, supports key lifecycle management and automatic triggering of QRNG to replenish new keys.
[0064] In some embodiments, the cryptographic machine can be directly connected to a quantum random number generator (QRNG) to receive and verify the generated random numbers in real time before storing them in the key pool, ensuring continuous key updates and achieving high-speed one-time pad encryption, thus breaking through the bandwidth limitations of the QKD network.
[0065] S404, the first device uses the first quantum key to encrypt the first random number sequence, generates an encrypted random number data packet, and sends it to the second device, so that the second device decrypts the encrypted random number data packet based on the first quantum key, obtains the first random number sequence, and stores the first random number sequence in the second device's second local quantum key pool, wherein the first quantum key is distributed to the first device and the second device through a quantum key distribution network.
[0066] In this embodiment, the first quantum key is a shared key negotiated between the first and second devices via a quantum key distribution network. It possesses information-theoretic security and can resist computational attacks and eavesdropping. The encrypted random number data packet is a ciphertext data packet obtained by the first device encrypting a random number sequence using the first quantum key, typically employing a symmetric encryption algorithm or a one-time pad encryption method. A one-time pad method means encrypting the plaintext using a random key of the same length as the plaintext, with each key used only once. The terminal device receiving the encrypted data packet needs to establish a shared key with the first device beforehand through the quantum key distribution network. The second local quantum key pool refers to a key storage pool in the second device that is synchronized with the first device, used to store the decrypted random number sequence to ensure consistency between the two key pools.
[0067] In some embodiments, the first random number sequence is used to encrypt service data when the first device or the second device transmits service data as a sender, and to decrypt service data when the first device or the second device transmits service data as a receiver.
[0068] Reference Figure 3 As shown, the second device can be either terminal A or terminal B. It can be understood that when the first device is terminal A, the second device is terminal B; conversely, when the first device is terminal B, the second device is terminal A. Terminal A and terminal B are connected to nodes QKD-A and QKD-B of the quantum key distribution network, respectively. Taking terminal A as an example, terminal A extracts a first quantum key from its local quantum key pool, encrypts a first random number sequence using the first quantum key, generates an encrypted data packet, and sends it to terminal B. Terminal B decrypts the data packet using the same first quantum key and stores the random number sequence in its local key pool, i.e., the second local quantum key pool. In subsequent communications, terminals A and B can extract this random number sequence from their respective local key pools as keys to achieve highly secure encrypted data transmission.
[0069] In some embodiments, to enhance the security and management efficiency of the second quantum key pool, a dedicated cryptographic machine can be deployed next to the second devices such as terminal A and terminal B. The cryptographic machine is connected to the terminal devices through a secure interface (such as PCIe or a private intranet line) to achieve secure storage and efficient management of the quantum key pool. The cryptographic machine uses a hardware-level encryption chip (such as TPM2.0) and a physically isolated storage area to protect the random number sequence in the second local quantum key pool, and restricts key access permissions through a multi-factor authentication mechanism. At the same time, the built-in key scheduling engine dynamically extracts random numbers on demand and converts them into directly usable encryption keys.
[0070] It should be noted that due to the limited key generation rate of quantum key distribution networks (QKDCs), in high-speed service scenarios, the key generation rate of QKDCs is insufficient to support the one-time pad encryption requirements of service data, resulting in inadequate performance. This embodiment addresses the limitation of the QKDC's key generation rate by expanding the quantum key pool capacity through a quantum random number generator and utilizing quantum keys to protect the transmission process. This enhances the overall key supply capability of the system to the generation rate of the quantum random number generator (e.g., on the order of Gbps), supporting the one-time pad encryption requirements of high-speed service scenarios.
[0071] In some embodiments, since the first quantum key is continuously generated, it will be directly discarded by the first device during idle periods when no business is occurring, resulting in wasted device performance. Therefore, during idle periods when no business is started, the first device can execute S402 to S404 to avoid the key being discarded without reason, make reasonable use of device resources, improve the utilization rate of the device during idle periods, and may more efficiently call the key when subsequent business starts, ensuring the timeliness and stability of communication encryption.
[0072] In some embodiments, Figure 5A This diagram illustrates a system for encrypting business data according to an embodiment of the present disclosure. Figure 5B This diagram illustrates a flowchart of a method for encrypting business data according to an embodiment of the present disclosure, in conjunction with... Figure 5A , Figure 5B As shown, the encryption of business data provided in this embodiment includes the following steps:
[0073] S502, obtain the transmission rate of business data.
[0074] In this embodiment, business data refers to the actual user business traffic that needs to be encrypted and transmitted using quantum keys, including but not limited to video conferencing, financial transactions, and other data. In high-speed business scenarios (such as 5G network transmission, 4K / 8K video live streaming, etc.), the transmission rate of business data can often reach hundreds of Mbps or even several Gbps. However, the key generation rate of current quantum key distribution (QKD) network devices is typically on the order of 10 Mbps. This order-of-magnitude difference makes it difficult for QKD systems to meet the "one-time pad" encryption requirement of business data. Specifically, the replenishment speed of the quantum key pool cannot keep up with the encryption consumption rate of business data, resulting in encryption delays or key exhaustion, ultimately leading to system performance bottlenecks and decreased security. Therefore, in this embodiment, when transmitting business data between the first device and the second device, either the first device or the second device, as the sending end, first obtains the transmission rate of the business data.
[0075] S504: When the transmission rate is greater than the preset transmission rate, the service data is encrypted using the first random number sequence.
[0076] In this embodiment, the preset transmission rate can be the rate at which the quantum key distribution network (QKD) device generates quantum keys. The first random number sequence is pre-stored in the local quantum key pools of the first and second devices. When the transmission rate of the service data exceeds the preset transmission rate, it indicates that relying on the quantum key distribution network to distribute quantum keys can no longer meet the transmission requirements of the service data. Therefore, the service data is encrypted using the first random number sequence pre-stored in the local quantum key pools of the first and second devices. Since the generation rate of the first random number sequence by the quantum random number generator is much higher than the QKD key distribution rate, the pressure on the key pool can be effectively alleviated. At the same time, the first random number sequence, generated by the quantum random number generator, possesses true randomness and unpredictability, which can meet the high security requirements.
[0077] In some embodiments, the first or second device acting as the transmitter can monitor the remaining amount of the local quantum key pool in real time, and can dynamically replenish the quantum key when the quantum key reserve is lower than the security threshold.
[0078] In some embodiments, when the transmission rate is less than or equal to a preset transmission rate, a quantum key is generated using a quantum key distribution network (QKD) device to encrypt the business data.
[0079] In this embodiment, a pre-stored high-security random number sequence is used for high-speed transmission, while a quantum key distributed in real time is used for low-speed transmission. This ensures both communication security and encryption requirements at different transmission rates, achieving a balance between efficiency and security.
[0080] In some embodiments, Figure 6A flowchart of a quantum key communication method according to an embodiment of this disclosure is shown, as follows: Figure 6 As shown, the quantum key communication method provided in this embodiment includes the following steps:
[0081] S602, obtain the identification information of the first random number sequence. The identification information is used to indicate the unique number of the first random number sequence and the starting position of the first random number sequence.
[0082] In this embodiment, the identification information of the first random number sequence includes two key elements: first, a unique number for the first random number sequence, used to distinguish different random number sequences in the key pool; and second, the starting position of the first random number sequence, used to locate the specific starting point of the sequence. For example, the unique number could be "QK-2023-001", and the starting position could be the 1024th bit of the sequence.
[0083] S604, based on the unique identifier of the first random number sequence and the starting position of the first random number sequence, encrypt the business data to generate an encrypted business data packet.
[0084] In this embodiment, a corresponding random number sequence is extracted from the quantum key pool based on the obtained unique identifier and starting position. Then, a quantum encryption algorithm (such as the BB84 or E91 protocol) is used to encrypt the business data, generating an encrypted business data packet containing encrypted data and verification information. For example, the first random number sequence can be used as a one-time password to perform bit-by-bit XOR encryption on the "Hello World" business data. The entire process ensures information security and anti-eavesdropping characteristics during communication through the uniqueness and non-replicability of the quantum key.
[0085] Figure 7 This diagram illustrates an embodiment of encrypting business data based on a first random number sequence. As shown, the key used in the one-time pad encryption mechanism consists of a unique key identifier and key data (i.e., the first random number sequence). The communication data packet structure includes other message information, key information, and the original data. The specific encryption process is as follows: by performing a 1:1 bitwise XOR operation between the first random number sequence and the original data, the resulting encrypted data packet includes other message information, the key identifier (i.e., the identifier information of the first random number sequence), and the encrypted data after the XOR operation.
[0086] It's important to note that the identification information of the first random number sequence is crucial data associated with it, containing two key parts. First, a "unique identifier," ensuring each random number sequence has a unique identifier for easy management and differentiation between different encryption operations. Second, a "starting position," indicating the specific position from which the sequence is applied during encryption, which is essential for accurately and systematically encrypting transmitted business data. By carrying the identification information of the first random number sequence, the encrypted business data packet allows the receiving end to correctly reconstruct the encrypted data, ensuring the security and accuracy of communication.
[0087] In some embodiments, Figure 8 This invention discloses a flowchart illustrating a method for decrypting business data according to an embodiment of the present invention. Figure 8 As shown, the decryption of business data provided in this embodiment includes the following steps:
[0088] S802, obtain encrypted business data packets.
[0089] S804, parse the encrypted service data packet to obtain the unique number of the first random number sequence and the starting position of the first random number sequence.
[0090] S806, decrypt the encrypted service data in the encrypted service data packet according to the unique number of the first random number sequence and the starting position of the first random number sequence to obtain the service data.
[0091] In some embodiments, to ensure the freshness of quantum keys in the quantum key pool, Figure 9 A flowchart of a quantum key communication method according to an embodiment of this disclosure is shown, as follows: Figure 9 As shown, the quantum key communication method provided in this embodiment further includes the following steps:
[0092] S902, Obtain the identifier used to indicate the validity of the first random number sequence.
[0093] In this embodiment, the identifier used to indicate the validity of the first random number sequence refers to a symbol or information that marks whether the first random number sequence is valid and can reflect the current state of the sequence, such as whether it is expired or damaged.
[0094] In some embodiments, to ensure key freshness, an expiration period is set for each random number sequence during generation. When the expiration period expires, the validity flag changes. For example, if initially flagged as "valid," it changes to "invalid" after the timeout.
[0095] In some embodiments, the identifier used to indicate the validity of the first random number sequence can be a first timestamp when the first random number sequence was generated.
[0096] S904, when the validity identifier of the first random number sequence meets the preset conditions, delete the first random number sequence.
[0097] In this embodiment, the system obtains this identifier during the process. If the identifier shows "invalid" (meets preset conditions), the corresponding first random number sequence will be deleted to avoid using expired sequences for encryption, which would affect communication security.
[0098] In some embodiments, when the validity identifier of the first random number sequence is the first timestamp when the first random number sequence was generated, a second timestamp used to represent the current time can be obtained; a time difference is determined based on the first timestamp and the second timestamp; when the time difference is greater than a preset time difference, the first random number sequence is deleted.
[0099] For example, if the preset time difference is 1 hour, and the sequence is generated at 1:00, and the current time is 2:30, the time difference is 1.5 hours. If this exceeds the preset value, the sequence will be deleted to ensure that the random number sequence used in communication is always valid and secure.
[0100] In some embodiments, considering group communication scenarios, a group may include multiple terminal devices. When the network is small and the security requirements for information output between terminals are high, a mesh networking mode can be adopted, in which terminals are interconnected in pairs. Figure 10 This is a schematic diagram of a group-based quantum key communication system provided as an embodiment of this disclosure. (In conjunction with...) Figure 10 As shown, taking the group-based quantum key communication system as an example, which includes three terminals, namely terminal A, terminal B and terminal C, terminal A, terminal B and terminal C are connected to the QKD nodes QKD-A, QKD-B and QKD-C of the quantum key distribution network, respectively, and terminal A, terminal B and terminal C are equipped with a cryptographic machine and a quantum random number generator.
[0101] When any two terminals in a group need to conduct highly secure point-to-point communication, such as highly secure communication between terminal A and terminal B in the group, when terminal A and terminal B are not busy, terminal A or terminal B can act as the first device to encrypt the random number sequence generated by QRNG with the QKD key to build a quantum key pool. In subsequent actual business, the method described above is used to select to call the QKD key or the key in the key pool for one-key communication according to the data transmission rate.
[0102] In some embodiments, to avoid maintaining too many local quantum key pools within the terminals of a group, which could affect terminal performance, a one-time one-pad communication can be performed by constructing local quantum key pools and calling keys in parallel. That is, if the first device and the second device are connected in a mesh networking mode, in response to the first device transmitting service data, the first device starts a quantum random number generator to generate a first random number sequence and stores the first random number sequence in the first device's first local quantum key pool. In this embodiment, at the start of the service, a small number of QRNG random number sequences are directly transmitted between terminals using the QKD key as the key for one-time one-pad communication between terminals, i.e., key synchronization is performed with few attempts and large quantities. It can be understood that a small number of QRNG random number sequences refer to the initial small number of random numbers transmitted between the first and second devices for key synchronization. And performing key synchronization with few attempts and large quantities refers to subsequently using quantum key distribution (QKD) keys to perform multiple key synchronization operations on large amounts of data between terminals.
[0103] At the start of the service, a small number of QRNG random number sequences were directly transmitted between terminals using QKD keys as the key for one-pad communication to quickly establish the initial key. Subsequently, with the help of the established connection and QKD keys, key synchronization of large amounts of data was performed frequently to continuously update and expand the local quantum key pool, meeting the need for a large number of keys for one-pad communication, while avoiding the impact of maintaining too many local quantum key pools within the terminal on performance.
[0104] In this embodiment, the business data will be packaged and transmitted to other terminals in parallel through several one-time encryption and decryption operations. Since one-time encryption and decryption differs from algorithm-based encryption and decryption, its mechanism of only requiring one XOR operation makes the encryption and decryption speed very fast and consumes very few resources. Therefore, multiple one-time encryption and decryption operations can be performed in parallel between terminals.
[0105] In some embodiments, considering group communication scenarios, the group may include multiple terminal devices. When the network is large, a centralized networking mode can be adopted, in which any terminal in the group (e.g., terminal A) is used as a key service management unit, responsible for distributing the first random number sequence to all communication terminals in the group. Figure 11 This is a schematic diagram of a group-based quantum key communication system provided as an embodiment of this disclosure. (In conjunction with...) Figure 11 As shown, taking the group-based quantum key communication system as an example, which includes four terminals, namely terminal A, terminal B, terminal C and terminal D, terminal A, terminal B, terminal C and terminal D are connected to the QKD nodes QKD-A, QKD-B, QKD-C and QKD-D of the quantum key distribution network, respectively, and terminal A, terminal B and terminal C are equipped with cryptographic machines, and at least terminal A is equipped with a quantum random number generator.
[0106] In some embodiments, if the first device and the second device are connected in a central networking mode, when there is no business data transmission between the first device and the second device, the first device starts a quantum random number generator to generate a first random number sequence and stores the first random number sequence in the first device's first local quantum key pool.
[0107] In some embodiments, during idle periods without business activity, terminal A, acting as the first device, distributes the first random number sequence generated by QRNG to other terminals in the group, acting as second devices, such as terminals B, C, and D, in an encrypted manner. At this time, all terminals in the group maintain the same quantum key pool K. all When conducting group services, use the quantum key pool K. all This involves a one-pad communication within the group. In this embodiment, each terminal in the group maintains the same quantum key pool K. all This ensures that all terminals within the group use the same key resources, facilitating unified management. Furthermore, when conducting group business, the quantum key pool is used for one-time pad communication, meeting the needs of large-scale data protection in group scenarios. This greatly enhances the security of group business communication and ensures the confidentiality and integrity of the communication content.
[0108] In some embodiments, considering the need for highly secure point-to-point communication between two terminals in the group, such as independent highly secure communication needs between terminals B and C, terminals B and C request an independent quantum key pool K from terminal A. BC During off-peak hours, terminal A encrypts and transmits the second random number sequence to terminals B and C, enabling terminals B and C to construct their own local quantum key pools K based on the second random number sequence. BC Terminals B and C, using the method described above, automatically select to call the QKD key or K key based on the data transmission rate. BC This embodiment not only meets the requirements for highly secure point-to-point communication, but also improves communication efficiency and security by utilizing off-peak hours for transmission and by selecting appropriate keys, while also reducing QKD resource consumption and communication costs.
[0109] It should be noted that the acquisition, storage, use, and processing of data in this disclosed technical solution comply with the relevant provisions of national laws and regulations. The various types of data, such as personal identity data, operational data, and behavioral data related to individuals, customers, and groups, obtained in the embodiments of this disclosure have all been authorized.
[0110] Based on the same inventive concept, this disclosure also provides a quantum key communication device, as described in the following embodiments. Since the principle by which this device solves the problem is similar to that of the method embodiments described above, the implementation of this device embodiment can refer to the implementation of the method embodiments described above, and repeated details will not be repeated.
[0111] Figure 12 A schematic diagram of a quantum key communication device according to an embodiment of this disclosure is shown, such as... Figure 12 As shown, the device includes: a generation module 121 and a transmission module 122; the generation module 121 is used for the first device to start a quantum random number generator to generate a first random number sequence and store the first random number sequence in the first device's first local quantum key pool; the transmission module 122 is used for the first device to encrypt the first random number sequence using a first quantum key to generate an encrypted random number data packet and send it to the second device, so that the second device decrypts the encrypted random number data packet based on the first quantum key to obtain the first random number sequence and stores the first random number sequence in the second device's second local quantum key pool, wherein the first quantum key is distributed to the first device and the second device through a quantum key distribution network.
[0112] In some embodiments, the first random number sequence is used to encrypt service data when the first device or the second device transmits service data as a sender, and to decrypt service data when the first device or the second device transmits service data as a receiver.
[0113] In some embodiments, the apparatus includes: an encryption module, configured to acquire the transmission rate of the service data; and when the transmission rate is greater than a preset transmission rate, to encrypt the service data using the first random number sequence.
[0114] In some embodiments, the encryption module is configured to obtain the identification information of the first random number sequence, the identification information being used to indicate the unique number of the first random number sequence and the starting position of the first random number sequence; and to encrypt the business data according to the unique number of the first random number sequence and the starting position of the first random number sequence to generate an encrypted business data packet.
[0115] In some embodiments, the apparatus includes: a decryption module, configured to acquire the encrypted service data packet; parse the encrypted service data packet to obtain a unique identifier of the first random number sequence and a starting position of the first random number sequence; and decrypt the encrypted service data in the encrypted service data packet according to the unique identifier of the first random number sequence and the starting position of the first random number sequence to obtain service data.
[0116] In some embodiments, the generation module is further configured to: obtain an identifier representing the validity of the first random number sequence; and delete the first random number sequence when the validity of the first random number sequence meets a preset condition.
[0117] In some embodiments, the generation module is further configured to: obtain a second timestamp representing the current time; determine a time difference based on the first timestamp and the second timestamp; and delete the first random number sequence when the time difference is greater than a preset time difference.
[0118] In some embodiments, the generation module is configured to: if the first device and the second device are connected in a mesh networking mode, in response to the first device transmitting service data, the first device starts a quantum random number generator to generate a first random number sequence and stores the first random number sequence in the first device's first local quantum key pool; if the first device and the second device are connected in a central networking mode, when there is no service data transmission between the first device and the second device, the first device starts a quantum random number generator to generate a first random number sequence and stores the first random number sequence in the first device's first local quantum key pool.
[0119] It should be noted that the examples and application scenarios implemented by the modules in the above device embodiments and the corresponding steps in the method embodiments are the same, but are not limited to the content disclosed in the above method embodiments. It should also be noted that the above modules, as part of the device, can be executed in a computer system such as a set of computer-executable instructions.
[0120] Those skilled in the art will understand that various aspects of this disclosure can be implemented in the following forms: a completely hardware implementation, a completely software implementation (including firmware, microcode, etc.), or a combination of hardware and software implementations, which can be collectively referred to herein as a "circuit", "module" or "system".
[0121] Based on the same inventive concept, this disclosure also provides an electronic device, which includes: a processor; and a memory for storing executable instructions of the processor; wherein the processor is configured to execute the quantum key communication method described above by executing the executable instructions. Since the principle by which this electronic device solves the problem is similar to that of the above method embodiments, the implementation of this electronic device embodiment can refer to the implementation of the above method embodiments, and repeated details will not be described again.
[0122] The following reference Figure 13 To describe an electronic device 1300 according to such an embodiment of the present disclosure. Figure 13The electronic device 1300 shown is merely an example and should not be construed as limiting the functionality and scope of use of the embodiments disclosed herein.
[0123] like Figure 13 As shown, the electronic device 1300 is manifested in the form of a general-purpose computing device. The components of the electronic device 1300 may include, but are not limited to: at least one processing unit 1310, at least one storage unit 1320, and a bus 1330 connecting different system components (including storage unit 1320 and processing unit 1310).
[0124] The storage unit stores program code that can be executed by the processing unit 1310, causing the processing unit 1310 to perform the steps described in the "Exemplary Methods" section of this specification according to various exemplary embodiments of this disclosure. For example, the processing unit 1310 can perform the following steps of the above method embodiment: a first device starts a quantum random number generator to generate a first random number sequence and stores the first random number sequence in a first local quantum key pool of the first device; the first device uses a first quantum key to encrypt the first random number sequence, generates an encrypted random number data packet, and sends it to a second device, so that the second device decrypts the encrypted random number data packet based on the first quantum key to obtain the first random number sequence, and stores the first random number sequence in a second local quantum key pool of the second device, wherein the first quantum key is distributed to the first device and the second device through a quantum key distribution network.
[0125] Storage unit 1320 may include readable media in the form of volatile storage units, such as random access memory (RAM) 13201 and / or cache memory 13202, and may further include read-only memory (ROM) 13203.
[0126] Storage unit 1320 may also include a program / utility 13204 having a set (at least one) of program modules 13205, such program modules 13205 including but not limited to: operating system, one or more application programs, other program modules and program data, each or some combination of these examples may include an implementation of a network environment.
[0127] Bus 1330 can represent one or more of several types of bus structures, including a memory cell bus or memory cell controller, a peripheral bus, a graphics acceleration port, a processing unit, or a local bus using any of the various bus structures.
[0128] Electronic device 1300 can also communicate with one or more external devices 1340 (e.g., keyboard, pointing device, Bluetooth device, etc.), and with one or more devices that enable a user to interact with electronic device 1300, and / or with any device that enables electronic device 1300 to communicate with one or more other computing devices (e.g., router, modem, etc.). This communication can be performed via input / output (I / O) interface 1350. Furthermore, electronic device 1300 can also communicate with one or more networks (e.g., local area network (LAN), wide area network (WAN), and / or public networks, such as the Internet) via network adapter 1360. As shown, network adapter 1360 communicates with other modules of electronic device 1300 via bus 1330. It should be understood that, although not shown in the figures, other hardware and / or software modules can be used in conjunction with electronic device 1300, including but not limited to: microcode, device drivers, redundant processing units, external disk drive arrays, RAID systems, tape drives, and data backup storage systems.
[0129] From the above description of the embodiments, those skilled in the art will readily understand that the exemplary embodiments described herein can be implemented by software or by combining software with necessary hardware. Therefore, the technical solutions according to the embodiments of this disclosure can be embodied in the form of a software product, which can be stored in a non-volatile storage medium (such as a CD-ROM, USB flash drive, external hard drive, etc.) or on a network, including several instructions to cause a computing device (such as a personal computer, server, terminal device, or network device, etc.) to execute the methods according to the embodiments of this disclosure.
[0130] Based on the same inventive concept, this disclosure also provides a computer-readable storage medium storing a computer program that, when executed by a processor, implements any of the above-described quantum key communication methods. Since the principle by which this computer-readable storage medium solves the problem is similar to that of the above-described method embodiments, the implementation of this computer-readable storage medium embodiment can refer to the implementation of the above-described method embodiments, and repeated details will not be elaborated further.
[0131] More specific examples of computer-readable storage media in this disclosure may include, but are not limited to: electrical connections having one or more wires, portable computer disks, hard disks, random access memory (RAM), read-only memory (ROM), erasable programmable read-only memory (EPROM or flash memory), optical fiber, portable compact disk read-only memory (CD-ROM), optical storage devices, magnetic storage devices, or any suitable combination of the foregoing.
[0132] In this disclosure, a computer-readable storage medium may include a data signal propagated in baseband or as part of a carrier wave, carrying readable program code. Such propagated data signals may take various forms, including but not limited to electromagnetic signals, optical signals, or any suitable combination thereof. A readable signal medium may also be any readable medium other than a readable storage medium, capable of transmitting, propagating, or transmitting a program for use by or in connection with an instruction execution system, apparatus, or device.
[0133] Optionally, the program code contained on the computer-readable storage medium may be transmitted using any suitable medium, including but not limited to wireless, wired, optical fiber, RF, etc., or any suitable combination thereof.
[0134] In practical implementation, program code for performing the operations of this disclosure can be written in any combination of one or more programming languages, including object-oriented programming languages such as Java and C++, and conventional procedural programming languages such as C or similar languages. The program code can execute entirely on the user's computing device, partially on the user's device, as a standalone software package, partially on the user's computing device and partially on a remote computing device, or entirely on a remote computing device or server. In cases involving remote computing devices, the remote computing device can be connected to the user's computing device via any type of network, including a local area network (LAN) or a wide area network (WAN), or it can be connected to an external computing device (e.g., via the Internet using an Internet service provider).
[0135] Based on the same inventive concept, this disclosure also provides a computer program product, comprising: a computer program or instructions, wherein the computer program or instructions, when executed by a processor, implement the quantum key communication method of any one of the above method embodiments. Since the principle by which this computer program product embodiment solves the problem is similar to that of the above method embodiments, the implementation of this computer program product embodiment can refer to the implementation of the above method embodiments, and repeated details will not be elaborated further.
[0136] It should be noted that although several modules or units for the device used to perform actions have been mentioned in the detailed description above, this division is not mandatory. In fact, according to embodiments of this disclosure, the features and functions of two or more modules or units described above can be embodied in one module or unit. Conversely, the features and functions of one module or unit described above can be further divided and embodied by multiple modules or units.
[0137] Furthermore, although the steps of the method in this disclosure are described in a specific order in the accompanying drawings, this does not require or imply that the steps must be performed in that specific order, or that all the steps shown must be performed to achieve the desired result. Additional or alternative steps may be omitted, multiple steps may be combined into one step, and / or a step may be broken down into multiple steps.
[0138] From the above description of the embodiments, those skilled in the art will readily understand that the exemplary embodiments described herein can be implemented by software or by combining software with necessary hardware. Therefore, the technical solutions according to the embodiments of this disclosure can be embodied in the form of a software product, which can be stored in a non-volatile storage medium (such as a CD-ROM, USB flash drive, external hard drive, etc.) or on a network, including several instructions to cause a computing device (such as a personal computer, server, mobile terminal, or network device, etc.) to execute the methods according to the embodiments of this disclosure.
[0139] Other embodiments of this disclosure will readily occur to those skilled in the art upon consideration of the specification and practice of the invention disclosed herein. This disclosure is intended to cover any variations, uses, or adaptations of this disclosure that follow the general principles of this disclosure and include common knowledge or customary techniques in the art not disclosed herein. The specification and examples are to be considered exemplary only, and the true scope and spirit of this disclosure are indicated by the appended claims.
Claims
1. A quantum key distribution method, characterized in that, The method includes: The first device activates a quantum random number generator to generate a first random number sequence and stores the first random number sequence in the first device's first local quantum key pool; wherein, the first random number sequence is used to encrypt service data when the first device or the second device transmits service data as a sender; and to decrypt service data when the first device or the second device transmits service data as a receiver. The first device uses a first quantum key to encrypt the first random number sequence, generates an encrypted random number data packet, and sends it to the second device, so that the second device decrypts the encrypted random number data packet based on the first quantum key to obtain the first random number sequence, and stores the first random number sequence in the second device's second local quantum key pool, wherein the first quantum key is distributed to the first device and the second device through a quantum key distribution network; The encryption of business data includes: Obtain the transmission rate of the service data; When the transmission rate is greater than the preset transmission rate, the service data is encrypted using the first random number sequence; When the transmission rate is less than or equal to the preset transmission rate, the quantum key distribution network device is used to generate a quantum key to encrypt the business data; If the first device and the second device are connected in a mesh networking mode, in response to the first device transmitting service data, the first device starts a quantum random number generator to generate a first random number sequence and stores the first random number sequence in the first device's first local quantum key pool; If the first device and the second device are connected in a central networking mode, when there is no business data transmission between the first device and the second device, the first device starts a quantum random number generator to generate a first random number sequence and stores the first random number sequence in the first device's first local quantum key pool.
2. The quantum key communication method according to claim 1, characterized in that, The step of encrypting business data using the first random number sequence includes: Obtain the identification information of the first random number sequence, wherein the identification information is used to indicate the unique number of the first random number sequence and the starting position of the first random number sequence; The business data is encrypted based on the unique identifier of the first random number sequence and the starting position of the first random number sequence to generate an encrypted business data packet.
3. The quantum key communication method according to claim 2, characterized in that, The decryption of business data includes: Obtain the encrypted service data packet; The encrypted service data packet is parsed to obtain the unique identifier of the first random number sequence and the starting position of the first random number sequence; The encrypted service data in the encrypted service data packet is decrypted based on the unique number of the first random number sequence and the starting position of the first random number sequence to obtain the service data.
4. The quantum key communication method according to claim 1, characterized in that, The method further includes: Obtain the validity identifier used to indicate the first random number sequence; When the validity identifier of the first random number sequence meets the preset conditions, the first random number sequence is deleted.
5. The quantum key communication method according to claim 4, characterized in that, The identifier used to indicate the validity of the first random number sequence is the first timestamp when the first random number sequence was generated; the step of deleting the first random number sequence when the validity identifier of the first random number sequence meets the preset conditions includes: Get the second timestamp used to represent the current time; The time difference is determined based on the first timestamp and the second timestamp; When the time difference is greater than a preset time difference, the first random number sequence is deleted.
6. A quantum key communication device, characterized in that, The device includes: A generation module is used for the first device to start a quantum random number generator to generate a first random number sequence and store the first random number sequence in the first device's first local quantum key pool; wherein, the first random number sequence is used to encrypt service data when the first device or the second device transmits service data as a sender; and to decrypt service data when the first device or the second device transmits service data as a receiver. The sending module is configured to have the first device encrypt the first random number sequence using a first quantum key to generate an encrypted random number data packet, and send it to the second device, so that the second device decrypts the encrypted random number data packet based on the first quantum key to obtain the first random number sequence, and stores the first random number sequence in the second device's second local quantum key pool, wherein the first quantum key is distributed to the first device and the second device through a quantum key distribution network; An encryption module is used to obtain the transmission rate of the service data; when the transmission rate is greater than a preset transmission rate, the service data is encrypted using the first random number sequence; when the transmission rate is less than or equal to the preset transmission rate, a quantum key is generated using a quantum key distribution network device to encrypt the service data. Generate modules for: If the first device and the second device are connected in a mesh networking mode, in response to the first device transmitting service data, the first device starts a quantum random number generator to generate a first random number sequence and stores the first random number sequence in the first device's first local quantum key pool; if the first device and the second device are connected in a central networking mode, when there is no service data transmission between the first device and the second device, the first device starts a quantum random number generator to generate a first random number sequence and stores the first random number sequence in the first device's first local quantum key pool.
7. An electronic device, characterized in that, include: processor; as well as Memory for storing the executable instructions of the processor; The processor is configured to execute the quantum key communication method according to any one of claims 1 to 5 by executing the executable instructions.
8. A computer-readable storage medium having a computer program stored thereon, characterized in that, When the computer program is executed by the processor, it implements the quantum key communication method according to any one of claims 1 to 5.
9. A computer program product, comprising: A computer program or instruction, characterized in that, when executed by a processor, the computer program or instruction implements the quantum key communication method according to any one of claims 1 to 5.
Citation Information
Patent Citations
High-speed quantum key distribution system and method
CN113810187A